Description: On-site in either King of Prussia, PA or Denver, PA
Our client is seeking a Senior Cybersecurity Governance, Risk & Compliance (GRC) Analyst to support cybersecurity governance, regulatory compliance, and risk management initiatives within a critical infrastructure environment. This role is responsible for helping ensure compliance with cybersecurity regulatory requirements, monitoring risk remediation activities, supporting governance programs, and collaborating across business and technology teams to strengthen cybersecurity maturity. The ideal candidate will have a background in GRC, cybersecurity compliance, and risk management, with hands-on experience supporting Operational Technology (OT), SCADA, Industrial Control Systems (ICS), and critical infrastructure environments. This individual will partner with Information Technology, Legal, Enterprise Risk Management, Human Resources, and business stakeholders to drive compliance, governance, and cybersecurity risk reduction initiatives. Candidates must be able to work on-site four days a week in the Denver/Lancaster, PA area and must demonstrate real-world experience supporting, assessing, governing, or auditing OT/SCADA/ICS environments.
This is a full-time, permanent opportunity, offering a competitive salary and comprehensive benefits package. Qualified applicants must be willing and able to work on a w2 basis.Salary: $80,000 - $105,000/ yr. w2
Responsibilities: - Track compliance to cybersecurity regulatory requirements such as TSA and PUC.
- Assist with maintaining processes and procedure documentation that supports regulatory compliance.
- Support the review of policies and standards in collaboration with stakeholders.
- Collaborate to establish and track metrics for cybersecurity regulatory governance programs.
- Support development and maintenance of cybersecurity governance frameworks for OT and SCADA, aligning with standards including NERC CIP, IEC 62443, and NIST SP 800-82.
- Collaborate with stakeholders to monitor regulatory changes and industry developments.
- Track activities including tabletop exercises, architecture design reviews, TSA Cybersecurity Action Plan, and biennial cybersecurity audits.
- Track gaps from internal and external assessments to completion.
- Assist with tracking risk assessments and remediation for OT/SCADA systems, including ICS, PLCs, and remote monitoring infrastructure.
- Create awareness of compliance to company policies, standards, and regulatory requirements through monitoring and reporting.
- Collaborate with IT stakeholders to monitor cybersecurity exceptions and other IT operational activities that present gaps.
- Partner with IT, Legal, HR, and Enterprise Risk Management to align risk and compliance efforts.
- Ensure stakeholders have operational metrics to monitor their compliance.
- Deliver regular risk and compliance metrics for IT senior leadership in partnership with the Cybersecurity GRC team.
Experience Requirements: - 4+ years of experience in GRC, risk management, or compliance roles.
- Strong understanding of GRC tools and platforms such as RSA Archer, ServiceNow GRC, or Fusion.
- Familiarity with frameworks and standards including NIST 800 series, COBIT, and FAIR.
- Proven experience supporting, assessing, governing, or auditing OT/SCADA/ICS environments.
- Analytical, problem-solving, and organizational skills.
- Written and verbal communication skills with stakeholder engagement capability.
- Certifications such as CISA, CRISC, CISSP, CMMC, or PCI preferred.
Education Requirements: - Bachelor's degree in Information Security, Risk Management, Computer Science, or related field.
Recruitment Transparency NoticeEliassen Group values transparency in our recruitment practices. Please be advised that Eliassen Group utilizes artificial intelligence (AI) tools as part of its initial application screening and hiring process. You may receive email and SMS notifications from the Eliassen Virtual Recruiting Team (, ) inviting you to complete a brief voice screening as part of your application process. These tools assist our hiring teams in different ways, including but not limited to, assistance in reviewing application materials to help identify candidates whose qualifications most closely match the requirements of the position. All AI-assisted evaluations and responses are reviewed by human recruiters before any hiring decisions are made. The use of AI in our process is intended to support fairness, efficiency, and consistency, and Eliassen Group takes measures to prevent bias or discrimination in connection with its hiring practices. By proceeding, you acknowledge, agree, and consent to Eliassen Group's use of these tools, including AI tools, as part of the application and hiring process.Skills, experience, and other compensable factors will be considered when determining pay rate. The pay range provided in this posting reflects a W2 hourly rate; other employment options may be available that may result in pay outside of the provided range.
W2 employees of Eliassen Group who are regularly scheduled to work 30 or more hours per week are eligible for the following benefits: medical (choice of 3 plans), dental, vision, pre-tax accounts, other voluntary benefits including life and disability insurance, 401(k) with match, and sick time if required by law in the worked-in state/locality.
If anyone reaches out to you about an open position connected with Eliassen Group, please ensure that you are working directly with us by confirming the following: When you work with Eliassen Group, all email communication will come from an Eliassen.com address, never Gmail, Yahoo, etc. Eliassen Group will never ask you for personal information (home address, bank account, or check routing number) until you have worked with someone clearly associated with Eliassen Group.If you have any indication of fraudulent activity, please contact .About Eliassen Group:Eliassen Group is a strategic consulting firm that helps organizations reach further and achieve more through our technology, business advisory, and life sciences solutions. For nearly 40 years, we have combined exceptional people, deep domain expertise, and intelligent capabilities to expand our clients' capacity and accelerate meaningful outcomes. We are driven by a purpose to positively impact the lives of our employees, clients, consultants, and the communities we serve.Eliassen is committed to building a diverse and inclusive team from a variety of backgrounds, perspectives, and skills. We are an Equal Opportunity and Affirmative Action Employer and all employment decisions are based on merit, performance, and business needs. Eliassen does not discriminate on the basis of race, color, gender identity or expression, sexual preference or orientation, sex (including pregnancy, childbirth, and related medical conditions), marital status, creed, religion, physical or mental disability, genetic information, military or veteran status, age, ancestry, national origin, citizenship status, prohibited criminal record inquiries of applicants and employees, or any other category protected by federal, state, or local laws.Don't miss out on our referral program! If we hire a candidate that you refer us to then you can be eligible for a $1,000 referral check!