Brown Advisory Incorporated

Cyber GRC Specialist

Brown Advisory Incorporated$95K — $115K *
Finance & Insurance
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in a relevant field or equivalent professional experience
  • 3-6 years of experience in cyber GRC, information security, or related control-management work
  • Knowledge of ISO 27001, SOC 2, NIST CSF, or similar control frameworks
  • Experience in regulated environments, especially in financial services
  • Professional designations like CISA, CRISC, CISM, or Security+ preferred but not essential.

Responsibilities

  • Support and enhance core cyber governance routines and policy management
  • Maintain the cyber risk register and collaborate on documentation of risk decisions
  • Administer and contribute to ISO and security-risk management platforms
  • Coordinate evidence collection, control testing, and compliance deliverables
  • Translate regulatory security expectations into practical controls and procedures
  • Facilitate communication for policy enforcement and risk remediation
  • Manage vulnerability governance including exception handling and reporting
  • Develop metrics for control effectiveness and governance activities

Benefits

  • Medical, dental, and vision coverage
  • Wellness program participation incentive
  • Financial wellness program and fitness event fee reimbursement
  • Gym membership discounts and colleague assistance program
  • Telemedicine program enrollment
  • Adoption benefits and daycare late pick-up fee reimbursement
  • Life and accident insurance options and short-term disability coverage
  • Paid parental leave and group long-term disability
  • Pet insurance and a 401(k) plan with employer match
Full Job Description
Brown Advisory is currently seeking a Cyber GRC Specialist to support and mature the firm's governance, risk, compliance, and control-management routines. This blended role is designed for someone who can translate security requirements into practical business processes, drive evidence and accountability, and communicate clearly with technical and non-technical stakeholders. As part of a lean Information Security team within a mid-sized financial services organization, this individual will serve as a central coordinator for cyber risk, policy management, control testing, audit readiness, client and regulatory response support, and vulnerability remediation governance. The role is not intended to be a hands-on vulnerability engineering role; rather, it ensures the process, ownership, exceptions, reporting, and governance routines are working. Blended Role Coverage Primary emphasis: Cyber GRC support for policies, controls, cyber risk tracking, audit coordination, exceptions, and governance routines. Blended coverage: Cyber Risk / Compliance Analyst work, ISO and risk-platform support, evidence coordination, client/regulatory response support, communications, and vulnerability governance. Duties and Responsibilities 3 Support and mature core cyber governance routines, including policy management, control ownership, risk acceptance, exception handling, standards maintenance, and periodic leadership reporting. 3 Maintain the cyber risk register and partner with technology and business owners to document risk decisions, remediation plans, due dates, dependencies, and residual risk. 3 Serve as a key administrator and process contributor for ISO and security-risk management platforms such as Vanta or similar tools. 3 Coordinate evidence collection, control testing, audit requests, client due diligence responses, regulatory requests, and recurring compliance deliverables. 3 Translate ISO 27001, regulatory, client, and internal security expectations into practical controls and operating procedures appropriate for Brown Advisory's size and risk profile. 3 Facilitate cross-functional communications for security change, SaaS inventory, policy enforcement, control adoption, and risk remediation. 3 Coordinate vulnerability management governance, including scan-result intake, prioritization routines, remediation tracking, exception handling, and reporting. 3 Partner with security engineers, infrastructure teams, application owners, Compliance, Legal, Operations, and Client Service to close control gaps in a business-aligned manner. 3 Develop clear metrics for control effectiveness, audit readiness, exceptions, overdue remediation, and recurring governance activities. 3 Identify process improvements that make security governance more repeatable, transparent, and useful without creating unnecessary bureaucracy. Preferred Qualifications 3 Bachelor's degree in cyber security, information systems, risk management, business, or a relevant field preferred; equivalent professional experience will be considered. 3 3-6 years of experience in cyber GRC, information security, technology risk, IT audit, compliance, or related control-management work preferred. 3 Working knowledge of ISO 27001, SOC 2, NIST CSF, CIS Controls, SEC/FINRA expectations, privacy requirements, or comparable control frameworks. 3 Experience supporting audits, evidence collection, control testing, policy updates, issue tracking, or risk-register maintenance in a regulated environment; financial services experience preferred. 3 CISA, CRISC, CISM, Security+, ISO 27001 Foundation/Lead Implementer, or similar professional designation preferred but not required. Technical Skills 3 Cyber risk registers, exception management, control testing, evidence management, policy lifecycle management, and audit coordination. 3 GRC or trust-management platforms such as Vanta, Archer, ServiceNow GRC, OneTrust, Drata, or similar tools. 3 Vulnerability management governance, including prioritization, remediation tracking, aging analysis, exception workflows, and executive reporting. 3 Strong knowledge of cyber security controls across identity, endpoint, cloud, network, data protection, application security, and third-party risk. 3 Excellent writing, facilitation, and stakeholder-management skills, including the ability to turn technical risk into clear business language. 3 Practical judgment about when to enforce, when to escalate, and when to help the business find a workable control path. 3 Demonstrates curiosity and a continuous improvement mindset by identifying opportunities to enhance processes, improve efficiency, and thoughtfully leverage new technologies and tools, including AI-enabled productivity solutions Personal Attributes 3 Take ownership and move initiatives forward without constant oversight. 3 Balance technical depth, process discipline, and sound business judgment. 3 Approach risk management pragmatically rather than theoretically. 3 Thrive in collaborative, high-accountability environments. 3 Communicate clearly with technical and non-technical colleagues. 3 Bring an entrepreneurial mindset to building and improving security capabilities. Applicants must be authorized to work in the United States without the need for current or future employer-sponsored work authorization (e.g., H-1B , O-1, F-1 (OPT), TN, or any other non-immigrant visa classifications that require employer support or sponsorship). MD Salary: $95-$115k. Commensurate with experience and location. Does not include bonus or long term incentive eligibility (if applicable). Benefits At Brown Advisory we offer a competitive compensation package, including full benefits.  Medical  Dental  Vision  Wellness program participation incentive  Financial wellness program  Fitness event fee reimbursement  Gym membership discounts  Colleague Assistance Program  Telemedicine Program (for those enrolled in Medical)  Adoption Benefits  Daycare late pick-up fee reimbursement  Basic Life & Accidental Death & Dismemberment Insurance  Voluntary Life & Accidental Death & Dismemberment Insurance  Short Term Disability  Paid parental leave  Group Long Term Disability  Pet Insurance  401(k) (50% employer match up to IRS limit, 4 year vesting)

About Brown Advisory Incorporated

Brown Advisory is an investment management firm that provides wealth management, strategic advisory, and philanthropic services to individuals, families, and institutions. The firm manages assets for clients in the United States and internationally. Brown Advisory was founded in 1993 and is headquartered in Baltimore, Maryland.
Learn more about Brown Advisory Incorporated
Size
700 employees
Industry
Founded
1993
NASDAQ

Similar Jobs

More Jobs at Brown Advisory Incorporated

More Finance & Insurance Jobs

Find similar Cyber GRC Specialist jobs: