Home › Companies › Careers Westernsouthern Icims Com › Cybersecurity Governance Analyst III
Cybersecurity Governance Analyst III
Careers Westernsouthern Icims Com · CINCINNATI, OH, US · Active · iCIMS
Job facts
| Field | Value |
|---|---|
| Company | Careers Westernsouthern Icims Com |
| Title | Cybersecurity Governance Analyst III |
| Normalized title | - |
| Department / team | Information Technology |
| Location | CINCINNATI, OH, United States |
| Work model | - |
| Employment type | Full Time |
| Salary | - |
| Status | active |
| ATS provider | iCIMS |
| Posted / first seen | 2024-06-06 / 2026-05-31 |
| Changed / last seen | 2026-06-06 / 2026-06-06 |
Related slices
| Page | What it contains | Open |
|---|---|---|
| Company jobs | Active postings from Careers Westernsouthern Icims Com. | Open |
| Company breakdowns | Role, location, ATS, and work model facets for this company. | Open |
| ATS provider jobs | Active postings observed through iCIMS. | Open |
| Provider filtered search | The same provider as a filtered job collection. | Open |
| City jobs | Active postings in CINCINNATI. | Open |
| Department jobs | Active postings in Information Technology. | Open |
| Lifecycle events | Open, update, close, and reopen events for this posting. | Open |
| Original posting | Canonical source or apply URL captured from the ATS. | Open |
Linked records
| Company | Careers Westernsouthern Icims Com |
| Source | 6feb552e-6843-4b93-a3aa-bade71ffaefb |
| ATS provider | iCIMS |
Description
Overview Provides support to business and IT teams including security consulting for major corporate initiatives and information security projects. Performs risk assessments, security assessments and policy reviews of WSFG systems and third-party vendors to identify areas of noncompliance with established information security standards and regulations, and helps recommend mitigations strategies and countermeasures. Provides security guidance to other IT and project teams in the evaluation, design, or implementation of secure computing environments. Develops, reviews, and monitors information security policies and procedures and makes recommendations for improvement. Identifies and defines overall security requirements for the proper operation and design of business and IT applications to ensure the protection of WSFG systems and data. Contributes to the development of the organization's information security awareness program. Escalates when needed and updates Director on a regular basis.
Responsibilities
What you will do:
Assists team in performing third-party vendor due diligence security reviews to ensure compliance with information security policy, security procedures, and regulatory requirements. Identifies and reports deficiencies or risks to the appropriate stakeholders. Follows up with business teams and third parties to escalate issues when necessary.
Participates in the effort to address identified IT audit findings and cybersecurity risks with corrective action plans. Works with senior team members to support process/program improvements. Conducts ongoing monitoring of the first-party security posture and performance. Acts as a liaison with Internal Audit on IT audits.
Works with project teams to ensure PMLC/SDLC tollgates are being met for security and that the appropriate security artifacts are being maintained. Helps in PMLC/SDLC planning and makes certain it assesses the protection of information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction in order to provide confidentiality, integrity, and availability.
Conducts in-depth research to understand industry best practices, emerging trends and the latest open source methods that will help address current security challenges and enable new ways of delivering value to the Enterprise.
Works with IT and the business serving as a technical security consultant on IT and business projects. Provides input on complex business problems and helps deliver solutions that address risks to the corporate network and information assets. Ensures the appropriate level of controls are applied based on industry standards, best practices, and cybersecurity regulations by developing repeatable processes to identify, evaluate, and measure IT security risk.
Helps manage the information security policy lifecycle, including policy creation, policy maintenance, policy exception, and policy change requests. Works with them to help improve the overall security policy framework. Works with the business and IT management to ensure that the security policy framework and internal controls are being appropriate followed. Conducts risk assessments based on policy and control evaluations.
Contributes to the development, review, implementation, and maintenance of the organization's information security awareness program. Assists in effort to collaborate with HR and Corporate Communication teams to deliver security training and security awareness to associates and consultants."
Helps manage the remediation of audit and security review findings and recommendations.
Performs other duties as assigned.
