GRC Analyst - Rockville, MD
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
Join us in driving growth and seizing new business opportunities. Roles & Responsibilities: A. Policy Exception Administration - The contractor shall
- Review submitted policy exception requests for completeness.
- Verify required documentation has been submitted.
- Validate business justifications against County requirements.
- Request additional information from departments when necessary.
- Maintain exception records within ServiceNow.
- Track requests through each stage of the approval process.
- Monitor exception expiration dates.
- Coordinate renewals and closures.Produce status reports.
B. Risk Analysis - Using County-approved methodologies, templates and procedures, the Contractor shall:
- Review policy exception requests.
- Evaluate business impact.
- Evaluate likelihood and risk.
- Identify applicable compensating controls.
- Prepare written risk analyses.
- Prepare approval or denial recommendations for CISO review.Document analysis within ServiceNow.
C. Enterprise Risk Register - Maintain the County Information Security Risk Register by:
- Creating new risk records.
- Updating existing risk records.
- Recording risks identified by: o Third-party penetration tests
- Third-party security assessments
- Internal risk assessments
- Vulnerability scanning
- Policy Exceptions
-
Security incidentsOther approved sources
- Track mitigation activities.
- Monitor due dates.
- Update risk status.
- Maintain supporting documentation.Generate reports.
D. ServiceNow - Utilize ServiceNow IRM to:
- Process Policy Exceptions
- Maintain Risk Register records
- Track approvals
- Maintain documentation
- Generate reportsProduce dashboards
Requirements
Bachelor’s degree in:
- Cybersecurity
- Information Systems
- Information Technology
- Computer Science
- Business Information Systems, * Certified Information Security Manager - Fundamentals (CISM-F)
- NIST Cybersecurity Framework (NCSF) Practitioner
- ISACA IT Risk Fundamentals Certificate
- ISACA Cybersecurity Audit CertificateHIPAA Security Training or Compliance Certificates
Preferred experience
-
One (1) year of professional Information Security, IT Governance, Compliance, Risk Management, Information Technology, Audit, or related experience.Recent graduate with relevant internship or equivalent experience.
- Experience using ServiceNow.
- Experience using Office 365 suite of products
- Experience with Governance, Risk and Compliance (GRC).
- Experience preparing technical documentation.
- Experience working in customer service environments.Experience with coordinating projects, tasks and/or workflows.
C. Knowledge Basic understanding of:
- Cybersecurity principles
- Information Security
- Risk Management
- NIST Cybersecurity Framework
- Risk Scoring Systems/Risk Quantitative Frameworks
- HIPAA
About the company
Creative Information Technology Inc (CITI) is an esteemed IT enterprise renowned for its exceptional customer service and innovation. We serve both government and commercial sectors, offering a range of solutions such as Healthcare IT, Human Services, Identity Credentialing, Cloud Computing, and Big Data Analytics. With clients in the US and abroad, we hold key contract vehicles including GSA IT Schedule 70, NIH CIO-SP3, GSA Alliant, and DHS-Eagle II.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.indeed.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
9 Ways to Make Money Hacking
Best Companies to work for in London: Top 25 Companies in 2023
Quick guide: How to write a Software Developer CV
Résumé-Driven Development: How IT trends affect the job market for software developers