← back to jobs
> job detail
P
👽Other

Lead Information Security GRC Analyst

Prosperity-Bank-0641fe9c · LUBBOCK ANNEX, Lubbock, TX, US | SUGAR LAND-EAST LAWN, Sugar Land, TX, US
// classified as
Other (Adjacent or hard to classify.)
posted
1d ago
location
LUBBOCK ANNEX, Lubbock, TX, US | SUGAR LAND-EAST LAWN, Sugar Land, TX, US
languages
tools
> description
External Applicants: Please apply through Prosperity Bank's Career Center at https://www.prosperitybankusa.com/Careers. Applying through any other source may prevent Prosperity from receiving your application. 

Internal Applicants: If you are a current associate of Prosperity Bank, please apply through the internal Talent - Career Center in ADP. Prosperity Bank is an Equal Opportunity Employer.

POSITION PURPOSE

 

The Lead Information Security Governance, Risk, and Compliance (IS GRC) Analyst is responsible for coordinating and supporting the execution of the Bank’s IS GRC program. This role serves as a senior analyst and technical lead for IS GRC activities, including information security governance, cyber risk management, security policies and standards, regulatory compliance, third-party cybersecurity risk management, control framework implementation, audit support, and security reporting.


Working closely with the IS GRC Manager, Enterprise Risk Management (ERM), Information Technology (IT), Vendor Management (VM), Human Resources (HR), Internal Audit (IA), Legal, Compliance, Procurement, and business stakeholders, the Lead IS GRC Analyst supports the implementation, administration, and continuous improvement of security governance processes and controls. The role serves as a subject matter expert in information security risk management and control frameworks, including the Cyber Risk Institute (CRI) Profile, NIST Cybersecurity Framework (CSF), NIST Special Publications, CIS Critical Security Controls, and other regulatory and industry requirements applicable to the financial services sector.


The Lead IS GRC Analyst performs and coordinates security risk assessments, maintains governance and risk management processes, supports third-party cybersecurity risk management activities, administers security exception and risk acceptance processes, supports audits and examinations, tracks remediation activities, and develops security metrics and reporting. This role also provides guidance and mentorship to other IS GRC Analysts and serves as a lead resource for complex IS GRC initiatives.


This position reports directly to the IS GRC Manager.


ESSENTIAL FUNCTIONS AND BASIC DUTIES

  • Lead and coordinate day-to-day execution of the Bank's IS GRC program and assist with continuous program improvement initiatives.
  • Serve as a lead resource and subject matter expert for IS GRC Analysts, providing guidance, mentoring, knowledge sharing, quality review, and coordination of assigned activities.
  • Administer and maintain the Information Security policy, standards, procedures, and control governance lifecycle, ensuring documentation remains current, effective, and aligned with applicable laws, regulations, industry frameworks, and emerging cyber threats.
  • Conduct and coordinate information security risk assessments, control evaluations, risk analyses, and risk reporting for technology solutions, business initiatives, third parties, and acquisition activities.
  • Maintain and administer the Information Security risk register, including tracking identified risks, remediation activities, risk treatment decisions, and status reporting.
  • Administer the Security Exception and Risk Acceptance process, including facilitating reviews, documenting compensating controls, tracking mitigation activities, and preparing management reporting.
  • Support Information Security compliance and framework activities, including assessments and reporting related to the CRI Profile, NIST CSF, NIST Special Publications, CIS Critical Security Controls, FFIEC guidance, and other applicable standards.
  • Coordinate and support internal audits, external audits, regulatory examinations, independent assessments, and control reviews while tracking remediation activities for identified findings.
  • Conduct and coordinate third-party cybersecurity risk management activities, including cybersecurity due diligence reviews, inherent risk assessments, ongoing monitoring, issue management, and reporting.
  • Partner with Enterprise Risk Management, Vendor Management, Compliance, Legal, Procurement, Information Technology, and business stakeholders to identify, assess, communicate, and address information security risks.
  • Develop, maintain, and report key risk indicators (KRIs), key performance indicators (KPIs), security metrics, dashboards, and management reports.
  • Monitor industry trends, emerging threats, security frameworks, and regulatory developments and recommend improvements to governance, risk, and compliance processes.
  • Serve as an advisor and subject matter expert on information security governance, risk management, compliance requirements, and security control frameworks.
  • Build and maintain effective working relationships across business, technology, risk management, compliance, and audit functions.
  • Communicate security risks, findings, recommendations, and program metrics effectively to technical and non-technical stakeholders.
  • Lead assigned projects and initiatives while coordinating activities across IS GRC team members and stakeholders.

The above statements describe the general nature and level of work only. They are not an exhaustive list of all required responsibilities, duties, and skills. Other duties may be added, or this job description amended at any time.

LEAD RESPONSIBILITIES:

 

  • Provide day-to-day guidance, mentoring, and technical leadership to IS GRC Analysts.
  • Assist in assigning, coordinating, reviewing, and prioritizing work activities within the IS GRC team.
  • Promote consistent processes, documentation standards, and quality practices across IS GRC activities.
  • Support onboarding, training, and development of IS GRC team members.
  • Serve as an escalation point for complex governance, risk, compliance, audit, and third-party risk matters.
  • Foster collaboration, accountability, knowledge sharing, and continuous improvement within the team.

