411,234open jobs
14,368companies
73,679added this week
Browse all
Salary
$105k – $215k per year (Estimated)
Location
Remote (United States)
Seniority
Senior · 5+ years exp
Overview
Company
Impact
Profile match
Admissions Apply Academics Majors & Minors Honors College Online Programs Graduate School Campus Life Cost & Aid Cost of Attendance Tuition & Fees Merit Scholarships Other Scholarships Visit Deposit Transfer Contact Meet the Team Request Information Resources Accepted Students Parents & Family…

The University of Maine System is seeking a Cybersecurity Governance, Risk & Compliance (GRC) Analyst to join our Information Security team.

This position plays an important role in protecting the information, systems, and data that support Maine's public universities. The GRC Analyst will help advance the University of Maine System's cybersecurity governance framework, risk management processes, regulatory compliance efforts, and security awareness program.

Working across Information Technology, academic departments, administrative units, and with external partners, the Cybersecurity GRC Analyst will coordinate cybersecurity risk and compliance activities, support audit readiness, develop and maintain policies and controls, and help strengthen a culture of shared responsibility for cybersecurity throughout the University of Maine System.

This is an excellent opportunity for a cybersecurity professional who enjoys connecting technical security requirements with policy, risk management, compliance, communication, and organizational strategy.

This is a fully remote position, open to candidates who live and are authorized to work in the United States. Standard hours are Monday through Friday, 8:00 AM to 4:30 PM ET, with occasional evening or weekend work as needs arise.

What You'll Do:

  • Manage and support the institutional cybersecurity risk program, including maintaining the risk register, documenting risks, developing and tracking Plans of Action and Milestones (POA&Ms), and coordinating corrective actions with systems and data owners.
  • Manage the cybersecurity risk review process for new solutions, services, and technology acquisitions, including intake and triage of risk review requests, conducting or coordinating security risk assessments (including third-party and vendor reviews using the Higher Education Community Vendor Assessment Toolkit (HECVAT), Standard and Organization Controls (SOC) 2 reports, and similar assurance documentation), documenting findings and recommendations, and routing risk acceptance and approval decisions to the appropriate authority.
  • Map and maintain cybersecurity controls against applicable frameworks and regulatory requirements, including National Institute of Standards and Technology Special Publication (NIST SP 800-171), Center for Internet Security (CIS) Controls, Family Educational Rights and Privacy Act (FERPA), Health Insurance Portability and Accountability Act (HIPAA), Criminal Justice Information Services (CJIS), Payment Card Industry (PCI), the Gramm-Leach-Bliley Act (GLBA) Safeguards Rule, and other relevant standards.
  • Develop, review, and maintain cybersecurity policies, standards, procedures, and guidelines.
  • Monitor compliance with cybersecurity policies and regulatory obligations and coordinate audit readiness activities, including evidence collection and documentation.
  • Serve as a liaison with internal and external auditors and regulatory entities.
  • Manage cybersecurity exception and risk acceptance processes, including documentation, approvals, and periodic reviews.
  • Facilitate periodic risk reviews with risk and system owners, including re-review of accepted risks and expiring exceptions, and escalate overdue items for decision.
  • Coordinate remediation of findings identified through audits, risk assessments, and compliance reviews.
  • Develop cybersecurity metrics, dashboards, and reports that support operational monitoring, executive decision-making, and governance.
  • Lead the development and administration of cybersecurity awareness and training initiatives, including phishing simulations, enterprise-wide campaigns, onboarding and annual education, and role-based training.
  • Support cybersecurity engagement and outreach efforts, including a cybersecurity champions network and other initiatives that promote shared responsibility for security.
  • Prepare reports, briefings, and presentations for executive leadership and governance bodies regarding cybersecurity risks, compliance posture, and program effectiveness.
  • Leverage artificial intelligence and automation to improve analysis, reporting, workflows, and cybersecurity program operations.

