> Markdown version of [/jobs/ext/2461678-security-awareness-analyst-grc-analyst](https://www.wearedevelopers.com/jobs/ext/2461678-security-awareness-analyst-grc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Awareness Analyst / GRC Analyst - **Company:** DevCare Solutions - **Location:** Harrisburg, PA, United States - **Salary:** $62,400.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Amazon Web Services, Apple Mac Systems, Microsoft Azure, Border Gateway Protocol, Ubuntu (Operating System), CentOS, Cisco PIX, Cisco Routers, Cloud Computing Security, Cloud Engineering, Control Objectives for Information and Related Technology (COBIT), Cyber Security, Computer Networks, Dynamic Host Configuration Protocol, Linux, Domain Name System (DNS), Information Security Management, IT Management, Internet Protocol Security (IP SEC), Intrusion Detection Systems, Virtual Private Networks (VPN), Network Security, Lightweight Directory Access Protocols (LDAP), Log Analysis, Routing, Network Protocols, Open Shortest Path First (OSPF), PCI Data Security Standards, Role-Based Access Control, Phishing, Security Software, Security Information and Event Management, Single Sign-On, TCP/IP, Software Vulnerability Management, Wide Area Networks, EndPointSecurity, Identity Services Engine, Google Cloud, Load Balancing, Firewalls (Computer Science), Information Technology, SolarWinds (Software), Network Support, Cybercrime, Splunk, Vulnerability Analysis - **Published:** August 10, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=93f38dd68d15879c ## About the Role * Proven experience working within cybersecurity frameworks such as NIST standards or COBIT; familiarity with IT governance practices is highly valued. * Hands-on knowledge of computer networking concepts including LAN/WAN architecture, Cisco routers/switches (Cisco ASA, Cisco ISE), network protocols (TCP/IP, DNS, DHCP), and network support tools. * Demonstrated expertise in information security compliance efforts related to ISO 27001/ISO 27000 series standards; experience with system hardening techniques on operating systems like Windows, Linux (Ubuntu, CentOS), macOS or BSD is preferred. * Practical experience utilizing cybersecurity tools such as SIEM platforms (Splunk), endpoint detection & response (EDR) solutions, vulnerability assessment tools, and threat detection & response methodologies. * Strong understanding of identity & access management concepts including RBAC (Role-Based Access Control), LDAP/Active Directory integration, SSO (Single Sign-On), and encryption technologies. * Knowledge of cloud infrastructure security principles for platforms like AWS or Azure; familiarity with cloud architecture best practices is a plus. * Excellent analytical skills in conducting security risk assessments investigation; ability to interpret complex data from intrusion detection systems or log analysis tools for actionable insights. Join us to be at the forefront of cybersecurity awareness and governance! Your expertise will help shape a resilient organization that values proactive defense strategies while fostering a culture of continuous learning and improvement in information security practices. ## Description Join our dynamic cybersecurity team as a Security Awareness Analyst / Cybersecurity GRC (Governance, Risk, and Compliance) Analyst! In this vital role, you will champion the development and implementation of security awareness programs while ensuring our organization's compliance with industry standards such as ISO 27001, ISO 27000 series, and NIST frameworks. Your energetic approach will help foster a security-conscious culture across all levels of the organization, empowering teams to recognize and mitigate cyber threats proactively. This position offers an exciting opportunity to blend security education with rigorous risk management, making a tangible impact on our cybersecurity posture., * Design, execute, and continuously improve security awareness campaigns to educate employees on cybersecurity best practices, including topics like phishing prevention, password hygiene, and data protection. * Conduct comprehensive security risk assessments and vulnerability management activities to identify potential threats within IT infrastructure, including network security components such as LAN, WAN, firewalls, IDS (Intrusion Detection Systems), and SIEM (Security Information and Event Management) tools. * Support the development and maintenance of system security plans aligned with standards like ISO 27001 and FedRAMP; ensure compliance with information security policies and regulations such as PCI DSS and FISMA. * Perform security assessments and vulnerability research using tools like vulnerability scanners, SIEM analysis, and threat intelligence platforms to detect anomalies or potential breaches. * Collaborate with network engineering teams to implement secure network architectures utilizing routing protocols (OSPF, BGP), VPNs (Virtual Private Networks), IPsec encryption, load balancing, and cloud security engineering in environments such as AWS or Google Cloud Platform. * Assist in incident response activities by investigating security events, analyzing logs via tools like Splunk or SolarWinds, and supporting incident recovery efforts following cybersecurity incidents. * Maintain documentation related to system hardening procedures, security event management processes, and compliance audits; prepare reports for executive leadership on risk posture and remediation strategies. ## Related Videos - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Turning Container security up to 11 with Capabilities](https://www.wearedevelopers.com/videos/718-turning-container-security-up-to-11-with-capabilities) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities)