Lead GRC Analyst

MSIG Holdings USA, Inc.

$110K — $130K *
Finance & Insurance
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5–8+ years in GRC, IT risk management, IT audit, or information security
  • Hands-on experience with regulatory compliance, audits, or risk assessments
  • Familiarity with NYDFS Cybersecurity Regulation (23 NYCRR 500) and a major framework
  • Experience with maintaining risk registers, audit evidence, or compliance documentation
  • Strong written communication skills to document risks and controls clearly

Responsibilities

  • Maintain and operate MSIG’s security governance and compliance program
  • Support compliance with key regulations and frameworks (e.g., HIPAA, GDPR, NIST CSF)
  • Track compliance obligations and deadlines using defined processes
  • Conduct IT and security risk assessments across various environments
  • Maintain the IT risk register and support remediation tracking
  • Coordinate internal and external audit activities
  • Support development and review of security policies and standards

Benefits

  • Opportunity for mentorship and leadership growth
  • Hands-on role with execution focus
  • Engagement with a variety of regulatory frameworks
  • Supportive environment for career development
  • Collaborative work with technical and compliance teams
Full Job Description

MSIG USA continues to grow! 

Role Overview

MSIG is seeking a Lead, Governance, Risk & Compliance (GRC) to help run and mature core security governance, risk management, and compliance activities. This role is ideal for an experienced GRC analyst, IT risk professional, or IT auditor who is ready to take on broader ownership, mentor others, and grow into a people or program leadership position. 

The Manager will be hands-on and execution-focused, supporting regulatory compliance, audits, IT risk management, and policy governance. While the role will contribute to leadership reporting, primary Board and executive-facing responsibilities are limited and supported by senior security leadership. 

Key Responsibilities

1. Governance & Compliance Execution

  • Maintain and operate MSIG’s security governance and compliance program 
  • Support compliance with key regulations and frameworks (e.g., NYDFS 23 NYCRR 500, HIPAA, GDPR, NIST CSF, ISO 27001) 
  • Track compliance obligations, evidence, and deadlines using defined processes and tools 
  • Assist with monitoring regulatory changes and assessing their operational impact 

2. IT Risk Management

  • Conduct and support IT and security risk assessments across infrastructure, applications, and cloud environments 
  • Maintain the IT risk register, including risk documentation, remediation tracking, and status updates 
  • Partner with technical teams to document controls and support risk remediation efforts 

3. Audit & Regulatory Support

  • Coordinate internal and external audit activities, including evidence collection and response tracking 
  • Support interactions with auditors and regulators, with senior leadership leading formal communications 
  • Track audit findings and assist with remediation planning and follow-up 

4. Policy & Standards Management

  • Support the development, review, and maintenance of security and IT policies and standards 
  • Manage policy review cycles and ensure documentation remains current and accessible 
  • Help promote awareness and adoption of security policies across the organization 

5. Third-Party Risk Management (TPRM)

  • Perform vendor and third-party security risk assessments 
  • Maintain vendor risk documentation, findings, and remediation tracking 
  • Partner with Procurement and Legal to support security due diligence activities 

6. Reporting & Program Support

  • Prepare GRC metrics, dashboards, and summary reports for security leadership 
  • Contribute to leadership and management-level reporting on risk and compliance posture 
  • Support continuous improvement initiatives across the GRC program 

Qualifications

Required

  • 5–8+ years of experience in GRC, IT risk management, IT audit, or information security 
  • Hands-on experience with regulatory compliance, audits, or risk assessments 
  • Working knowledge of NYDFS Cybersecurity Regulation (23 NYCRR 500) and at least one major framework (NIST CSF, ISO 27001, etc.) 
  • Experience maintaining risk registers, audit evidence, or compliance documentation 
  • Strong written communication skills with the ability to document risks, controls, and findings clearly 

Preferred

  • Experience in insurance or financial services 
  • Familiarity with GRC tools (e.g., ServiceNow GRC, Archer, OneTrust, or similar) 
  • Exposure to cloud environments (Azure and/or AWS) 
  • Relevant certifications such as CISA, CRISC, CISM, or CISSP (or actively pursuing) 




Similar Jobs

More Jobs at MSIG Holdings USA, Inc.

More Finance & Insurance Jobs

Find similar Lead GRC Analyst jobs: