Protera logo

Get help on your job search

Need help in your climate job search? Dive deep into climate with Terra.do’s 12-week climate bootcamp course.

Terra.do has partnered with ClimateTechList to give ClimateTechList users a 15% discount for its flagship Climate Change: Learning for Action program.

Job Description

Summary: We are looking for a highly skilled and detail-oriented professional to fill a dual role as a GRC Analyst with a focus on Vulnerability Management and Governance, Risk, and Compliance (GRC). This position involves overseeing the entire lifecycle of vulnerability management while simultaneously supporting GRC initiatives across the organization. The ideal candidate will be experienced in vulnerability scanning, risk assessment, threat intelligence, and compliance frameworks such as NIST, GDPR, and ISO 27001. Strong communication and organizational skills are essential for preparing reports, conducting client reviews, and ensuring the timely closure of vulnerabilities and risk-related tasks.

Key Responsibilities:

Vulnerability Management:

  • Manage the end-to-end vulnerability management process, including identification, assessment, and remediation.
  • Collaborate with cross-functional teams to ensure timely identification and resolution of vulnerabilities.
  • Conduct regular vulnerability scans, analyze results, and document findings for further action.
  • Generate detailed reports on vulnerability status, severity, risks, and recommendations.
  • Prioritize vulnerabilities based on potential impact and ensure critical issues are addressed first.
  • Prepare and present vulnerability management reports and status updates to stakeholders, including clients and senior leadership.
  • Track and follow up on remediation efforts to ensure vulnerabilities are resolved within established timelines.

Governance, Risk, and Compliance (GRC):

  • Assist in the implementation and maintenance of compliance frameworks such as NIST, GDPR, SOC2, and ISO 27001.
  • Ensure the organization adheres to industry best practices for risk management and regulatory compliance.
  • Work with clients to create customized vulnerability and risk management reports, ensuring specific requirements are met.
  • Analyze security tools to ensure their alignment with security requirements and compliance standards.
  • Conduct user access audits and address any discrepancies with security policies and configurations.
  • Analyze and follow up on penetration testing results, ensuring vulnerabilities are remediated in a timely manner.
  • Identify non-compliance issues and recommend improvements to security and compliance processes.
  • Provide support for GRC-related initiatives, including risk assessments, audits, and regulatory compliance reviews.

Collaboration and Communication:

  • Work closely with legal, compliance, and IT teams to align vulnerability management with regulatory and legal requirements.
  • Present vulnerability management findings, remediation plans, and progress updates in meetings with stakeholders.
  • Respond to ad-hoc requests from internal teams and clients, addressing specific security, risk, or compliance needs.

Requirements

Skills & Experience:

  • 4–5 years of experience in both vulnerability management and GRC.
  • Proficiency with vulnerability management tools such as Qualys, Nessus, and Rapid7.
  • Familiarity with compliance frameworks like NIST, GDPR, and ISO 27001.
  • Strong analytical, communication, and reporting skills.
  • Ability to manage multiple projects and meet deadlines.
  • Relevant certifications (e.g., ISO 27001 LA/LI) are a plus.
ClimateTechList.com logo

Protera number of job openings over time by month

ClimateTechList is the web's largest aggregator of climate, clean tech, renewable energy & green jobs. Contact us if you'd like to use partner or use our current or historical jobs data in any way.

Apply to Job

👉 Please mention that you found the job on ClimateTechList, this helps us get more climate tech companies listed here, thanks!

Get a referral to Protera

If possible, try to get a warm intro/referral to Protera before applying! Do a LinkedIn search to see who you may know at the company. See this LinkedIn post from Steven for more details on this tactic.

All job openings from Protera

Join ClimateTechList Talent Collective

Want to be matched with companies directly? Apply to the talent collective.

Here's how it works:

  1. You submit an application

  2. We'll share your profile with climate tech companies potentially interested in chatting with you

  3. We'll reach out if there's a company interested in talking to you.

Join ClimateTechList Talent Collective

Want to be matched with companies directly? Apply to the talent collective.

Here's how it works:

  1. You submit an application

  2. We'll share your profile with climate tech companies potentially interested in chatting with you

  3. We'll reach out if there's a company interested in talking to you.