UGI Corporation

Global Cybersecurity Senior GRC Analyst

UGI Corporation$90K — $120K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Information Security, Risk Management, Computer Science, or related field preferred.
  • Minimum of 4 years in GRC, risk management, or compliance roles.
  • Strong understanding of GRC tools (e.g., RSA Archer, ServiceNow GRC) and risk management frameworks (e.g., COBIT, FAIR).
  • Exceptional analytical, problem-solving, and organizational abilities.
  • Strong communication skills, capable of engaging with stakeholders across all levels.
  • Certifications such as CRISC, CISM, CISA, or CISSP are highly preferred.

Responsibilities

  • Develop and maintain corporate policies and procedures aligned with industry best practices.
  • Conduct gap assessments to identify threats, vulnerabilities, and impacts to the organization.
  • Maintain the risk register to document and prioritize risks for mitigation.
  • Perform assessments on third-party vendors to evaluate associated risks.
  • Ensure compliance with regulatory requirements like GDPR, HIPAA, SOX, and PCI-DSS.
  • Collaborate with business units to collect metrics for governance programs and track compliance changes.
  • Create and present regular risk and compliance metrics to senior leadership.

Benefits

  • Collaborative work environment with cross-functional team interactions.
  • Opportunity to influence governance processes and compliance metrics.
  • Exposure to industry standards and frameworks, enhancing professional growth.
  • Chance to work with advanced GRC tools and technologies.
Full Job Description
Requisition Number: 29670

Job Summary:

The Global Cybersecurity Senior GRC Analyst plays a critical role in ensuring that the organization operates within its regulatory, legal, and compliance obligations while managing risk effectively. The Global GRC Senior Analyst will report directly to the Global Cybersecurity Governance, Risk and Compliance Manager. This role involves collaborating with cross-functional teams to design, implement, and maintain governance, risk, and compliance processes. The ideal candidate is detail-oriented, analytical, and experienced in regulatory compliance, risk management frameworks, and governance best practices and must develop and apply continuous improvement strategies in all aspects of the job function.

Key Responsibilities:

Governance:
• Develop and maintain corporate policies, procedures, and frameworks to align with industry best practices (e.g., NIST CSF, SOX, PCI, etc.).
  • Assist with the development and maintenance of GRC process and procedure documentation.

• Ensure IT functions are in compliance with best practices and company policies and standards through assessments (i.e. peer reviews, audits, etc.)
  • Track key risk indicators and security metrics


Risk Management:
• Assist with conducting gap assessments to identify threats, vulnerabilities, and potential impacts on the organization.
• Develop and maintain the risk register, ensuring risks are documented, prioritized, and mitigated.
• Perform third-party/vendor risk assessments to evaluate potential risks associated with external partnerships and perform on-going monitoring to assess risk of engagement.
  • Maintain centralized documentation, continuous monitoring for vendors, formal escalation protocols for non-compliance to ensure alignment with enterprise risk tolerance.
  • Document risk acceptance decisions and compensating controls
  • Develop and maintain templates for consistent risk documentation
  • Assist in evaluating cybersecurity risk on incoming projects.
  • Assist and support team in performing cybersecurity due diligence on merger/acquisition targets.


Compliance:
• Ensure compliance with regulatory requirements (e.g., GDPR, HIPAA, SOX, PCI-DSS) and industry standards through monitoring and reporting metrics, security exceptions and using other methods to monitor compliance
• Drive compliance by maintaining the compliance framework to ensure policies and standards align to regulatory requirements, laws and best practices.

Stakeholder Engagement
  • Collaborate with business units to understand critical processes
  • Educate stakeholders on risk management concepts and frameworks
  • Partner with technical teams to validate remediation plans
  • Present risk findings to appropriate governance committees
  • Coordinate and collaborate with stakeholders to establish and track metrics for governance programs.

• Collaborate with stakeholders to monitor regulatory and industry developments to ensure

compliance with changes.
  • Coordinate and collaborate with stakeholders to track outcomes and metrics for all third-party breaches.
  • Advise stakeholders on compliance requirements and incorporate new metrics into governance life cycle process, including new tools as they are onboarded.
  • Coordinate the review of Policies and Standards through collaborating with stakeholders.


Collaboration and Reporting:
• Partner with IT, Legal, HR, and other departments to ensure alignment on risk and compliance efforts.
• Create and deliver regular risk and compliance metrics for senior leadership and boards.
• Serve as a subject matter expert (SME) for GRC-related queries and initiatives.

Qualifications:

Education and Experience:
• Bachelor's degree in Information Security, Risk Management, Computer Science, or related field, preferred.
• At least 4 years of experience in GRC, risk management, or compliance roles.

Skills and Competencies:
• Strong understanding of GRC tools and platforms (e.g., RSA Archer, ServiceNow GRC).
• Familiarity with risk management frameworks (e.g., COBIT, FAIR) and compliance standards.
• Exceptional analytical, problem-solving, and organizational skills.
• Strong written and verbal communication skills, with the ability to interact effectively with stakeholders at all levels.
• Certifications such as CRISC, CISM, CISA or CISSP highly preferred.

Key Attributes:
• Attention to detail and ability to manage multiple priorities.
• Proactive mindset with a focus on continuous improvement.
• Collaborative team player who can influence without authority.

About UGI Corporation

UGI Corporation is a holding company that operates through its subsidiaries in the energy distribution, storage, and services industries. The company's subsidiaries include UGI Utilities, AmeriGas, and UGI International. UGI Utilities provides natural gas and electric service to customers in Pennsylvania. AmeriGas is the largest retail propane marketer in the United States. UGI International distributes liquefied petroleum gas in Europe. UGI Corporation was founded in 1882 and is headquartered in King of Prussia, Pennsylvania.
Learn more about UGI Corporation
Size
11,000 employees
Market Cap
$8.6 billion
Industry
Net Income
$623 million
Founded
1882
5 Year Trend
-0.4%
Revenue
$6.4 billion
NASDAQ

Similar Jobs

More Jobs at UGI Corporation

More Information Technology Jobs

Find similar Global Cybersecurity Senior GRC Analyst jobs: