1

Cybersecurity Governance Risk Compliance Jobs in Rhode Island

Assisting in Governance Risk and Compliance (GRC) program's design, process reengineering or enhancements and tool and technology implementations as applicable. * Leading current risk assessments ...

You will lead end-to-end cybersecurity risk assessments of third-party vendors and solutions-going ... Evaluate vendor security programs, control effectiveness, and governance, along with deep-dive ...

Emphasizes a systematic approach to security assessment and connects cybersecurity to business risk management, compliance requirements, and ethical computing practices. * Curriculum Awareness ...

The Cybersecurity Engineers will prepare, implement, and ensure compliance with cybersecurity ... or risk mitigation strategies. * Ensure appropriate security controls are in place that will ...

Showing results 41-60

Cybersecurity Governance Risk Compliance information

What is cybersecurity governance, risk, and compliance (GRC)?

Cybersecurity Governance, Risk, and Compliance (GRC) refers to a framework used by organizations to align their IT and security strategies with business objectives, manage risks, and ensure compliance with laws and regulations. Governance involves setting policies and procedures, risk focuses on identifying and addressing threats, and compliance ensures adherence to required standards. Professionals in this field help organizations protect sensitive data, avoid regulatory penalties, and build trust with stakeholders. GRC is essential for maintaining effective cybersecurity and demonstrating due diligence.

What are the key skills and qualifications needed to thrive as a cybersecurity governance, risk, and compliance (GRC) professional?

To thrive as a Cybersecurity GRC professional, you need a solid understanding of information security frameworks, risk management principles, and regulatory compliance, often supported by a degree in cybersecurity or related fields. Familiarity with tools like GRC platforms (e.g., Archer, ServiceNow), and certifications such as CISSP, CISM, or CRISC are highly valued. Strong analytical thinking, attention to detail, and effective communication skills help you interpret regulations and collaborate with stakeholders. These skills ensure organizations can manage cybersecurity risks proactively while meeting regulatory and industry standards.

What are some typical challenges faced by professionals in cybersecurity governance, risk, and compliance (GRC) roles?

Professionals in Cybersecurity GRC roles often navigate the challenge of keeping up with rapidly changing regulatory requirements while ensuring company policies align with both business objectives and security best practices. Balancing the need for robust security controls with operational efficiency, educating non-technical stakeholders about risk, and managing audits are common aspects of the job. Additionally, GRC professionals frequently collaborate with IT, legal, and business teams to ensure a cohesive approach to risk management and compliance. This dynamic environment requires strong communication skills, adaptability, and a commitment to continuous learning.

What is the difference between Cybersecurity Governance Risk Compliance vs Cybersecurity Analyst?

AspectCybersecurity Governance Risk ComplianceCybersecurity Analyst
CertificationsCISA, CISSP, CISMCompTIA Security+, CISSP, CEH
Work EnvironmentPolicy development, audits, compliance frameworksMonitoring security systems, incident response
Employer & Industry UsageOrganizations with compliance needs, regulatory bodiesIT security teams, cybersecurity firms

While Cybersecurity Governance Risk Compliance focuses on establishing policies, ensuring regulatory adherence, and managing risks, Cybersecurity Analysts primarily monitor security systems, analyze threats, and respond to incidents. Both roles are essential in a comprehensive cybersecurity strategy but differ in scope and daily responsibilities.

What are popular job titles related to Cybersecurity Governance Risk Compliance jobs in Rhode Island?

For Cybersecurity Governance Risk Compliance jobs in Rhode Island, the most frequently searched job titles are:

What job categories do people searching Cybersecurity Governance Risk Compliance jobs in Rhode Island look for?

The top searched job categories for Cybersecurity Governance Risk Compliance jobs in Rhode Island are:

Infographic showing various Cybersecurity Governance Risk Compliance job openings in Rhode Island as of August 2026, with employment types broken down into 1% As Needed, 79% Full Time, 16% Part Time, and 4% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution.

