Information Security Risk Advisory professional assessing and managing technology risks at Grainger. Collaborating with teams on risk assessments and technology initiatives in a hybrid work environment.
Responsibilities
Perform information security risk assessments, control testing, and security reviews across systems, applications, and processes
Support compliance efforts by assessing alignment with internal policies, regulatory requirements, and industry frameworks such as NIST CSF, PCI DSS 4.0, and related standards, and by assisting in the identification and tracking of remediation activities
Contribute to third-party risk management activities, including reviewing vendor security documentation, conducting risk assessments, and supporting risk rating, issue tracking, and risk acceptance processes
Support technology initiatives—such as new system implementations, cloud services, and process changes—by identifying potential risks and control gaps and advising on mitigation strategies
Work independently on assigned assessments while escalating complex risks as needed, contributing to continuous improvement of the organization’s information security risk management program
Requirements
Bachelor’s degree in Information Security, Information Systems, Computer Science, Risk Management, or a related field, or equivalent practical experience
2-4 years of experience in information security, technology risk, cybersecurity, GRC, internal audit, or risk advisory roles
Working knowledge of information security and risk frameworks such as NIST CSF, NIST 800-53, or similar standards
Experience conducting risk assessments, control reviews, and gap analyses across applications, infrastructure, cloud environments, or business processes
Familiarity with third-party and vendor risk management, including review of security questionnaires, SOC reports, and other assurance artifacts
Ability to document findings clearly and communicate technical risks in business-focused language
Experience supporting audits, regulatory examinations, or compliance initiatives in collaboration with internal audit, legal, and compliance teams
Strong analytical, organizational, and time-management skills with the ability to manage multiple assessments concurrently
Benefits
Medical, dental, vision, and life insurance plans with coverage starting on day one of employment
6 free sessions each year with a licensed therapist to support your emotional wellbeing
18 paid time off (PTO) days annually for full-time employees (accrual prorated based on employment start date) and 6 company holidays per year
6% company contribution to a 401(k) Retirement Savings Plan each pay period, no employee contribution required
Employee discounts, tuition reimbursement, student loan refinancing and free access to financial counseling, education, and tools
Maternity support programs, nursing benefits, and up to 14 weeks paid leave for birth parents and up to 4 weeks paid leave for non-birth parents
Security Analyst II role at Deepwatch focusing on incident handling and cybersecurity analysis. Working with a team to improve security posture and customer experience in a hybrid environment.
Information Security Analyst II at West Bend handling security projects and collaboration with IT teams. Supporting security incidents and enhancing organizational information security policies.
Product Security Analyst establishing risk management across CHG Healthcare's multi - brand portfolio. Leading data classification initiatives and reporting on security risks.
Cybersecurity Analyst at Northrop Grumman leading systems accreditation and mentoring junior analysts. Involves development and implementation of Risk Management Framework and information assurance activities.
Sr. Cybersecurity Analyst supporting the full lifecycle of security assessments at Dexcom. Coordinating with internal stakeholders and ensuring comprehensive coverage across assessments.
Information Security Analyst responsible for conducting internal audits and compliance in information technology. Working with audit teams and enhancing compliance frameworks at Ness Digital Engineering.
Intern supporting IT Security team at OneDigital with hands - on experience and mentoring. Engaging in real - world assignments and responsibilities within IT Security.
Cyber Threat Intelligence Analyst at AIG specializing in cyber threat research and intelligence production. Collaborating with an interdisciplinary team to enhance cybersecurity situational awareness and reporting.
Senior Cyber Security Analyst protecting customers from cyber threats while enhancing cyber security services at technology firm. Focused on both security operations and technical delivery.
Cybersecurity Analyst assisting in the review and implementation of cybersecurity initiatives across a large environment at Kemper. Responding to cyber threats and improving processes and technologies.