Complies with all policies and standards.
Qualifications
Bachelor's Degree Computer Science, Computer Engineering, IT or a related technical field, or commensurate selection criteria experience. - Required
Typically requires at least five years of combined work experience in information assurance and security roles such as IT Audit, Risk, Compliance and Information Security. - Required
Experience in the areas of information security governance and third-party risk management. - Required
Experience working with IT risk and compliance frameworks such as NIST (preferred), ISO, COBIT, COSO, COBIT, etc. - Required
Experience working with best practices and industry cybersecurity regulations. - Required
Experience with information security, security awareness, and risk assessment and mitigation concepts, methodologies, and processes. - Required
Proven experience in completing assigned tasks accurately and on a timely basis. - Required
Proven ability to identify and assess the severity and potential impact of risks. - Required
Demonstrated inherent passion for information security and service excellence. - Required
Ability to identify project risks and gaps, developing creative and workable solutions to complex problems and policy issues. - Required
Strong team player - collaborates well with others to solve problems and actively incorporate input from various sources. - Required
Demonstrated strong analytical and problem-solving skills with the ability to grasp new concepts and apply them; effectively evaluates information / data to make decisions; anticipate obstacles and develop plans to resolve. - Required
Possess and display excellent verbal and written communication skills with ability to convey information to internal and external customers in a clear, focused, and concise manner. - Required
Demonstrated calm and professional demeanor when handling demanding situations. - Required
Proven ability to work with a team and multiple stakeholders to provide direction and oversight. - Required
Demonstrated self-starter with strong internal motivation. - Required
Proven ability to work under multiple deadlines and with minimal supervision. - Required
Basic computer, network, and system knowledge and skills with a thorough understanding of security controls. - Required
Strong proficiency in the use of Microsoft Office, particularly Word, Excel, PowerPoint. - Required
CISSP Certified Information Systems Security Professional Candidate encouraged to hold one or more of the following security certifications: Certified Information Systems Security Professional (CISSP), any GIAC certification or ISACA certifications. Upon Hire - Preferred
Work Setting/Position Demands:
Works in an office setting and remains in a stationary position for long periods of time while working at a desk, on a computer or with other standard office equipment, or while in meetings.
Requires the ability to verbally communicate and exchange accurate information to customers and associates on a regular basis.
Requires visual acuity to read and interpret a variety of correspondence, procedures, reports and forms via paper and electronic documents, visual inspection involving small defects; small parts, and/or operation of machinery (including inspection); using measurement devices continuously. Visual acuity is required to determine accuracy, neatness, and thoroughness of work assigned.
Requires the ability to prepare written correspondence, reports and forms using prescribed formats and conforming to rules of punctuation, grammar, diction, and style on a regular basis.
Requires the ability to apply principles of logical thinking to define problems, collect data, establish facts, and draw valid conclusions
Performs substantial movement of wrists, hands, and fingers for continuous computer work.
Extended hours required during peak workloads or special projects/events.
Travel Requirements:
None
Full job record
| Job ID | cb8046a280dfe4492c2e1d2e2ab86ecf02b9d709 |
| Org ID | e4b523bc-62d8-4c8e-af49-804ec2e5dbe3 |
| Source ID | 6feb552e-6843-4b93-a3aa-bade71ffaefb |
| Board ID | 6feb552e-6843-4b93-a3aa-bade71ffaefb |
| Provider | icims |
| Provider Job Key | 24045 |
| Title | Cybersecurity Governance Analyst III |
| Normalized Title | — |
| Status | active |
| Active | yes |
| Location Text | CINCINNATI, OH, US |
| Department | Information Technology |
| Team | — |
| Employment Type | full_time |
| Workplace Type | — |
| Remote Policy | — |
| Country | United States |
| Region | OH |
| City | CINCINNATI |
| Salary Raw | Overview Provides support to business and IT teams including security consulting for major corporate initiatives and information security projects. Performs risk assessments, security assessments and policy reviews of WSFG systems and third-party vendors to identify areas of noncompliance with established information security standards and regulations, and helps recommend mitigations strategies and countermeasures. Provides security guidance to other IT and project teams in the evaluation, design, or implementation of secure computing environments. Develops, reviews, and monitors information security policies and procedures and makes recommendations for improvement. Identifies and defines overall security requirements for the proper operation and design of business and IT applications to ensure the protection of WSFG systems and data. Contributes to the development of the organization's information security awareness program. Escalates when needed and updates Director on a regular basis. Responsibilities What you will do: Assists team in performing third-party vendor due diligence security reviews to ensure compliance with information security policy, security procedures, and regulatory requirements. Identifies and reports deficiencies or risks to the appropriate stakeholders. Follows up with business teams and third parties to escalate issues when necessary. Participates in the effort to address identified IT audit findings and cybersecurity risks with corrective action plans. Works with senior team members to support process/program improvements. Conducts ongoing monitoring of the first-party security posture and performance. Acts as a liaison with Internal Audit on IT audits. Works with project teams to ensure PMLC/SDLC tollgates are being met for security and that the appropriate security artifacts are being maintained. Helps in PMLC/SDLC planning and makes certain it assesses the protection of information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction in order to provide confidentiality, integrity, and availability. Conducts in-depth research to understand industry best practices, emerging trends and the latest open source methods that will help address current security challenges and enable new ways of delivering value to the Enterprise. Works with IT and the business serving as a technical security consultant on IT and business projects. Provides input on complex business problems and helps deliver solutions that address risks to the corporate network and information assets. Ensures the appropriate level of controls are applied based on industry standards, best practices, and cybersecurity regulations by developing repeatable processes to identify, evaluate, and measure IT security risk. Helps manage the information security policy lifecycle, including policy creation, policy maintenance, policy exception, and policy change requests. Works with them to help improve the overall security policy framework. Works with the business and IT management to ensure that the security policy framework and internal controls are being appropriate followed. Conducts risk assessments based on policy and control evaluations. Contributes to the development, review, implementation, and maintenance of the organization's information security awareness program. Assists in effort to collaborate with HR and Corporate Communication teams to deliver security training and security awareness to associates and consultants." Helps manage the remediation of audit and security review findings and recommendations. Performs other duties as assigned. Complies with all policies and standards. Qualifications Bachelor's Degree Computer Science, Computer Engineering, IT or a related technical field, or commensurate selection criteria experience. - Required Typically requires at least five years of combined work experience in information assurance and security roles such as IT Audit, Risk, Compliance and Information Security. - Required Experience in the areas of information security governance and third-party risk management. - Required Experience working with IT risk and compliance frameworks such as NIST (preferred), ISO, COBIT, COSO, COBIT, etc. - Required Experience working with best practices and industry cybersecurity regulations. - Required Experience