Senior Cybersecurity GRC Analyst

King of Prussia, PA


Apply Save

Type: Permanent

Category: Regulatory/Compliance

Industry: Energy

Standard Hours: Open

Reference ID: JN -072026-107785

Date Posted: 10/05/2026

Shortcut: http://careers.eliassen.com/lRT3LP


Description:

On-site in either King of Prussia, PA or Denver, PA

 

Our client is seeking a Senior Cybersecurity Governance, Risk & Compliance (GRC) Analyst to support cybersecurity governance, regulatory compliance, and risk management initiatives within a critical infrastructure environment. This role is responsible for helping ensure compliance with cybersecurity regulatory requirements, monitoring risk remediation activities, supporting governance programs, and collaborating across business and technology teams to strengthen cybersecurity maturity. The ideal candidate will have a background in GRC, cybersecurity compliance, and risk management, with hands-on experience supporting Operational Technology (OT), SCADA, Industrial Control Systems (ICS), and critical infrastructure environments. This individual will partner with Information Technology, Legal, Enterprise Risk Management, Human Resources, and business stakeholders to drive compliance, governance, and cybersecurity risk reduction initiatives. Candidates must be able to work on-site four days a week in the Denver/Lancaster, PA area and must demonstrate real-world experience supporting, assessing, governing, or auditing OT/SCADA/ICS environments.

 

This is a full-time, permanent opportunity, offering a competitive salary and comprehensive benefits package. Qualified applicants must be willing and able to work on a w2 basis.

 

Salary: $80,000 - $105,000/ yr. w2


Responsibilities:
  • Track compliance to cybersecurity regulatory requirements such as TSA and PUC.
  • Assist with maintaining processes and procedure documentation that supports regulatory compliance.
  • Support the review of policies and standards in collaboration with stakeholders.
  • Collaborate to establish and track metrics for cybersecurity regulatory governance programs.
  • Support development and maintenance of cybersecurity governance frameworks for OT and SCADA, aligning with standards including NERC CIP, IEC 62443, and NIST SP 800-82.
  • Collaborate with stakeholders to monitor regulatory changes and industry developments.
  • Track activities including tabletop exercises, architecture design reviews, TSA Cybersecurity Action Plan, and biennial cybersecurity audits.
  • Track gaps from internal and external assessments to completion.
  • Assist with tracking risk assessments and remediation for OT/SCADA systems, including ICS, PLCs, and remote monitoring infrastructure.
  • Create awareness of compliance to company policies, standards, and regulatory requirements through monitoring and reporting.
  • Collaborate with IT stakeholders to monitor cybersecurity exceptions and other IT operational activities that present gaps.
  • Partner with IT, Legal, HR, and Enterprise Risk Management to align risk and compliance efforts.
  • Ensure stakeholders have operational metrics to monitor their compliance.
  • Deliver regular risk and compliance metrics for IT senior leadership in partnership with the Cybersecurity GRC team.

Experience Requirements:
  • 4+ years of experience in GRC, risk management, or compliance roles.
  • Strong understanding of GRC tools and platforms such as RSA Archer, ServiceNow GRC, or Fusion.
  • Familiarity with frameworks and standards including NIST 800 series, COBIT, and FAIR.
  • Proven experience supporting, assessing, governing, or auditing OT/SCADA/ICS environments.
  • Analytical, problem-solving, and organizational skills.
  • Written and verbal communication skills with stakeholder engagement capability.
  • Certifications such as CISA, CRISC, CISSP, CMMC, or PCI preferred.

Education Requirements:
  • Bachelor’s degree in Information Security, Risk Management, Computer Science, or related field.

Recruitment Transparency Notice
 
Eliassen Group values transparency in our recruitment practices. Please be advised that Eliassen Group utilizes artificial intelligence (AI) tools as part of its initial application screening and hiring process. You may receive email and SMS notifications from the Eliassen Virtual Recruiting Team (noreply@eliassen.com, 781-808-2924) inviting you to complete a brief voice screening as part of your application process. These tools assist our hiring teams in different ways, including but not limited to, assistance in reviewing application materials to help identify candidates whose qualifications most closely match the requirements of the position. All AI-assisted evaluations and responses are reviewed by human recruiters before any hiring decisions are made. The use of AI in our process is intended to support fairness, efficiency, and consistency, and Eliassen Group takes measures to prevent bias or discrimination in connection with its hiring practices. By proceeding, you acknowledge, agree, and consent to Eliassen Group’s use of these tools, including AI tools, as part of the application and hiring process.
 

