
GRC Analyst I
Posted Aug 27

Posted Aug 27
This is a fully remote position, open to applicants in United States.
• Conduct regular evaluations of cybersecurity controls to ensure compliance with relevant requirements.
• Perform fundamental assessments of controls and document the outcomes of tests.
• Oversee compliance activities and pinpoint any missing or incomplete requirements.
• Provide assistance with monthly and quarterly compliance monitoring tasks.
• Monitor remediation efforts and outstanding compliance issues.
• Request, gather, organize, and verify compliance evidence.
• Maintain repositories of evidence, ensuring that documentation is thorough and up-to-date.
• Identify evidence that is missing, outdated, or insufficient, and escalate as necessary.
• Ensure evidence traceability to relevant controls and requirements.
• Aid in the upkeep of cybersecurity policies, standards, procedures, and related documentation.
• Examine documentation for alignment with established compliance standards.
• Keep compliance records, assessment workpapers, and control documentation organized.
• Assist in recognizing compliance gaps and deficiencies in controls.
• Track Plans of Action and Milestones (POA&Ms), corrective measures, and remediation efforts.
• Follow up with control owners on outstanding remediation tasks.
• Escalate overdue or significant issues to the Compliance Manager.
• Support both internal and external audits and assessments.
• Prepare necessary evidence and documentation as requested.
• Assist with auditor inquiries and manage audit request tracking.
• Engage in activities for assessment preparation.
• Compile regular compliance status reports and dashboards.
• Maintain compliance metrics and tracking spreadsheets.
• Escalate significant compliance issues or emerging trends.
• Collaborate with Governance, Risk, and Compliance (GRC) analysts, compliance managers, technical teams, and client stakeholders.
• 1 to 3 years of experience in cybersecurity, IT, auditing, risk management, compliance, or a related area.
• Fundamental understanding of cybersecurity concepts and controls.
• Familiarity with frameworks such as NIST CSF, NIST SP 800-53, NIST SP 800-171, CMMC, ISO 27001, SOC 2, HIPAA, or PCI DSS.
• Exceptional documentation and organizational abilities.
• Capability to analyze data and identify inconsistencies or gaps.
• Strong written and oral communication skills.
• Proficiency in Microsoft Office or equivalent productivity tools.
• Security+ certification is preferred but not mandatory.
• ISC2 CC certification is preferred but not mandatory.
• CISA certification is preferred but not mandatory.
• Additional cybersecurity or compliance certifications are a plus.
• Opportunity for remote work.
• Business hours aligned with U.S. Eastern Time (ET).
The Alumni Society
TD
NOVALINK SOLUTIONS LLC
Get handpicked remote jobs straight to your inbox weekly.