> Markdown version of [/jobs/ext/2238459-cybersecurity-grc-analyst](https://www.wearedevelopers.com/jobs/ext/2238459-cybersecurity-grc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity GRC Analyst - **Company:** REQUEST TECHNOLOGY - **Location:** Chicago, IL, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, User Authentication, Cyber Security, Intrusion Detection and Prevention, Information Systems Security Architecture Professional, Security Information and Event Management, Mobile Security, Software Vulnerability Management, Firewalls (Computer Science), Information Technology, RSA Archer Platform - **Published:** August 26, 2026 - **Apply:** https://www.dice.com/job-detail/30d31e84-5f5e-408a-bf8f-439107d86b52 ## About the Role * Bachelor's degree or equivalent with five (5) years of work experience in IT Security is required. * Certified Information Systems Security Professional (CISSP), Certified Information Security Auditor (CISA), Certified Information Security Manager (CISM), Advanced in AI Audit (AAIA), Advanced in AI Risk (AAIR), Advanced in AI Security Management (AAISM) or other relevant training and certifications are preferred. * Four (4) or more years of Information Security experience, with hands on technical experience strongly preferred. * Strong working knowledge of security frameworks and standards such as ISO 27001, National Institute of Standards and Technology (NIST), System and Organization Controls (SOC), and Standardized Information Gathering (SIG) is required. * Experience in Artificial Intelligence (AI) governance, security, and risk management is required. * Proven ability to produce clear, well-structured security documentation and communicate complex technical topics to varied audiences. * Experience leading risk assessments, vendor security reviews, and client-facing security discussions with professionalism and tact. * Familiarity with GRC platforms, role-based access controls, and a broad range of security technologies and tools. * Working knowledge of areas such as authentication, encryption, firewalls, SIEM, intrusion detection/prevention, vulnerability management, mobile security, and privileged access management. ## Description * Lead responses to client security assessments, questionnaires, and audits, documenting evidence and performing risk assessments as needed. * Create, maintain, and evolve security policies, standards, guidelines, and supporting documentation through strong technical writing. * Manage and support processes that ensure Information Technology (IT) systems meet cybersecurity, risk, and compliance requirements. * Serve as an Information Security subject matter expert, advising technical and non-technical stakeholders across the organization. * Manage the third-party Security Vendor Risk Management program, including assessments, remediation tracking, and lifecycle oversight. * Oversee the security exception request process and provide guidance on appropriate risk treatment decisions. * Manage the full lifecycle of the Security Awareness program, including roadmap development, training evaluation, and effectiveness measurement. * Support and optimize Governance, Risk, and Compliance (GRC) technology platforms and associated workflows. * Conduct evaluations of IT programs and components to confirm alignment with published security standards and frameworks. ## Related Videos - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Forecasting Cyber Attacks with Glassdoor Reviews - Lianne Potter](https://www.wearedevelopers.com/videos/2143-forecasting-cyber-attacks-with-glassdoor-reviews-lianne-potter) - [Delegating the chores of authenticating users to Keycloak](https://www.wearedevelopers.com/videos/1558-delegating-the-chores-of-authenticating-users-to-keycloak) - [DevSecOps: Injecting Security into Mobile CI/CD Pipelines](https://www.wearedevelopers.com/videos/273-devsecops-injecting-security-into-mobile-ci-cd-pipelines) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [SSO with Ethereum and Next JS](https://www.wearedevelopers.com/videos/288-sso-with-ethereum-and-next-js) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries)