Information Security GRC Analyst - Sugar Land or Lubbock

Internal Applicants: If you are a current associate of Prosperity Bank, please apply through the internal Talent - Career Center in ADP. Prosperity Bank is an Equal Opportunity Employer.
POSITION PURPOSE
The Information Security Governance, Risk, and Compliance (IS GRC) Analyst is responsible for supporting the execution of the Bank's Information Security Governance, Risk, and Compliance program. This role performs and supports information security governance, cyber risk management, policy and standards administration, regulatory compliance, third-party cybersecurity risk management, control framework activities, audit and examination support, risk exception processes, remediation tracking, and security metrics and reporting.
Working closely with the IS GRC Manager, Lead IS GRC Analyst, Enterprise Risk Management (ERM), Information Technology (IT), Vendor Management (VM), Human Resources (HR), Internal Audit (IA), Legal, Compliance, Procurement, and business stakeholders, the IS GRC Analyst supports the implementation, administration, and continuous improvement of information security governance processes and controls. The role assists with security risk assessments, control evaluations, third-party cybersecurity risk management activities, audit and examination support, risk exception administration, remediation tracking, and security reporting while helping ensure alignment with applicable laws, regulations, industry frameworks, and organizational requirements.
This position reports directly to the IS GRC Manager.
ESSENTIAL FUNCTIONS AND BASIC DUTIES
- Support day-to-day execution of the Bank's IS GRC program and related governance, risk, compliance, and reporting activities.
- Assist with the administration and maintenance of Information Security policies, standards, procedures, control documentation, and governance processes.
- Conduct and document information security risk assessments, control evaluations, and risk analyses for technology solutions, business initiatives, third parties, and other assigned activities.
- Support the Information Security risk register by documenting identified risks, remediation activities, treatment decisions, status updates, and supporting evidence.
- Support the Security Exception and Risk Acceptance process by collecting information, documenting compensating controls, tracking mitigation activities, and preparing management reporting.
- Support Information Security compliance and control framework activities, including assessments and reporting related to the CRI Profile, NIST CSF, NIST Special Publications, CIS Critical Security Controls, FFIEC guidance, and other applicable standards.
- Support internal audits, external audits, regulatory examinations, independent assessments, and control reviews by gathering evidence, preparing documentation, tracking responses, and monitoring remediation activities.
- Conduct third-party cybersecurity risk management activities, including cybersecurity due diligence reviews, inherent risk assessments, assurance evidence reviews, issue tracking, and ongoing monitoring.
- Analyze cybersecurity, GRC, risk, control, and third-party risk data to identify trends, control weaknesses, concentrations, emerging risks, and opportunities for program improvement.
- Assist with the development and reporting of KRIs, KPIs, security metrics, dashboards, and management reports.
- Monitor emerging cybersecurity threats, regulatory developments, control framework changes, and industry practices and escalate relevant observations as appropriate.
- Communicate security risks, control issues, findings, recommendations, and status updates clearly to technical and non-technical stakeholders.
- Build and maintain effective working relationships with Information Technology, Enterprise Risk Management, Vendor Management, Compliance, Legal, Procurement, Internal Audit, and business stakeholders.
The above statements describe the general nature and level of work only. They are not an exhaustive list of all required responsibilities, duties, and skills. Other duties may be added, or this job description may be amended at any time.
SUPERVISORY RESPONSIBILITIES:
This position does not have direct supervisory responsibilities.
QUALIFICATIONS
Education/Certification: Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, a related discipline, or the equivalent of combined education and related work experience.
Professional certifications such as CISSP, CRISC, CGRC, CISA, Security+, or equivalent certifications are preferred.
Experience Required: Minimum of 2 years of experience in information security, cybersecurity governance, risk management, compliance, information technology auditing, or a related field.
Experience supporting information security governance, risk management, compliance, control assessment, audit, examination, or third-party cybersecurity risk management activities.
Experience applying information security and risk management frameworks and standards, including the Cyber Risk Institute (CRI) Profile, NIST Cybersecurity Framework (CSF), FFIEC guidance, CIS Critical Security Controls, ISO standards, or similar industry frameworks.
Experience conducting security risk assessments, control evaluations, risk analyses, remediation tracking, security exception reviews, or related governance and risk management activities.
Experience supporting internal audits, external audits, regulatory examinations, compliance initiatives, or independent assessments.
Experience reviewing and assessing cybersecurity controls, policies, procedures, third-party security documentation, or related assurance evidence.
Experience creating, maintaining, or supporting policy, standard, procedure, governance, or risk management documentation.
