> Markdown version of [/jobs/ext/2529339-cybersecurity-grc-analyst](https://www.wearedevelopers.com/jobs/ext/2529339-cybersecurity-grc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Cybersecurity GRC Analyst - **Company:** Tpx Inc - **Location:** United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Bioinformatics, Cyber Security, Disaster Recovery, Information Technology Audit, PCI Data Security Standards, Smartsuite, Cloud Platform System, Information Technology - **Published:** August 6, 2026 - **Apply:** https://recruiting.adp.com/srccsh/public/RTI.home?r=5001216792606&c=1175915&d=ExternalCareerSite ## About the Role * Team Player with strong communication, organizational, and relationship management skills. * Self-motivated, with keen attention to detail and excellent judgment skills. * Strong knowledge of security frameworks and regulations (e.g., NIST CSF, ISO 27001, SOC, PCI-DSS, HIPAA). * Demonstrated ability to own audit engagements end-to-end, from planning and prioritizing through evidence submission and remediation follow-up. * Can develop, track, enhance and communicate risk and security process. * Strong stakeholder management skills with the ability to communicate clearly at both technical and executive levels. * Experience leading cross-functional initiatives to improve compliance posture or remediate findings. * Excellent organizational and project management skills, with attention to detail and deadlines. * Ability to write and present articulated documentation and processes. * Knowledge of hybrid IT systems, networking, co-locations, and cloud environments. * Degree in cybersecurity, computer science, information technology or 1+ years IT work experience in the area of Governance, Risk and Compliance. * Use or knowledge of GRC Tools * Proven experience working with auditors in IT audit, compliance, or security control assessment within a regulated industry. * Professional certification preferred (e.g., CISA, CISSP, CISM, or equivalent). * Record of demonstrating sound judgment and ability to exercise discretion on matters of significance with minimal oversight. Other Qualifications: * Collaborative team player who works effectively with cross-functional colleagues * Strong written and verbal communication skills * Demonstrated ability to build productive working relationships across teams ## Description Lead and manage GRC activities including internal/external audits, risk assessments, DR/BCP, third-party risk, and remediation. Develop and maintain policies, conduct BIAs, run tabletop exercises, mentor junior analysts, and collaborate with stakeholders to improve compliance posture and reporting across business and technology teams. The summary above was generated by AI Job Summary & Responsibilities General Purpose: The ideal candidate will have a strong understanding of cybersecurity best practices, excellent problem-solving skills, and a proactive approach to identifying and mitigating risks. Knowledge of frameworks, attestations and audits, including customer and internal audits such as ISO27001, SOC1, SOC2. Familiar with DR strategies and plans. The ability to write, update and version policies and procedures. Direct Reports: No, * Own and lead internal and external audit engagements, including determining audit scope, evidence requirements and collection, control testing methodology, evaluating control effectiveness, and remediation follow-up, ensuring continual compliance and continuous improvement across multiple business units. * Drive risk management activities, including risk identification, assessment, prioritization, tracking, and reporting, to provide recommendations to leadership regarding appropriate mitigation strategies and strengthen the enterprise risk posture. * Develop, maintain, and enhance governance, risk management, disaster recovery, business continuity, and third-party risk management programs. * Interpret applicable cybersecurity frameworks, regulatory requirements, customer obligations, and industry standards, and exercise independent judgment in developing, implementing, and improving governance, risk, and compliance policies, procedures, and controls. * Lead Business Impact Assessments (BIA) and collaborate with stakeholders to align critical processes with recovery objectives. * Manage Disaster Recovery (DR) and Business Continuity Planning (BCP) activities, including tabletop exercises, plan maintenance, and validation of recovery strategies. * Collaborate with business and technology leaders to mature governance, risk, and compliance processes, streamline reporting, and reduce recurring issues. * Lead and mentor junior analysts across GRC domains, fostering a culture of compliance and risk awareness. * Build and maintain the TPRM program. Other Responsibilities: * Willingness to learn other aspects of Security Operations. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Cyber Sleuth: Finding Hidden Connections in Cyber Data](https://www.wearedevelopers.com/videos/893-cyber-sleuth-finding-hidden-connections-in-cyber-data) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) - [Less Is More: How Lagom and Agile Can Create Harmonious Workflows](https://www.wearedevelopers.com/videos/1993-less-is-more-how-lagom-and-agile-can-create-harmonious-workflows) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Building Security Champions](https://www.wearedevelopers.com/magazine/87-building-security-champions)