6 days ago

IT GRC Analyst, Cyber Contract Management

NBCUniversal

Hybrid
Full Time
$75,000
Hybrid

Job Overview

Job TitleIT GRC Analyst, Cyber Contract Management
Job TypeFull Time
CategoryCommerce
Experience5 Years
DegreeMaster
Offered Salary$75,000
LocationHybrid

Who's the hiring manager?

Sign up to PitchMeAI to discover the hiring manager's details for this job. We will also write them an intro email for you.

Uncover Hiring Manager

Job Description

Job Description: IT GRC Analyst, Cyber Contract Management

NBCUniversal is one of the world's leading media and entertainment companies, creating and distributing world-class content across film, television, and streaming, and bringing it to life through global theme park destinations, consumer products, and experiences. We own and operate leading entertainment and news brands, including NBC, NBC News, NBC Sports, Telemundo, Bravo, and Peacock. As a subsidiary of Comcast Corporation, NBCUniversal is committed to improving the communities where our employees, customers, and audiences live and work, fostering an inclusive culture, and attracting a diverse workforce.

NBCUniversal is seeking an experienced Governance, Risk, and Compliance (GRC) Analyst to support various functions within the Security Assurance – Governance team. The ideal candidate will have a strong understanding of cybersecurity, vendor contracts, negotiation of third-party security standards, and the ability to support additional governance functions like 3rd Party Security Reviews.

Responsibilities

  • Collaborate with business leadership, Legal, Procurement, and Cyber to review terms and conditions, ensuring vendor and client obligations are aligned with internal cyber controls.
  • Undertake research as needed when control or regulatory questions arise.
  • Track status of risk remediations in the risk register with business stakeholders.
  • Monitor completeness and sustainability of remediation efforts.
  • Educate and raise awareness on risks and controls.
  • Contribute to overall program enhancements and drive automation with various IT and Cybersecurity stakeholders.
  • Contribute to enterprise IT Risk and Control awareness efforts.
  • Maintain deep understanding of organization-wide objectives, interactions, issues, and risks.
  • Stay abreast of current and emerging information risks, including current or proposed cyber legislation or control frameworks.
  • Perform other related duties and special projects, as assigned, to support evolving GRC and cybersecurity program needs.

Qualifications

Requirements:

  • Bachelor's degree or equivalent experience.
  • Minimum of 2 years of experience in IT Governance, Risk or Compliance functions.
  • Knowledge of IT Risk Frameworks such as NIST, ISO, CSA, PCI, etc.
  • Knowledge of contracting lifecycle.
  • Ability to work independently and in cross-functional teams.
  • Strong analytic skills for problem analysis and resolution.
  • Experience in process management systems like Jira, Azure DevBoards, ServiceNow.
  • Experience with the MS office suite – Excel, PowerPoint, Word etc.
  • Strong written/verbal communication and organizational skills.

Desired Characteristics:

  • Ability to prioritize activities based on business criticality, audits, threats, vulnerabilities, and regulatory requirements.
  • Experience supporting enterprise-wide technology initiatives and creating a risk-aware culture.
  • Ability to understand the big picture by aligning activities to business objectives and partnering with other IT GRC functions to align strategies and enterprise priorities.
  • Industry certifications such as CRISC or CISA are a plus.

Additional Requirements:

  • Fully Remote: This position has been designated as fully remote, meaning that the position is expected to contribute from a non-NBCUniversal worksite, most commonly an employee’s residence.
  • This position is eligible for company sponsored benefits, including medical, dental and vision insurance, 401(k), paid leave, tuition reimbursement, and a variety of other discounts and perks.
  • Salary range: $65,000 - $85,000

Key skills/competency

  • IT Governance
  • Risk Management
  • Compliance
  • Cybersecurity
  • Contract Management
  • Vendor Security
  • NIST Framework
  • ISO 27001
  • PCI DSS
  • Jira/ServiceNow

Tags:

IT GRC Analyst
Governance
Risk
Compliance
Cybersecurity
Contract Management
Vendor Management
Risk Assessment
Remediation
Regulatory Compliance
Security Standards
NIST
ISO
CSA
PCI
Jira
Azure DevBoards
ServiceNow
MS Office Suite
Excel
PowerPoint
Word

Share Job:

How to Get Hired at NBCUniversal

  • Research NBCUniversal's culture: Study their mission, values, recent news, and employee testimonials on LinkedIn and Glassdoor.
  • Customize your resume for GRC: Highlight experience in IT risk frameworks like NIST, ISO, CSA, PCI, and contract management.
  • Showcase cyber negotiation skills: Emphasize any experience negotiating third-party security standards.
  • Prepare for GRC-specific questions: Be ready to discuss risk assessment, control implementation, and regulatory compliance.
  • Network within the industry: Connect with current NBCUniversal employees in GRC or cybersecurity roles on LinkedIn.

Frequently Asked Questions

Find answers to common questions about this job opportunity

Explore similar opportunities that match your background