FirstBank PR logo

GRC ANALYST- CORP. IT SECURITY - FIRSTBANK PR

FirstBank PR

San Juan, PRJobSeen 4w ago

Most applications go out cold — see where you stand first. No sign-up to start.

Watch jobs like this.

At a glance

Compensation
No compensation found
Location
San Juan, PR
Work Authorization
Not specified

Olive lists jobs from US employers, including remote roles you can work from the United States.

Requirements

Credentials this posting asks for.

Bachelor's degree

Job overview

The GRC Analyst will assess, prioritize, and remediate cybersecurity, technology, and compliance risks across FirstBank PR. They will support governance, risk, and compliance program design, maintain policies, conduct risk assessments, coordinate audits, and drive security initiatives using frameworks such as ISO 27001, NIST, GLBA, and SOX while collaborating with cross‑functional stakeholders.

Skills & qualifications

RequiredNice to have

Skills

ISO 27001NISTGLBASOXCOBITAdvanced Microsoft OfficeBilingual English Spanish

Qualifications

Bachelor's Degree in Information Systems or Computer ScienceThree to Five Years Experience in Similar RoleCISA Certification

Full job description

GOVERNANCE, RISK & COMPLIANCE (GRC) ANALYST

CORPORATE IT SECURITY

FIRSTBANK PR

Our Company

At FirstBank PR, we strive to be trusted advisors to our clients, and our employees are the ones that ensure we deliver on our promise of excellence in personalized customer service. Our more than 3,100 employees in Puerto Rico, the Virgin Islands and Florida share a passion for excellent customer service. We are proud of our team because they are continuously surpassing our client’s expectations.

Do you have a passion for helping customers, building relationships, and delivering extraordinary, personalized customer service? If your answer is yes, FirstBank is the number one place for you.

A Brief Overview

Responsible for assessing, prioritizing, reporting, and driving the remediation of cybersecurity, technology, and compliance risks across the Corporation. Support the design, implementation, and continuous improvement of governance, risk, and compliance programs aligned with regulatory requirements, industry standards, and business objectives. Partner with cross-functional stakeholders, including Finance, Legal, Audit, Human Resources, and Technology teams, to implement security and compliance initiatives, strengthen risk management practices, and ensure the protection of the Corporation’s assets and technology environment. Apply recognized frameworks and standards such as ISO 27001, NIST, GLBA, and SOX to enhance the organization’s overall security and compliance posture.

What you’ll do

  • This position will assist the GRC Manager in maintaining the GRC Program from end-to-end. Core functions include:

  • Support the Governance, Risk, and Compliance (GRC) program by maintaining and enhancing information security policies, procedures, standards, and governance practices in alignment with regulatory requirements, internal policies, and industry best practices.

  • Assist in the development, monitoring, and reporting of the Information Security Program, including security metrics, KRIs, dashboards, scorecards, self-assessments, and reporting to management, committees, and the Board of Directors.

  • Conduct risk assessments, identify information security and technology-related risks, recommend mitigation strategies, and track remediation efforts to ensure timely and effective risk resolution.

  • Coordinate and support internal audits, external audits, and regulatory examinations by providing documentation, evidence, subject matter expertise, and follow-up on findings, observations, and corrective action plans.

  • Monitor the remediation of technology, cybersecurity, and business audit findings, ensuring accountability, management commitment, and successful closure of identified deficiencies.

  • Review and monitor IT security controls, access management processes, and governance activities to support ongoing compliance, quality assurance, and operational effectiveness.

  • Maintain vendor governance documentation and support third-party risk management activities in accordance with Vendor Management and Information Security requirements.

  • Assist with security awareness initiatives, special projects, vendor evaluations, and continuous improvement efforts that strengthen the organization's cybersecurity and compliance posture.

  • Participates in special projects and research as it relates to Corporate Security, including assessing current relationships, the need for request for proposals (RFPs), and coordinating upgrades to current, or transition to new vendors.

  • Performs special tasks in order to assist internal, external auditors and regulators in their procedures

  • Performs other tasks as requested by the GRC Manager.

  • Performs/Supports highly technical tasks such as:

§ Systems and procedures review and implementation

§ Policies Awareness training

§ Special Investigations (Forensic)

§ Root Cause Analysis Process

  • Perform other duties as assigned.

Competencies

  • Bilingual Communication Excellence: Communicates complex risk and security concepts clearly in both English and Spanish to diverse stakeholders.

  • Advanced Technical Proficiency: Effectively analyzes and validates technical controls using strong knowledge of systems and security tools.

  • Information Security Framework Expertise: Applies leading frameworks (COBIT, ISO 27001, NIST) to design, assess, and improve security and compliance programs.

  • Collaboration and Leadership Skills: Drives cross-functional collaboration and influences stakeholders to strengthen risk and compliance outcomes.

  • Adaptability in High-Performance Environments: Performs effectively under pressure while managing multiple priorities in fast-paced environments.

  • Analytical & Problem-Solving Skills: Identifies risks and control gaps using strong analytical thinking and delivers practical, risk-based solutions.

  • Advanced Microsoft Office Skills: Produces data-driven insights and professional reports using advanced Microsoft Office tools.

  • Organizational & Prioritization Skills: Manages tasks efficiently through strong organization, attention to detail, and prioritization.

  • Risk & Compliance Mindset: Integrates governance, risk, and compliance principles into business decisions and operational processes.

What You’ll Need to Succeed

A Bachelor’s degree in Information Systems or Computer Science related field, and at least three (3) to five (5) years of experience in a similar job is required. CISA certification is preferred but not required.

Disclaimer: The above statements describe the general nature and level of work performed by individuals assigned to this position and are not intended to be an exhaustive list of all duties or responsibilities.

EQUAL EMPLOYMENT OPPORTUNITY EMPLOYER

Similar jobs, posted recently

Open roles like this one, listed in the last 30 days.

You've read the whole posting — now see how you match it.