with information security, security awareness, and risk assessment and mitigation concepts, methodologies, and processes. - Required Proven experience in completing assigned tasks accurately and on a timely basis. - Required Proven ability to identify and assess the severity and potential impact of risks. - Required Demonstrated inherent passion for information security and service excellence. - Required Ability to identify project risks and gaps, developing creative and workable solutions to complex problems and policy issues. - Required Strong team player - collaborates well with others to solve problems and actively incorporate input from various sources. - Required Demonstrated strong analytical and problem-solving skills with the ability to grasp new concepts and apply them; effectively evaluates information / data to make decisions; anticipate obstacles and develop plans to resolve. - Required Possess and display excellent verbal and written communication skills with ability to convey information to internal and external customers in a clear, focused, and concise manner. - Required Demonstrated calm and professional demeanor when handling demanding situations. - Required Proven ability to work with a team and multiple stakeholders to provide direction and oversight. - Required Demonstrated self-starter with strong internal motivation. - Required Proven ability to work under multiple deadlines and with minimal supervision. - Required Basic computer, network, and system knowledge and skills with a thorough understanding of security controls. - Required Strong proficiency in the use of Microsoft Office, particularly Word, Excel, PowerPoint. - Required CISSP Certified Information Systems Security Professional Candidate encouraged to hold one or more of the following security certifications: Certified Information Systems Security Professional (CISSP), any GIAC certification or ISACA certifications. Upon Hire - Preferred Work Setting/Position Demands: Works in an office setting and remains in a stationary position for long periods of time while working at a desk, on a computer or with other standard office equipment, or while in meetings. Requires the ability to verbally communicate and exchange accurate information to customers and associates on a regular basis. Requires visual acuity to read and interpret a variety of correspondence, procedures, reports and forms via paper and electronic documents, visual inspection involving small defects; small parts, and/or operation of machinery (including inspection); using measurement devices continuously. Visual acuity is required to determine accuracy, neatness, and thoroughness of work assigned. Requires the ability to prepare written correspondence, reports and forms using prescribed formats and conforming to rules of punctuation, grammar, diction, and style on a regular basis. Requires the ability to apply principles of logical thinking to define problems, collect data, establish facts, and draw valid conclusions Performs substantial movement of wrists, hands, and fingers for continuous computer work. Extended hours required during peak workloads or special projects/events. Travel Requirements: None |
| Salary Min | — |
| Salary Max | — |
| Salary Currency | — |
| Salary Period | hour |
| Source URL | https://careers-westernsouthern.icims.com/jobs/24045/cybersecurity-governance-analyst-iii/job |
| Apply URL | https://careers-westernsouthern.icims.com/jobs/24045/cybersecurity-governance-analyst-iii/job |
| First Seen At | 2026-05-31 18:42:43Z |
| Last Seen At | 2026-06-06 08:25:34Z |
| Last Checked At | 2026-06-06 08:25:34Z |
| Last Changed At | 2026-06-06 08:25:34Z |
| Inactive At | — |
| Source Posted At | 2024-06-06 08:25:33Z |
| Source Updated At | 2026-04-27 15:55:20Z |
| Raw Payload Uri | s3://job-postings-prod-raw-590183727216/raw/provider=icims/board=careers-westernsouthern.icims.com/date=2026-06-06/2026-06-06T08-25-31-644Z-daf95a8a4a66b3e9299b2f440025dc8f6d8ea1405adbd3d6b00bc36dc5033fff.json |
Event Fields
{
"content_hash": "5b0ac27035ab34d25aff42bbea6d91cff565a6c7cd4ac1512ffff07eaed87c2c",
"source_hash": "82ddd6696a312dfe693696fcd62d43bf57c6ee6b521eaade1160cf9f53bf582d",
"last_changed_at": "2026-06-06T08:25:34.794Z",
"active_status": "active"
}Parsed Structured
{
"language": "en",
"location": {
"raw": "CINCINNATI, OH, US",
"city": "CINCINNATI",
"region": "OH",
"country": "United States",
"is_remote": false,
"confidence": 0.8
},
"salary_max": null,
"salary_min": null,
"inferred_at": "2026-06-06T08:25:34.777Z",
"launch_scope": {
"reason": "english_us_canada",
"included": true,
"language": "en",
"location": {
"raw": "CINCINNATI, OH, US",
"city": "CINCINNATI",
"region": "OH",
"country": "United States",
"is_remote": false,
"confidence": 0.8
},
"countries": [
"United States"
]
},
"remote_policy": null,
"salary_period": "hour",
"workplace_type": null,
"salary_currency": null
}Extensions
{}Native Structured
{
"json_ld": {
"url": "https://careers-westernsouthern.icims.com/jobs/24045/cybersecurity-governance-analyst-iii/job",
"@type": "JobPosting",
"title": "Cybersecurity Governance Analyst III",
"@context": "http://schema.org",
"datePosted": "2024-06-06T08:25:33.894Z",
"description": "<h2>Overview</h2>Provides support to business and IT teams including security consulting for major corporate initiatives and information security projects. Performs risk assessments, security assessments and policy reviews of WSFG systems and third-party vendors to identify areas of noncompliance with established information security standards and regulations, and helps recommend mitigations strategies and countermeasures. Provides security guidance to other IT and project teams in the evaluation, design, or implementation of secure computing environments. Develops, reviews, and monitors information security policies and procedures and makes recommendations for improvement. Identifies and defines overall security requirements for the proper operation and design of business and IT applications to ensure the protection of WSFG systems and data. Contributes to the development of the organization's information security awareness program. Escalates when needed and updates Director on a regular basis.\n<h2>Responsibilities</h2>\n<p><strong>What you will do:</strong></p>\n<ul>\n <li>Assists team in performing third-party vendor due diligence security reviews to ensure compliance with information security policy, security procedures, and regulatory requirements. Identifies and reports deficiencies or risks to the appropriate stakeholders. Follows up with business teams and third parties to escalate issues when necessary.</li>\n <li>Participates in the effort to address identified IT audit findings and cybersecurity risks with corrective action plans. Works with senior team members to support process/program improvements. Conducts ongoing monitoring of the first-party security posture and performance. Acts as a liaison with Internal Audit on IT audits.</li>\n <li>Works with project teams to ensure PMLC/SDLC tollgates are being met for security and that the appropriate security artifacts are being maintained. Helps in PMLC/SDLC planning and makes certain it assesses the protection of information and information systems from unauthorized access, use, disclosure, disruption, modification, or destruction in order to provide confidentiality, integrity, and availability.</li>\n <li>Conducts in-depth research to understand industry best practices, emerging trends and the latest open source methods that will help address current security challenges and enable new ways of delivering value to the Enterprise.</li>\n <li>Works with IT and the business serving as a technical security consultant on IT and business projects. Provides input on complex business problems and helps deliver solutions that address risks to the corporate network and information assets. Ensures the appropriate level of controls are applied based on industry standards, best practices, and cybersecurity regulations by developing repeatable processes to identify, evaluate, and measure IT security risk.</li>\n <li>Helps manage the information security policy lifecycle, including policy creation, policy maintenance, policy exception, and policy change requests. Works with them to help improve the overall security policy framework. Works with the business and IT management to ensure that the security policy framework and internal controls are being appropriate followed. Conducts risk assessments based on policy and control evaluations.</li>\n <li>Contributes to the development, review, implementation, and maintenance of the organization's information security awareness program. Assists in effort to collaborate with HR and Corporate Communication teams to deliver security training and security awareness to associates and consultants.\"</li>\n <li>Helps manage the remediation of audit and security review findings and recommendations.</li>\n <li>Performs other duties as assigned.</li>\n <li>Complies with all policies and standards.</li>\n</ul>\n<h2>Qualifications</h2>\n<ul>\n <li>Bachelor's Degree Computer Science, Computer Engineering, IT or a related technical field, or commensurate selection criteria experience. - Required</li>\n <li>Typically requires at least five years of combined work experience in information assurance and security roles such as IT Audit, Risk, Compliance and Information Security. - Required</li>\n <li>Experience in the areas of information security governance and third-party risk management. - Required</li>\n <li>Experience working with IT risk and compliance frameworks such as NIST (preferred), ISO, COBIT, COSO, COBIT, etc. - Required</li>\n <li>Experience working with best practices and industry cybersecurity regulations. - Required</li>\n <li>Experience with information security, security awareness, and risk assessment and mitigation concepts, methodologies, and