
Security Governance, Risk & Compliance (GRC) Analyst
Posted Jul 21

Posted Jul 21
This is a fully remote position, open to applicants in District of Columbia, +1 more state.
• Oversee the management and execution of intricate control frameworks for extensive systems, encompassing Cloud infrastructure and Software as a Service (SaaS) solutions (GCP, AWS, GitHub, Okta, etc).
• Develop and design automation solutions for gathering evidence across Cloud infrastructure, endpoints, and SaaS platforms.
• Perform risk assessments throughout various business units and processes. Identify risk issues and propose remediation and risk mitigation strategies.
• Engage in incident response (IR) activities, offering risk analysis and remediation support as required.
• Assist in or implement automated controls to bolster risk mitigation efforts in collaboration with stakeholders across different business units.
• Integrate CMMC certification into Virtru’s suite of compliance assessments and ongoing monitoring activities (FedRAMP, SOC 2, PCI).
• Streamline the third-party vendor onboarding and annual review processes by assessing the security measures of existing and potential partners.
• Enrich the team with your unique perspective, enthusiasm, and passion for learning.
• A minimum of 5+ years of experience in information security, IT audit and/or IT Risk Management, or as a GRC Analyst/Engineer.
• Profound understanding of several of the following: CMMC, NIST 800-53 & 800-171, FedRAMP, SOC 2, PCI, and/or other international privacy compliance frameworks.
• Technical expertise with a strong grasp of contemporary cloud technologies (AWS, GCP, Azure, etc.) alongside familiarity with GRC tools (Hyperproof, Vanta, Drata, etc.) and SIEM tools (Datadog, Splunk).
• Proven ability to build relationships, having collaborated with both business and technical risk, and adept at translating risk across various organizational levels.
• Experience in training and mentoring teams to enhance their skills in security and privacy practices.
• Enjoy working within an autonomous agile team environment. At Virtru, you’ll take ownership of security while collaborating with others to develop and implement effective solutions.
• Capability to resolve conflicts and drive issues to resolution.
• Ability to work independently with minimal supervision while maintaining a high level of productivity.
• A Flexible PTO policy — we strongly encourage you to take time off (in addition to 14 holidays) to ensure that you are getting the proper time needed to unplug and recharge.
• A $1,500 annual Learning & Development Stipend focused on providing you the resources to continually learn and professionally grow.
• Frequent company-sponsored team celebrations that provide ample opportunities to connect with teammates and be social!
• Access to an Employee Assistance Program.
• Access to Headspace, a mental health app tailored to your specific needs.
• A flat 3% contribution to your retirement account.
• A high degree of flexibility — Have an appointment, errand, or family emergency to take care of? Hop to it! We give you the time and space to take care of you and your own first.
Proficio
Compass
CyberSheath
StarTekk
Get handpicked remote jobs straight to your inbox weekly.