
GRC Analyst
AXIS Capital
Job description
This is your opportunity to join AXIS Capital โ a trusted global provider of specialty lines insurance and reinsurance. We stand apart for our outstanding client service, intelligent risk taking and superior risk adjusted returns for our shareholders. We also proudly maintain an entrepreneurial, disciplined and ethical corporate culture. As a member of AXIS, you join a team that is among the best in the industry.
At AXIS, we believe that we are only as strong as our people. We strive to create an inclusive and welcoming culture where employees of all backgrounds and from all walks of life feel comfortable and empowered to be themselves. This means that we bring our whole selves to work.
All qualified applicants will receive consideration for employment without regard to any protected characteristic, including age, color, disability, ethnicity, gender identity, marital status, national origin, pregnancy, race, religion, sex, sexual orientation, veteran status, or any basis prohibited by the laws that govern its operations.
Job Description: GRC Analyst
How does this role contribute to our collective success?
Job Description:
The Security Awareness and Training (SAT) team, part of IRM Governance, Risk, and Compliance (GRC), helps improve overall cyber resilience by strengthening secure behaviors across AXIS. In this role, you will support the day-to-day execution and continuous improvement of our security awareness and training program, helping employees and contractors recognize and respond to threats like phishing and social engineering. You will contribute to operational delivery, communications, metrics, and insights that help leaders understand program effectiveness and prioritize risk-reducing improvements
What will you do in this role?
Job Responsibilities:
-
Support the planning, execution, and quality checks of simulated phishing and social engineering campaigns (for example, email phishing and other simulation types as applicable), including operational setup, testing, campaign scheduling, targeting, and post-campaign follow-up.
-
Support assignment of follow-up and remedial training based on campaign outcomes, including tracking repeat-risk behaviors and completion of assigned learning.
-
Assist with administration of awareness and training activities (onboarding, mandatory training, assignment tracking, learner support, and coordination) using AXIS learning platforms.
-
Support intake and triage of user-reported phishing submissions and awareness-related inquiries, including coordination of follow-ups aligned to program processes.
-
Draft and coordinate awareness communications (campaign notices, advisories, and user education content) in a clear, user-friendly format, and support multi-channel campaigns (for example, webinars and internal communications).
-
Support creation and maintenance of awareness materials (newsletters, intranet articles, micro-learning, and role-based messaging), including development of multimedia content (for example, infographics and short videos) as needed.
-
Help produce recurring awareness program reporting and dashboards, including click and report behaviors, credential submission trends, training completion, and other effectiveness indicators (for example, participation and user feedback where applicable).
-
Assist with analysis of program outcomes and behavioral signals to identify trends, training gaps, and improvement opportunities to support risk-informed program adjustments.
-
Maintain audit-ready documentation and records of campaign execution, results, and training completion to support compliance and reporting needs.
-
Support coordination with awareness and training vendors (as needed) for operational follow-ups, content updates, and scheduling support.
-
Partner with stakeholders across Information Security, Risk, HR, and business teams to support program goals and delivery.
-
You may also be required to take on additional GRC duties, responsibilities and activities appropriate to the nature of this role.
About You
We encourage you to bring your own experience and expertise to the table. While there are some qualifications and experiences we need you to have, we are open to discussing how your individual knowledge can help you be successful in this role and support AXIS goals.
What You Need To Have
-
Bachelorโs degree in Cybersecurity, Information Security, Computer Science, or a related discipline (or equivalent practical experience).
-
Foundational understanding of common cyber threats and controls, including phishing, social engineering, identity and access management (IAM), multifactor authentication (MFA), and data protection concepts.
-
Ability to work with data and translate results into clear, metrics-driven updates for stakeholders.
-
Ability to communicate security concepts clearly in user-facing messages and stakeholder summaries.
-
Strong organization skills, attention to detail, and ability to manage multiple priorities with moderate supervision.
What We Prefer You To Have
-
Exposure to phishing simulation and awareness platforms.
-
Familiarity with enterprise learning platforms.
-
Familiarity with a cybersecurity framework (for example, the NIST Cybersecurity Framework).
-
Entry-level cybersecurity certification (for example, ISC2 Certified in Cybersecurity (CC) or CompTIA Security+).
Role Factors
In this role, you will typically be required to:
- Work in a hybrid capacity with 3 days in person, at the Stamford office in CT.
What We Offer
For this position, we currently expect to offer a base salary in the range of
US$75,000 to $80,000 (CT)
. Your salary offer will be based on an assessment of a variety of factors including your specific experience and work location. In addition, you will be offered competitive target incentive compensation, with awards based on overall corporate performance and individual performance. You will also be eligible for a comprehensive and competitive benefits package.
Where this role is based in the United States of America, this role is
[Exempt/Non-Exempt]
for FLSA purposes.
This posting is for an existing vacancy.