GRC, Vulnerability Management Analyst
Atlanta, GA - USA
Job Summary
About Acrisure
A global fintech leader Acrisure empowers millions of ambitious businesses and individuals with the right solutions to grow boldly forward. By bringing cutting-edge technology and top-tier human support together we connect clients with customized solutions across insurance reinsurance payroll benefits cybersecurity mortgage services and more.
In the last twelve years Acrisure has grown in revenue from $38 million to nearly $5 billion with over 19000 colleagues in more than 20 countries. Acrisure was built on entrepreneurial spirit. Prioritizing leadership accountability and collaboration we equip our teams to work at the highest levels possible.
Job Summary
The Cybersecurity Vulnerability Governance Analyst is responsible for governing and overseeing the organizations Vulnerability Management Program from a risk compliance and accountability perspective. This role serves as the bridge between Cybersecurity IT Operations Infrastructure Cloud Application Development and business stakeholders to ensure vulnerabilities are appropriately evaluated assigned remediated accepted or escalated according to established policies and risk tolerance.
This position does not perform engineering work and instead the analyst is responsible for vulnerability governance risk reporting metrics exception management policy adherence and executive-level visibility into the organizations vulnerability posture.
Success in this role means establishing strong accountability across the organization for vulnerability remediation while providing clear visibility into cyber risk remediation performance and program effectiveness. The analyst enables informed risk decisions supports regulatory compliance and helps reduce organizational exposure by ensuring vulnerabilities are managed in accordance with enterprise risk expectations and security governance standards.
Responsibilities:
Essential Duties and Responsibilities - Vulnerability Governance
- Govern the enterprise Vulnerability Management Program to ensure alignment with cybersecurity policies standards and risk management requirements.
- Track vulnerabilities through their lifecycle from identification through remediation mitigation risk acceptance or closure.
- Monitor vulnerability remediation performance against established service level objectives and risk-based remediation timelines.
- Facilitate regular vulnerability review meetings with infrastructure cloud endpoint application and business stakeholders.
- Coordinate remediation activities by validating ownership accountability and risk prioritization across responsible teams.
Risk Management and Exception Governance
- Review document and manage vulnerability exception requests risk acceptances and compensating control assessments.
- Evaluate business and technical justifications for remediation extensions and risk acceptance decisions.
- Ensure vulnerability risks are assessed and managed in accordance with enterprise risk tolerance and governance standards.
- Escalate overdue vulnerabilities repeat offenders and unresolved risk issues to appropriate leadership and governance forums.
- Partner with Enterprise Risk Management and Compliance teams to maintain consistent risk management practices.
Reporting Metrics and Compliance Oversight
- Develop and maintain vulnerability management dashboards scorecards and executive reporting.
- Track and report key performance indicators including remediation SLA compliance vulnerability aging exception volumes and closure rates.
- Analyze vulnerability trends recurring findings and remediation performance across business units and technology domains.
- Support internal audits external audits regulatory examinations and compliance assessments involving vulnerability management practices.
- Provide risk-based reporting and recommendations to cybersecurity leadership governance committees and executive stakeholders.
Program Governance and Continuous Improvement
- Establish and maintain vulnerability management standards procedures workflows and governance documentation.
- Drive continuous improvement initiatives that enhance program maturity accountability and operational effectiveness.
- Identify recurring control gaps and process deficiencies contributing to vulnerability exposure.
- Partner with Security Operations Security Engineering Infrastructure Application Development and Cloud teams to improve remediation processes.
- Support the development of governance policies reporting frameworks and vulnerability management program roadmaps.
Minimum Qualifications
- Bachelors degree in Cybersecurity Information Security Information Technology Risk Management Business Administration or a related field.
- 3 years of experience in cybersecurity governance risk management compliance audit or vulnerability management.
- Knowledge of vulnerability management concepts remediation workflows vulnerability prioritization and risk-based decision making.
- Understanding of cybersecurity frameworks and standards including NIST CIS Controls ISO 27001 and COBIT.
- Experience developing executive reporting metrics dashboards and performance indicators.
- Strong analytical communication and stakeholder management skills.
- Ability to coordinate activities across technical and non-technical teams.
Preferred Qualifications
- 5 years of experience supporting enterprise cybersecurity governance or vulnerability management programs.
- Experience with GRC platforms such as Archer ServiceNow MetricStream or similar solutions.
- Familiarity with vulnerability management platforms including Tenable Qualys Rapid7 Wiz or Microsoft Defender Vulnerability Management.
- Experience supporting regulatory compliance programs including SOX HIPAA NYDFS PCI-DSS SOC 2 or ISO certifications.
- Relevant certifications such as:
- CRISC
- CISA
- CISM
- CGRC
- Security
Candidates should be comfortable with an on-site presence to support collaboration team leadership and cross-functional partnership.
Why Join Us:
At Acrisure were building more than a business were building a community where people can grow thrive and make an impact. Our benefits are designed to support every dimension of your life from your health and finances to your family and future.
Making a lasting impact on the communities it serves Acrisure has pledged more than $22 million through its partnerships with Corewell Health Helen DeVos Childrens Hospital in Grand Rapids Michigan UPMC Childrens Hospital in Pittsburgh Pennsylvania and Blythedale Childrens Hospital in Valhalla New York.
Employee Benefits
We also offer our employees a comprehensive suite of benefits and perks including:
Physical Wellness: Comprehensive medical insurance dental insurance and vision insurance; life and disability insurance; fertility benefits; wellness resources; and paid sick time.
Mental Wellness: Generous paid time off and holidays; Employee Assistance Program (EAP); and a complimentary Calm app subscription.
Financial Wellness: Immediate vesting in a 401(k) plan; Health Savings Account (HSA) and Flexible Spending Account (FSA) options; commuter benefits; and employee discount programs.
Family Care: Paid maternity leave and paid paternity leave (including for adoptive parents); legal plan options; and pet insurance coverage.
and so much more!
This list is not exhaustive of all available benefits. Eligibility and waiting periods may apply to certain offerings. Benefits may vary based on subsidiary entity and geographic location.
Acrisure is an Equal Opportunity Employer. We consider qualified applicants without regard to race color religion sex national origin disability or protected veteran status. Applicants may request reasonable accommodation by contacting .
Final candidates will be required to complete post-offer verification processes related to the role and in accordance with applicable laws.
California Residents: Learn more about our privacy practices for applicants by visiting the Acrisure California Applicant Privacy Policy.
Recruitment Fraud: Please visit here to learn more about our Recruitment Fraud Notice.
Welcome your new opportunity awaits you.
Required Experience:
IC
About Company
Acrisure connects ambitious people and entrepreneurs with the insurance and business solutions they need for success.