Senior Analyst, Cyber Governance, Risk and Compliance (GRC)

Posted Yesterday
Be an Early Applicant
Coral Gables, FL, USA
In-Office
Senior level
Fintech • Financial Services
The Role
Supports cybersecurity governance, risk management, and compliance initiatives, including control and policy development, framework alignment, audits, third-party risk assessments, risk tracking, remediation coordination, reporting, access reviews, and security awareness activities. Collaborates with technology, risk, and business stakeholders to strengthen the organization’s security posture and ensure timely completion of governance deliverables.
Summary Generated by Built In

Firm Overview:


H.I.G. Capital is a leading global private equity investment firm with $75 billion of assets under management with a focus on the mid cap segment of the market. The H.I.G. family of funds includes private equity, growth equity, real estate, direct lending, special situation credit, and growth-stage healthcare. We focus on providing capital to businesses with attractive growth potential and align ourselves with committed management teams and entrepreneurs to help grow businesses of significant value. Our team of over 500 investment professionals has substantial operating, consulting, technology, and financial management experience, enabling us to contribute meaningfully to our portfolio companies. H.I.G. is based in Miami, with offices in Atlanta, Boston, Chicago, Los Angeles, New York, and San Francisco, and affiliate offices in Hamburg, London, Luxembourg, Madrid, Milan, and Paris in Europe as well as Bogotá, Rio de Janeiro, and São Paulo in Latin America, Dubai in the Middle East, and Hong Kong in Asia.


Role Overview:

The Senior Cyber Governance, Risk, and Compliance (GRC) Analyst is a key member of the Cyber GRC team and the broader Information Security organization. This full-time role is responsible for supporting and advancing the organization’s cybersecurity governance, risk management, and compliance initiatives. The Senior Analyst works closely with cross-functional teams to help ensure that cybersecurity risks are identified, assessed, and managed in alignment with business objectives, regulatory requirements, and industry best practices.

This role is designed for experienced professionals who are passionate about cybersecurity risk management and committed to strengthening enterprise security programs. The Senior Cyber GRC Analyst contributes to the development, implementation, and continuous improvement of governance processes, compliance activities, and cyber risk management practices that support an effective and resilient Information Security program.

A critical expectation of this role is a strong sense of ownership, dedication, commitment, and accountability. The Senior Analyst is expected to take responsibility for assigned workstreams and deliverables from initiation through completion, proactively manage deadlines and dependencies, maintain clear and timely communication with stakeholders, and appropriately escalate risks, blockers, or delays. The successful candidate will demonstrate consistent follow-through and accountability for the quality, timeliness, and completion of their work.

In this position, the Senior Analyst will collaborate with stakeholders across technology, risk, and business teams to support security assessments, policy and control development, regulatory and framework alignment, and risk remediation efforts. This role provides the opportunity to influence and enhance the organization’s security posture while working alongside experienced cybersecurity leaders and practitioners.

Through these responsibilities, the Senior Cyber GRC Analyst plays an important role in helping the organization maintain a strong cybersecurity governance structure and ensuring that the Information Security program effectively addresses evolving threats, regulatory expectations, and business priorities.

Role Responsibilities:

Governance and Compliance

  • Support the firm’s Cyber Governance, Risk, and Compliance (GRC) program by evaluating and enhancing security controls, policies, standards, procedures, and guidelines in alignment with the organization’s reference security framework.

  • Support the alignment of the firm’s Information Security Program with recognized security frameworks and regulatory expectations (e.g., NIST CSF, ISO 27001, CIS Controls, and applicable financial regulatory requirements) by mapping controls, identifying gaps, and recommending improvements.

  • Contribute to the ongoing development and maintenance of cybersecurity policies, standards, and governance documentation, ensuring they remain aligned with evolving threats, regulatory requirements, and industry best practices.

  • Provide support for internal and external audits by coordinating documentation requests, collecting control evidence, and ensuring timely delivery of required artifacts.

  • Participate in the execution of recurring GRC program activities, including quarterly access reviews, control validation activities, and other governance processes that support compliance and risk oversight.

Risk Management and Security Program Operations

  • Conduct and support the firm’s Third-Party Risk Management (TPRM) activities by performing vendor risk assessments, evaluating security documentation, and producing risk evaluations for both new and existing third-party vendors.

  • Identify, assess, and track cybersecurity risks affecting the firm and its third parties through the organization’s cyber risk monitoring platform, and collaborate with stakeholders to support risk mitigation and remediation efforts.

  • Collaborate with technology, risk, and business teams to support security risk assessments for new initiatives, systems, and third-party integrations, ensuring cybersecurity risks are identified and addressed during project planning and implementation.

  • Assist in the preparation of cyber risk reporting and metrics for security leadership and internal stakeholders, providing visibility into the organization’s cybersecurity risk posture and control effectiveness.

  • Proactively monitor assigned deadlines and commitments, identify potential delays, risks, or blockers, and ensure timely communication and appropriate escalation to Cyber GRC leadership and relevant stakeholders.

