1

Insider Risk Jobs in Illinois (NOW HIRING)

Senior Cloud Engineer

Chicago, IL · On-site +1

$70K - $144K/yr

Secure M365 workloads with a strong focus on tenant hardening, conditional access, DLP, and insider risk policies Your Skills And Experience Required Qualifications : * US Citizenship or Green Card ...

Director, Security

Chicago, IL · On-site

$149 - $206/hr

Experience leading complex investigations, including threat management, insider risk, or protective intelligence. * Bilingual (English/Spanish or English/Portuguese). Compensation & Benefits Base Pay ...

Implement and support data protection capabilities, including Microsoft Purview, sensitivity labels, DLP, and insider risk policies. Automation & Engineering * Build and maintain security automation ...

Implement and support data protection capabilities, including Microsoft Purview, sensitivity labels, DLP, and insider risk policies. Automation & Engineering * Build and maintain security automation ...

Showing results 21-40

Insider Risk information

What are the key skills and qualifications needed to thrive as an insider risk analyst, and why are they important?

To thrive as an Insider Risk Analyst, you need a solid background in information security, risk assessment, and data analysis, often supported by a degree in cybersecurity or a related field. Familiarity with security information and event management (SIEM) tools, user behavior analytics, and certifications such as CISSP or CISA are commonly required. Strong analytical thinking, discretion, and communication skills are crucial for identifying threats and collaborating with cross-functional teams. These skills ensure prompt detection and mitigation of internal security threats, protecting organizational assets and data integrity.

What is an insider risk professional?

An Insider Risk professional is responsible for identifying, assessing, and mitigating threats posed by individuals within an organization, such as employees, contractors, or business partners. These threats can include data theft, fraud, sabotage, or unintentional errors that could harm the company. Insider Risk professionals develop policies, monitor user behavior, and implement security controls to protect sensitive information and assets. Their goal is to balance organizational security with privacy and productivity.

What is the difference between Insider Risk vs Insider Threat Analyst?

AspectInsider RiskInsider Threat Analyst
Primary FocusIdentifying and managing potential risks posed by insiders to prevent security breachesDetecting, analyzing, and responding to insider threats and security incidents
Required CredentialsSecurity certifications (CISSP, CISA), risk management experienceCybersecurity certifications (CEH, GIAC), threat analysis experience
Work EnvironmentRisk management teams, security departments, corporate settingsSecurity operations centers, incident response teams, cybersecurity units

Insider Risk professionals focus on proactively identifying and mitigating potential insider-related threats, emphasizing risk management strategies. In contrast, Insider Threat Analysts are more involved in detecting and responding to actual threats and security incidents. Both roles require cybersecurity knowledge and certifications but differ in their primary responsibilities within security teams.

What are some common challenges faced by professionals in insider risk roles, and how can they be addressed?

Professionals in Insider Risk roles often face challenges such as balancing employee privacy with security needs, detecting subtle behavioral indicators of risk, and fostering a culture of trust while enforcing policies. Addressing these challenges requires strong communication skills, collaboration with HR and IT departments, and the utilization of advanced monitoring tools that respect privacy regulations. Additionally, ongoing training and clear protocols help teams respond effectively while maintaining organizational transparency.

What does an insider risk analyst do?

An insider risk analyst monitors and investigates potential threats from employees or trusted individuals who may intentionally or unintentionally compromise an organization’s security. They analyze data, use security tools, and develop strategies to detect, prevent, and respond to insider threats, often working with cybersecurity and compliance teams. Strong analytical skills and knowledge of security protocols are essential for this role.
Infographic showing various Insider Risk job openings in Illinois as of August 2026, with employment types broken down into 1% As Needed, 91% Full Time, 6% Part Time, and 2% Contract. Highlights an 88% Physical, 4% Hybrid, and 8% Remote job distribution.

