> Markdown version of [/jobs/ext/2551837-it-security-grc-analyst](https://www.wearedevelopers.com/jobs/ext/2551837-it-security-grc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Security GRC Analyst - **Company:** Everforth Apex - **Location:** Charlotte, NC, United States (Remote available) - **Experience:** Experienced - **Contract:** Temporary to permanent - **Skills:** Amazon Web Services, Microsoft Azure, Cloud Computing, Cloud Computing Security, Cyber Security, Data Retention, Information Technology Audit, Information Security Management System, Google Cloud, Cloud Platform System, RSA Archer Platform, Servicenow - **Published:** August 28, 2026 - **Apply:** https://www.dice.com/job-detail/bb2618c7-99a1-4891-ab58-0c5dfac529fa ## About the Role * 3+ years of experience within Information Security, Cybersecurity Governance, Risk & Compliance (GRC), IT Audit, Risk Management, or related areas. * Foundational understanding of cybersecurity governance, risk management, and compliance principles. * Experience supporting one or more frameworks such as NIST, ISO 27001, SOC 2, SOX, FedRAMP, or CMMC. * Familiarity with cybersecurity controls, audits, assessments, and policy management. * Experience with risk assessments, control documentation, and remediation tracking. * Strong organizational, analytical, communication, and documentation skills. * Ability to collaborate effectively with both technical and non-technical stakeholders. Preferred Qualifications * Experience supporting an Information Security Management System (ISMS). turn1search1 * Knowledge of cloud security environments (AWS, Azure, or Google Cloud Platform). * Experience with privay initiatives and vendor risk management. * Professional certifications such as Security+, CISA, CRISC, CGRC, CISSP, or ISO 27001 certifications. * Experience with GRC platforms such as ServiceNow GRC, Archer, AuditBoard, or OneTrust. ## Description This is an excellent opportunity for candidates with a strong foundation in Governance, Risk, and Compliance (GRC), cybersecurity audits, risk assessments, regulatory compliance, data privacy, or third-party risk management who are looking to make an immediate impact within a growing program., Compliance Program Support * Support execution and continuous improvement of the cybersecurity compliance program. * Maintain control inventories, compliance documentation, policies, standards, and procedures. * Coordinate compliance-related activities across IT, Security, Infrastructure, Cloud, and business teams. * Monitor compliance obligations and track remediation efforts through completion. * Support ongoing reporting and program maturity initiatives. Cybersecurity Risk Management * Perform cybersecurity risk assessments for applications, infrastructure, cloud environments, vendors, and business processes. * Facilitate risk identification, analysis, evaluation, and mitigation activities. * Maintain and update the cybersecurity risk register. * Track remediation plans and risk treatment activities through closure. * Assist with risk reporting and risk-based decision-making efforts. Audit, Assessment & Framework Alignment * Coordinate internal audits, external assessments, and compliance reviews. * Collect, review, and organize audit evidence and supporting documentation. * Support control mapping and framework alignment efforts for: + NIST Cybersecurity Framework (CSF) + ISO 27001 + SOC 2 + SOX + FedRAMP + CMMC * Track findings, observations, corrective actions, and remediation activities. Data Privacy & Third-Party Risk Management * Support privacy initiatives including: + Privacy Impact Assessments (PIAs) + Data Protection Impact Assessments (DPIAs) + Data inventories and classification efforts + Data retention and protection programs * Conduct vendor cybersecurity and privacy risk reviews. * Review security questionnaires, attestations, audit reports, certifications, and remediation plans for third-party service providers. Policy, Governance, Reporting & Metrics * Assist with cybersecurity policy, standard, and procedure development and maintenance. * Facilitate periodic reviews and governance activities. * Track policy exceptions and governance review processes. * Develop dashboards, key risk indicators (KRIs), compliance metrics, and management reporting. * Analyze trends related to risk, compliance, remediation progress, and control effectiveness., * Join a growing Security & Compliance initiative from the ground up. * Gain exposure across governance, risk, compliance, privacy, audits, and third-party risk management. * Opportunity to convert to a long-term permanent position. * Hybrid work environment located in Charlotte, NC. * Collaborate with cross-functional technology and business teams in a highly visible program. Interested? Qualified candidates are encouraged to submit their resume for review to . Please include "IT Security GRC Analyst " in the subject line for consideration. ## Related Videos - [The Cloud is Calling: Answer with In-Demand Skills](https://www.wearedevelopers.com/videos/945-the-cloud-is-calling-answer-with-in-demand-skills) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Find a Developer Job: 12 Best Job Sites For Developers](https://www.wearedevelopers.com/magazine/165-find-a-developer-job-12-best-job-sites-for-developers)