Associate Analyst, IT Governance Risk & Compliance
Neurocrine Biosciences
- Location
- US CA San Diego
- Work model
- On-Site
- Level
- Entry
- H-1B history
- 1 approvals (FY2023)
- Posted
- Aug 26, 2026
Skills
About this role
Who We Are
Neurocrine Biosciences is a leading biopharmaceutical company with a simple purpose: to relieve suffering for people with great needs. We are dedicated to discovering, developing and commercializing life-changing treatments for patients with under-addressed neurological, psychiatric, endocrine and immunological disorders. The company's diverse portfolio includes FDA-approved treatments for tardive dyskinesia, chorea associated with Huntington's disease, classic congenital adrenal hyperplasia, hyperphagia in Prader-Willi syndrome, endometriosis* and uterine fibroids*, as well as a robust pipeline including multiple compounds in mid- to late-phase clinical development across our core therapeutic areas. For more than three decades, we have applied our unique insight into neuroscience and the interconnections between brain and body systems to treat complex conditions. We relentlessly pursue medicines to ease the burden of debilitating diseases and disorders, because you deserve brave science. For more information, visit neurocrine.com , and follow the company on LinkedIn , X , Facebook and YouTube . ( *in collaboration with AbbVie ) About the Role: Provides entry-level support for the Cyber Security Governance, Risk, and Compliance (GRC) program, under regular guidance and direction from the GRC Lead. Supports risk assessments, third-party reviews, audit and compliance support, policy administration, evidence collection, issue tracking, and reporting. Builds practical knowledge of GRC processes, business objectives, regulatory requirements, and cybersecurity frameworks while delivering accurate, timely work. _ Your Contributions (include, but are not limited to): Assist with routine IT and Cyber Security risk assessments by gathering evidence, documenting results in established templates, and escalating questions, exceptions or potential concerns for review Supports third-party risk activities by tracking requests and questionnaires, organizing vendor evidence, completing initial completeness checks, and maintaining assessment records Supports framework assessments, audits and compliance reviews by coordinating evidence requests, organizing artifacts, reviewing submissions for completeness against established requirements, and documenting follow-up items Maintains accurate GRC records, including risk registries, controls, issues, action plans, exceptions, and assessment status, in approved systems and repositories Assists with mapping policies, controls, and evidence to requirements and frameworks, such as NIST CSF 2.0, ISO 27001, and CIS Controls, using documented procedures Tracks assigned remediation activities and due dates, follows up with action owners, documents updates, and escalates overdue or unclear items Supports policy and procedure administration through formatting, review routing, version control, publication, and maintenance of communication or training records Prepares routine metrics, dashboards, and status reports using established templates; validates data accuracy and supports investigation of identified data variances under guidance Participates in meetings, training, assigned research and process improvements activities; communicates professionally, protects confidential information, and performs assigned GRC support duties Requirements: Bachelor's degree in Cybersecurity, IT, Information Systems, Business, Risk Management, or a related field and 0-2 years of related experience; internships, co-ops, academic projects, labs, or equivalent practical experience qualify OR Associate's degree in Cybersecurity, IT, Information Systems, Business, Risk Management, or a related field and 1+ year of related experience, including internships, co-ops, military service, or equivalent practical experience Certification is not required; relevant coursework, training, or a foundational certification is preferred Understands Neurocrine's objectives and begins to develop knowledge of its business,