Demonstrated ability to successfully execute assignments and initiatives in a complex and highly regulated environment.
Experience with GRC platforms, workflow automation, reporting, or data analysis tools preferred.
Banking or financial services industry experience strongly preferred.
Required Knowledge: Knowledge of information security governance, policy management, risk management, compliance, control assessment methodologies, and accountability structures.
Knowledge of information security control design, implementation, testing, and effectiveness assessment across governance, operational, and technical domains.
Knowledge of risk-based control assessment and testing techniques, including evidence evaluation, validation, documentation, and quality review.
Working knowledge of banking cybersecurity regulatory expectations and industry frameworks, including NIST, FFIEC, GLBA, and applicable state and federal requirements.
Knowledge of the CRI Profile, NIST Cybersecurity Framework (CSF), NIST risk management publications, CIS Critical Security Controls, and recognized cybersecurity control frameworks.
Knowledge of cybersecurity threats, vulnerabilities, attack techniques, technology risks, and risk assessment methodologies sufficient to evaluate control adequacy and business impact.
Broad knowledge of enterprise technology and security architecture sufficient to assess risks across infrastructure, applications, cloud services, identity, data, and security technologies.
Knowledge of third-party and cybersecurity supply-chain risk management, including due diligence, contractual controls, assurance reviews, monitoring, concentration risk, and exit considerations.
Knowledge of cyber resilience, business continuity, disaster recovery, backup, dependency, and recovery control concepts.
Knowledge of cybersecurity metrics, KRIs, control performance measures, governance reporting, GRC platforms, dashboard development, and data analysis techniques.
Working knowledge of privacy and data protection requirements relevant to information security risk and control oversight.
Skills/Abilities: Excellent written, verbal, and presentation skills with the ability to communicate
complex security and risk concepts to technical and non-technical audiences.
Ability to discuss cybersecurity, risk, compliance, and control matters with technical teams, business stakeholders, and management.
Willingness to work beyond standard business hours when necessary.
Ability to effectively manage multiple assignments, priorities, and projects concurrently.
Strong analytical skills with the ability to apply critical thinking and professional judgment.
Ability to independently assess security controls, identify deficiencies, and develop well-supported conclusions regarding control effectiveness.
Ability to analyze cybersecurity risks and translate technical and control issues into business-relevant risk conclusions.
Ability to research, analyze, and resolve complex issues with minimal supervision and escalate matters as appropriate.
Ability to collect, verify, validate, and critically evaluate evidence and data for sufficiency, reliability, relevance, consistency, and conformance with laws, regulations, policies, standards, and control requirements.
Ability to perform security risk assessments, control evaluations, third-party cybersecurity reviews, and related governance and risk management activities.
Ability to prepare clear, concise, and defensible observations, risk statements, recommendations, reports, and supporting documentation.
Ability to build effective working relationships while maintaining appropriate independence, objectivity, and constructive challenge.
Ability to interpret regulatory, policy, framework, and contractual requirements and translate them into practical security expectations and assessment criteria.
PHYSICAL ACTIVITIES AND REQUIREMENTS OF THIS POSITION
Talking: Especially where one must frequently convey detailed or important instructions or ideas accurately, loudly, or quickly.
Average Hearing: Able to hear average or normal conversations and receive ordinary information.
Repetitive Motion: Movements frequently and regularly required using the wrists, hands, and/or fingers.
Average Visual Abilities: Average, ordinary, visual acuity necessary to prepare or inspect documents or products, or operate machinery.
Physical Strength: Sedentary work; sitting most of the time. Exerts up to 10 lbs. of force occasionally. (Almost all office jobs.)
WORKING CONDITIONS
None: No hazardous or significantly unpleasant conditions (such as in a typical office).
MENTAL ACTIVITIES AND REQUIREMENTS OF THIS POSITION
Reasoning Ability: Ability to apply logical or scientific thinking to define problems, collect data establish facts and draw conclusions.
Able to interpret a variety of technical instructions and can deal with multiple variables.
Mathematics Ability: Ability to compute discount, interest, profit, and loss; commission markup and selling price; and ratio, proportion, and percentage.
Able to perform very simple algebra.
Language Ability: Ability to read periodicals, journals, manuals, dictionaries, thesauruses, and encyclopedias.
Ability to prepare business letters, proposals, summaries, and reports using prescribed format and conforming to all rules of punctuation, grammar, diction, and style.
Ability to conduct training, communicates at panel discussions, and make professional presentations.
Monday - Friday: 8:00AM - 5:00PM
40 hours
You'll be redirected to
the company's application page