> Markdown version of [/jobs/ext/215957-grc-analyst](https://www.wearedevelopers.com/jobs/ext/215957-grc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # GRC Analyst - **Company:** Futran Solutions - **Location:** Portland, OR, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Cyber Security, Document Management Systems, Identity and Access Management, Information Technology Audit, Software Vulnerability Management - **Published:** May 22, 2026 - **Apply:** https://www.dice.com/job-detail/d398caa6-2f75-4828-b0e9-4f8ad66887b1 ## About the Role * Experienced and Passionate: You are a seasoned security professional with a passion for governance, risk, and compliance * Methodical and Pragmatic: You approach control testing with precision and can identify pragmatic solutions to addressing risks * Self-Motivated and Curious: You are driven to understand the "why", you thoughtfully investigate complex issues and ask probing questions * Leadership-Oriented: You demonstrate initiative and are experienced in mentoring and developing others * Relationship Driven: You build rapport and support your team and colleagues across functions * Influential Communicator: Whether in writing or verbally, you can effectively explain technical concepts and risks to colleagues and management without excessive jargon. * Bachelor's degree in a technical field such as cybersecurity or business information systems * Security certifications such as CISSP, CISA, CRISC, Sec+, or CC preferred. * Minimum 8 years' experience in GRC, IT audit, or information security within mid-size to large corporate environment * Proven expertise in cybersecurity frameworks such as NIST CSF or ISO 27001 * Hands-on experience in leading IT audits, risk assessments, or compliance programs ## Description We are seeking a detail-oriented and technically proficient Principal GRC Analyst to join our Information Security team, with a focus on validating and testing security controls across the enterprise. This role will serve as the most senior member of a small team focused on validating the effectiveness of information security controls. It is ideal for professionals with 8 or more years of experience in GRC, IT audit, or cybersecurity operations who have supervised IT control testing teams and are passionate about driving continuous improvement. * Plan, lead, and execute control validation and testing activities across various domains (e.g., access management, vulnerability management, incident response, data protection). * Mentor junior analysts, providing guidance on control validation methodologies and best practices while fostering a culture of accountability * Provide subject matter expertise regarding information security control validation and compliance frameworks to the CDT organization and its business partners * Document control issues and collaborate with stakeholders to develop remediation recommendations * Develop and enhance control testing methodologies, procedures, and reporting mechanisms * Prepare risk reports and dashboards for management and governance committees. * Influence the evolution of the GRC program through maturing tools, automation, processes, and metrics, and processes. ## Related Videos - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Same Tower, New Confusion: The Tower of Babel 2.0](https://www.wearedevelopers.com/videos/100101-same-tower-new-confusion-the-tower-of-babel-2-0) - [Fireside Chat: AI and Sustainability - Thorsten Jonas](https://www.wearedevelopers.com/videos/1769-fireside-chat-ai-and-sustainability-thorsten-jonas) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Résumé-Driven Development: How IT trends affect the job market for software developers](https://www.wearedevelopers.com/magazine/59-resume-driven-development-how-it-trends-affect-the-job-market-for-software-developers) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [How to Write a CV and Interview if You Don't Fully Qualify For The Job](https://www.wearedevelopers.com/magazine/183-how-to-write-a-cv-and-interview-if-you-don-t-fully-qualify-for-the-job) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)