Cybersecurity Governance Analyst

Agero · Remote · Engineering

Posted 2026-08-25

Apply for this role →

Role Description and Mission:

The Cybersecurity Governance Analyst is responsible for developing and maintaining Cybersecurity Security policies and standards across the enterprise.  Partners with key IT leaders to ensure the information is updated and accurate.  Drives security awareness across the organization. Coordinates security assessments, identifies risks and recommends appropriate corrective action.

Key Outcomes:

Assist in identifying, developing, and maintaining enterprise cybersecurity policies and standards, aligning processes with established frameworks such as ISO 27001, PCI-DSS, and SOC 2.

Perform vendor security and privacy risk assessments, evaluate control environments, monitor findings, and track ongoing vendor remediation efforts.

Respond to client security questionnaires, coordinate evidence collection, and support customer trust reviews and external audits.

Provide guidance on core security controls—including access management, data encryption, logging, and business continuity—while investigating deficiencies to recommend and track corrective actions.

Act as a liaison between business units and IT/Engineering teams to support data security implementations and drive enterprise-wide security awareness programs.

Partner with IT and Engineering leaders to create and refine the enterprise security architecture while supporting security control assessment strategies.

Skills, Education and Experience:

3-5 years in information security compliance with hands-on experience to industry compliance frameworks such as PCI-DSS, SOC 2, or ISO 27001.  Experience maintaining compliance documentation, ability to map controls to technical implementations and evaluate evidence quality.

Demonstrates the ability to identify, evaluate, and mitigate security risks across application, network, endpoint, and cloud environments—including DevSecOps practices and emerging technologies like AI—while ensuring strict alignment with enterprise security policies.

Possesses a comprehensive understanding of industry-standard control frameworks (e.g., ISO 27001, PCI-DSS, SOC 2) to evaluate controls, manage evidence collection, and maintain enterprise-wide compliance.

Skilled at building productive relationships across all organizational levels, including IT management, technical staff, external vendors, and consultants, to drive security awareness and risk remediation.

Demonstrates strong written and oral communication skills; adept at authoring technical documentation, delivering security presentations, and accurately completing complex client security questionnaires.

Rapidly learns and applies advanced technical security concepts, adapting governance strategies seamlessly within a fast-paced, constantly evolving cybersecurity environment.

Applies strong analytical skills and sound independent judgment to evaluate complex risk scenarios, pay close attention to detail, and execute effective decision-making.

Hiring In:

United States: Arizona, California, Florida, Georgia, Illinois, Massachusetts, Michigan, New Hampshire, New York State, New Mexico, North Carolina, Tennessee, Virginia

The anticipated closing date to submit applications for this role is 9/18/2026. Join our Greenhouse Candidate Portal to track your application status and receive instant alerts for future openings.

The base salary range presented represents the anticipated low and high end salary range for new hires in this position. Your final base salary will be determined based on factors such as work location, experience, job related skills, and relevant training and education. The range listed is just one component of the total compensation package provided by Agero to employees.

National Pay Range

$75,000—$95,000 USD

Apply for this role →

← Back to all jobs