 

QUALIFICATIONS

Education/Certification: Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, a related discipline, or the equivalent of combined education and related work experience.

Professional certifications such as CISSP, CRISC, CGRC, CISA, CISM, Security+, or equivalent certifications are preferred.

experience required: Minimum of 3 years of progressive experience in information security, cybersecurity governance, risk management, compliance, information technology auditing, or a related field.

Experience supporting IS GRC programs, processes, and controls.

Experience applying information security and risk management frameworks and standards, including the CRI Profile, FFIEC guidance, NIST frameworks, CIS Controls, PCI-DSS, or similar industry frameworks.

Experience conducting security risk assessments, maintaining risk registers, supporting remediation activities, and administering security exception processes.

Experience supporting internal audits, external audits, regulatory examinations, and compliance initiatives within a regulated environment.

Experience conducting third-party cybersecurity risk assessments and ongoing monitoring activities.

Experience developing and utilizing KPIs, KRIs, metrics, dashboards, and reporting.

Experience with GRC platforms, workflow automation, data analysis, and reporting tools.

Demonstrated ability to lead projects, mentor junior team members, and collaborate effectively with business and technology stakeholders.

Banking or financial services experience strongly preferred.

REQUIRED KNOWLEDGE: Strong knowledge of information security governance, risk management, compliance, control assessment methodologies, and recognized cybersecurity frameworks and standards, including the CRI Profile, NIST CSF, NIST SP 800-series publications, FFIEC guidance, and CIS Critical Security Controls.

Strong understanding of cybersecurity risk management concepts, including inherent and residual risk, risk treatment strategies, and risk reporting.

Working knowledge of applicable regulatory, privacy, and information security requirements within the financial services industry.

Knowledge of third-party cybersecurity risk management, security exception governance, audit processes, and regulatory examinations.

Knowledge of information security control design, implementation, testing, effectiveness assessment, and risk-based control evaluation techniques, including evidence review and validation.

Knowledge of cybersecurity metrics, KRIs, trend analysis, governance reporting, GRC platforms, reporting tools, dashboard development, and data analysis techniques.

Knowledge of cyber resilience, business continuity, disaster recovery, and recovery-control concepts.

Skills/Abilities: Ability to build and maintain effective working relationships at all levels of the organization.

Strong written, verbal, and presentation skills with the ability to communicate complex risk and security concepts to technical and non-technical audiences.

Strong analytical, organizational, and problem-solving skills.

Ability to manage multiple priorities and projects in a dynamic, highly regulated environment.

Ability to provide technical leadership, mentoring, and guidance to team members.

Ability to influence stakeholders and support risk-informed decision-making across business and technology functions.

Proficiency with Microsoft Office applications, reporting tools, and GRC platforms.

Ability to independently assess security controls, evaluate evidence for sufficiency, reliability, relevance, and consistency, identify deficiencies, and develop well-supported conclusions regarding control effectiveness.

Ability to analyze cybersecurity risks and translate technical and control issues into business-relevant risk conclusions.

Ability to prepare clear, concise, and defensible observations, risk statements, recommendations, reports, and supporting documentation.

Ability to provide quality review of assessments, findings, reports, and other IS GRC deliverables.

Ability to communicate cybersecurity risks, findings, recommendations, and program metrics to technical teams, business leaders, senior management, auditors, and regulators.

Ability to interpret regulatory, policy, framework, and contractual requirements and translate them into practical security expectations and assessment criteria.


PHYSICAL ACTIVITIES AND REQUIREMENTS OF THIS POSITION


Talking: Especially where one must frequently convey detailed or important instructions or ideas accurately, loudly, or quickly.

Average Hearing: Able to hear average or normal conversations and receive ordinary information.

Repetitive Motion: Movements frequently and regularly required using the wrists, hands, and/or fingers.

Average Visual Abilities: Average, ordinary, visual acuity necessary to prepare or inspect documents or products, or operate machinery.

Physical Strength: Sedentary work; sitting most of the time. Exerts up to 10 lbs. of force occasionally. (Almost all office jobs.)


WORKING CONDITIONS

None: No hazardous or significantly unpleasant conditions (such as in a typical office).


MENTAL ACTIVITIES AND REQUIREMENTS OF THIS POSITION


Reasoning Ability: Ability to apply logical or scientific thinking to define problems, collect data establish facts and draw conclusions.

Able to interpret a variety of technical instructions and can deal with multiple variables.


Mathematics Ability: Ability to compute discount, interest, profit, and loss; commission markup and selling price; and ratio, proportion, and percentage.

Able to perform very simple algebra.


Language Ability: Ability to read periodicals, journals, manuals, dictionaries, thesauruses, and encyclopedias.

Ability to prepare business letters, proposals, summaries, and reports using prescribed format and conforming to all rules of punctuation, grammar, diction, and style.

Ability to conduct training, communicates at panel discussions, and make professional presentations.




Monday - Friday: 8:00AM - 5:00PM
40 hours