Selective Insurance Group Inc

Vulnerability Management Specialist- GRC (Hybrid)

Selective Insurance Group Inc$116K — $157K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Working understanding of cybersecurity and risk management concepts.
  • Ability to evaluate and escalate potential risk concerns.
  • Strong attention to detail and document handling capabilities.
  • Clear communication skills for presenting information to stakeholders.
  • Proficiency in Microsoft Office, with GRC tools experience preferred.

Responsibilities

  • Execute GRC activities such as risk documentation and assessment record maintenance.
  • Support the policy lifecycle by coordinating updates and input collection.
  • Prepare materials for audit discussions and compliance reporting.
  • Coordinate vendor assessment intake and due diligence communications.
  • Review vendor documentation for completeness and risk relevance.
  • Support vulnerability governance by tracking remediation and exception requests.
  • Collect and validate audit evidence to meet control objectives.

Benefits

  • Comprehensive health care plans for employees and families.
  • Retirement savings plan with company match.
  • Discounted Employee Stock Purchase Program.
  • Tuition assistance and reimbursement opportunities.
  • 20 days of paid time off.
Full Job Description
Overview

The GRC, Third-Party Risk, Vulnerability Management Analyst performs established governance, risk, compliance, vendor risk, and vulnerability management activities with increasing independence. This role is designed for a developing risk professional who can execute risk assessments, analyze control evidence, support regulatory and audit requirements, coordinate remediation tracking, and produce clear reporting for stakeholders. The role applies working knowledge of cybersecurity controls, risk frameworks, third-party due diligence, vulnerability governance, and issue management to support consistent, defensible risk decisions.

Responsibilities

GRC Program Execution
  • Execute assigned GRC activities, including risk documentation, control mapping, exception tracking, and assessment record maintenance.
  • Support policy, standard, and procedure lifecycle activities by coordinating updates, collecting input, and validating evidence of approvals.
  • Prepare materials for governance forums, risk reviews, audit discussions, and compliance reporting using established templates and data sources.

Third-Party Risk Management
  • Coordinate vendor assessment intake, due diligence requests, follow-ups, and stakeholder communications through closure.
  • Review vendor questionnaires, SOC reports, ISO certifications, penetration test summaries, vulnerability information, business continuity documentation, and other due diligence artifacts for completeness and risk relevance.
  • Document assessment conclusions, remediation items, missing evidence, and residual risk considerations in alignment with defined TPRM procedures.

Vulnerability Management Governance
  • Support vulnerability governance activities by tracking remediation status, exception requests, risk acceptance documentation, and aging issues.
  • Partner with technology and risk stakeholders to validate ownership, required evidence, and remediation progress for identified vulnerabilities or control gaps.
  • Contribute to recurring metrics and reporting related to vulnerability trends, overdue remediation, exception volume, and issue closure.

Audit and Compliance Support
  • Collect, organize, and validate audit evidence in accordance with defined control objectives and regulatory expectations.
  • Assist with remediation tracking for audit findings, control gaps, risk acceptances, and compliance action items.
  • Maintain documentation aligned to frameworks and requirements such as NIST CSF, NIST 800-53, NYDFS, GLBA, SOX, SOC reporting, and ISO 27001.

Metrics and Continuous Improvement
  • Maintain and enhance routine metrics for risk assessment volume, vendor status, vulnerability remediation, open issues, and documentation completeness.
  • Identify opportunities to improve templates, procedures, evidence requests, stakeholder instructions, and process consistency.
  • Support process improvement efforts by documenting pain points, recommending practical updates, and helping implement approved changes.

Qualifications

Required
  • Working understanding of cybersecurity, risk management, compliance, vulnerability management, audit, or third-party risk concepts.
  • Ability to evaluate common security evidence, identify incomplete or inconsistent information, and escalate potential risk concerns.
  • Strong attention to detail, documentation discipline, and ability to manage multiple assessment or remediation activities concurrently.
  • Clear written and verbal communication skills, including the ability to summarize technical or control information for business stakeholders.
  • Proficiency with Microsoft Office; experience with GRC, vendor risk, vulnerability management, ticketing, or reporting tools is preferred.

Preferred
  • 3-5 years of experience in GRC, cybersecurity, third-party risk, vulnerability management, audit, compliance, procurement risk, or vendor management.
  • Experience contributing to audits, regulatory compliance activities, control testing, risk assessments, or vendor due diligence reviews.
  • Familiarity with frameworks and regulations such as NIST CSF, NIST 800-53, NYDFS, GLBA, SOX, SOC reporting, ISO 27001, or related standards.
  • Relevant certification or progress toward a certification such as CRISC, CISA, Security+, CDPSE, CTPRP, or similar is a plus.

Total Rewards

Selective Insurance offers a total rewards package that includes a competitive base salary, incentive plan eligibility at all levels, and a wide array of benefits designed to help you and your family stay healthy, achieve your financial goals, and balance the demands of your work and personal life. These benefits include comprehensive health care plans, retirement savings plan with company match, discounted Employee Stock Purchase Program, tuition assistance and reimbursement programs, and 20 days of paid time off. Additional details about our total rewards package can be found by visiting our benefits page.

The actual base salary is based on geographic location, and the range is representative of salaries for this role throughout Selective's footprint. Additional considerations include relevant education, qualifications, experience, skills, performance, and business needs.

Pay Range

USD $116,000.00 - USD $157,000.00 /Yr.

About Selective Insurance Group Inc

Selective Insurance Group, Inc. is a holding company for ten property and casualty insurance companies. The company provides insurance products and services to businesses, non-profit organizations, and individuals. Selective Insurance Group has been in business for over 90 years and has a strong reputation for customer service and financial stability. The company is headquartered in Branchville, New Jersey, and has over 2,450 employees. Selective Insurance Group is committed to giving back to the communities where it operates and has a strong focus on corporate social responsibility. The company is publicly traded on the NASDAQ stock exchange under the ticker symbol SIGI.
Learn more about Selective Insurance Group Inc
Size
2,440 employees
Market Cap
$5.4 billion
Industry
Net Income
$246.3 million
Founded
1926
5 Year Trend
+6.9%
Revenue
$2.9 billion
NASDAQ

Similar Jobs

More Jobs at Selective Insurance Group Inc

More Information Technology Jobs

Find similar Vulnerability Management Specialist- GRC (Hybrid) jobs: