GRC Analyst I

Posted Aug 27

This is a fully remote position, open to applicants in United States.

📋 Description

• Conduct regular evaluations of cybersecurity controls to ensure compliance with relevant requirements.

• Perform fundamental assessments of controls and document the outcomes of tests.

• Oversee compliance activities and pinpoint any missing or incomplete requirements.

• Provide assistance with monthly and quarterly compliance monitoring tasks.

• Monitor remediation efforts and outstanding compliance issues.

• Request, gather, organize, and verify compliance evidence.

• Maintain repositories of evidence, ensuring that documentation is thorough and up-to-date.

• Identify evidence that is missing, outdated, or insufficient, and escalate as necessary.

• Ensure evidence traceability to relevant controls and requirements.

• Aid in the upkeep of cybersecurity policies, standards, procedures, and related documentation.

• Examine documentation for alignment with established compliance standards.

• Keep compliance records, assessment workpapers, and control documentation organized.

• Assist in recognizing compliance gaps and deficiencies in controls.

• Track Plans of Action and Milestones (POA&Ms), corrective measures, and remediation efforts.

• Follow up with control owners on outstanding remediation tasks.

• Escalate overdue or significant issues to the Compliance Manager.

• Support both internal and external audits and assessments.

• Prepare necessary evidence and documentation as requested.

• Assist with auditor inquiries and manage audit request tracking.

• Engage in activities for assessment preparation.

• Compile regular compliance status reports and dashboards.

• Maintain compliance metrics and tracking spreadsheets.

• Escalate significant compliance issues or emerging trends.

• Collaborate with Governance, Risk, and Compliance (GRC) analysts, compliance managers, technical teams, and client stakeholders.


⛳️ Requirements

• 1 to 3 years of experience in cybersecurity, IT, auditing, risk management, compliance, or a related area.

• Fundamental understanding of cybersecurity concepts and controls.

• Familiarity with frameworks such as NIST CSF, NIST SP 800-53, NIST SP 800-171, CMMC, ISO 27001, SOC 2, HIPAA, or PCI DSS.

• Exceptional documentation and organizational abilities.

• Capability to analyze data and identify inconsistencies or gaps.

• Strong written and oral communication skills.

• Proficiency in Microsoft Office or equivalent productivity tools.

• Security+ certification is preferred but not mandatory.

• ISC2 CC certification is preferred but not mandatory.

• CISA certification is preferred but not mandatory.

• Additional cybersecurity or compliance certifications are a plus.


🏝️ Benefits

• Opportunity for remote work.

• Business hours aligned with U.S. Eastern Time (ET).

People also viewed

The Alumni Society11 hours ago

Director, Commercial Systems, Data Management & Governance

US flagUnited States OnlyFull-timeRisk$210k – $260k/year
ApplyView job
TD12 hours ago

Risk Manager II, Unsecured Lending

US flagNew Jersey, +1 more stateFull-timeRisk$115.4k – $173.2k/year
ApplyView job
NOVALINK SOLUTIONS LLC12 hours ago

Public Health Data Governance Analyst

US flagNebraska OnlyFull-timeRisk
ApplyView job
Leega13 hours ago

Data Governance Analyst, Mid-Level

BR flagBrazil OnlyFull-timeRisk
ApplyView job
Grupo Boticário13 hours ago

Governance Specialist I – Treasury

BR flagBrazil OnlyFull-timeRisk
ApplyView job
CTI Clinical Trial and Consulting Services14 hours ago

Manager, Risk Based Quality Management

US flagKentucky OnlyFull-timeRisk
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers