Governance, Risk and Compliance Analyst III

United StatesUnited States·Madisonmid
Finance & AccountingCompliance Analyst
0 views0 saves0 applied

Quick Summary

Overview

Overview The Information Security Governance Risk and Compliance (GRC) Analyst is responsible for ensuring the confidentiality, integrity,

Technical Tools
Finance & AccountingCompliance Analyst

The Information Security Governance Risk and Compliance (GRC) Analyst is responsible for ensuring the confidentiality, integrity, and availability of University of Wisconsin Credit Union (UWCU) information by working with a team of GRC analysts who continually assess UWCU's information security posture. This role regularly reviews information security policies, standards, and procedures to ensure UWCU is aligned with industry best practices including applicable laws and regulations. Additionally, this role conducts third-party risk evaluations and assessments to minimize cybersecurity risk exposure and impacts on the business. The individual in this role supports legal, audit, accounting and loss prevention departments in assessing compliance and works to develop, implement, and maintain a comprehensive information security compliance program that encompasses all aspects of the organization’s information management life cycle. By safeguarding UWCU’s information, you will have the opportunity to make a positive impact on our organization and our members.

Responsibilities

~1 min read
  • Recommend procedures to ensure compliance with relevant laws, regulations, and industry standards.
  • Ensure technical controls are effective by coordinating reviews with technical engineers and analysts.
  • Continually research and stay up to date on emerging compliance issues.
  • Coordinate with stakeholders to ensure policies and standards are communicated effectively, supporting training and awareness initiatives.
  • Support audits to assess the effectiveness of security controls and identify compliance gaps, in accordance with legal and regulatory requirements.
  • Work with regulatory examiners and auditors as necessary.
  • Maintain documentation for internal audits, external audits, and independent third-party assessments.
  • Train and educate employees on cybersecurity compliance requirements.

 

  • Ensure ethics, transparency and accountability in the practice of information security governance.
  • Support the policy and standard lifecycle, including creation, review, revision, approval, communication, and retirement.
  • Develop and implement robust information security policies and standards that align with industry best practices, security frameworks, and regulatory requirements.
  • Conduct policy and standard reviews, ensuring to address emerging threats or changes in the regulatory landscape.
  • Coordinate review of policies and procedures with technology engineers ensuring practicality for implementation.
  • Identify and resolve conflicting policies.
  • Facilitate Information Security Steering Committee (ISSC) meetings, providing insight into the implementation and effectiveness of information security governance.
  • Integrate security measures into business processes to ensure that security is considered in all organizational activities.
  • Collaborate with cross-functional teams to address security issues and implement corrective measures.

 

  • Support the Information Security Risk Management Program, planning and coordinating the execution of risk assessments, monitoring emerging risks, and maintaining the risk register.
  • Conduct and coordinate regular risk assessments to identify vulnerabilities and potential threats.
  • Implement risk mitigation strategies and controls to manage identified risks effectively.
  • Support the identification and ranking of third-party cybersecurity risks and impacts.
  • Implement communication and escalation plans for third-party cybersecurity risk management activities within the enterprise.
  • Evaluate third-party cybersecurity risks as defined in contracts and in accordance with existing risk management programs and policies.
  • Develop, monitor, and execute third-party remediation actions, mitigation, and contingency plans when cybersecurity risks or events are identified.
  • Evaluate external party compliance with regulatory requirements.
  • Support the security onboarding process for new vendors.
  • Gather third-party cybersecurity risk assessment data and prepare assessments for critical third parties, to be published and communicated to stakeholders.
  • Track identified cybersecurity risks and events.
  • Support communication plans to report identified cybersecurity risk requirements and violations to internal stakeholders, end users, and responsible third parties, supporting the response and resolution of these issues.
  • Guide third parties and business partnears to ensure compliance with cybersecurity risk management policies.
  • Support a monitoring system for third-party cybersecurity risk management.
  • Review Enterprise Risk Management products, to ensure enterprise risks are evaluated for information security impacts.

 

  • Foster a culture of security awareness within the organization.
  • Support the implementation of the Security and Awareness Training Program, including New Employee Orientation, New Leader Onboarding, and additional programs as needed to implement information security best practices and policies.
  • Evaluate the success of the program, recommending necessary changes to address deficiencies.
  • Assess the effectiveness of policies, standards, and procedures during exercises and testing.

 

Requirements

~1 min read
  • Bachelor’s Degree Computer science or similar technology related field, or equivalent relevant work experience required (Master’s Degree preferred).
  • 6-7 years of experience in one or more of the following roles required:  NCUA or Financial Auditing Chief Compliance Officer, Cybersecurity GRC Manager, Cybersecurity Compliance and Risk Manager, GRC Manager, Data Protection Officer, IT Security Officer, Information Security Auditor, GRC Analyst, Information Security Analyst, or Cybersecurity Analyst.
  • CISSP, CRISC, CISA, CGEITR or equivalent. Technical certifications such as GSEC Sec+, or equivalent preferred.

 

  • Deep understanding of security controls and alignment to key regulations.
  • Strong knowledge of IT hardware, software, environmental controls, networks, resiliency, virtualization and cloud computing.
  • Experience with risk assessment and security audits.
  • Solid understanding of security frameworks such as CIS Critical Controls, NIST, and COBIT. Effective communication within the team and across the department.
  • Excellent verbal and written communication skills, with the ability to adjust messages to the correct technical level of the target audience.
  • Understanding of organizational mission, values, and goals, and consistent application of this knowledge.
  • Strong problem-solving and troubleshooting skills.
  • Talent and passion for technology; creativity and resourcefulness in solving problems.

What We Offer

~1 min read

 

Join one of Wisconsin’s premier financial institutions, a National Top Workplace and multi-year recipient of Madison Magazine’s Best Places to Work, Wisconsin State Journal’s Top Workplaces, and Milwaukee Journal Sentinel’s Top Workplaces to receive:

 

✓21.5 days of annual time off (accrued per pay period)
✓2 weeks paid caregiver leave
✓2.5 weeks paid new child parental leave
✓2 days paid volunteer time
✓10 paid holidays (including your birthday!)
✓401k company match of up to 5%, plus approximately 4% discretionary match
✓Variable bonus reward
✓Competitive Medical, Dental, and Vision plans, including domestic partner eligibility
✓Employee Assistance Program
✓And more!

Location & Eligibility

Where is the job
Madison, United States
On-site at the office
Who can apply
US

Listing Details

Posted
October 8, 2026
First seen
October 9, 2026
Last seen
October 9, 2026

Posting Health

Days active
-1
Repost count
0
Trust Level
56%
Scored at
October 9, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

Governance, Risk and Compliance Analyst III