GRC Analyst
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
Own the day-to-day execution of the cybersecurity Governance, Risk, and Compliance program, including cyber risk assessments, enterprise risk reporting, risk register management, and board-level risk dashboards. Lead policy and standards management, ensuring alignment with frameworks such as NIST, HITRUST, HIPAA, and PCI DSS. Partner with Compliance, Internal Audit, Legal, IT, Engineering, and Product teams to identify, assess, mitigate, and track cybersecurity risks. Support audits and certifications, manage client security questionnaires, review security-related contract language, facilitate risk governance meetings, and provide leadership with clear insights into cybersecurity risk and compliance posture.
Requirements
3+ years of experience in cybersecurity GRC, IT audit, information security, or compliance.
Hands-on experience managing risk registers and the full cyber risk management lifecycle.
Experience supporting audits/certifications across at least two frameworks such as NIST CSF, HITRUST, HIPAA, PCI DSS, or SOC 2.
Strong knowledge of NIST CSF, HITRUST, HIPAA, and PCI DSS 4.0.
Experience reviewing cybersecurity and data protection language in contracts, BAAs, and DPAs.
Experience with a GRC platform (ServiceNow GRC, Archer, OneTrust, LogicGate, AuditBoard, etc.).
Strong communication skills with the ability to translate technical risks for executive and business audiences.
Ability to manage multiple priorities and collaborate across Legal, Compliance, IT, Engineering, Product, Audit, and Leadership teams. Industry certifications such as CISSP, CISA, CISM, CRISC, CIPP, HCISPP, HITRUST CCSFP, or PCI ISA.
Experience in healthcare, financial services, or other regulated industries.
Hands-on experience supporting HITRUST r2 certifications and/or PCI DSS 4.0 attestations.
Knowledge of GDPR, CCPA/CPRA, and other privacy regulations.
Familiarity with cloud environments (AWS, Azure, GCP) and SaaS security models.
Experience supporting organizations undergoing rapid growth, M&A activity, or technology modernization initiatives.
Experience with executive-level risk reporting and board presentations.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
What Are The Top Skills Required For Azure Developers?
Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud
Walking Into The Era of Supply Chain Risks
9 Ways to Make Money Hacking