GRC Analyst

Insight Global
Carol Stream, IL, United States
1 day ago
Apply on dejobs.org
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Working hours
Regular working hours
Job source

Tech stack

Amazon Web Services Microsoft Azure Cloud Computing Security Cyber Security Information Technology Audit PCI Data Security Standards Google Cloud Cloud Platform System Cyber Threat Analysis Servicenow

Job description

Own the day-to-day execution of the cybersecurity Governance, Risk, and Compliance program, including cyber risk assessments, enterprise risk reporting, risk register management, and board-level risk dashboards. Lead policy and standards management, ensuring alignment with frameworks such as NIST, HITRUST, HIPAA, and PCI DSS. Partner with Compliance, Internal Audit, Legal, IT, Engineering, and Product teams to identify, assess, mitigate, and track cybersecurity risks. Support audits and certifications, manage client security questionnaires, review security-related contract language, facilitate risk governance meetings, and provide leadership with clear insights into cybersecurity risk and compliance posture.

Requirements

3+ years of experience in cybersecurity GRC, IT audit, information security, or compliance.

Hands-on experience managing risk registers and the full cyber risk management lifecycle.

Experience supporting audits/certifications across at least two frameworks such as NIST CSF, HITRUST, HIPAA, PCI DSS, or SOC 2.

Strong knowledge of NIST CSF, HITRUST, HIPAA, and PCI DSS 4.0.

Experience reviewing cybersecurity and data protection language in contracts, BAAs, and DPAs.

Experience with a GRC platform (ServiceNow GRC, Archer, OneTrust, LogicGate, AuditBoard, etc.).

Strong communication skills with the ability to translate technical risks for executive and business audiences.

Ability to manage multiple priorities and collaborate across Legal, Compliance, IT, Engineering, Product, Audit, and Leadership teams. Industry certifications such as CISSP, CISA, CISM, CRISC, CIPP, HCISPP, HITRUST CCSFP, or PCI ISA.

Experience in healthcare, financial services, or other regulated industries.

Hands-on experience supporting HITRUST r2 certifications and/or PCI DSS 4.0 attestations.

Knowledge of GDPR, CCPA/CPRA, and other privacy regulations.

Familiarity with cloud environments (AWS, Azure, GCP) and SaaS security models.

Experience supporting organizations undergoing rapid growth, M&A activity, or technology modernization initiatives.

Experience with executive-level risk reporting and board presentations.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on dejobs.org
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:11 min

Addressing security audits and regional data compliance legislation

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

6:10 min

Unlocking free learning credits via Google Cloud Innovators

Asrar Asrar · World Congress 2024

56 sec

Integrating automated approval workflows into the portal

Markus Eisele Markus Eisele · World Congress 2025

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

4:42 min

Container hosting options available on Google Cloud Platform

Federico Fregosi · World Congress 2022

Videos

See all

Related articles

See all