GRC Analyst

Covenant LLC
Winthrop, MA, United States
3 days ago
Apply on www.disabledperson.com
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours

Tech stack

Control Objectives for Information and Related Technology (COBIT) Cyber Security Information Technology Audit CIS Benchmarks

Job description

  • Manage and respond to client and operational due-diligence requests, translating security and technology controls into clear responses for clients, auditors, and external stakeholders
  • Support SOC 1/SOC 2, SOX, internal, and external audit activities, including evidence collection and coordination with control owners
  • Conduct and coordinate technology, cybersecurity, information-security, and operational risk assessments
  • Maintain risk registers, control inventories, audit findings, policies, standards, exceptions, remediation plans, and supporting evidence
  • Partner with Information Security, Technology, Legal and Compliance, Internal Audit, Operations, and client-facing teams
  • Perform third-party risk activities, including vendor security assessments, SOC report reviews, risk documentation, and ongoing monitoring
  • Support governance and oversight of DLP and information-protection controls
  • Track identified issues and remediation activities through completion and coordinate with appropriate stakeholders
  • Develop management reporting related to risk, audits, controls, findings, and remediation
  • Identify opportunities to automate and streamline GRC, audit, evidence-collection, and due-diligence processes
  • Financial services, asset management, institutional investment management, or other regulated-industry experience is strongly preferred
  • Relevant certifications such as CISA, CRISC, CISM, CISSP, CIA, Security+, or ISO 27001 are preferred

Requirements

  • 3-6 years of relevant GRC/security-risk experience across information security, technology risk, IT audit, operational risk, or a related discipline
  • Hands-on client and operational due-diligence experience responding to RFPs, RFIs, DDQs, ODD requests, client security questionnaires, or similar security/technology-risk inquiries
  • Control and audit assurance experience supporting SOC 1/SOC 2, SOX, internal/external audits, evidence collection, control-owner coordination, issue management, and remediation
  • Strong GRC fundamentals, including risk assessments, control design/testing, policy governance, remediation tracking, third-party risk, and frameworks such as NIST CSF, ISO 27001, COBIT, or CIS Controls
  • Independent, highly organized communicator capable of managing multiple concurrent questionnaires, audits, assessments, and remediation activities across technical and business stakeholders.

About the company

Company - Our client is a cybersecurity services and consulting organization focused on helping enterprises strengthen their security programs through technology, advisory, risk and compliance, and specialized security services. The organization takes a highly consultative, client-centric approach to solving complex cybersecurity challenges.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.disabledperson.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:14 min

Establishing legal admissibility through immutable blockchain attestations

Frederik Gregaard Frederik Gregaard +1 · World Congress 2026 Europe

2:15 min

Auditing container configurations against CIS benchmark security standards

Madhu Akula · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

2:07 min

Summarizing critical actions for organizational cybersecurity compliance readiness

Matthew Brady Matthew Brady · World Congress 2026 Europe

3:39 min

Validating data queries and infrastructure security configurations

Philipp Krenn · World Congress 2023

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · World Congress 2026 Europe

Videos

See all

Related articles

See all