{"id":1150970,"url":"https://alion.io/job/msig-usa-lead-grc-analyst","title":"Lead GRC Analyst","company":{"id":2059232,"name":"MSIG USA","domain":"msigusa.com","url":"https://alion.io/company/msigusa","size_band":"51-200","is_staffing_agency":false,"is_intermediary":false,"listed_via":null,"ats_vendor":"Workday","truth_index":{"grade":"B","score":75,"open_postings":9,"ghost_share":0,"stale_share":1,"repost_share":0,"time_to_fill_p50_days":null,"computed_at":"2026-09-24T05:45:00Z"}},"role":"Security","role_family":"Security","seniority":"lead","employment_type":"full_time","work_mode":"hybrid","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":120000,"max_usd":262000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":182},"experience_years_min":8,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"GDPR","optional":false},{"name":"HIPAA","optional":false},{"name":"ISO 27001","optional":false},{"name":"NIST CSF","optional":false},{"name":"ServiceNow","optional":false}],"status":"live","first_seen_at":"2026-09-15T00:00:00Z","employer_posted_date":"2026-09-15","last_verified_at":"2026-09-24T12:21:59Z","board_verified":true,"closed_at":null,"days_open":9,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":9},"description":"MSIG USA continues to grow!\nCompany Overview:\nMSIG USA is the US-based subsidiary of MS&AD Insurance Group Holdings, Inc., one of the world’s top P&C carriers and a global Class 15 insurer, with A+ ratings and a reach that spans 40+ countries and regions. Leveraging our 350-year heritage, MSIG USA brings the financial strength, expertise, and global footprint to offer commercial insurance solutions that address your business’s unique risks.\nRole Overview\nMSIG is seeking a Lead , Governance, Risk & Compliance (GRC) to help run and mature core security governance, risk management, and compliance activities. This role is ideal for an experienced GRC analyst, IT risk professional, or IT auditor who is ready to take on broader ownership, mentor others, and grow into a people or program leadership position.\nThe Manager will be hands-on and execution-focused, supporting regulatory compliance, audits, IT risk management, and policy governance. While the role will contribute to leadership reporting, primary Board and executive-facing responsibilities are limited and supported by senior security leadership.\nKey Responsibilities\n1. Governance & Compliance Execution\nMaintain and operate MSIG’s security governance and compliance program \nSupport compliance with key regulations and frameworks (e.g., NYDFS 23 NYCRR 500, HIPAA, GDPR, NIST CSF, ISO 27001) \nTrack compliance obligations, evidence, and deadlines using defined processes and tools \nAssist with monitoring regulatory changes and assessing their operational impact \n2. IT Risk Management\nConduct and support IT and security risk assessments across infrastructure, applications, and cloud environments \nMaintain the IT risk register, including risk documentation, remediation tracking, and status updates \nPartner with technical teams to document controls and support risk remediation efforts \n3. Audit & Regulatory Support\nCoordinate internal and external audit activities, including evidence collection and response tracking \nSupport interactions with auditors and regulators, with senior leadership leading formal communications \nTrack audit findings and assist with remediation planning and follow-up \n4. Policy & Standards Management\nSupport the development, review, and maintenance of security and IT policies and standards \nManage policy review cycles and ensure documentation remains current and accessible \nHelp promote awareness and adoption of security policies across the organization \n5. Third-Party Risk Management (TPRM)\nPerform vendor and third-party security risk assessments \nMaintain vendor risk documentation, findings, and remediation tracking \nPartner with Procurement and Legal to support security due diligence activities \n6. Reporting & Program Support\nPrepare GRC metrics, dashboards, and summary reports for security leadership \nContribute to leadership and management-level reporting on risk and compliance posture \nSupport continuous improvement initiatives across the GRC program \nQualifications\nRequired\n5-8+ years of experience in GRC, IT risk management, IT audit, or information security \nHands-on experience with regulatory compliance, audits, or risk assessments \nWorking knowledge of NYDFS Cybersecurity Regulation (23 NYCRR 500) and at least one major framework (NIST CSF, ISO 27001, etc.) \nExperience maintaining risk registers, audit evidence, or compliance documentation \nStrong written communication skills with the ability to document risks, controls, and findings clearly \nPreferred\nExperience in insurance or financial services \nFamiliarity with GRC tools (e.g., ServiceNow GRC, Archer, OneTrust, or similar) \nExposure to cloud environments (Azure and/or AWS) \nRelevant certifications such as CISA, CRISC, CISM, or CISSP (or actively pursuing) \n\nIt's an exciting time for our company and a great opportunity to join a financially sound and growing global insurance group!\nIt is the policy of MSIG USA to provide equal employment opportunity (EEO) to all persons regardless of age, color, national origin, citizenship status, physical or mental disability, race, religion, creed, gender, sex, sexual orientation, gender identity and/or expression, genetic information, marital status, status with regard to public assistance, veteran status, or any other characteristic protected by federal, state or local law. In addition, MSIG USA will provide reasonable accommodations for qualified individuals with disabilities.","description_format":"text","description_chars":4427,"description_truncated":false,"requirements":{"experience_years_min":8,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Financial Services"],"lifecycle":[{"event":"open","at":"2026-09-23T17:40:15Z"}],"liveness":{"score":85,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.847,"p_room":1,"age_days":9,"expected_fill_days":35,"reasons":["conf:2","urgency","win:early"],"computed_at":"2026-09-24T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/msig-usa-lead-grc-analyst","json_url":"https://alion.io/job/msig-usa-lead-grc-analyst.json","meta":{"generated_at":"2026-09-24T15:18:04Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers"}}