> Markdown version of [/jobs/ext/2628943-it-grc-analyst](https://www.wearedevelopers.com/jobs/ext/2628943-it-grc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT GRC Analyst - **Company:** Globalstar Inc. - **Location:** Covington, LA, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Systems, Data Mapping, Information Technology Audit, IT Management, Microsoft Office, Presentation Programs, Product Software Implementation Methods, Data Processing - **Published:** August 11, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=3d1743135fb07a01 ## About the Role * Excellent verbal and written communication skills, including the ability to interact clearly and concisely with all departments and levels of management with a focus on customer service * Excellent organizational skills with attention-to-detail * Ability to meet multiple deadlines in a fast-paced environment * Ability to effectively manage time and prioritize tasks * Ability to act with integrity, professionalism, and confidentiality * Proficiency with Microsoft Office * Strong problem-solving skills, especially under time constraints * In-depth understanding of IT compliance frameworks and regulations such as NIST SP 800-53, SOC 2, SOX, CCPA, and GDPR * Comprehensive knowledge of the concepts and principles of internal controls and regulatory compliance, * Bachelor's degree in Business Administration, Information Systems, Risk Management, Security Management, or equivalent work experience. * 2-5 years of progressive experience in IT governance, risk, and compliance, IT audit, or a closely related discipline. * Demonstrated hands-on experience with SOC 2 and/or ISO 27001 audit or assessment cycles. * IT security and privacy certifications such as CISA, CISSP, CRISC, CISM, CIPM, or CDPSE preferred. Physical Requirements: * Willingness and ability to travel as needed * Willingness and ability to work after regularly scheduled hours as needed * Ability to sit at a desk for prolonged periods working on a computer (4 to 8 hours) * Ability to operate the equipment used for the job * Ability to lift 15 pounds at times * Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions of this job ## Description The IT GRC Analyst is responsible for supporting Globalstar's information security governance, risk, and compliance programs. This role executes control oversight activities, maintains compliance with applicable regulatory frameworks, supports internal and external audit readiness, and assists with vendor risk management. The IT GRC Analyst will leverage GRC tooling to automate and streamline compliance monitoring, produce highly accurate and consistent documentation, and serve as a knowledgeable resource across IT and business teams. Additionally, this role provides project coordination support for IT implementations and installations, assisting in the organization, scheduling, and communication of project activities as needed., Governance, Risk & Compliance * Execute user access reviews, control evidence collection, and recurring risk reviews. * Collect, review, and validate control evidence and supporting artifacts to assess completeness, accuracy, and alignment with defined requirements. * Maintain and update the organization's risk register, documenting identified risks, current controls and recommended treatment options. * Identify, document, and escalate control exceptions, discrepancies, and potential gaps to senior team members for evaluation and remediation. * Monitor compliance with information security policies and assess potential risks associated with data handling and system changes. * Support the maintenance of governance documentation and continuous improvement of department processes and procedures. Audit & Regulatory Readiness * Administer and support the organization's audit plan across SOC 2, ISO 27001, and SOX, ensuring controls are designed and operating effectively. * Support internal and external audit activities by organizing evidence, coordinating with control owners, and responding to information requests. * Assist with the preparation and maintenance of compliance artifacts. * Coordinate with independent auditors and ensure the timely delivery of supporting documentation and data. * Analyze audit results, prepare presentations of findings, and develop recommendations to reduce risk and increase protection of organizational assets. * Review SOC reporting for third-party compliance and coordinate data privacy matters with the Data Protection Officer (DPO) as applicable. Vendor & Third-Party Risk Management * Support third-party risk management activities including vendor intake, security questionnaire review, ongoing monitoring, and follow-up with internal stakeholders. * Evaluate vendors' security posture and assess residual risk for inclusion in procurement and program decisions. * Maintain accurate and up-to-date information within vendor and control tracking systems. Data Privacy Oversight * Support oversight and ongoing management of Globalstar's data privacy program, ensuring compliance with applicable privacy regulations including GDPR, CCPA, and other relevant privacy frameworks. * Coordinate with the Data Protection Officer (DPO) and relevant stakeholders to monitor data privacy obligations, assess compliance posture, and track remediation of identified gaps. * Support privacy impact assessments and data mapping activities to maintain an accurate record of personal data processing activities across the organization. * Incorporate data privacy requirements into vendor risk assessments and third-party due diligence activities, ensuring vendors handling personal data meet applicable contractual and regulatory obligations. GRC Tooling & Documentation * Administer and maintain GRC platform(s) (Drata, OneTrust), including control mapping, evidence collection workflows, and compliance dashboards. * Produce compliance posture reporting and audit readiness metrics for governance forums and leadership review. * Recommend new or modified procedures that improve efficiency or compliance and mitigate risk or loss. IT Project Coordination Support * Provide coordination support for IT implementation and installation projects, including scheduling, stakeholder communication, task tracking, and follow-up on open items across internal teams and vendors. * Serve as the primary point of contact for project coordination activities, ensuring timely communication of status, issues, and dependencies to relevant stakeholders. * Assist in ensuring that IT implementations satisfy applicable compliance and control requirements prior to go-live., A review of this job description may have omitted some of the marginal functions of the position that are incidental to the performance of the job duties and responsibilities. This job description, in no way, states or implies that these are the only duties and/or responsibilities to be performed by the employee in this position. The employee in this position will be required to follow any other job-related instructions and to perform any other job-related duties requested by his/her supervisor. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Web-based Information Visualization](https://www.wearedevelopers.com/videos/84-web-based-information-visualization) - [Your Manager Doesn’t Come with a User Manual (But You Can Totally Write One)](https://www.wearedevelopers.com/videos/1495-your-manager-doesn-t-come-with-a-user-manual-but-you-can-totally-write-one) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Great DevEx and Regulatory Compliance - Possible?](https://www.wearedevelopers.com/videos/1426-great-devex-and-regulatory-compliance-possible) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [A Guide to Green Tech and Green IT Careers](https://www.wearedevelopers.com/magazine/374-a-guide-to-green-tech-and-green-it-careers) - [Data Analyst Salary in Switzerland](https://www.wearedevelopers.com/magazine/276-data-analyst-salary-in-switzerland) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Quick guide: How to write a Software Developer CV](https://www.wearedevelopers.com/magazine/37-quick-guide-how-to-write-a-software-developer-cv) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023)