GRC Analyst
Covenant LLC
Milton, MA, United States
3 days ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Apply on www.disabledperson.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source
Tech stack
Control Objectives for Information and Related Technology (COBIT)
Cyber Security
Information Technology Audit
CIS Benchmarks
Job description
- Manage and respond to client and operational due-diligence requests, translating security and technology controls into clear responses for clients, auditors, and external stakeholders
- Support SOC 1/SOC 2, SOX, internal, and external audit activities, including evidence collection and coordination with control owners
- Conduct and coordinate technology, cybersecurity, information-security, and operational risk assessments
- Maintain risk registers, control inventories, audit findings, policies, standards, exceptions, remediation plans, and supporting evidence
- Partner with Information Security, Technology, Legal and Compliance, Internal Audit, Operations, and client-facing teams
- Perform third-party risk activities, including vendor security assessments, SOC report reviews, risk documentation, and ongoing monitoring
- Support governance and oversight of DLP and information-protection controls
- Track identified issues and remediation activities through completion and coordinate with appropriate stakeholders
- Develop management reporting related to risk, audits, controls, findings, and remediation
- Identify opportunities to automate and streamline GRC, audit, evidence-collection, and due-diligence processes
- Financial services, asset management, institutional investment management, or other regulated-industry experience is strongly preferred
- Relevant certifications such as CISA, CRISC, CISM, CISSP, CIA, Security+, or ISO 27001 are preferred
Requirements
- 3-6 years of relevant GRC/security-risk experience across information security, technology risk, IT audit, operational risk, or a related discipline
- Hands-on client and operational due-diligence experience responding to RFPs, RFIs, DDQs, ODD requests, client security questionnaires, or similar security/technology-risk inquiries
- Control and audit assurance experience supporting SOC 1/SOC 2, SOX, internal/external audits, evidence collection, control-owner coordination, issue management, and remediation
- Strong GRC fundamentals, including risk assessments, control design/testing, policy governance, remediation tracking, third-party risk, and frameworks such as NIST CSF, ISO 27001, COBIT, or CIS Controls
- Independent, highly organized communicator capable of managing multiple concurrent questionnaires, audits, assessments, and remediation activities across technical and business stakeholders.
About the company
Company - Our client is a cybersecurity services and consulting organization focused on helping enterprises strengthen their security programs through technology, advisory, risk and compliance, and specialized security services. The organization takes a highly consultative, client-centric approach to solving complex cybersecurity challenges.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.disabledperson.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
DC
Daniel Cranney
7 months ago
IK
Igor Khokhriakov
How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again
21 days ago
TL
Thomas Limbüchler
Should senior developers refuse interview coding challenges?
over 5 years ago
JF
Jonas Fritzsch
Résumé-Driven Development: How IT trends affect the job market for software developers
almost 5 years ago
LM
Luis Minvielle
9 Ways to Make Money Hacking
over 2 years ago
CS
Christina Schaireiter
Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence
3 months ago