×
Register Here to Apply for Jobs or Post Jobs. X

Lead Cybersecurity GRC, DB​/BC Analyst

Job in Salem, Rockingham County, New Hampshire, 03079, USA
Listing for: University System of New Hampshire
Full Time position
Listed on 2026-09-26
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 90000 - 120000 USD Yearly USD 90000.00 120000.00 YEAR
Job Description & How to Apply Below

Team lead for the Cybersecurity Governance, Risk, and Compliance (GRC) functions for the University System of New Hampshire. Coordinate the use of risk management frameworks such as NIST CSF to assess the security posture of USNH services and operations and support compliance with regulatory standards like CMMC, FERPA, GLBA, HIPAA, and PCI DSS. Prepare quantitative measures of risk and compliance to support the CISO and CIO.

Oversee cybersecurity policy and standards drafting and review processes to maintain currency and cohesiveness across the various security domains, preparing updates to policies and standards for review and approval by IT governance groups. Perform specific risk assessments of third-party products and services for the university system. Support cybersecurity awareness and education for the USNH student, faculty, and staff community members.

Job Duties /Responsibilities:

Cybersecurity Policies & Standards 30%

Assist with the development and publication of cybersecurity policies and standards aligned with the NIST Cybersecurity Framework and leveraging the NIST 800-53 and 800-171 control sets. Coordination of ongoing review sessions with key stakeholders and overall program monitoring to ensure all Policies & Standards are maintained appropriately. Draft new and updated policies and standards to maintain currency and applicability to evolving threats, compliance requirements, and business needs.

Maintain and oversee an annual cycle and schedule for review of all existing policy and standards.

Coordinate cybersecurity policy & standard exception process. Communicate with stakeholders during the process of exception request and review as well as expiration and/or renewal. Maintain all records of exceptions, their associated risks, risk mitigations, and approved durations.

Compliance & Risk Management 30%

Oversee third-party vendor security assessment & review (SAR) programs and processes. Assist in design, development, and updates of SAR processes. Maintain all records of vendor security reviews and communicate to stakeholders on required updates and renewals.

Coordinate contracted risk assessments from outside contractors including scheduling, communication, and recordkeeping involving administrative, academic, and business units and related IT departments and teams.

Participate in performing internal risk assessments and risk analysis of USNH systems and services. Assist in management of the risk register including providing periodic reporting of metrics on the scope and potential impact of risks to the organization.

Assist with the development of information handling standards and procedures for all regulated information in use across USNH. Build relationships with regulated data subject matter experts at each institution. Assist with other tasks related to safeguarding regulated data across USNH as needed.

Assist with development and implementation of disaster recovery and business continuity plans. Assist with setup, coordination, and execution of periodic tests of the plans and processes.

Awareness & Training 15%

Work with other IT teams as well as administrative, academic, and other business units to develop and deliver cybersecurity training programs, both generic and role-specific, computer-based and in-person.

Administer phishing awareness and similar activities including designing and proposing phishing simulations, deploying, and measuring simulated phishing attacks, and tracking and reporting on program metrics.

Incident Response 15%

Oversee the processes used for record keeping roles during cybersecurity incident response. Contributed to the overall incident response plan, especially related to incident tracking, reporting, and after-action reviews. Assist in the…

To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary