Cybersecurity GRC Analyst at Western National Group & Umialik Insurance
Edina, MN
$66,300–$114,290
Jul 1, 2026
Edina, MN
Jul 21, 2026
What this job asks for AI summary
A governance, risk, and compliance role at a Midwestern property-and-casualty insurer, focused on maintaining regulatory compliance across multiple states, assessing third-party vendor security risk, and managing the organization's security awareness training program. The position also involves mapping controls to frameworks such as NIST CSF and CIS Controls, conducting gap assessments, and producing security metrics, dashboards, and executive reporting materials. It suits candidates with a background in GRC or cybersecurity compliance.
Mid level · 2+ years · Minneapolis-St. Paul-Bloomington, MN-WI · Full-time
Pay in the description: $66,300–$114,290
“or” means any one of them counts — you don't need all of them.
We read this from the posting text with AI. Skim the description below before ruling yourself out.
How this req sits in the market our data
Roughly 300 people in the Minneapolis-St. Paul-Bloomington, MN-WI area plausibly meet what this posting asks for (information security analysts). range 60–450
Applicant volume Moderate — A normal amount of company. The rare requirements below are what will separate a shortlisted application from the rest.
What the occupation pays Median $133,584 (middle half $105,561–$161,750). This posting is about at that midpoint.
Estimated from BLS employment for this occupation and area, per-skill prevalence across our listing corpus, and published wage benchmarks — as of Jul 28, 2026. It is a model, not a headcount.
Why we read it this way (8)
The role is a GRC (Governance, Risk, and Compliance) Analyst with a cybersecurity focus — primarily compliance, vendor risk, security awareness, and framework mapping rather than hands-on security operations or engineering. 15-1212 (Information Security Analysts) is the best fit, though the GRC/compliance emphasis could also point toward 15-1299.
The degree requirement lists 'Bachelor's degree in communications, business, or a related field OR equivalent relevant experience,' so no formal degree is hard-gated.
NIST CSF, CIS Controls, and COBIT are listed together as examples of frameworks the candidate must understand; they are emitted as separate skills since they are distinct frameworks, with CIS Controls and COBIT also noted as alternatives to NIST CSF for the single 'strong understanding of frameworks' gate.
GRC platforms (Drata, Vanta, OneTrust, Archer) appear under the 'ideal candidate' / preferred section and are not hard requirements.
The compensation range ($66,300–$114,290/year) is wide; the posting notes pay may vary by qualifications, scope, and location.
The posting references a hybrid/flexible work arrangement but does not offer fully remote work; remote is set to false.
Several items in the required qualifications (e.g., 'strong understanding of GRC concepts', 'excellent communication skills', 'ability to analyze information') are soft skills or generic competencies with no named technology and are omitted from the skills list per extraction rules.
Ignored 1 non-technology phrase(s) as skills (responsibilities/concepts, not named tools): vendor security risk assessments.
Read the full posting
The employer publishes the full description on their own site — read it there ↗. Or sign in to read it here — it's free, and it also lets you track this application.