What We Are Looking For: The successful candidate will bring knowledge of cybersecurity governance, risk management, and compliance principles along with the ability to translate complex security requirements into practical policies, processes, recommendations, and communications.

Required Qualifications

  • Bachelor's degree in Cybersecurity, Information Systems, Information Technology, Risk Management, or a related field, or an equivalent combination of education and experience.
  • Five years of professional experience in cybersecurity, IT risk management, compliance, or information security program support.
  • Experience with audit preparation and evidence documentation practices.
  • Knowledge of cybersecurity frameworks and standards, including NIST, CIS Controls, ISO standards, and applicable regulatory requirements.
  • Knowledge of cybersecurity risk assessment methodologies and security control frameworks.
  • Experience maintaining risk registers, POA&Ms, or corrective action tracking, and supporting risk acceptance or exception processes.
  • Ability to analyze cybersecurity risks and develop practical mitigation recommendations.
  • Ability to develop policies, procedures, and governance documentation.
  • Ability to develop reports, dashboards, and metrics for leadership and governance audiences.
  • Strong written communication skills, including policy documentation and executive-level reporting.
  • Ability to collaborate effectively with both technical and nontechnical stakeholders.
  • Demonstrated use of AI-assisted tools or automation to improve security workflows, processes, or reporting.
  • Familiarity with the responsible use of artificial intelligence and automation in professional environments, including appropriate data protection considerations.

Preferred Qualifications

  • Relevant governance, risk, compliance, audit, or privacy certifications, such as:
    • CISA - Certified Information Systems Auditor
    • CRISC - Certified Risk and Information Systems Control
    • CGRC - Certified in Governance, Risk, and Compliance
    • CISM - Certified Information Security Manager
    • CIPP - Certified Information Privacy Professional
    • CIPM - Certified Information Privacy Manager
  • Certification or professional development related to artificial intelligence, automation, or emerging technologies.
  • Experience working in higher education, the public sector, a multi-campus organization, or another complex enterprise IT environment.
  • Experience supporting cybersecurity governance, risk management, and compliance programs.
  • Experience with GRC platforms such as ServiceNow GRC, Isora GRC, OneTrust, or Archer, and familiarity with HECVAT for vendor security reviews.
  • Experience coordinating internal and external cybersecurity awareness and training programs.
  • Experience designing or implementing automation solutions that improve workflows, reporting, or operational efficiency.

What We Offer: Ourcomprehensive benefits package can be worth up to 50% of your annual salary and is designed to support your health, financial well-being, professional growth, and work-life balance. Benefits include:

  • Competitive salary: $65,000-$75,000 commensurate with education and experience. This is a fixed range set within a predefined wage band; therefore, we are unable to negotiate a starting salary above the posted range.
  • Comprehensive health benefits, including medical, dental, vision, flexible spending accounts (FSA), and Health Savings Account (HSA) options
  • Employer-paid benefits, including basic life insurance and long-term disability coverage, with additional voluntary coverage options available
  • Retirement plan through TIAA with 10% employer contribution and opportunities for additional tax-deferred retirement savings
  • Generous paid time off, including vacation and sick leave, plus 13 paid holidays each year
  • Tuition waiver program for employees, including graduate courses and Maine Law, plus substantial tuition discounts for eligible spouses and dependent children
  • Employee Assistance Program (EAP) and wellness programs supporting your health and well-being
  • Professional development and opportunities to grow your career within Maine's public university system
  • Additional voluntary benefits, including pet insurance, home and auto insurance discounts, and supplemental disability and life insurance options

Why Join the University of Maine System?

At the University of Maine System, technology plays a vital role in advancing education, research, and public service. As part of Information Security team, you'll have the opportunity to work on meaningful, system-wide initiatives that impact thousands of students, faculty, and staff across Maine.

Apply Today!

Materials must be submitted via “Apply Now” below. You will need to complete an application and upload the following:

  • A cover letter that describes your experience, interests, and suitability for the position.
  • A resume or curriculum vitae.

