Demo

ISO27001 SR Governance and Compliance Analyst

Elsevier
Atlanta, GA Full Time
POSTED ON 4/7/2025 CLOSED ON 4/13/2025

What are the responsibilities and job description for the ISO27001 SR Governance and Compliance Analyst position at Elsevier?

ISO27001 SR GRC Analyst


About the role: We are seeking an experienced ISO27001 Senior Governance, Risk, and Compliance (GRC) Analyst to lead the development and implementation of our cybersecurity governance program and maintain compliance with our information security standards and frameworks. The successful candidate will have a deep understanding of cybersecurity frameworks, risk management, and compliance standards, and will work collaboratively with cross-functional teams to ensure alignment with business objectives and regulatory requirements.


About the team: This diverse team is ensuring that the GRC policy landscape is being adhered to and ensuring that all necessary protections are in place.


Key Responsibilities:

  • Designing, implementing, and maintaining a comprehensive cybersecurity governance framework that aligns with industry’s best practices (e.g., ISO 27001, NIST, COBIT).
  • Creating, reviewing, and updating cybersecurity policies and procedures to ensure compliance with applicable laws and regulations.
  • Monitoring compliance with internal policies and external regulations and prepare for audits and assessments.
  • Establishing enterprise level security governance structure, charters, participants and roles, and perform periodic role reviews to ensure appropriate accountability is maintained.
  • Working closely with IT, legal, and business units to ensure cybersecurity governance initiatives are integrated into overall business processes.
  • Driving security-related certification efforts such as ISO 27001, ISO 27701, ISO 27017, ISO 27018, ISO 42001, FedRamp, StateRamp, TX Ramp, HIPAA, PCI, etc. Drive communication and upwards reporting of the highest risk initiatives to Director of GRC, VP GRC and other key stakeholders. Generate regular reporting including KPIs, metrics and SLAs reporting, executive reporting, and other ad hoc reporting as required by management.
  • Responsible for resolution of cybersecurity GRC issues.
  • Serving as a trusted advisor to the business and technology stakeholders across the enterprise to partner on security issues and stay aligned on common goals.



Requirements:

  • Experience designing, implementing, and maintaining a comprehensive cybersecurity governance framework (ISO27001) that aligns with industry best practices
  • Experiencing creating, reviewing and updating cybersecurity policies and procedures to ensure compliance with applicable laws and regulations.
  • Experience implementing cybersecurity and compliance related frameworks such as ISO 27001, ISO 27701, ISO 27017, ISO 27018, ISO 42001, FedRamp, StateRamp, TX Ramp, HIPAA, PCI, etc.
  • Experience managing an enterprise cybersecurity GRC program. Experience in defining cybersecurity controls, particularly related to regulatory, legislative, and industry specific compliance requirements.
  • Ability to develop and implement security programs.
  • Advanced problem-solving experience involving leading teams in identifying, researching, and coordinating the resources necessary to effectively troubleshoot/diagnose complex project issues; prior success extracting/translating findings into alternatives/solutions; and identifying risks/impacts and schedule adjustments to facilitate management decision-making.
  • Advanced communication (verbal and written) and customer service skills. Strong interpersonal, communication, and presentation skills applicable to a wide audience including senior and executive management, customers, etc., including diction/terminology and presenting information in a concise and effective manner to clients, management, and various departments using assorted communication mediums.
  • Excellent stakeholder management skills. Ability to cultivate and maintain solid relationships with key stakeholders across organizational teams and third-party suppliers.



Helpful Licensing/Certifications

  • Certified Information System Security Professional (CISSP)
  • Certified Information Security Manager (CISM)
  • Certified Information Systems Auditor (CISA)

Senior Governance and Compliance Analyst
Elsevier -
Tate, GA
Senior Governance and Compliance Analyst
RELX -
Atlanta, GA
Security Analyst - Governance, Risk and Compliance (GRC)
EMCOR Group -
Atlanta, GA

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a ISO27001 SR Governance and Compliance Analyst?

Sign up to receive alerts about other jobs on the ISO27001 SR Governance and Compliance Analyst career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$152,549 - $188,894
Income Estimation: 
$194,072 - $240,547
Income Estimation: 
$135,994 - $168,063
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$70,462 - $84,818
Income Estimation: 
$77,991 - $108,747
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$139,945 - $168,577
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
This job has expired.
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Elsevier

Elsevier
Hired Organization Address Kansas, MO Full Time
Are you a skilled relationship builder with a passion for customer success? Are you a customer focused account strategis...
Elsevier
Hired Organization Address Philadelphia, PA Full Time
The Portfolio Delivery and Management Office (PDMO) is committed to executing projects and driving operational efficienc...
Elsevier
Hired Organization Address PA Full Time
Are you a highly skilled product management operator with technical and commercial acumen? Do you have a proven track re...
Elsevier
Hired Organization Address Philadelphia, PA Full Time
Elsevier employs 9,200 people worldwide, including over 2,500 technologists. We have supported the work of our research ...

Not the job you're looking for? Here are some other ISO27001 SR Governance and Compliance Analyst jobs in the Atlanta, GA area that may be a better fit.

Governance and Compliance Analyst

Elsevier, Atlanta, GA

AI Assistant is available now!

Feel free to start your new journey!