Skills, experience, and other compensable factors will be considered when determining pay rate. The pay range provided in this posting reflects a W2 hourly rate; other employment options may be available that may result in pay outside of the provided range.

W2 employees of Eliassen Group who are regularly scheduled to work 30 or more hours per week are eligible for the following benefits: medical (choice of 3 plans), dental, vision, pre-tax accounts, other voluntary benefits including life and disability insurance, 401(k) with match, and sick time if required by law in the worked-in state/locality.
If anyone reaches out to you about an open position connected with Eliassen Group, please ensure that you are working directly with us by confirming the following:

· When you work with Eliassen Group, all email communication will come from an Eliassen.com address, never Gmail, Yahoo, etc.

· Eliassen Group will never ask you for personal information (home address, bank account, or check routing number) until you have worked with someone clearly associated with Eliassen Group.

If you have any indication of fraudulent activity, please contact fraud@eliassen.com.

 
About Eliassen Group:
 
Eliassen Group is a strategic consulting firm that helps organizations reach further and achieve more through our technology, business advisory, and life sciences solutions. For nearly 40 years, we have combined exceptional people, deep domain expertise, and intelligent capabilities to expand our clients’ capacity and accelerate meaningful outcomes. We are driven by a purpose to positively impact the lives of our employees, clients, consultants, and the communities we serve.
 
Eliassen is committed to building a diverse and inclusive team from a variety of backgrounds, perspectives, and skills. We are an Equal Opportunity and Affirmative Action Employer and all employment decisions are based on merit, performance, and business needs. Eliassen does not discriminate on the basis of race, color, gender identity or expression, sexual preference or orientation, sex (including pregnancy, childbirth, and related medical conditions), marital status, creed, religion, physical or mental disability, genetic information, military or veteran status, age, ancestry, national origin, citizenship status, prohibited criminal record inquiries of applicants and employees, or any other category protected by federal, state, or local laws.
 
Don’t miss out on our referral program! If we hire a candidate that you refer us to then you can be eligible for a $1,000 referral check!
 

  • Product Security Lead

    Irvine, CA

    Description: On-site Monday–Thursday in Irvine, CA Our client seeks a Product Security Lead to build, own, and mature the product security program. The role will partner with an MSP to implement EU Cyber Resilience Act (CRA) compliance, then transition...

    Date Posted: 09/17/2026 Recommended

  • Remote Software Asset Management (SAM) Analyst – SBOM

    Anywhere

    Description: We are seeking a Software Asset Management (SAM) Analyst – SBOM & Open Source Compliance to join our Software Asset Management team. This role will be responsible for supporting and advancing our Software Bill of Materials (SBOM) program, ...

    Date Posted: 10/04/2026 Recommended

  • Policy & Procedure Documentation Specialist

    Anywhere

    Description: Remote Our client seeks a senior technical writer responsible for policy documentation supporting the enterprise risk framework and management within the Canadian Wealth business segment. The specialist will develop, maintain, and enhance ...

    Date Posted: 09/18/2026 Recommended

  • Release Governance Analyst

    St. Petersburg, FL

    Description: On-site 3 on in St. Petersburg, FL Our client seeks a Release Governance Analyst to support Grid Technology Solutions. The role coordinates large-scale deployments and production releases across SCADA, ADMS, and related grid operations tec...

    Date Posted: 09/14/2026 Recommended

  • Information Security Analyst - Exposure Management Lead

    Cincinnati, OH

    Description: On-site in Cincinnati, OH Our client seeks a Lead, Exposure Management to coordinate urgent cybersecurity exposure events. The role will manage day-to-day response activities, assess enterprise exposure, coordinate stakeholders, track reme...

    Date Posted: 09/24/2026 Recommended

  • SOX Business Process Controls Senior Manager (Non-Order-to-Cash)

    San Francisco, CA

    Description: Location: San Francisco, CA (Hybrid - 4 days onsite per week) Our client is seeking a seasoned leader to drive and strengthen its SOX compliance and business process controls program, with a focus on key operational and financial cycles (N...

    Date Posted: 09/20/2026 Recommended

  • SOX Business Process Controls Manager

    San Francisco, CA

    Description: Hybrid 4x / week on-site in San Francisco, CA Our client seeks a SOX Business Process Controls Manager to lead end-to-end internal audit services across industries, with emphasis on compute controls over infrastructure and the computing en...

