Hagerty is an automotive enthusiast brand and the world’s largest membership organization. Along with being a best-in-class provider of specialty insurance for enthusiasts, Hagerty is also home to the Hagerty Drivers Foundation, Garage + Social, Hagerty Drivers Club, Marketplace and so much more. Committed to saving driving for future generations, each and every thing Hagerty does is dedicated to the love of the automobile. Hagerty is a rapidly growing company that values a winning culture. We provide meaningful work for and invest in every single team member. At Hagerty, we share the road. We are an inclusive automotive community where all are welcomed, valued and belong regardless of race, gender, age, or car preference. We are united by our shared passion for driving, our commitment to preserve car culture for future generations and our desire to make a positive impact in the world. If you like wild growth and working with happy, enthusiastic over-achievers, you'll enjoy your career with us!
GRC, Information Security Risk Analyst II
Location
United States
Posted
3 days ago
Salary
Not specified
Job Description
Role Description
As a Security Risk Analyst II, you will be responsible for supporting the organization’s Governance, Risk & Compliance program with a primary focus on conducting and managing risk assessments within ServiceNow Integrated Risk Management (IRM). This role plays a key part in evaluating security and compliance risks across business units, ensuring alignment with frameworks such as ISO 27001, PCI, NYDFS, and regulatory requirements. The analyst will collaborate with technical and business stakeholders to assess risks, identify control gaps, track remediation, and support continuous improvement of the risk management lifecycle.
What you’ll do
-
Risk Assessment & Analysis
- Perform comprehensive security and compliance risk assessments using ServiceNow IRM Risk, Policy & Compliance, and Vendor Risk modules.
- Review and validate inherent and residual risk scoring, ensuring consistent application of risk methodologies.
- Evaluate control effectiveness using evidence, documentation, interviews, and technical data.
- Identify security risks, gaps, and vulnerabilities across processes, technologies, vendors, and applications.
- Document detailed findings, recommendations, and remediation plans.
-
ServiceNow IRM Administration & Optimization
- Create, update, and manage risk records, assessments, workflows, indicators, and control attestations.
- Support enhancements to IRM processes, playbooks, and automation capabilities.
- Assist with platform data integrity, reporting, dashboards, and process optimization.
-
Governance, Risk & Compliance Support
- Support ongoing compliance efforts aligned to ISO 27001, PCI, NYDFS, and other regulatory frameworks.
- Participate in internal and external audit readiness activities by gathering evidence, validating controls, and tracking requirements.
- Maintain documentation including policies, standards, risk methodology, and control libraries.
-
Stakeholder Collaboration
- Work closely with business owners, security engineers, procurement, and IT teams to explain risks and required actions.
- Track remediation plans, validate closure, and assist teams in interpreting control obligations.
- Present risk findings and trends to GRC leadership and cross-functional teams.
-
Reporting & Metrics
- Produce dashboards and risk reports from ServiceNow IRM for leadership review.
- Monitor KPIs and KRIs related to risk posture, control performance, and compliance obligations.
Qualifications
- 2+ years of experience in GRC, information security, risk management, or compliance roles.
- Hands-on experience using ServiceNow IRM (Risk, Policy & Compliance, Vendor Risk, or Audit modules).
- Strong understanding of information security and GRC frameworks (ISO 27001, PCI, NYDFS and other regulatory frameworks).
- Experience conducting or supporting risk assessments for applications, processes, or technology.
- Ability to analyze complex security issues and communicate findings clearly to technical and non-technical stakeholders.
- Familiarity with security controls, vulnerability management, and audit concepts.
Requirements
- Certifications such as Security+, CySA+, CCSK, CISA, CRISC, CGEIT, or ISO 27001 Lead Implementer/Auditor.
- Experience with risk quantification models (e.g., FAIR) a plus.
- Background supporting audits (ISO 27001, PCI, etc.).
- Experience contributing to GRC process improvements or workflow automation.
- Strong analytical and critical-thinking skills.
- Excellent written and verbal communication.
- Detail-oriented with strong documentation capabilities.
- Ability to manage multiple tasks and deadlines independently.
Other things to note
- This position is open to U.S. remote work. However, team members who reside within 20 miles of the Traverse City headquarters will follow a hybrid schedule, working from the office three days per week.
- May require travel for quarterly events.
- Familiarity with public company requirements, including Sarbanes Oxley and key regulations, if applicable.
Job Requirements
- 2+ years of experience in GRC, information security, risk management, or compliance roles.
- Hands-on experience using ServiceNow IRM (Risk, Policy & Compliance, Vendor Risk, or Audit modules).
- Strong understanding of information security and GRC frameworks (ISO 27001, PCI, NYDFS and other regulatory frameworks).
- Experience conducting or supporting risk assessments for applications, processes, or technology.
- Ability to analyze complex security issues and communicate findings clearly to technical and non-technical stakeholders.
- Familiarity with security controls, vulnerability management, and audit concepts.
- Certifications such as Security+, CySA+, CCSK, CISA, CRISC, CGEIT, or ISO 27001 Lead Implementer/Auditor.
- Experience with risk quantification models (e.g., FAIR) a plus.
- Background supporting audits (ISO 27001, PCI, etc.).
- Experience contributing to GRC process improvements or workflow automation.
- Strong analytical and critical-thinking skills.
- Excellent written and verbal communication.
- Detail-oriented with strong documentation capabilities.
- Ability to manage multiple tasks and deadlines independently.
- Other things to note
- This position is open to U.S. remote work. However, team members who reside within 20 miles of the Traverse City headquarters will follow a hybrid schedule, working from the office three days per week.
- May require travel for quarterly events.
- Familiarity with public company requirements, including Sarbanes Oxley and key regulations, if applicable.
Related Guides
Related Categories
Related Job Pages
More Security Analyst Jobs
SAP Security Specialist
CACI InternationalCACI is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, age, national origin, disability, status as a protected veteran, or any other protected characteristic.
The specialist will translate functional specifications into SAP role designs, manage technical roles, user authorizations, and handle Segregation of Duties conflict remediation projects. They will also provide subject matter expertise and technical direction to clients while ensuring system reliability through day-to-day sustainment support.
Security Analyst II maintaining data integrity for Garner's healthcare technology
This role involves conducting tactical threat monitoring and detection activities using internal tools to assess and communicate risks to customers through tactical-level reports. Analysts will produce high-quality tactical assessments, manage customer alerting profiles, and synthesize data to identify information credibility and relevance.
AGE Solutions is looking for a Security Control Assessor, Mid to join our team in support of a cybersecurity risk management and assessment program with our DoD customer. Conduct cybersecurity assessments, audits, and inspections for DoD organizations and partners handling DoD in...