Cybersecurity GRC Analyst

Follett Content Solutions

Mchenry, IL • On-site

$115K - $120K/yr

Full-time

Posted 5 days ago


Job description

Job Type
Full-time
Description
Follett Content Solutions has been a trusted partner for educators since 1873! We support our educators that touch more than 45 million students worldwide. Follett Content Solutions helps build a diverse collection of print and digital resources to support every student. We are currently hiring for Cybersecurity GRC Analyst.
This position is an exempt full-time position located in McHenry, IL or remote for the right person. The pay for this position is $!15,000-$120,000 annually. We offer a hybrid work schedule with 3 days in the office (Monday, Tuesday & Thursday) and 2 remote days (Wednesday & Friday).
The Cybersecurity GRC Analyst is responsible for strengthening the organization's governance, risk, and compliance posture by formalizing IT policies, operationalizing Microsoft Purview, and ensuring audit readiness. This individual plays a critical role in aligning security practices with business risk, regulatory requirements, and industry frameworks such as SOC 2, NIST CSF, and PCI DSS. Serves as the primary point of contact for governance initiatives, including evidence collection, control mapping, and coordination with external auditors and consultants.
Develops and maintains policies, standards, and procedures across device management, identity, and data handling. Oversees data classification, DLP, insider risk, and compliance reporting through Microsoft Purview. Partners with the Cybersecurity Specialist and SOC provider to integrate governance with operational telemetry. Tracks remediation activities, supports risk assessments, and ensures timely closure of audit findings.
Maintains documentation for audit readiness and leadership reporting, enabling transparency and accountability across the organization. Leads annual cybersecurity awareness training efforts and promotes a culture of compliance. Monitors emerging regulatory trends and frameworks, recommending updates to policies, tools, and practices to ensure the organization remains resilient and compliant.
Key Responsibilities:
Governance & Policy Development
  • Drafts, maintains, and enforces IT security policies, standards, and procedures across device management, identity, and data handling.
  • Operationalizes Microsoft Purview for data classification, DLP, insider risk, and compliance reporting.
  • Aligns governance practices with organizational risk appetite and regulatory requirements.
  • Ensures policies are auditable, scalable, and communicated effectively across the organization.

Audit Readiness & Compliance
  • Serves as primary point of contact for SOC 2 Type II certification efforts, coordinating evidence collection and control mapping.
  • Supports PCI DSS self-assessment activities and other compliance initiatives.
  • Maintains documentation for audit readiness and leadership reporting.
  • Coordinates with external auditors, consultants, and vendors to ensure successful certification outcomes.
  • Tracks remediation plans and ensures timely closure of audit findings

Risk Assessment & Remediation
  • Assists in internal risk assessments, identifying gaps and recommending remediation strategies.
  • Partners with IT and business stakeholders to translate technical risks into business impact.
  • Monitors compliance telemetry and integrates findings into governance processes.
  • Ensures remediation activities are documented and aligned with organizational priorities.

Project Management & Deployments
  • Identifies and coordinates projects to close security gaps.
  • Works with IT Operations and Cybersecurity teams on tool deployments and implementation/tuning.
  • Works with Application Development teams on defining guardrails for AI initiatives to ensure AI agents are inventoried and managed properly.
  • Works closely with IT Stakeholders on identifying and prioritizing projects based on risk assessment.

Security Awareness & Training
  • Develops and deploys annual cybersecurity awareness training programs.
  • Promotes a culture of compliance and risk awareness across all levels of the organization.
  • Provides guidance and education on governance frameworks (SOC 2, NIST CSF, PCI DSS, CIS Controls).
  • Shares knowledge of emerging regulatory trends and best practices with leadership and staff

Requirements
  • 7-10 years experience
  • Bachelor's degree or equivalent in Computer Science, Information Systems, Cybersecurity, or related discipline OR demonstrated ability to meet job requirements through comparable years of applicable work experience.
  • 7+ years related experience in IT, cybersecurity operations, or governance, risk, and compliance.
  • Strong written and oral communication skills with the ability to positively engage with business stakeholders, IT management, and external auditors.
  • Experience with Microsoft Purview, Intune, Defender, SentinelOne, or similar governance/security platforms.
  • Familiarity with compliance frameworks such as SOC 2, PCI DSS, ISO 27001, and NIST CSF.
  • Ability to translate business requirements and risks into actionable governance and compliance controls.
  • Knowledge of risk assessment procedures, policy formation, role-based authorization methodologies, and incident response governance.
  • Solid project management skills, especially in cross-functional environments involving external vendors or auditors.
  • Strong team-oriented interpersonal skills; ability to effectively interface with diverse teams across all levels of the organization.
  • Previous experience coordinating with third-party providers, consultants, or auditors for compliance initiatives.
  • Experience creating leadership ready documentation, dashboards, or reports that communicate compliance posture, risk trends, or remediation progress.
  • Prior involvement in security awareness training programs or organizational compliance initiatives.
  • Experience supporting or implementing role based access controls (RBAC), least privilege models, or identity governance processes.
  • Experience coordinating with external auditors, consultants, or managed service providers for compliance, risk, or governance initiatives.
  • Background working with IT Operations, Infrastructure, or Application Development teams to implement governance controls, close audit gaps, or deploy compliance related tooling.

*As an Equal Opportunity Employer, we are committed to providing reasonable accommodations to job applicants with disabilities. If you are interested in applying for employment and need assistance or an accommodation in the application process due to a disability, please contact us by email or phone. Email: Send request to fcshr@follettcontent.com Phone: Request assistance by calling 800.773.7010 x45130. When contacting us, please provide your contact information, the job position or title, and state the nature of your accessibility issue.
Salary Description
$115,000-$120,000