Important items to know about the recruitment process:

Review of applications will begin immediately. The position will remain open until filled. For full consideration, applications must be submitted by September 13, 2026.

  • Incomplete application materials cannot be considered.
  • Candidates selected to proceed to the final stages of the search process will be requested to provide three (3) names and contact information for references.
  • The successful applicant is subject to appropriate background screenings.

Work authorization: This position requires U.S. work authorization that does not require employer sponsorship now or in the future. We are unable to consider applicants who require visa sponsorship or OPT extensions at any point.

EEO Statement

The University of Maine System (the System) is an equal opportunity institution committed to fostering a nondiscriminatory environment and complying with all applicable nondiscrimination laws. Consistent with State and Federal law, the System does not discriminate on the basis of race, color, religion, sex, sexual orientation, transgender status, gender, gender identity or expression, ethnicity, national origin, citizenship status, familial status, ancestry, age, disability (physical or mental), genetic information, pregnancy, or veteran or military status in any aspect of its education, programs and activities, and employment. The System provides reasonable accommodations to qualified individuals with disabilities upon request. If you believe you have experienced discrimination or harassment, you are encouraged to contact the System Office of Equal Opportunity and Title IX Services at 5713 Chadbourne Hall, Room 412, Orono, ME 04469-5713, by calling 207.581.1226, or via TTY at 711 (Maine Relay System). For more information about Title IX or to file a complaint, please contact the UMS Title IX Coordinator at www.maine.edu/title-ix/.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
411,234 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$100k – $150k per year • Remote • 5+ years exp • PhD
PowerShell
Python
DevOps
Azure
Azure AKS
Azure DevOps
Bicep
CI/CD
FinOps
GitHub
GitHub Actions
Kubernetes
Service Mesh
Terraform
Cybersecurity
FedRAMP
HIPAA
PCI DSS
SOC 2
Apply
$100k – $150k per year • Remote • 6+ years exp • Bachelor's Degree
Bash
Python
DevOps
Ansible
ArgoCD
AWS
Azure
CI/CD
GCP
GitOps
Helm
Istio
Jenkins
Kubernetes
Linkerd
OpenShift
Red Hat
Service Mesh
Tekton
Terraform
Cybersecurity
HIPAA
PCI DSS
SOC 2
Apply
$100k – $150k per year • Remote • 6+ years exp • Bachelor's Degree
Python
DevOps
IAM
Terraform
Cybersecurity
CIS Benchmarks
HIPAA
ISO 27001
PCI DSS
SOC 2
Zero Trust
Apply
$120k – $170k per year • Remote • 6+ years exp • Bachelor's Degree
PowerShell
Python
DevOps
Azure
Azure AKS
Azure DevOps
Bicep
CI/CD
FinOps
GitHub
GitHub Actions
Istio
Kubernetes
Linkerd
Service Mesh
Terraform
Cybersecurity
FedRAMP
HIPAA
PCI DSS
SOC 2
Apply
$100k – $150k per year • Remote • 6+ years exp • Bachelor's Degree
Bash
Go
Python
DevOps
Ansible
ArgoCD
AWS
Azure
CI/CD
GCP
GitOps
Helm
Istio
Jenkins
Kubernetes
Linkerd
OpenShift
Red Hat
Service Mesh
Tekton
Terraform
Cybersecurity
HIPAA
PCI DSS
SOC 2
Apply
$42k per year • In office • 2+ years exp
Apply
In office • 3+ years exp
PHP
PHP
WordPress
Management
Google Drive
Apply
$36k – $89k per year (Estimated) • In office • Bachelor's Degree • Portland
PHP
PHP
WordPress
Apply
$138k – $278k per year (Estimated) • In office • 7+ years exp • Master's Degree • Portland
Apply
$60k per year • Remote • 5+ years exp • Bachelor's Degree
Apply
See all jobs
This is one of many
411,234 more open roles from verified company boards, updated every day.