Cybersecurity GRC Analyst / Consultant
TechNix LLC
Sacramento, CA, United States
10 days ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Apply on www.dice.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source
Tech stack
Cyber Security
RSA Archer Platform
Job description
Can attend the Sacramento office for two consecutive days each month, generally the first Wednesday and Thursday., The GRC & Incident Response Security Professional will support the client’s information-security governance, risk, compliance, third-party risk, and incident-response functions. The role will work closely with the Information Security Office and provide risk advisory, compliance, incident management, and remediation support., * Governance, Risk & Compliance
- Develop, update, and maintain security policies, procedures, standards, and documentation.
- Administer and support enterprise GRC platforms.
- Perform security risk assessments and compliance reviews.
- Provide risk advisory services aligned with:
- CMS ARC-AMPE
- NIST SP 800-53 Revision 5
- IRS Publication 1075
- Applicable laws, regulations, and internal security requirements.
- Conduct third-party/vendor security due diligence.
- Perform vendor risk assessments and contract/control reviews.
- Support continuous monitoring and risk reporting.
- Develop corrective-action plans and track remediation.
- Incident Response
- Develop and maintain incident-response plans and playbooks.
- Support security investigations and incident-management activities.
- Assist with evidence handling and documentation.
- Coordinate incident communications and reporting.
- Support post-incident reviews.
- Serve as backup security incident manager.
- Provide incident status and escalation reporting to the CISO when required.
- Participate in after-hours/on-call incident-response activities when necessary.
Requirements
- Experience in information security, GRC, risk management, or incident response.
- Strong knowledge of security policies, procedures, standards, and controls.
- Experience with enterprise GRC platforms.
- Experience performing security risk assessments and third-party risk assessments.
- Knowledge of NIST SP 800-53 and security-control frameworks.
- Experience developing incident-response plans and playbooks.
- Experience supporting investigations, evidence handling, and post-incident activities.
- Strong documentation and communication skills.
- Experience in regulated public-sector, healthcare, health-exchange, or similar environments is preferred.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.dice.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
DC
Daniel Cranney
7 months ago
LM
Luis Minvielle
9 Ways to Make Money Hacking
over 2 years ago
DC
Daniel Cranney
The Overflow: Security and Privacy
6 months ago
CH
Chris Heilmann
Dev Digest 134 - Where pixels sing?
almost 2 years ago
BB
Benedikt Bischof
Walking Into The Era of Supply Chain Risks
about 4 years ago
BB
Benedikt Bischof
Building Security Champions
over 4 years ago