processes. - Required</li>\n <li>Proven experience in completing assigned tasks accurately and on a timely basis. - Required</li>\n <li>Proven ability to identify and assess the severity and potential impact of risks. - Required</li>\n <li>Demonstrated inherent passion for information security and service excellence. - Required</li>\n <li>Ability to identify project risks and gaps, developing creative and workable solutions to complex problems and policy issues. - Required</li>\n <li>Strong team player - collaborates well with others to solve problems and actively incorporate input from various sources. - Required</li>\n <li>Demonstrated strong analytical and problem-solving skills with the ability to grasp new concepts and apply them; effectively evaluates information / data to make decisions; anticipate obstacles and develop plans to resolve. - Required</li>\n <li>Possess and display excellent verbal and written communication skills with ability to convey information to internal and external customers in a clear, focused, and concise manner. - Required</li>\n <li>Demonstrated calm and professional demeanor when handling demanding situations. - Required</li>\n <li>Proven ability to work with a team and multiple stakeholders to provide direction and oversight. - Required</li>\n <li>Demonstrated self-starter with strong internal motivation. - Required</li>\n <li>Proven ability to work under multiple deadlines and with minimal supervision. - Required</li>\n <li>Basic computer, network, and system knowledge and skills with a thorough understanding of security controls. - Required</li>\n <li>Strong proficiency in the use of Microsoft Office, particularly Word, Excel, PowerPoint. - Required</li>\n <li>CISSP Certified Information Systems Security Professional Candidate encouraged to hold one or more of the following security certifications: Certified Information Systems Security Professional (CISSP), any GIAC certification or ISACA certifications. Upon Hire - Preferred</li>\n</ul>\n<p><strong>Work Setting/Position Demands:</strong></p>\n<ul>\n <li>Works in an office setting and remains in a stationary position for long periods of time while working at a desk, on a computer or with other standard office equipment, or while in meetings.</li>\n <li>Requires the ability to verbally communicate and exchange accurate information to customers and associates on a regular basis.</li>\n <li>Requires visual acuity to read and interpret a variety of correspondence, procedures, reports and forms via paper and electronic documents, visual inspection involving small defects; small parts, and/or operation of machinery (including inspection); using measurement devices continuously. Visual acuity is required to determine accuracy, neatness, and thoroughness of work assigned.</li>\n <li>Requires the ability to prepare written correspondence, reports and forms using prescribed formats and conforming to rules of punctuation, grammar, diction, and style on a regular basis.</li>\n <li>Requires the ability to apply principles of logical thinking to define problems, collect data, establish facts, and draw valid conclusions</li>\n <li>Performs substantial movement of wrists, hands, and fingers for continuous computer work.</li>\n <li>Extended hours required during peak workloads or special projects/events.</li>\n</ul>\n<p><strong>Travel Requirements:</strong></p>\n<ul>\n <li>None</li>\n</ul>",
"directApply": true,
"jobLocation": [
{
"@type": "Place",
"address": {
"@type": "PostalAddress",
"postalCode": "45202",
"addressRegion": "OH",
"streetAddress": "250 EAST 5TH STREET",
"addressCountry": "US",
"addressLocality": "CINCINNATI",
"postOfficeBoxNumber": "UNAVAILABLE"
}
}
],
"validThrough": "2027-06-06T08:25:33.894Z",
"employmentType": "FULL_TIME",
"hiringOrganization": {
"name": "Western & Southern Financial Group",
"@type": "Organization",
"sameAs": "UNAVAILABLE"
},
"occupationalCategory": "Information Technology"
},
"detail_meta": {
"url": "https://careers-westernsouthern.icims.com/jobs/24045/cybersecurity-governance-analyst-iii/job?in_iframe=1",
"http_status": 200,
"content_type": "text/html;charset=UTF-8",
"response_bytes": 43376,
"compact_response_bytes": 9139,
"original_response_bytes": 43376
},
"sitemap_job": {
"id": "24045",
"url": "https://careers-westernsouthern.icims.com/jobs/24045/cybersecurity-governance-analyst-iii/job",
"slug": "cybersecurity-governance-analyst-iii",
"lastmod": "2026-04-27T11:55:20-04:00"
},
"detail_errors": []
}Get this page with API
Rendered from the bluedoor Job Postings API. Reproduce it:
GET https://api.bluedoor.sh/job-postings/v1/jobs/cb8046a280dfe4492c2e1d2e2ab86ecf02b9d709?include=descriptionJSONGET https://api.bluedoor.sh/job-postings/v1/orgs/e4b523bc-62d8-4c8e-af49-804ec2e5dbe3JSONGET https://api.bluedoor.sh/job-postings/v1/sources/6feb552e-6843-4b93-a3aa-bade71ffaefbJSONGET https://api.bluedoor.sh/job-postings/v1/jobs/cb8046a280dfe4492c2e1d2e2ab86ecf02b9d709/eventsJSON