    Date Posted: 09/20/2026 Recommended

  • Data Protection Analyst

    Boston, MA

    Description: Hybrid 3 days onsite in Boston, MA Our client seeks a Sr. Analyst, Data Protection to help define strategy, design policies, partner with stakeholders, analyze risks and metrics, and advance an enterprise Data Protection Program. You will ...

    Date Posted: 09/22/2026 Recommended

  • Internal Audit/SOX Director

    San Francisco, CA

    Description: Our client seeks an Internal Audit/SOX Director who will lead independent and objective assessments of financial statements and internal controls, enhance credibility of information for stakeholders, and build, optimize, and deliver intern...

    Date Posted: 09/20/2026 Recommended

  • Data Governance & Analytics

    New York, NY

    Description: Hybrid 3-4 days onsite in New York, NY Our client seeks a highly technical Data Governance & Analytics professional to lead data governance standards, oversee marketing analytics data quality, and partner across analytics, engineering, leg...

    Date Posted: 09/28/2026 Recommended

  • IT Applications Analyst - DEF Delivery & Support

    St. Petersburg, FL

    Description: Hybrid 3 days on-site in St. Petersburg, FL Our client seeks a Senior IT Applications Analyst to support the St. Petersburg Distribution Control Center and the operational health of SCADA and ADMS within a large ADMS modernization program....

    Date Posted: 09/15/2026 Recommended

  • Network Engineer II

    St. Petersburg, FL

    Description: Hybrid 3 days on-site in St. Petersburg, FL Our client is seeking a Telecom Data Network Engineer to support the implementation, modernization, and lifecycle management of critical network infrastructure across the Midwest region. This rol...

    Date Posted: 09/08/2026 Recommended

  • Project Manager - Life & Annuity Operations

    Anywhere

    Description: We are seeking an experienced Project Manager with Life & Annuity and Service Operations experience to support a large-scale merger planning and integration initiative. This individual will partner closely with business and operational sta...

    Date Posted: 09/29/2026 Recommended

  • SOX Business Process Controls Manager (Order to Cash)

    San Francisco, CA

    Description: Location: San Francisco, CA (Hybrid - 4 days onsite per week) Our client is seeking a SOX Business Process Controls Manager to lead Sarbanes-Oxley (SOX) compliance, internal audit, and business process controls initiatives within a dynamic...

    Date Posted: 09/20/2026 Recommended

  • Cisco Network Engineer

    Charlotte, NC

    Description: Hybrid 3 days on-site in Charlotte, NC Our client seeks a Cisco Network Engineer to implement, modernize, and manage critical network infrastructure across the Midwest region. The role focuses on Cisco enterprise routing, switching, SD-WAN...

    Date Posted: 09/17/2026 Recommended

  • Sr Technical Project/Program Manager

    Anywhere

    Description: Remote Our client seeks a Sr Technical Project/Program Manager to lead planning and delivery of digital technology initiatives supporting a state health plan. The role will coordinate cross-functional teams, manage risks and dependencies, ...

    Date Posted: 09/27/2026 Recommended

  • Manager, Data Governance

    Irvine, CA

    Description: On-site in Irvine, CA Our client seeks a deeply technical Manager, Data Governance to design, build, and operationalize an enterprise data governance program across engineering, manufacturing, and supply chain data domains. The leader will...

    Date Posted: 09/17/2026 Recommended

  • AWS AI Platform Engineer

    Cincinnati, OH

    Description: On-site in Cincinnati, OH Our client seeks an AWS AI Platform Engineer to enable and advance enterprise AI and machine learning capabilities within a secure, governed, and scalable environment. The role will architect, implement, and maint...

    Date Posted: 09/08/2026 Recommended

  • Database Security Engineer

    Richmond, VA

    Description: Hybrid in Richmond, VA Our client seeks a Database Security Engineer to manage, optimize, and expand the Imperva Database Activity Monitoring platform. The contractor will ensure comprehensive monitoring coverage across enterprise database...

    Date Posted: 09/16/2026 Recommended

  • SOX Business Process Controls - Senior Manager

    San Francisco, CA

    Description: Hybrid 4x / week on-site in San Francisco, CA Our client seeks a SOX Business Process Controls - Senior Manager with Order-to-Cash controls design and remediation expertise. The role delivers internal audit services across industries, leve...

    Date Posted: 09/20/2026 Recommended

  • Solutions Architect (Oracle Fusion & EPM)

    Anywhere

    Description: Remote Our client is undertaking a multi-year finance transformation to replace legacy Oracle EBS and GBS with Oracle Fusion Cloud ERP and Oracle EPM. The program includes Chart of Accounts redesign, universal subledger architecture, large...

