1

Cybersecurity Governance Risk Compliance Jobs in Minnesota

Cybersecurity Sr. Specialist The Cybersecurity Sr. Specialist support cybersecurity operations by ... Experience with implementation and operational use of GRC toolsets (Governance Risk and Compliance)

Showing results 21-40

Cybersecurity Governance Risk Compliance information

What is the difference between Cybersecurity Governance Risk Compliance vs Cybersecurity Analyst?

AspectCybersecurity Governance Risk ComplianceCybersecurity Analyst
CertificationsCISA, CISSP, CISMCompTIA Security+, CISSP, CEH
Work EnvironmentPolicy development, audits, compliance frameworksMonitoring security systems, incident response
Employer & Industry UsageOrganizations with compliance needs, regulatory bodiesIT security teams, cybersecurity firms

While Cybersecurity Governance Risk Compliance focuses on establishing policies, ensuring regulatory adherence, and managing risks, Cybersecurity Analysts primarily monitor security systems, analyze threats, and respond to incidents. Both roles are essential in a comprehensive cybersecurity strategy but differ in scope and daily responsibilities.

What are the key skills and qualifications needed to thrive as a cybersecurity governance, risk, and compliance (GRC) professional?

To thrive as a Cybersecurity GRC professional, you need a solid understanding of information security frameworks, risk management principles, and regulatory compliance, often supported by a degree in cybersecurity or related fields. Familiarity with tools like GRC platforms (e.g., Archer, ServiceNow), and certifications such as CISSP, CISM, or CRISC are highly valued. Strong analytical thinking, attention to detail, and effective communication skills help you interpret regulations and collaborate with stakeholders. These skills ensure organizations can manage cybersecurity risks proactively while meeting regulatory and industry standards.

What are some typical challenges faced by professionals in cybersecurity governance, risk, and compliance (GRC) roles?

Professionals in Cybersecurity GRC roles often navigate the challenge of keeping up with rapidly changing regulatory requirements while ensuring company policies align with both business objectives and security best practices. Balancing the need for robust security controls with operational efficiency, educating non-technical stakeholders about risk, and managing audits are common aspects of the job. Additionally, GRC professionals frequently collaborate with IT, legal, and business teams to ensure a cohesive approach to risk management and compliance. This dynamic environment requires strong communication skills, adaptability, and a commitment to continuous learning.

Is cybersecurity governance risk compliance a good career?

Cybersecurity Governance, Risk, and Compliance (GRC) is a growing field that offers opportunities in managing organizational security policies, risk assessments, and regulatory compliance. It requires knowledge of security frameworks, certifications like CISSP or CISM, and strong analytical skills. The role is in demand across various industries due to increasing cybersecurity threats and regulatory requirements.

Is cybersecurity governance risk compliance a good job?

Cybersecurity Governance, Risk, and Compliance (GRC) roles are in high demand due to increasing cybersecurity threats and regulatory requirements. These jobs typically require knowledge of security frameworks, risk management, and compliance standards, offering opportunities for career growth and specialization. They often involve collaboration across departments and may require certifications like CISSP or CISA.

What is cybersecurity governance, risk, and compliance (GRC)?

Cybersecurity Governance, Risk, and Compliance (GRC) refers to a framework used by organizations to align their IT and security strategies with business objectives, manage risks, and ensure compliance with laws and regulations. Governance involves setting policies and procedures, risk focuses on identifying and addressing threats, and compliance ensures adherence to required standards. Professionals in this field help organizations protect sensitive data, avoid regulatory penalties, and build trust with stakeholders. GRC is essential for maintaining effective cybersecurity and demonstrating due diligence.
What are popular job titles related to Cybersecurity Governance Risk Compliance jobs in Minnesota? For Cybersecurity Governance Risk Compliance jobs in Minnesota, the most frequently searched job titles are:
What job categories do people searching Cybersecurity Governance Risk Compliance jobs in Minnesota look for? The top searched job categories for Cybersecurity Governance Risk Compliance jobs in Minnesota are:
What cities in Minnesota are hiring for Cybersecurity Governance Risk Compliance jobs? Cities in Minnesota with the most Cybersecurity Governance Risk Compliance job openings:
Infographic showing various Cybersecurity Governance Risk Compliance job openings in Minnesota as of August 2026, with employment types broken down into 1% As Needed, 84% Full Time, 11% Part Time, and 4% Contract. Highlights an 93% Physical, 3% Hybrid, and 4% Remote job distribution.

Cybersecurity Risk Oversight Professional

US Bank

Minneapolis, MN • On-site

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 22 days ago


U.S. Bank rating

8.2

Company rating: 8.2 out of 10

Based on 360 frontline employees who took The Breakroom Quiz

51st of 170 rated banks


Job description

At U.S. Bank, we're on a journey to do our best. Helping the customers and businesses we serve to make better and smarter financial decisions and enabling the communities we support to grow and succeed. We believe it takes all of us to bring our shared ambition to life, and each person is unique in their potential. A career with U.S. Bank gives you a wide, ever-growing range of opportunities to discover what makes you thrive at every stage of your career. Try new things, learn new skills and discover what you excel at-all from Day One.

Job Description

NOTE: This position is not eligible for current or future visa sponsorship.

The Cybersecurity Risk Oversight Professional serves as a key member of the Cybersecurity Risk Oversight team within the Second Line of Defense (2LoD). This role is accountable for providing independent oversight and credible challenge of the First Line to ensure risks are appropriately identified, assessed, managed, monitored, and reported in alignment with regulatory requirements, industry standards, and internal risk appetite.

This position is intentionally designed for a senior, autonomous professional who can manage their own program portfolio, prioritize work based on material risk, and engage effectively with Information Security Services, Technology teams, and senior leadership.

