Metlife Legal Plans

MetLife Legal Plans is the country's largest provider of legal voluntary benefits. We have more than 40 years of experience in employee legal services and are committed to providing excellent care to our plan members, sponsors, and 18,000+ attorneys. Trusted by nearly 7 million families and more than 200 Fortune 500 companies who offer our service as an employee benefit. Growing quickly with a bold vision for our future as we evolve our company to dream bigger, move faster, and use creativity and technology to build products people love.

Cybersecurity GRC Specialist

Security AnalystSecurity AnalystFull TimeRemote

Location

United States

Posted

6 days ago

Salary

Not specified

GRCISO 27001Risk AssessmentPolicy DevelopmentThird Party Risk ManagementIncident ResponseAudit SupportSecurity AwarenessRegulatory ComplianceVulnerability Assessment

Job Description

This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more.

Role Description

The Cybersecurity GRC Specialist is responsible for managing and strengthening MetLife Legal Plans' Technology Governance, Risk, and Compliance (GRC) program. This role helps ensure the organization effectively identifies, assesses, and mitigates technology and cybersecurity risks while maintaining compliance with regulatory requirements, industry standards, and internal policies.

This individual plays a key role in protecting MetLife Legal Plans’ information assets by developing and maintaining risk management frameworks, overseeing security and compliance initiatives, and partnering with technology, legal, and business teams to integrate security best practices across the organization.

The Cybersecurity GRC Specialist also supports the organization’s Third-Party Risk Management (TPRM) program, ensuring that vendors, partners, and sponsors meet required security and risk standards before and during their engagement with the organization.

A successful candidate will have a strong background in IT risk management, cybersecurity, and information security governance, along with the ability to communicate effectively with both technical and non-technical stakeholders. Staying informed about emerging threats, evolving regulatory requirements, and industry best practices is essential to this role.

Qualifications

  • 5+ years of experience in IT Governance, Risk, Compliance (GRC), cybersecurity, or information security
  • Bachelor’s degree in Computer Science, Information Security, or related field preferred
  • Security certifications such as CISSP, CISA, CRISC, or similar highly preferred
  • Experience with Third-Party Risk Management (TPRM) programs
  • Prior experience with the ISO 27001:2022 Framework
  • Prior experience leading projects, initiatives, or mentoring team members preferred

Requirements

  • Support the development and ongoing maturity of MLP’s IT risk management framework
  • Conduct and oversee risk assessments to identify potential threats, vulnerabilities, and business impacts across systems and data environments
  • Contribute to the development, maintenance, and enforcement of IT security policies, standards, and procedures
  • Ensure policies align with regulatory requirements, internal governance standards, and industry best practices
  • Provide guidance on secure system and application design
  • Partner with IT teams to ensure security controls are incorporated into infrastructure, systems, and application development
  • Support the development and delivery of security awareness programs for employees
  • Promote a culture of security and risk awareness across the organization
  • Assist in the development and maintenance of incident response procedures
  • Participate in security incident investigations and response coordination as needed
  • Help ensure IT systems and security practices comply with applicable laws, regulations, and industry standards
  • Support internal and external audits and assist with remediation efforts when needed
  • Review vendor security documentation, certifications, and controls to ensure alignment with MLP security standards
  • Partner with procurement, legal, and technology teams to manage vendor risk throughout the vendor lifecycle
  • Support the continuous improvement of MLP’s third-party risk management program
  • Evaluate security technologies, tools, and solutions to strengthen the organization’s security posture
  • Stay informed on emerging cybersecurity trends and recommend improvements where appropriate
  • Work closely with IT teams including infrastructure, application development, and network security
  • Provide guidance on security best practices and assist with implementing appropriate controls
  • Communicate technology and security risks to leadership and key stakeholders
  • Translate technical security concepts into clear business impact and risk language
  • Review and respond to security questionnaires from clients, sponsors, and partners
  • Evaluate vendor and partner security responses to assess risk exposure
  • Support internal and external audit activities, including documentation preparation and evidence collection
  • Partner with internal teams to address audit findings and strengthen controls
  • Support contract reviews to ensure appropriate security and risk management provisions are included
  • Collaborate with legal, procurement, and technology teams to align vendor agreements with security standards
  • Contribute to the ongoing improvement of MLP’s risk, security, and governance programs
  • Identify opportunities to enhance processes, controls, and risk visibility across the organization

Benefits

  • Occasional travel may be required (10% or less)

