> Markdown version of [/jobs/ext/1113070-grc-specialist](https://www.wearedevelopers.com/jobs/ext/1113070-grc-specialist). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # GRC Specialist - **Company:** Beacon Hill Technologies - **Location:** Beacon Hill, United States (Remote available) - **Experience:** Experienced - **Contract:** Temporary to permanent - **Skills:** Cloud Computing Security, CompTIA Security+, Cyber Security, Identity and Access Management, Information Technology Audit, Software Vulnerability Management, RSA Archer Platform, CIS Benchmarks, Servicenow - **Published:** June 30, 2026 - **Apply:** https://www.dice.com/job-detail/3dd952b6-0863-4d2c-9f75-649dcb5fc791 ## About the Role * 3+ years of experience in GRC, cybersecurity compliance, IT audit, information security, or related areas. * Knowledge of frameworks including NIST, ISO 27001, SOC 2, and CIS Controls. * Experience supporting audits, control testing, evidence collection, and remediation activities. * Ability to develop and maintain security policies, standards, and procedures. * Experience with risk assessments, compliance reviews, and vendor risk management. * Strong documentation, organizational, and communication skills. * Experience collaborating with IT, Security, Engineering, Legal, Compliance, and other business teams. * Working knowledge of cloud security, identity and access management, vulnerability management, and incident response., * Experience in regulated or critical infrastructure industries. * Relevant certifications such as CISA, CISM, CISSP, CRISC, Security+, or ISO 27001. * Experience with GRC platforms including ServiceNow GRC, Archer, OneTrust, AuditBoard, LogicGate, Drata, or Vanta. * Familiarity with privacy, data protection, and third-party risk management programs. * Experience creating compliance reporting, risk dashboards, and executive-level presentations. ## Description Seeking a GRC Specialist to support the Information Security team by managing security compliance, audits, risk assessments, policy governance, and regulatory requirements across enterprise technology environments. This role will help strengthen the organization's security posture through effective governance and continuous compliance monitoring., * Support governance, risk, and compliance initiatives across the organization. * Maintain security documentation, policies, and compliance records. * Coordinate audit activities and compliance evidence collection. * Track remediation efforts, audit findings, exceptions, and risk treatment plans. * Conduct control testing, risk assessments, and vendor reviews. * Assist with mapping controls to security and compliance frameworks. * Maintain risk registers, control inventories, and compliance reporting. * Partner with internal stakeholders to support security and regulatory requirements. * Monitor compliance trends and contribute to continuous improvement of the security program. ## Related Videos - [A practical guide to writing secure Dockerfiles](https://www.wearedevelopers.com/videos/109-a-practical-guide-to-writing-secure-dockerfiles) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Great DevEx and Regulatory Compliance - Possible?](https://www.wearedevelopers.com/videos/1426-great-devex-and-regulatory-compliance-possible) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [OPA for the cloud natives](https://www.wearedevelopers.com/videos/713-opa-for-the-cloud-natives) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Top HR Tech Conferences in 2024](https://www.wearedevelopers.com/magazine/303-top-hr-tech-conferences-in-2024)