HEB
Staff GRC Analyst-Austin or San Antonio, Texas
San Antonio, Texas · On-site · Posted today
Opens careers.heb.com
Get a version of your resume written for this job.
- Salary
- Not listed
- Job type
- Full-time
- Work mode
- On-site
- Source
- iCIMS (employer's hiring system)
Skills mentioned
AWS, Azure, GCP, Cybersecurity, IAM, SOC 2, ISO 27001, Threat Modeling
About the role
Responsibilities Job Summary: As a Staff Governance, Risk & Compliance (GRC) Analyst, you'll assess and document H-E-B's information asset compliance and risk posture while serving as a trusted advisor to engineering, architecture, and business teams. You'll review technology solutions, identify security risks, provide risk-based recommendations, and help drive secure outcomes across the organization. This role also provides coaching and mentorship to team members and stakeholders, helping strengthen security awareness and risk management practices across the business. Location: San Antonio (Preferred) or Austin, TX-Hybrid Key Responsibilities & Essential Functions: Analytics / Information Technology / Auditing: Contributes to development / continuous improvement of H-E-B security program goals and objectives. Leads development / implementation of system-wide risk management function to ensure information security risks are identified / monitored. Serves as SME and advisor to help manage risk at an acceptable level. Collaborates to define information security policies, standards, and procedures, and to ensure controls are adequate, appropriate, and effective. Establishes / maintains control objectives and procedures; maintains a risk register to identify / evaluate / prioritize / monitor risk findings to be reported to executive committee. Performs internal risk assessments; validates effectiveness of security controls; recommends appropriate actions to mitigate risks; assesses / evaluates / makes recommendations related to adequacy of security controls. Supports vendor due-diligence process; helps define overall third-party risk management efforts. Supports internal and external audit processes for related compliance requirements. Supports vulnerability management efforts (e.g., remediation tracking, status reporting, enhancements) Liaises with external auditors on regulatory assessments. Stays current on developing regulatory concerns and changing IT and InfoSec trends. Ensures robust reporting processes related to security topics. Coaches / mentors team Partners The responsibilities and essential functions outlined above describe the general nature and level of work assigned to this position. This is not an exhaustive list of all duties, responsibilities, and skills required. Duties and responsibilities may be modified at any time based on business needs. Employees may be required to perform other job-related tasks as requested by their supervisor, subject to reasonable accommodations. Qualifications & Key Requirements: Work Experience: 7+ years of experience in Cybersecurity, Information Security, GRC, Security Architecture, or Security Consulting, Risk Management. Experience evaluating the security design, architecture, and implementation of enterprise applications, platforms, cloud environments, and technology solutions. Strong understanding of modern technologies including cloud platforms (AWS, Azure, or GCP), Identity and Access Management (IAM), application security, data security, and enterprise security controls. Experience conducting security assessments, architecture reviews, threat modeling, risk assessments, or similar technical security evaluations Ability to partner with engineers, architects, product teams, and business stakeholders to identify security risks and influence secure design decisions. Experience presenting security risks, recommendations, and business impact to senior leaders, including Directors, VPs, or executive stakeholders. Knowledge of security and regulatory frameworks such as PCI DSS, HIPAA, SOX ITGC, NIST 800-53, or similar standards. Knowledge/Skills/Abilities: Advanced working knowledge of security issues for desktop, virtual, cloud services, and network infrastructures; of risk management methodologies, frameworks, principles (e.g., NIST, ISO 27001, ITIL, PCI, CCPA, SOC 2, SOX, etc.), and IT GRC / IRM platforms Advanced interpersonal and relationship-building skills Advanced communication and presentation skills Advanced problem-solving skills Strong time management and prioritization skills; detail-oriented Ability to quickly connect business requirements with GRC functional capabilities. Ability to professionally handle confidential information. Ability to meet deadlines and prioritize appropriately on concurrent projects. Ability to analyze for potential future issues. Ability to stay current on technology trends and quickly learn new technologies. Ability to communicate and collaborate at all levels. Education: A related degree or comparable formal training, certification, or work experience Licenses/Certifications: One or more professional security certifications (e.g., CISSP, CISA, CISM, CRISC) Physical Demands & Working Conditions: Function in a fast-paced, retail, office environment Work extended hours / sit for extended periods. The work environment characteristics described here are representative of those a Partner encounters while performing the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. JDSECURITY JDENGINEERING
