Vulnerability Management Specialist - GRC
Overview
You will own the governance, risk, and compliance (GRC) activities for a midsized property and casualty insurer with 100 years of financial stability. You will assess third-party risk, manage vulnerability governance, and support audit and compliance efforts across NIST CSF, NYDFS, and ISO 27001. You will work with technology and risk stakeholders to track remediation and produce clear reporting. This role offers hybrid work in New York and a clear path for growth in a Forbes Best Midsize Employer.
What You'll Do8
- 1Execute GRC activities including risk documentation, control mapping, and exception tracking.
- 2Coordinate vendor assessment intake, due diligence requests, and follow-ups through closure.
- 3Review vendor questionnaires, SOC reports, ISO certifications, and penetration test summaries for risk relevance.
- 4Track vulnerability remediation status, exception requests, and aging issues in alignment with defined procedures.
- 5Collect and validate audit evidence for control objectives and regulatory expectations.
- 6Maintain metrics for risk assessment volume, vendor status, and vulnerability remediation.
- 7Collaborate with stakeholders to validate ownership and progress on identified vulnerabilities.
- 8Identify and implement process improvements to enhance template and procedure consistency.
Requirements8
- 13-5 years of experience in GRC, cybersecurity, third-party risk, or vulnerability management.
- 2Working knowledge of cybersecurity, risk management, and compliance concepts.
- 3Ability to evaluate security evidence and escalate potential risk concerns.
- 4Strong attention to detail and documentation discipline.
- 5Clear written and verbal communication skills for technical and business audiences.
- 6Proficiency with Microsoft Office; experience with GRC or ticketing tools preferred.
- 7Familiarity with NIST CSF, NIST 800-53, NYDFS, GLBA, SOX, SOC reporting, and ISO 27001.
- 8Relevant certification such as CRISC, CISA, Security+, CDPSE, or CTPRP is a plus.
Salary Insight
$116 - $157k per year
Location
Required Skills
Similar open positions
Explore active roles that match your skills and interests.

Mergen IT LLC
VerifiedCybersecurity GRC Consultant NIST CSF 2.0
Lead end to end engagement governance project planning milestones risks oversee Cybersecurity GRC Consultant NIST CSF 2.0 San Francisco CA (Onsite) drive practical improvement roadmap deliver results within 90 days
OCT Consulting, LLC
VerifiedIT Security Vulnerability Specialist - OCT Consulting
OCT Consulting seeks an Associate IT Security Vulnerability Specialist to lead vulnerability remediation for federal clients. This hybrid role requires 3 days weekly presence in Suitland MD. The ideal candidate will drive efficiency in vulnerability management while articulating risk to leadership. You will conduct assessments monitor tools develop policies and participate in incident response. Experience with NIST RMF and security frameworks is essential.

Icon International Group LLC
VerifiedIT Risk Consultant, Technology Risk & GRC
You will own technology risk management for enterprise applications and architecture at Icon International Group LLC, embedding controls across the SDLC. You will partner with control owners to design, review, and strengthen technology controls, working in a hybrid model from New York. This 6-month contract offers direct influence over GRC, RCSA, and control frameworks.

Javen Technologies, Inc
VerifiedSenior IT Risk and Compliance Analyst - GRC Framework Expertise
Lead ownership of IT governance alignment supporting Bank's GRC framework Enterprise Risk Management and Sarbanes-Oxley compliance. Drive improvements through collaboration with IT staff. Analyze technology risks and develop appropriate controls. Stand out by delivering measurable risk reduction outcomes within first 90 days.
LPL Financial Corp
VerifiedAnalyst II Tech Governance & Assurance
We seek a skilled IT Risk & Controls professional to lead our first line of defense in IT compliance. You will own daily readiness testing and audit facilitation for critical programs like SOX SOC 1 SOC 2 CCPA/CPRA cybersecurity audits and NYDFS attestation. This hands-on role embeds within control owners to perform self-testing and drive automation reducing manual effort. Expect collaboration with IT Engineering Security and external auditors to maintain audit readiness year-round.
PricewaterhouseCoopers Advisory Services LLC
VerifiedCyber Strategy Manager, Compliance & Risk
You will lead cyber strategy and transformation engagements, guiding clients through complex regulatory landscapes and enhancing internal controls. In this role, you will own project delivery, from planning to execution, while mentoring junior staff and collaborating with senior stakeholders. You will implement frameworks like NIST CSF and ISO/IEC 27001 to strengthen data protection and compliance. This position offers exposure to high-impact client work across industries, with up to 60% travel and a focus on innovation and technology adoption.