    Date Posted: 10/01/2026 Recommended

  • Cloud Application Software Security Engineer

    St. Louis, MO

    Description: Hybrid 4 days on-site, 1 day work from home in St. Louis, MO Our client seeks a Cloud Application Software Security Engineer to remediate vulnerabilities and mature SDLC pipelines. The role will focus on addressing findings from Mythos, CV...

    Date Posted: 09/08/2026 Recommended

  • Systems Engineer III

    Fort Belvoir, VA

    Description: On-site in Fort Belvoir, VA Our client seeks a Systems Engineer III to integrate enterprise networking, data center virtualization, and cyber compliance within defense signal and communications environments. The role will plan and support ...

    Date Posted: 09/28/2026 Recommended

  • Data Platforms Administrator

    4100 Coca Cola Plaza

    Description: Hybrid 4/1 in Charlotte, NC Our client seeks a Data Platform Administrator to install, configure, maintain, and support data analytics and business intelligence platforms including Tableau, Sigma, Alteryx, Alation, DBT, Palantir, and Snowf...

    Date Posted: 09/21/2026 Recommended

  • IT Audit Controls/SOX Manager

    San Francisco, CA

    Description: Hybrid 4x / week on-site in San Francisco, CA Our client seeks an IT Audit Controls/SOX Manager to deliver internal audit services across industries. The role focuses on optimizing internal audit functions, leveraging AI and risk technolog...

    Date Posted: 09/20/2026 Recommended

  • IT Audit Controls/SOX - Senior Manager

    San Francisco, CA

    Description: Our client seeks an IT Audit Controls/SOX - Senior Manager to lead comprehensive internal audit services across industries. The role focuses on enhancing the credibility and reliability of financial statements and internal controls, enabli...

    Date Posted: 09/20/2026 Recommended

  • SOX Business Process Controls Senior Manager

    San Francisco, CA

    Description: Our client seeks a SOX Business Process Controls Senior Manager to lead and optimize internal audit services across industries, with emphasis on compute controls over infrastructure and computing environments that support business processe...

    Date Posted: 09/20/2026 Recommended

  • Program Manager – Print & Mail Operations

    Anywhere

    Description: Remote Our client seeks an experienced Program Manager to lead a large-scale Print and Mail Operations transformation. The role oversees the transition of high-volume print and mail from internal facilities to a strategic third-party vendo...

    Date Posted: 10/01/2026 Recommended

  • Internal Audit/SOX - Director

    San Francisco, CA

    Description: Our client seeks an Internal Audit/SOX Director to lead independent and objective assessments of financial statements and internal controls across diverse industries. The role will set strategic direction, build and optimize internal audit...

    Date Posted: 09/20/2026 Recommended

  • QA Practice Lead

    Washington, DC

    Description: Hybrid 3 days onsite in Washington, DC Our client seeks a QA Practice Lead to stand up and run a transversal QA Practice across an enterprise IT roadmap. The lead will operationalize governance and frameworks, mature toolchains, coach team...

    Date Posted: 09/16/2026 Recommended

Eliassen Group is an Equal Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, gender identity, national origin, age, protected veteran status, or disability status. Eliassen Group’s Affirmative Action Plan (AAP) is available for inspection by any employee or applicant for employment upon request, during normal business hours of Monday through Friday, 8:30am to 5:30pm EST. Interested persons should contact Phaedra Wells at pwells@eliassen.com for assistance. It is unlawful in Massachusetts and Maryland to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.

Applicants with disabilities that believe they require an accommodation or assistance with a position, please email our HR team at hradmin@eliassen.com. This email inbox is designed exclusively to assist job seekers whose disability prevents them from being able to apply online. Emails sent for other purposes will not receive a response.


Please be advised that a number of fraudulent job postings have been released under the Eliassen Group brand.

Unfortunately, fraudulent job postings can happen. If anyone reaches out to you about an open position connected with Eliassen Group, never provide personal or financial information to anyone who is not clearly associated with Eliassen Group

If anyone seemingly from Eliassen Group has ever requested this personal information in the past or does so in the future, please contact fraud@eliassen.com.

Please ensure that you are working directly with us by confirming the following:

  • When you work with Eliassen Group, all email communication will come from an Eliassen.com address, never Gmail, Yahoo, etc.
  • Eliassen Group will never ask you for personal information (home address, bank account, or check routing number) until you have worked with someone clearly associated with Eliassen Group, as indicated above