Job Summary: As a Staff Governance, Risk & Compliance (GRC) Analyst, you'll assess and document H-E-B's information asset compliance and risk posture while serving as a trusted advisor to engineering, architecture, and business teams. You'll review technology solutions, identify security risks, provide risk-based recommendations, and help drive secure outcomes across the organization. This role also provides coaching and mentorship to team members and stakeholders, helping strengthen security awareness and risk management practices across the business. Location: San Antonio (Preferred) or Austin, TX-Hybrid Key Responsibilities & Essential Functions: Analytics / Information Technology / Auditing: Contributes to development / continuous improvement of H-E-B security program goals and objectives. Leads development / implementation of system-wide risk management function to ensure information security risks are identified / monitored. Serves as SME and advisor to help manage risk at an acceptable level. Collaborates to define information security policies, standards, and procedures, and to ensure controls are adequate, appropriate, and effective. Establishes / maintains control objectives and procedures; maintains a risk register to identify / evaluate / prioritize / monitor risk findings to be reported to executive committee. Performs internal risk assessments; validates effectiveness of security controls; recommends appropriate actions to mitigate risks; assesses / evaluates / makes recommendations related to adequacy of security controls. Supports vendor due-diligence process; helps define overall third-party risk management efforts. Supports internal and external audit processes for related compliance requirements. Supports vulnerability management efforts (e.g., remediation tracking, status reporting, enhancements) Liaises with external auditors on regulatory assessments. Stays current on developing regulatory concerns and changing IT and InfoSec trends. Ensures robust reporting processes related to security topics. Coaches / mentors team Partners The responsibilities and essential functions outlined above describe the general nature and level of work assigned to this position. This is not an exhaustive list of all duties, responsibilities, and skills required. Duties and responsibilities may be modified at any time based on business needs. Employees may be required to perform other job-related tasks as requested by their supervisor, subject to reasonable accommodations. Qualifications & Key Requirements: Work Experience: 7+ years of experience in Cybersecurity, Information Security, GRC, Security Architecture, or Security Consulting, Risk Management. Experience evaluating the security design, architecture, and implementation of enterprise applications, platforms, cloud environments, and technology solutions. Strong understanding of modern technologies including cloud platforms (AWS, Azure, or GCP), Identity and Access Management (IAM), application security, data security, and enterprise security controls. Experience conducting security assessments, architecture reviews, threat modeling, risk assessments, or similar technical security evaluations Ability to partner with engineers, architects, product teams, and business stakeholders to identify security risks and influence secure design decisions. Experience presenting security risks, recommendations, and business impact to senior leaders, including Directors, VPs, or executive stakeholders. Knowledge of security and regulatory frameworks such as PCI DSS, HIPAA, SOX ITGC, NIST 800-53, or similar standards. Knowledge/Skills/Abilities: Advanced working knowledge of security issues for desktop, virtual, cloud services, and network infrastructures; of risk management methodologies, frameworks, principles (e.g., NIST, ISO 27001, ITIL, PCI, CCPA, SOC 2, SOX, etc.), and IT GRC / IRM platforms Advanced interpersonal and relationship-building skills Advanced communication and presentation skills Advanced problem-solving skills Strong time management and prioritization skills; detail-oriented Ability to quickly connect business requirements with GRC functional capabilities. Ability to professionally handle confidential information. Ability to meet deadlines and prioritize appropriately on concurrent projects. Ability to analyze for potential future issues. Ability to stay current on technology trends and quickly learn new technologies. Ability to communicate and collaborate at all levels. Education: A related degree or comparable formal training, certification, or work experience Licenses/Certifications: One or more professional security certifications (e.g., CISSP, CISA, CISM, CRISC) Physical Demands & Working Conditions: Function in a fast-paced, retail, office environment Work extended hours / sit for extended periods. The work environment characteristics described here are representative of those a Partner encounters while performing the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. JDSECURITY JDENGINEERING
Job ID ic-careers-heb-com-238242 · Original posting ↗
Similar jobs
GRC AnalystNewAmbience HealthcareSan Francisco, California · Hybrid · US$164,000–205,000 / year
Sr. GRC Analyst, Common Control FrameworkNewSalesforceBellevue, Washington · On-site
Sr. GRC Analyst, Policy OperationsNewSalesforceSeattle, Washington · On-site
Information Security GRC Analyst III, Controls Assurance5dFanatics Inc.Jacksonville, Florida
- GRC Analyst7dBase Power CompanyAustin, Texas · On-site