  • Coordinate with business and technology stakeholders to follow up on GRC-related action items, ensuring that risk remediation tasks and control activities are completed within defined timelines.

  • Support and enhance the firm’s Cybersecurity Awareness Program, including monitoring training completion, engaging with users on outstanding requirements, and identifying opportunities for additional targeted training where needed.

Requirements & Qualifications:

  • Bachelor’s degree in Information Security, Cybersecurity, Computer Science, Management Information Systems, Engineering, or a related technical discipline from an accredited university, or a high school diploma and equivalent professional experience.

  • Demonstrated knowledge of information security principles and logical security domains, including governance, risk management, compliance, and security control frameworks.

  • Familiarity with cybersecurity frameworks and standards such as NIST, ISO 27001, CIS Controls, or similar industry-recognized security frameworks.

  • Experience or exposure to areas such as security governance, regulatory compliance, risk assessments, third-party risk management, or security program operations.

  • Strong analytical and problem-solving abilities, with the capacity to evaluate complex situations and apply sound judgment when assessing cybersecurity risks.

  • Excellent written and verbal communication skills, with the ability to clearly document security assessments, policies, and risk findings for both technical and non-technical audiences.

  • Demonstrated ability to organize, prioritize, and manage multiple tasks and deadlines in a dynamic environment.

  • Strong interpersonal skills with the ability to collaborate effectively with technology teams, business stakeholders, and risk management functions.

  • High level of professional initiative, accountability, and self-motivation, with the ability to work independently while contributing to a collaborative team environment.

  • Strong attention to detail and commitment to maintaining high standards of accuracy, documentation quality, and program integrity.

Skills Required

  • Bachelor’s degree in Information Security, Cybersecurity, Computer Science, Management Information Systems, Engineering, or a related technical discipline; alternatively, a high school diploma with equivalent professional experience.
  • Knowledge of information security principles and logical security domains, including governance, risk management, compliance, and security control frameworks.
  • Familiarity with cybersecurity frameworks and standards such as NIST, ISO 27001, CIS Controls, or similar recognized frameworks.
  • Experience or exposure to security governance, regulatory compliance, risk assessments, third-party risk management, or security program operations.
  • Strong analytical and problem-solving abilities for evaluating complex situations and cybersecurity risks.
  • Excellent written and verbal communication skills for documenting assessments, policies, and risk findings for technical and non-technical audiences.
  • Ability to organize, prioritize, and manage multiple tasks and deadlines in a dynamic environment.
  • Strong interpersonal and collaboration skills with technology teams, business stakeholders, and risk management functions.
  • Professional initiative, accountability, self-motivation, and ability to work independently and collaboratively.
  • Strong attention to detail and commitment to accuracy, documentation quality, and program integrity.
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Miami, Florida
1,270 Employees
Year Founded: 1993

What We Do

H.I.G. Capital is a leading global private investment firm with $62 billion of equity capital currently under management.* H.I.G.'s family of funds includes private equity, real estate, growth equity and debt/credit. H.I.G. Capital has invested in and controlled over 400 organizations globally since it was founded more than 20 years ago. The firm currently manages a portfolio of companies with combined sales in excess of $53 billion. H.I.G. is based in Miami, with offices in New York, Boston, Chicago, Dallas, Los Angeles, San Francisco and Atlanta, and affiliate offices in London, Hamburg, Luxembourg, Madrid, Milan and Paris in Europe as well as Bogotá, Rio de Janeiro and São Paulo in Latin America and Dubai in the Middle East. H.I.G. focuses on providing capital to small and mid-sized businesses with attractive growth potential. The firm invests in management-led buyouts and recapitalizations of well-managed and profitable manufacturing and service businesses. H.I.G. Capital also has extensive experience with operational turnarounds and financial restructurings. The firm has a proven strategy built around; (1) a flexible investment approach which emphasizes speed as well as responsiveness; (2) a large team with unique skills and capabilities, as well as a "can-do"​ approach; (3) a long-standing focus on small and medium sized businesses typically from $50-500 million in value, as well as an understanding of the challenges and opportunities these business present. * Based on total capital raised by H.I.G. Capital and its affiliates.

Similar Jobs

Shield AI Logo Shield AI

Staff Travel and Expense Specialist

Aerospace • Artificial Intelligence • Machine Learning • Robotics • Software
In-Office or Remote
2 Locations

BAE Systems, Inc. Logo BAE Systems, Inc.

Information Technology Project Manager

Aerospace • Hardware • Information Technology • Security • Software • Cybersecurity • Defense
Remote or Hybrid
Delray Beach, FL, USA
40000 Employees
121K-205K Annually

Cloudflare Logo Cloudflare

Account Executive

Cloud • Information Technology • Security • Software • Cybersecurity
Remote or Hybrid
United States
4400 Employees

Snap! Mobile Logo Snap! Mobile

Account Executive

Edtech • Fintech • Sports
Easy Apply
In-Office
Clearwater, FL, USA
350 Employees
75-95 Annually

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account