Key Responsibilities

  • Provide independent oversight and credible challenge across multiple security and technology pillars, including governance, risk assessments, controls, metrics, and issue management.

  • Perform riskbased assessments of first line security practices, identifying gaps, weaknesses, thematic concerns, emerging risks, and control deficiencies.

  • Develop and articulate independent risk opinions supported by sound analysis, evidence, and professional judgment.

  • Evaluate alignment of first line activities with applicable laws, regulations, regulatory guidance, industry standards (e.g., NIST 800-53, FFIEC, PCI, NIST CSF 2.0, etc), and internal policies.

  • Monitor key risk indicators, security metrics, assessment results, and issue trends to identify systemic risks or areas requiring escalation.

  • Escalate material risks, control weaknesses, or ineffective risk management practices through appropriate governance and reporting channels.

  • Act as a subject matter expert on technology and information security risk, providing insights and guidance to stakeholders while maintaining 2LoD independence.

  • Build and maintain strong, professional relationships with first line stakeholders while confidently challenging assumptions, conclusions, and risk positions when necessary.

  • Contribute to executivelevel risk reporting by clearly summarizing risk posture, trends, and areas of concern in a concise and defensible manner.

  • Stay current on evolving cybersecurity threats, regulatory expectations, and industry best practices to continuously strengthen oversight effectiveness.

Basic Qualifications

  • Bachelor's degree, or equivalent work experience

  • Typically more than eight years of applicable experience

Preferred Skills/Experience

  • Strong foundational understanding of information security domains (e.g., vulnerability management, identity and access management, application security, cloud security, security governance, incident management).

  • Demonstrated ability to perform risk assessments and oversight activities with depth, critical thinking, and professional skepticism.

  • Experience operating in or with a Second Line of Defense, audit, or regulatory environment is strongly preferred.

  • Proven ability to work independently and autonomously, managing priorities and delivering highquality work with limited direction.

  • Strong written and verbal communication skills, including the ability to translate technical risk into clear, executiveready insights.

  • Ability to engage confidently with senior stakeholders while maintaining independence, objectivity, and professionalism.

  • Relevant certifications (e.g., CISSP, CISA, CRISC, CISM) are preferred but not required.

LOCATION EXPECTATIONS: This role requires working from a U.S. Bank Location three (3) or more days per week.

NOTE: This position is not eligible for current or future visa sponsorship.

If there's anything we can do to accommodate a disability during any portion of the application or hiring process, please refer to ourdisability accommodations for applicants.

Benefits:

Our approach to benefits and total rewards considers our team members' whole selves and what may be needed to thrive in and outside work. That's why our benefits are designed to help you and your family boost your health, protect your financial security and give you peace of mind. Our benefits include the following:

  • Healthcare (medical, dental, vision)

  • Basic term and optional term life insurance

  • Short-term and long-term disability

  • Pregnancy disability and parental leave

  • 401(k) and employer-funded retirement plan

  • Paid vacation (from two to five weeks depending on salary grade and tenure)

  • Up to 11 paid holiday opportunities

  • Adoption assistance

  • Sick and Safe Leave accruals of one hour for every 30 worked, up to 80 hours per calendar year unless otherwise provided by law

Review our full benefits available by employment status here.

U.S. Bank is an equal opportunity employer. We consider all qualified applicants without regard to race, religion, color, sex, national origin, age, sexual orientation, gender identity, disability or veteran status, and other factors protected under applicable law.

E-Verify

U.S. Bank participates in the U.S. Department of Homeland Security E-Verify program in all facilities located in the United States and certain U.S. territories. The E-Verify program is an Internet-based employment eligibility verification system operated by the U.S. Citizenship and Immigration Services. Learn more about theE-Verify program.

The salary range reflects figures based on the primary location, which is listed first. The actual range for the role may differ based on the location of the role. In addition to salary, U.S. Bank offers a comprehensive benefits package, including incentive and recognition programs, equity stock purchase 401(k) contribution and pension (all benefits are subject to eligibility requirements). Pay Range: $119,765.00 - $140,900.00

U.S. Bank will consider qualified applicants with arrest or conviction records for employment. U.S. Bank conducts background checks consistent with applicable local laws, including the Los Angeles County Fair Chance Ordinance and the California Fair Chance Act as well as the San Francisco Fair Chance Ordinance. U.S. Bank is subject to, and conducts background checks consistent with the requirements of Section 19 of the Federal Deposit Insurance Act (FDIA). In addition, certain positions may also be subject to the requirements of FINRA, NMLS registration, Reg Z, Reg G, OFAC, the NFA, the FCPA, the Bank Secrecy Act, the SAFE Act, and/or federal guidelines applicable to an agreement, such as those related to ethics, safety, or operational procedures.

Applicants must be able to comply with U.S. Bank policies and procedures including the Code of Ethics and Business Conduct and related workplace conduct and safety policies.

Posting may be closed earlier due to high volume of applicants.


What U.S. Bank employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


U.S. Bank logo

About U.S. Bank

Sourced by ZipRecruiter

U.S. Bank is a reputable and established financial institution that plays a significant role in the banking sector. With a history spanning over 150 years, U.S. Bank has built a strong foundation of trust and reliability. As a comprehensive bank, they offer a wide array of financial products and services to cater to the diverse needs of their customers, including individuals, businesses, and communities. Customer satisfaction is of utmost importance to U.S. Bank. They prioritize delivering exceptional service and fostering long-term relationships with their clients. Through their extensive network of branches and advanced digital banking platforms, U.S. Bank ensures convenient access to their services, empowering customers to manage their finances efficiently and securely.

Industry

Banking and credit intermediation

Company size

10,000+ Employees

Headquarters location

Minneapolis, MN, US

Year founded

1863

Social media