UL Solutions

Global Cybersecurity Governance Analyst

UL Solutions Northbrook, Illinois, United States

Professional Services · 10,001+ employees

8 h ago
security Junior (0-2 yrs) Full-time United States
Create a free account to apply — email only, no card. You can also save this posting or score it against your profile with AI.

About the role

The analyst supports global cybersecurity governance, risk, and compliance activities, including managing security awareness programs and policy documentation. They also coordinate governance processes within ServiceNow, track metrics, and assist with audit and compliance assessments.

What they look for

Cybersecurity Governance Risk Management Compliance Security Awareness Training KnowBe4 ServiceNow Policy Management KPI Reporting Audit Support NIST CSF ISO 27001 Data Analysis Stakeholder Engagement Technical Writing Project Coordination Information Security

Requirements

Candidates must hold a bachelor's degree in a relevant field and possess 1-3 years of experience in cybersecurity, risk, or compliance. Strong communication, analytical, and organizational skills are required, along with foundational knowledge of security frameworks and GRC principles.

Full description

The Global Cybersecurity Governance Analyst I is an entry-level individual contributor responsible for supporting cybersecurity governance, risk, and compliance activities across the organization. Reporting to the Senior Manager, Global Cybersecurity Governance, this role helps coordinate governance initiatives, maintain cybersecurity documentation, support awareness and training programs, monitor key performance indicators, and assist with audit and compliance activities.

This position provides an excellent opportunity for individuals seeking to develop expertise in Governance, Risk, and Compliance (GRC) while gaining exposure to enterprise cybersecurity programs, executive reporting, security frameworks, regulatory requirements, and cross-functional stakeholder engagement.

The successful candidate will demonstrate strong organizational skills, attention to detail, effective communication abilities, and a willingness to learn cybersecurity governance practices in a fast-paced global environment.

Responsibilities

  • Serve as the primary administrator for the KnowBe4 Security Awareness platform.
  • Develop, schedule, and monitor security awareness training campaigns and phishing simulations.
  • Track training completion rates, user participation, and awareness program effectiveness metrics.
  • Generate and distribute awareness program reports and KPI dashboards to cybersecurity leadership and business stakeholders.
  • Coordinate cybersecurity awareness communications, educational campaigns, and targeted training initiatives.
  • Analyze awareness program trends and recommend improvements to increase employee engagement and reduce organizational risk.
  • Maintain awareness program documentation, procedures, and governance records.

Given what you've described, I would strengthen the responsibilities section further with the following:

Additional Responsibilities

  • Own day-to-day administration of cybersecurity governance processes within ServiceNow, including policy exceptions, risk acceptances, and workflow management.
  • Maintain cybersecurity policy, standard, procedure, and guideline repositories and coordinate periodic reviews with control owners and stakeholders.
  • Develop and maintain governance metrics, scorecards, dashboards, and KPI reporting for cybersecurity leadership.
  • Support cybersecurity audits, compliance reviews, assessments, and evidence collection activities.
  • Assist with the governance of Artificial Intelligence (AI) technologies and Non-Human Identity (NHI) programs.
  • Support the development of executive presentations, governance committee materials, and leadership reporting.
  • Facilitate stakeholder engagement across cybersecurity, technology, legal, procurement, and business teams.
  • Track remediation activities, action items, compliance obligations, and governance program deliverables.
  • Identify opportunities for process improvements and automation within governance, risk, and compliance processes.

Qualifications

Required Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Information Systems, Risk Management, Business Administration, or a related field.
  • 1-3 years of experience supporting cybersecurity, information security, governance, risk management, compliance, audit, or information technology functions.
  • Foundational understanding of cybersecurity concepts, terminology, threats, vulnerabilities, and security best practices.
  • Knowledge of Governance, Risk, and Compliance (GRC) principles, processes, and methodologies.
  • Familiarity with cybersecurity policies, standards, procedures, and control frameworks.
  • Experience coordinating multiple workstreams, projects, or tasks in a fast-paced environment.
  • Strong verbal and written communication skills with the ability to interact effectively with technical and non-technical stakeholders.
  • Strong analytical, organizational, problem-solving, and time management skills.
  • Ability to manage competing priorities while maintaining attention to detail.
  • Proficiency with Microsoft Office applications, including Excel, PowerPoint, Word, and Teams.

Preferred Qualifications

  • Experience supporting cybersecurity governance, compliance, audit, risk management, or policy management programs.
  • Familiarity with cybersecurity frameworks and standards such as NIST Cybersecurity Framework (CSF), NIST 800-53, ISO 27001, CIS Controls, or similar industry standards.
  • Experience administering or supporting security awareness and training platforms, including KnowBe4.
  • Experience managing documentation repositories, governance records, policies, standards, and procedures.
  • Experience using ServiceNow or similar workflow management and GRC platforms.
  • Experience developing reports, scorecards, dashboards, KPI reporting, and executive presentations.
  • Exposure to audit support activities, evidence collection, compliance assessments, and remediation tracking.
  • Understanding of cybersecurity risks related to Artificial Intelligence (AI), emerging technologies, and Non-Human Identities (NHI).
  • Experience working with cross-functional stakeholders in cybersecurity, technology, legal, procurement, risk, compliance, or business organizations.

Certifications (Preferred but Not Required)

  • CompTIA Security+
  • Certified in Risk and Information Systems Control (CRISC)
  • Certified Information Security Manager (CISM)
  • Certified Information Systems Security Professional (CISSP)
  • ISO 27001 Foundation, Lead Implementer, or Lead Auditor

A global leader in applied safety science, UL Solutions (NYSE: ULS) transforms safety, security and sustainability challenges into opportunities for customers in more than 110 countries. UL Solutions delivers testing, inspection and certification services, together with software products and advisory offerings, that support our customers’ product innovation and business growth. The UL Mark serves as a recognized symbol of trust in our customers’ products and reflects an unwavering commitment to advancing our safety mission. We help our customers innovate, launch new products and services, navigate global markets and complex supply chains, and grow sustainably and responsibly into the future. Our science is your advantage.

Similar roles