Cybersecurity GRC Analyst / Consultant

TechNix LLC
Sacramento, CA, United States
10 days ago
Apply on www.dice.com
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Job source

Tech stack

Cyber Security RSA Archer Platform

Job description

Can attend the Sacramento office for two consecutive days each month, generally the first Wednesday and Thursday., The GRC & Incident Response Security Professional will support the client’s information-security governance, risk, compliance, third-party risk, and incident-response functions. The role will work closely with the Information Security Office and provide risk advisory, compliance, incident management, and remediation support., * Governance, Risk & Compliance

  • Develop, update, and maintain security policies, procedures, standards, and documentation.
  • Administer and support enterprise GRC platforms.
  • Perform security risk assessments and compliance reviews.
  • Provide risk advisory services aligned with:
  • CMS ARC-AMPE
  • NIST SP 800-53 Revision 5
  • IRS Publication 1075
  • Applicable laws, regulations, and internal security requirements.
  • Conduct third-party/vendor security due diligence.
  • Perform vendor risk assessments and contract/control reviews.
  • Support continuous monitoring and risk reporting.
  • Develop corrective-action plans and track remediation.
  • Incident Response
  • Develop and maintain incident-response plans and playbooks.
  • Support security investigations and incident-management activities.
  • Assist with evidence handling and documentation.
  • Coordinate incident communications and reporting.
  • Support post-incident reviews.
  • Serve as backup security incident manager.
  • Provide incident status and escalation reporting to the CISO when required.
  • Participate in after-hours/on-call incident-response activities when necessary.

Requirements

  • Experience in information security, GRC, risk management, or incident response.
  • Strong knowledge of security policies, procedures, standards, and controls.
  • Experience with enterprise GRC platforms.
  • Experience performing security risk assessments and third-party risk assessments.
  • Knowledge of NIST SP 800-53 and security-control frameworks.
  • Experience developing incident-response plans and playbooks.
  • Experience supporting investigations, evidence handling, and post-incident activities.
  • Strong documentation and communication skills.
  • Experience in regulated public-sector, healthcare, health-exchange, or similar environments is preferred.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.dice.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

2:07 min

Summarizing critical actions for organizational cybersecurity compliance readiness

Matthew Brady Matthew Brady · World Congress 2026 Europe

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · World Congress 2026 Europe

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

4:27 min

Embracing a new perspective on mobile cyber attacks

Tom Tovar · World Congress 2023

Videos

See all

Related articles

See all