IT Security GRC Analyst

Everforth Apex
Charlotte, NC, United States
7 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Temporary to permanent
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Microsoft Azure Cloud Computing Cloud Computing Security Cyber Security Data Retention Information Technology Audit Information Security Management System Google Cloud Cloud Platform System RSA Archer Platform Servicenow

Job description

This is an excellent opportunity for candidates with a strong foundation in Governance, Risk, and Compliance (GRC), cybersecurity audits, risk assessments, regulatory compliance, data privacy, or third-party risk management who are looking to make an immediate impact within a growing program., Compliance Program Support

  • Support execution and continuous improvement of the cybersecurity compliance program.
  • Maintain control inventories, compliance documentation, policies, standards, and procedures.
  • Coordinate compliance-related activities across IT, Security, Infrastructure, Cloud, and business teams.
  • Monitor compliance obligations and track remediation efforts through completion.
  • Support ongoing reporting and program maturity initiatives.

Cybersecurity Risk Management

  • Perform cybersecurity risk assessments for applications, infrastructure, cloud environments, vendors, and business processes.
  • Facilitate risk identification, analysis, evaluation, and mitigation activities.
  • Maintain and update the cybersecurity risk register.
  • Track remediation plans and risk treatment activities through closure.
  • Assist with risk reporting and risk-based decision-making efforts.

Audit, Assessment & Framework Alignment

  • Coordinate internal audits, external assessments, and compliance reviews.
  • Collect, review, and organize audit evidence and supporting documentation.
  • Support control mapping and framework alignment efforts for:
  • NIST Cybersecurity Framework (CSF)
  • ISO 27001
  • SOC 2
  • SOX
  • FedRAMP
  • CMMC
  • Track findings, observations, corrective actions, and remediation activities.

Data Privacy & Third-Party Risk Management

  • Support privacy initiatives including:
  • Privacy Impact Assessments (PIAs)
  • Data Protection Impact Assessments (DPIAs)
  • Data inventories and classification efforts
  • Data retention and protection programs
  • Conduct vendor cybersecurity and privacy risk reviews.
  • Review security questionnaires, attestations, audit reports, certifications, and remediation plans for third-party service providers.

Policy, Governance, Reporting & Metrics

  • Assist with cybersecurity policy, standard, and procedure development and maintenance.
  • Facilitate periodic reviews and governance activities.
  • Track policy exceptions and governance review processes.
  • Develop dashboards, key risk indicators (KRIs), compliance metrics, and management reporting.
  • Analyze trends related to risk, compliance, remediation progress, and control effectiveness., * Join a growing Security & Compliance initiative from the ground up.
  • Gain exposure across governance, risk, compliance, privacy, audits, and third-party risk management.
  • Opportunity to convert to a long-term permanent position.
  • Hybrid work environment located in Charlotte, NC.
  • Collaborate with cross-functional technology and business teams in a highly visible program.

Interested?

Qualified candidates are encouraged to submit their resume for review to . Please include “IT Security GRC Analyst “ in the subject line for consideration.

Requirements

  • 3+ years of experience within Information Security, Cybersecurity Governance, Risk & Compliance (GRC), IT Audit, Risk Management, or related areas.
  • Foundational understanding of cybersecurity governance, risk management, and compliance principles.
  • Experience supporting one or more frameworks such as NIST, ISO 27001, SOC 2, SOX, FedRAMP, or CMMC.
  • Familiarity with cybersecurity controls, audits, assessments, and policy management.
  • Experience with risk assessments, control documentation, and remediation tracking.
  • Strong organizational, analytical, communication, and documentation skills.
  • Ability to collaborate effectively with both technical and non-technical stakeholders.

Preferred Qualifications

  • Experience supporting an Information Security Management System (ISMS). turn1search1
  • Knowledge of cloud security environments (AWS, Azure, or Google Cloud Platform).
  • Experience with privay initiatives and vendor risk management.
  • Professional certifications such as Security+, CISA, CRISC, CGRC, CISSP, or ISO 27001 certifications.
  • Experience with GRC platforms such as ServiceNow GRC, Archer, AuditBoard, or OneTrust.

About the company

Everforth Apex is a world-class IT services company that serves thousands of clients across the globe. When you join Everforth Apex, you become part of a team that values innovation, collaboration, and continuous learning. We offer quality career resources, training, certifications, development opportunities, and a comprehensive benefits package. Our commitment to excellence is reflected in many awards, including ClearlyRateds Best of Staffing in Talent Satisfaction in the United States and Great Place to Work in the United Kingdom and Mexico.

Everforth Apex uses a virtual recruiter as part of the application process. Click for more details. By applying for this job, you agree to receive calls, AI-generated calls, text messages, or emails from Everforth Apex and its affiliates, and contracted partners. Frequency varies for text messages. Message and data rates may apply. Carriers are not liable for delayed or undelivered messages. You can reply STOP to cancel and HELP for help. You can access our privacy policy at

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

6:10 min

Unlocking free learning credits via Google Cloud Innovators

Asrar Asrar · World Congress 2024

56 sec

Integrating automated approval workflows into the portal

Markus Eisele Markus Eisele · World Congress 2025

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

4:42 min

Container hosting options available on Google Cloud Platform

Federico Fregosi · World Congress 2022

Videos

See all

Related articles

See all