Cyber GRC Specialist
Listed on 2026-08-22
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Company Overview
Every firm has a culture – the values, beliefs, methodology, attitudes and standards that reflect an organization’s DNA. But the truly inspiring firms – the game‑changers, the industry leaders and the disruptors – have cultures that propel them to innovate and stand out. At Brown Advisory, we aim to be one of those inspired firms. Over the years, we have purposefully built and nurtured our client‑first culture.
CompanyOverview
Every firm has a culture – the values, beliefs, methodology, attitudes and standards that reflect an organization’s DNA. But the truly inspiring firms – the game‑changers, the industry leaders and the disruptors – have cultures that propel them to innovate and stand out. At Brown Advisory, we aim to be one of those inspired firms. Over the years, we have purposefully built and nurtured our client‑first culture.
Brown Advisory is an independent investment management and strategic advisory firm committed to delivering a combination of first‑class performance, strategic advice and the highest level of client service. The firm’s clients—including individuals, families, family offices, endowments, foundations, charities, institutions, consultants, and financial intermediaries—are served by over 1,000 colleagues worldwide, all of whom are equity owners of the firm.
Brown Advisory is currently seeking a Cyber GRC Specialist to support and mature the firm's governance, risk, compliance, and control‑management routines. This blended role is designed for someone who can translate security requirements into practical business processes, drive evidence and accountability, and communicate clearly with technical and non‑technical stakeholders.
As part of a lean Information Security team within a mid‑sized financial services organization, this individual will serve as a central coordinator for cyber risk, policy management, control testing, audit readiness, client and regulatory response support, and vulnerability remediation governance. The role is not intended to be a hands‑on vulnerability engineering role; rather, it ensures the process, ownership, exceptions, reporting, and governance routines are working.
BlendedRole Coverage
Primary emphasis:
Cyber GRC support for policies, controls, cyber risk tracking, audit coordination, exceptions, and governance routines.
Blended coverage:
Cyber Risk / Compliance Analyst work, ISO and risk‑platform support, evidence coordination, client/regulatory response support, communications, and vulnerability governance.
- Support and mature core cyber governance routines, including policy management, control ownership, risk acceptance, exception handling, standards maintenance, and periodic leadership reporting.
- Maintain the cyber risk register and partner with technology and business owners to document risk decisions, remediation plans, due dates, dependencies, and residual risk.
- Serve as a key administrator and process contributor for ISO and security‑risk management platforms such as Vanta or similar tools.
- Coordinate evidence collection, control testing, audit requests, client due diligence responses, regulatory requests, and recurring compliance deliverables.
- Translate ISO 27001, regulatory, client, and internal security expectations into practical controls and operating procedures appropriate for Brown Advisory's size and risk profile.
- Facilitate cross‑functional communications for security change, SaaS inventory, policy enforcement, control adoption, and risk remediation.
- Coordinate vulnerability management governance, including scan‑result intake, prioritization routines, remediation tracking, exception handling, and reporting.
- Partner with security engineers, infrastructure teams, application owners, Compliance, Legal, Operations, and Client Service to close control gaps in a business‑aligned manner.
- Develop clear metrics for control effectiveness, audit readiness, exceptions, overdue remediation, and recurring governance activities.
- Identify process improvements that make security governance more repeatable, transparent, and useful without creating unnecessary bureaucracy.
- Bachelor's…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).