Analyst, Information Security GRC at ICE in US-GA-Atlanta
- Company: ICE
- Location: US-GA-Atlanta
- Posted: Sep 17, 2026
- Type: Full-time
- Experience: 4+ years
- Visa sponsorship available
Overview
Job Purpose The Analyst, Information Security GRC is part of a team responsible for the global Information Security program. The role would gain exposure to the full suite of businesses and products which underpin the Parent ICE company.
Job description
- Job Purpose
- The Analyst, Information Security GRC is part of a team responsible for the global Information Security program. The role would gain exposure to the full suite of businesses and products which underpin the Parent ICE company.
- Preventing impactful cybersecurity and physical security incidents,
- maintaining a reputation with customers, regulators, and key stakeholders as running a best-in-class cybersecurity and physical security program, and
- avoiding negative impact to business agility and growth from cybersecurity and physical security policies and controls.
- Governance, Risk, and Compliance maintain said policies, ensure controls are operating effectively via assessment and attestation, and own the vulnerability management program to identify and correct any problems within.
Responsibilities
- Security Metrics – Uses automated and manual processes to produce regular reports communicating the status of the Information Security program
- Policies and Procedures – Maintains corporate Information Security policies and departmental procedures and maps them to relevant control standards
- Regulator, Audit, and Customer Inquiries – Organizes and updates departmental documentation and responds to inquiries in an organized and repeatable fashion
- Recertification – Operates periodic processes to ensure hire, transfer, and termination protocols are complied with and regular access reviews are conducted
- Security Awareness – Builds and maintains company awareness and education programs
- Risk Assessment – Builds and operates the company platform to document, measure, and report assessments, risks, controls, findings, and remediation activity
Requirements
- University degree in Information Security, Engineering, MIS, CIS, or related discipline or equivalent years of experience required
- Experience with Systems Administration and/or IP Networking is a plus
- Experience with Regulatory Compliance is a plus
- Experience in an exchange, trading facility, or financial services is a plus
- Experience with senior management and board metrics generation and communication is a plus
- Advanced certifications (for example, the CISSP)
- Advanced technical writing and/or communication education and experience
- Excel, Workflow automation tools, Data collection, normalization, indexing, correlation, and visualization. Scripting, regular expressions, string-parsing, light SDLC, and project management. NIST Cyber Security Framework, CIS, and GRC Platforms.
Skills
Required
- Excel
- Workflow automation tools
- Scripting
- Regular expressions
- String-parsing
- Light SDLC
- Project management
- NIST Cyber Security Framework
- CIS
- GRC Platforms
Preferred
- Systems Administration
- IP Networking
- Regulatory Compliance
- Advanced certifications (e.g., CISSP)