
GRC Analyst
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in United States.
• Assist in the ongoing enhancement and management of the organization's Governance, Risk, and Compliance (GRC) program.
• Ensure adherence to NIST SP 800-53, CJIS Security Policy, SOC 2, and GovRAMP standards.
• Oversee the enterprise risk register and contribute to regular risk assessments.
• Evaluate control performance and pinpoint areas for remediation or improvement.
• Develop, update, organize, and sustain security and compliance policies and procedures.
• Manage policy version control, approvals, annual reviews, and employee attestations.
• Support SOC 2 and GovRAMP audit and authorization processes.
• Assist with gap assessments and monitor remediation efforts until completion.
• Collect, organize, validate, and maintain evidence for audits.
• Collaborate with engineering and technical teams to fulfill compliance-related requirements.
• Serve as the primary contact for customer security questionnaires, vendor assessments, and compliance reviews.
• Maintain approved questionnaire responses, supporting documentation, and materials intended for customer security.
• Monitor contractual obligations related to security, privacy, compliance, reporting, and services.
• Keep a calendar of recurring contractual deliverables and deadlines.
• Coordinate reports, Service Level Agreement (SLA) documentation, insurance certificates, certifications, and other necessary compliance materials.
• Collaborate with the Growth team on government and public-sector RFPs, solicitations, and proposal opportunities.
• Create and refine sections for security, technical, compliance, and management proposals.
• Assist with proposal amendments, address customer inquiries, provide formal responses, and support post-award activities.
• Develop reusable proposal content and translate technical security capabilities for procurement and government stakeholders.
• 3–5+ years of experience in GRC, security compliance, information security, internal audit, or a related field.
• Experience in a federal, regulated, or cloud-based technology setting.
• Hands-on involvement in at least one complete audit or authorization cycle involving SOC 2, FedRAMP, StateRAMP/GovRAMP, ISO 27001, CMMC, or a similar framework.
• Working knowledge of NIST SP 800-53, SOC 2, and GovRAMP standards.
• Technical understanding of both cloud and/or on-premises environments.
• Familiarity with identity and access management, encryption, security logging and monitoring, network architecture, software development lifecycle, and change management.
• Practical experience utilizing AI tools for research, drafting, documentation, analysis, or evidence management.
• Strong written and verbal communication skills across cross-functional teams.
• Evidence-first mindset with the ability to identify, collect, organize, and validate control evidence.
• Capability to create scalable workflows in an evolving process landscape.
• Strong organizational and execution skills to manage multiple priorities, stakeholders, and deadlines.
• Combination of strategic thinking and hands-on execution capabilities.
• Adaptability, independent problem-solving skills, and a sense of ownership.
• Proven ability to coordinate multiple concurrent initiatives while meeting stringent external deadlines.
• Ability to work autonomously and establish processes with minimal direction.
• Must reside in the United States.
• Must be a US Citizen or Green Card Holder.
• Must be able to work without requiring sponsorship.
• Preferred: experience with CJIS Security Policy, FBI NGI, or criminal justice information systems.
• Preferred: experience in supporting government or public-sector RFPs and proposal development.
• Preferred: familiarity with compliance automation platforms such as Vanta, Drata, or similar tools.
• Preferred: experience working directly with government agencies or entities subject to federal security regulations.
• Competitive salary and performance-based bonuses.
• Comprehensive health, dental, and vision insurance.
• Generous paid time off and holiday schedules.
• Opportunities for professional development and training.
• Flexible work hours and remote work options.
Inova Health
VCA Animal Hospitals
Allied Benefit Systems
Grupo Boticário
Get handpicked remote jobs straight to your inbox weekly.