
Senior Lead Information Security Governance, Risk, and Compliance (GRC) Analyst
Posted Jul 25

Posted Jul 25
This is a fully remote position, open to applicants in United States.
• Lead the design, configuration, and governance of control frameworks and risk workflows within the GRC platform, ensuring alignment with organizational objectives and compliance requirements.
• Establish and maintain enterprise control procedures, ensuring alignment with relevant frameworks (Internal Policy, HIPAA, HITRUST, PCI, SOC 2, NIST, and other applicable frameworks).
• Oversee the development and maintenance of control libraries, including control narratives, ownership assignments, testing frequency, and evidence requirements.
• Monitor and update risk registers, ensuring accurate tracking, scoring, and prioritization of risks within the platform.
• Drive automation workflows to streamline control testing, evidence collection, attestations, and remediation processes.
• Track policy review cycles and ensure documentation remains current with regulatory and business changes.
• Lead and maintain information security risk assessments across IT, operational, and third-party domains.
• Perform control walkthroughs and operating effectiveness testing; document results and identify control gaps.
• Collaborate with internal teams and external auditors to facilitate audits and assessments using the GRC platform for evidence management, issue tracking, and reporting.
• Ensure ongoing compliance with regulatory requirements and industry standards by maintaining up-to-date documentation and control mappings.
• Prepare and present reports, dashboards, and metrics on control effectiveness, risk status, and compliance gaps.
• Map controls to applicable regulatory and framework requirements, identifying overlaps to reduce duplicative testing.
• Support internal and external audits by gathering evidence, coordinating stakeholder responses, and tracking remediation through closure.
• Track and manage audit findings, corrective action plans (CAPs), and remediation timelines within the GRC platform.
• Guide risk assessments to identify potential vulnerabilities and threats, documenting findings and supporting evidence in the GRC platform.
• Partner with stakeholders to develop and implement risk mitigation strategies, tracking progress and ownership within the platform.
• Develop, monitor, and report on key risk indicators (KRIs) and key performance indicators (KPIs) to proactively identify and address emerging risks.
• Maintain and apply consistent risk scoring methodologies, including likelihood, impact, and residual risk calculations.
• Escalate significant risks and control deficiencies to management and governance committees, providing recommendations for mitigation and improvement in a timely manner.
• Lead the development, maintenance, and lifecycle management of information security policies, procedures, standards, and guidelines.
• Direct policy review and approval workflows with policy owners and stakeholders.
• Ensure policies remain aligned with evolving regulatory requirements and organizational changes.
• Lead evaluations of third-party vendors for security and compliance risks, including review of SOC reports, security questionnaires, and contractual requirements.
• Track vendor risk assessments, reassessment cycles, and risk ratings within the GRC platform.
• Work with business owners to develop and monitor vendor remediation action plans.
• Support vendor onboarding and offboarding risk reviews, ensuring appropriate due diligence is documented.
• Identify opportunities to enhance GRC processes and workflows to improve efficiency, accuracy, and effectiveness.
• Stay current on industry trends, emerging threats, and best practices in GRC, recommending improvements to the security and compliance program.
• Champion automation and integration initiatives to reduce manual effort.
• Guide periodic program assessments and maturity benchmarking to guide roadmap priorities.
• Perform other duties and responsibilities as assigned.
• Bachelor’s degree in information security, cybersecurity, computer science, information technology, business administration, or a closely related field required.
• Equivalent experience may be considered in lieu of a degree (e.g., 4+ years of relevant experience in information security, compliance, or GRC roles).
• Minimum of 8 years’ relevant experience in governance, risk, and compliance functions within IT or information security.
• Certified Information Systems Auditor (CISA) preferred.
• Certified Risk and Information Systems Control (CRISC) preferred.
• Certified Information Security Manager (CISM) preferred.
• Other relevant certifications (e.g., CompTIA Security+, ISO 27001 Lead Auditor) preferred.
• Prior experience implementing, managing, or auditing security policies and procedures.
• Familiarity with compliance frameworks (HIPAA, NIST CSF, SOC 2, HITRUST, etc.).
• Prior experience conducting risk assessments and supporting risk management activities.
• Excellent written and verbal communication skills, including the ability to communicate technical concepts and compliance requirements to both technical and non-technical stakeholders.
• Ability to manage multiple priorities, work independently, and collaborate effectively across cross-functional teams.
• This position is eligible for an annual bonus. Bonuses are not guaranteed and are awarded based on company and individual performance.
Proficio
StarTekk
CyberSheath
Compass
Get handpicked remote jobs straight to your inbox weekly.