Third Party Risk Sr Analyst

Citizens

Johnston, RI • Hybrid

Full-time

Re-posted 28 days ago


Job description

Description

As the Third Party Risk Sr Analyst, you will manage vendor issues, complete quality assurance functions and execute Third Party Vendor Assessment reviews. This will include managing relationships with both business leaders and vendors, while providing robust and challenging insight on business risk and on the adequacy and effectiveness of the test control processes in place. The role holder delivers assessment review and provides opinion on the quality of the vendor control environment as is needed to meet Citizens policies including identifying issues and subsequently assisting the business to agree to any appropriate action plans to mitigate the risk. The Third-Party Assessment function adds value by providing specific business function assurance on vendors, in relation to customer, financial or reputational risk and bringing momentum to action plans to address risk and leveraging findings and best practice on a bank wide scale.

Primary responsibilities include

  • Collaborating with senior management to influence key decisions.
  • Evaluating third party vendors' control infrastructure effectiveness and obtaining evidence of controls.
  • Applying experience in audit, security and regulatory frameworks including ISO 27001, GLBA, SOX, PCI, HIPPA, States Privacy Regulation and FFIEC.
  • Assisting in Governance Risk and Compliance (GRC) program's design, process reengineering or enhancements and tool and technology implementations as applicable.
  • Leading current risk assessments, continual risk assessments, and risk metrics and visualizations.
  • Performing quality assurance on vendor assessment and remediation activities.
  • Working directly with key business leaders to facilitate risk analysis and risk management processes, identifying acceptable levels of risk and establish roles and responsibilities with regards to risk management.
  • Maintaining and monitoring enterprise risk exception process to identify areas of noncompliance.
  • Supporting and participating in regulatory exam preparation and execution as well as remediation where applicable.
  • Coaching and mentoring junior analysts and clearly articulating Third Party Vendor Assessment program goals and objectives to the wider audience.
  • Producing Third Party Vendor Assessment reports that clearly articulate risks in order to speak to a varied audience.
  • Translating security risk and communicating effectively to business partners within the organization.
  • The ability to travel within the United States is required.

Qualifications, Education, Certifications and/or Other Professional Credentials

  • Required Qualifications
    • Ability to navigate program requirements independently.

    • Demonstrates advanced critical thinking.

    • Identifies opportunities and recommended solutions.

    • Ability to appropriately manage multiple complex assessments and related activities.

    • Demonstrates strong verbal and written communications amongst various internal and external stakeholders.  

    • Strong analytical skills to identify and classify inherent and residual risks.

    • Effectively leads calls with various stakeholders to achieve desired results.

    • Experience in financial services organization, particularly in Risk, Audit, Compliance, Cyber or Third-Party Risk
    • Proficient use of Microsoft Word and Microsoft Excel
    • Experience gathering and analyzing evidence through various methods (e.g., email, virtual sessions, or onsite) and sources (e.g., artifacts, interviews, meetings, demonstrations, independent audits, review of processes/policies, etc.)

  • Preferred Qualifications
    • Bachelor's Degree (preferred)
    • Holds relevant industry certification(s) (i.e. CISA, CRCM, CRISC, CTPRP, TPCRA, etc.) (preferred)

Hours & Work Schedule

  • Hours per Week: 40 
  • Work Schedule: 8-5 (4 days in office, 1 day remote)

Work Authorization: 
This role is not eligible for new employer sponsored or current H-1 B visa holders. Applicants, including current OPT, L and other visa holders, must be authorized to work in the U.S. without the need for new employer sponsorship for themselves or their spouses now and in the future.

#LI-CITIZENS2

Some job boards have started using jobseeker-reported data to estimate salary ranges for roles. If you apply and qualify for this role, a recruiter will discuss accurate pay guidance.

Equal Employment Opportunity

Citizens, its parent, subsidiaries, and related companies (Citizens) provide equal employment and advancement opportunities to all colleagues and applicants for employment without regard to age, ancestry, color, citizenship, physical or mental disability, perceived disability or history or record of a disability, ethnicity, gender, gender identity or expression, genetic information, genetic characteristic, marital or domestic partner status, victim of domestic violence, family status/parenthood, medical condition, military or veteran status, national origin, pregnancy/childbirth/lactation, colleague's or a dependent's reproductive health decision making, race, religion, sex, sexual orientation, or any other category protected by federal, state and/or local laws. At Citizens, we are committed to fostering an inclusive culture that enables all colleagues to bring their best selves to work every day and everyone is expected to be treated with respect and professionalism. Employment decisions are based solely on merit, qualifications, performance and capability.

Education:Why Work for UsEmployment Type: 1ST