Hard Rock International logo

Cyber Compliance Analyst III

Hard Rock International

On-siteDavie, FLseniorPosted 7h ago

Job description

Our team members are the key to our company’s success, and their health and well-being, as well as that of their families, is very important to us. We offer a comprehensive benefits package that allows our team members stay healthy, plan for their future and maintain a healthy work-life balance. Benefits may vary with employment status. To see our fill list of Team Member Benefits please visit our career site: www.gotoworkhappy.com/benefits

Job Description:

The Cybersecurity Governance Analyst III is a key member of the Cybersecurity Strategy & Governance function responsible for improving cybersecurity governance programs, processes, reporting, governance technologies, and technology-enabled workflows.

This role requires a strong understanding of cybersecurity principles, technologies, operational practices, and governance disciplines, with the ability to work across cybersecurity functions and translate requirements, risks, controls, and operational needs into practical and scalable governance solutions.

The ideal candidate combines cybersecurity governance, process engineering, business analysis, technology administration, automation, data analytics, and human risk management experience. The individual should be comfortable working directly with governance and security awareness platforms, developing workflows and automation, building dashboards and reporting, leveraging AI-enabled tools, and identifying opportunities to improve operational effectiveness, program maturity, and user experience across cybersecurity functions.

Key Responsibilities

Governance & Process Management

  • Develop and maintain cybersecurity governance artifacts, including policies, standards, procedures, workflows, playbooks, templates, job aids, and knowledge resources.

  • Lead process engineering efforts by analyzing current-state processes, identifying process and control gaps, translating cybersecurity and business requirements into future-state designs, and implementing sustainable improvements.

  • Manage cybersecurity governance processes, including issue management, remediation tracking, exception management, action governance, and stakeholder follow-up, ensuring commitments are tracked through resolution.

  • Use metrics, stakeholder feedback, and operational data to evaluate process effectiveness and identify improvement opportunities.

  • Partner with cybersecurity teams and business stakeholders to drive governance initiatives and workstreams through completion.

  • Support the Cybersecurity Maturity Assessment (CMA) program, including assessment coordination, data collection, analysis, maturity scoring, action tracking, reporting, and continuous improvement activities.

  • Analyze maturity assessment results, control effectiveness data, and remediation progress to identify trends, gaps, risks, and opportunities for improvement.

Governance Technology & Enablement

  • Configure, administer, and improve governance, GRC, security awareness, and related platforms that support cybersecurity governance processes and programs.

  • Translate governance requirements into workflows, forms, approvals, notifications, dashboards, reporting, and other technology-enabled solutions.

  • Identify and implement opportunities to improve governance through workflow automation, low-code/no-code technologies, analytics, and AI-enabled capabilities.

  • Partner with technical teams and vendors to troubleshoot issues, support integrations, and enhance governance solutions.

Human Risk Management & Security Awareness

  • Support and administer the cybersecurity human risk management and security awareness program, including phishing simulations, awareness activities, communications, platform administration, metrics, and reporting.

  • Configure and manage security awareness platforms, including user administration, campaign setup, troubleshooting, and operational support.

  • Analyze human risk and awareness performance to identify trends and opportunities to improve program effectiveness.

  • Coordinate with vendors and internal stakeholders to resolve issues and support program enhancements.

Reporting, Analytics & Program Support

  • Develop cybersecurity governance dashboards, scorecards, KPIs, KRIs, and recurring reporting to support performance measurement and leadership decision-making.

  • Analyze governance and operational data to identify trends, risks, and actionable insights.

  • Support cybersecurity strategic initiatives, roadmap activities, governance projects, and process improvement efforts through research, analysis, documentation, and coordination.

  • Research cybersecurity frameworks, industry practices, emerging technologies, and governance approaches to support recommendations and program maturity.

Required Qualifications

  • Bachelor’s degree in Cybersecurity, Information Technology, Information Systems, Business, Risk Management, Process Engineering, or a related field; or an equivalent combination of education and experience.

  • 5+ years of relevant experience in cybersecurity governance, GRC, IT governance, process improvement, security awareness, risk management, compliance, cybersecurity operations, or a related discipline.

  • Strong understanding of cybersecurity governance, policies and standards, risk and issue management, controls, process management, and performance reporting.

  • Strong working knowledge of cybersecurity principles, technologies, and operational practices.

  • Demonstrated experience independently managing governance activities, operational responsibilities, or cross-functional workstreams.

  • Experience documenting, analyzing, and improving cybersecurity or IT processes.

  • Hands-on experience working with technology platforms, including configuration, administration, workflow development, reporting, troubleshooting, or operational support.

  • Working knowledge of workflow automation, system integrations, data flows, APIs, and related technical concepts.

  • Experience developing dashboards, metrics, reporting, and actionable insights from governance, operational, or cybersecurity data.

  • Practical experience using AI-enabled tools to improve analysis, documentation, reporting, workflow development, or operational efficiency.

  • Strong analytical, problem-solving, communication, facilitation, and stakeholder management skills.

  • Ability to manage multiple priorities and deliver high-quality work with limited supervision.

Preferred Qualifications

  • Experience with GRC, security awareness, workflow, or reporting platforms such as Onspring, ServiceNow GRC/IRM, Archer, Hoxhunt, Proofpoint, KnowBe4, Power BI, or similar technologies.

  • Experience with low-code/no-code automation tools such as Microsoft Power Automate, Power Apps, ServiceNow Flow Designer, or comparable workflow technologies.

  • Experience using enterprise generative AI, copilots, AI agents, or AI-enabled automation in cybersecurity, governance, or business workflows.

  • Experience with business process modeling and design, including current-state and future-state mapping, swimlane diagrams, workflow analysis, and BPMN 2.0 or similar modeling standards, using tools such as Microsoft Visio, Lucidchart, Signavio, Bizagi, or comparable platforms.

  • Experience applying process improvement methodologies and analytical techniques such as Lean, Six Sigma, SIPOC, value stream mapping, root cause analysis, and continuous improvement practices to identify inefficiencies and optimize business processes.

  • Familiarity with API concepts, integrations, data mapping, and related technical concepts.

  • Experience supporting cybersecurity audits, assessments, or compliance activities, including SOC 1, SOC 2, PCI DSS, ISO 27001, internal audits, or similar assurance programs.

  • Familiarity with cybersecurity frameworks such as NIST Cybersecurity Framework (CSF), CIS Controls, ISO/IEC 27001, PCI DSS, or COBIT.

  • Experience developing cybersecurity metrics, dashboards, scorecards, and leadership or executive-level reporting.

Preferred Certifications

  • Certified Information Systems Security Professional (CISSP) — strongly preferred

  • Certified Information Security Manager (CISM)

  • Certified in Governance, Risk and Compliance (CGRC)

  • Certified in Risk and Information Systems Control (CRISC)

  • Certified Information Systems Auditor (CISA)

  • CompTIA Security+

  • ISC2 Certified in Cybersecurity (CC)

  • Lean Six Sigma Green Belt or higher

  • Project Management Professional (PMP) or equivalent project/program management certification