Associates Degree in Computer and Information Science or Management Information Systems; Bachelor's preferred.
3+ years in cybersecurity governance, risk, compliance, or related fields.
Strong knowledge of ISO/IEC 27001, NIST CDF, NIST SP 800-53, COBIT, or similar frameworks.
Familiarity with Microsoft 365.
Experience managing regulatory requirements and supporting audits.
Strong organizational and documentation skills with attention to detail.
Excellent written and verbal communication skills for engaging senior leadership.
Responsibilities
Lead the development and review of cybersecurity policies and standards to align with regulations and business goals.
Maintain the cybersecurity control framework and centralized controls library.
Ensure compliance control mapping between regulatory requirements and internal objectives.
Support regulatory change management, including tracking and updating policies and controls.
Maintain a repository of cybersecurity requirements for auditability and regulatory examinations.
Manage governance processes for consistent execution of GRC activities across functions.
Align cybersecurity governance practices with enterprise risk appetite and strategic objectives.
Collaborate with Risk, Compliance, Security Operations, IT, Legal, and Enterprise Risk teams to implement governance requirements effectively.
Provide governance-related reporting and decision support to leadership and executive committees.
Benefits
Opportunity to shape and mature the enterprise cybersecurity governance framework.
Engagement with cross-functional teams, enhancing collaboration skills.
Exposure to regulatory change management and compliance processes.
Access to a centralized repository of governance artifacts for professional development.
Potential for career advancement in a critical area of cybersecurity.
Full Job Description
The Sr. IT Cybersecurity Governance Analyst is responsible for establishing, maintaining, and maturing the enterprise cybersecurity governance framework. This role provides structure, consistency, and oversight across policies, standards, control frameworks, and regulatory requirements to ensure alignment with business objectives, risk appetite, and external obligations. The individual leads policy and standards management, maintains the cybersecurity control framework and controls library, oversees regulatory change management, and ensures governance processes are integrated into enterprise decision-making and risk management activities.
What will you do?
Lead development, maintenance, and periodic review of enterprise cybersecurity policies, standards, and procedures to ensure alignment with regulatory requirements, industry frameworks, and business objectives.
Maintain the enterprise cybersecurity control framework and centralized controls library aligned to standards such as ISO/IEC 27001 and NIST SP 800-53.
Ensure traceability between regulatory, legal, and contractual requirements and internal control objectives through structured compliance control mapping.
Support regulatory change management activities, including identification, tracking, impact assessment, and coordination of required updates to policies, controls, procedures, and documentation.
Maintain a centralized repository of cybersecurity requirements and governance artifacts to support auditability and regulatory examinations.
Manage governance processes that support consistent execution of GRC activities across cybersecurity, IT, and business functions.
Ensure cybersecurity governance practices align with enterprise risk appetite, strategic objectives, and enterprise risk management (ERM) processes.
Partner with Risk, Compliance, Security Operations, IT, Legal, and Enterprise Risk teams to ensure governance requirements are understood and implemented effectively.
Support leadership and executive committees by providing governance-related reporting, updates, and decision support.
Promote consistency, accountability, and ownership across cybersecurity governance activities.
What do you need for this role?
Associates Degree required, major inComputer and Information Science, orManagement Information Systems. Bachelors Degree preferred.
3+ years experience in cybersecurity governance, risk, compliance, or related disciplines..
Strong knowledge of ISO/IEC 27001, NIST CDF, NIST SP 800-53, COBIT, or similar governance framework
Microsoft 365
US -ITIL V3 6 Other preferred
Experience managing regulatory requirements and supporting regulatory examinations or audits.
Strong organizational and documentation skills with attention to detail.
Excellent written and verbal communication skills, with ability to engage senior leadership and cross-functional stakeholders.
About The Mosaic Company
The Mosaic Company is a producer and marketer of concentrated phosphate and potash crop nutrients. Mosaic is the largest producer of finished phosphate products in North America and one of the largest potash producers in the world. The company also owns and operates mines in South America and has investments in fertilizer production operations in China. Mosaic is headquartered in Plymouth, Minnesota, and has operations in six countries.