Client: Seminole Hard Rock Hotels
Role: Senior Cybersecurity Governance Analyst
Interview: Virtual
Position Summary
The Cybersecurity Governance & Process Analyst is a key member of the Cybersecurity Strategy & Governance function, responsible for improving cybersecurity governance programs, processes, reporting, governance technologies, and technology-enabled workflows. This role requires a strong understanding of cybersecurity principles, technologies, and governance disciplines, with the ability to translate requirements, risks, and controls into practical, scalable governance solutions.
Key Responsibilities
Governance & Process Management
Develop and maintain governance artifacts: policies, standards, procedures, workflows, playbooks, templates, job aids
Lead process engineering — analyze current-state processes, identify gaps, design and implement future-state improvements
Manage governance processes: issue management, remediation tracking, exception management, stakeholder follow-up
Use metrics and stakeholder feedback to evaluate process effectiveness
Governance Technology & Enablement
Configure, administer, and improve GRC, security awareness, and governance platforms
Translate governance requirements into workflows, forms, approvals, dashboards, and reporting
Implement automation via low-code/no-code and AI-enabled tools
Partner with technical teams/vendors on integrations and troubleshooting
Human Risk Management & Security Awareness
Support/administer human risk and security awareness programs (phishing simulations, campaigns, metrics)
Configure and manage awareness platforms — user admin, campaign setup, troubleshooting
Analyze performance trends to improve program effectiveness
Reporting, Analytics & Program Support
Build dashboards, scorecards, KPIs, and KRIs for leadership reporting
Analyze governance/operational data for trends and actionable insights
Support strategic initiatives and governance projects through research and documentation
Research cybersecurity frameworks and emerging practices to inform program maturity.
Must-Have Skills
5+ years in cybersecurity governance, GRC, IT governance, process improvement, security awareness, risk management, compliance, or cybersecurity operations
Strong understanding of cybersecurity governance, policies/standards, risk & issue management, controls, and performance reporting
Hands-on experience with technology platforms — configuration, administration, workflow development, reporting, and troubleshooting
Working knowledge of workflow automation, system integrations, data flows, and APIs
Experience developing dashboards, metrics, and reporting from governance/operational/cybersecurity data
Practical experience using AI-enabled tools for analysis, documentation, reporting, or workflow efficiency
Demonstrated ability to independently manage governance activities or cross-functional workstreams
Strong analytical, problem-solving, communication, facilitation, and stakeholder management skills
Must-Have Qualifications
Bachelor's degree in Cybersecurity, IT, Information Systems, Business, Risk Management, Process Engineering, or related field (or equivalent experience)
Ability to manage multiple priorities and deliver high-quality work with limited supervision
Preferred Certifications
CISSP — strongly preferred
CISM (Certified Information Security Manager)
CGRC (Certified in Governance, Risk and Compliance)
CRISC (Certified in Risk and Information Systems Control)
CISA (Certified Information Systems Auditor)
CompTIA Security+
ISC2 Certified in Cybersecurity (CC)
Lean Six Sigma Green Belt or higher
PMP or equivalent project/program management certification
Preferred Experience
Platforms: Onspring, ServiceNow GRC/IRM, Archer, Hoxhunt, Proofpoint, KnowBe4, Power BI
Automation tools: Power Automate, Power Apps, ServiceNow Flow Designer
Enterprise generative AI, copilots, AI agents/automation
Business process modeling: BPMN 2.0, swimlane diagrams, using Visio, Lucidchart, Signavio, Bizagi, ARIS
Process improvement methods: Lean, Six Sigma, SIPOC, value stream mapping, root cause analysis
Cybersecurity frameworks: NIST CSF, CIS Controls, ISO/IEC 27001, PCI DSS, COBIT