Job Requirements

  • 5+ years of experience in IT Governance, Risk, Compliance (GRC), cybersecurity, or information security
  • Bachelor’s degree in Computer Science, Information Security, or related field preferred
  • Security certifications such as CISSP, CISA, CRISC, or similar highly preferred
  • Experience with Third-Party Risk Management (TPRM) programs
  • Prior experience with the ISO 27001:2022 Framework
  • Prior experience leading projects, initiatives, or mentoring team members preferred
  • Support the development and ongoing maturity of MLP’s IT risk management framework
  • Conduct and oversee risk assessments to identify potential threats, vulnerabilities, and business impacts across systems and data environments
  • Contribute to the development, maintenance, and enforcement of IT security policies, standards, and procedures
  • Ensure policies align with regulatory requirements, internal governance standards, and industry best practices
  • Provide guidance on secure system and application design
  • Partner with IT teams to ensure security controls are incorporated into infrastructure, systems, and application development
  • Support the development and delivery of security awareness programs for employees
  • Promote a culture of security and risk awareness across the organization
  • Assist in the development and maintenance of incident response procedures
  • Participate in security incident investigations and response coordination as needed
  • Help ensure IT systems and security practices comply with applicable laws, regulations, and industry standards
  • Support internal and external audits and assist with remediation efforts when needed
  • Review vendor security documentation, certifications, and controls to ensure alignment with MLP security standards
  • Partner with procurement, legal, and technology teams to manage vendor risk throughout the vendor lifecycle
  • Support the continuous improvement of MLP’s third-party risk management program
  • Evaluate security technologies, tools, and solutions to strengthen the organization’s security posture
  • Stay informed on emerging cybersecurity trends and recommend improvements where appropriate
  • Work closely with IT teams including infrastructure, application development, and network security
  • Provide guidance on security best practices and assist with implementing appropriate controls
  • Communicate technology and security risks to leadership and key stakeholders
  • Translate technical security concepts into clear business impact and risk language
  • Review and respond to security questionnaires from clients, sponsors, and partners
  • Evaluate vendor and partner security responses to assess risk exposure
  • Support internal and external audit activities, including documentation preparation and evidence collection
  • Partner with internal teams to address audit findings and strengthen controls
  • Support contract reviews to ensure appropriate security and risk management provisions are included
  • Collaborate with legal, procurement, and technology teams to align vendor agreements with security standards
  • Contribute to the ongoing improvement of MLP’s risk, security, and governance programs
  • Identify opportunities to enhance processes, controls, and risk visibility across the organization

Benefits

  • Occasional travel may be required (10% or less)

Related Job Pages

More Security Analyst Jobs

Security Analyst6 days ago
ContractRemote

We are seeking a Junior to Mid-Level Security Operations Center (SOC) Analyst to support the National Incident and Response Team (NIRT). In this role, you will: Review security monitoring data and identify anomalies. Assist with investigating potential security incidents. Operate...

SIEMTCP/IPPacket AnalysisFirewallIntrusion Detection SystemsOperating SystemsDatabasesEncryptionLoad BalancingEnterprise Security Tools
United States

Senior Investigator

Cotiviti

Enabling a high-quality and viable healthcare system

Security Analyst6 days ago
Full TimeRemoteTeam 5,001-10,000H1B Sponsor

As a Senior Investigator, you will investigate suspected incidents of healthcare fraud, waste, or abuse through data analysis (a high level of proficiency with Excel is required). This is not a physical investigator role. Identify, investigate, analyze and evaluate instances of p...

United States

Security Compliance Analyst, PCI/NIST

Velera

Formerly PSCU/Co-op Solutions

Security Analyst6 days ago
Full TimeRemoteTeam 1,001-5,000H1B No Sponsor

Support technology compliance programs at a fintech credit union.

CloudCyber Security
United States
$84.9K - $108.2K / year
Security Analyst6 days ago
Full TimeRemoteTeam 5,001-10,000

Architects and authors System Security Plans (SSPs), the "source of truth" for the client's security posture, detailing exactly how each NIST 800-171 control is implemented. Develops and manages the Plan of Action and Milestones (POAM), tracking every deficiency and guiding the c...

NIST SP 800-171CMMC 2.0System Security PlansPlan of Action and MilestonesIncident ResponseDisaster RecoveryFIPS 140-2FIPS 140-3Network ArchitectureLog AnalysisSOC2ISO 27001HIPAAGDPRTechnical WritingCCPCISASecurity+Access ControlMFABoundary Protection
United States