> Markdown version of [/jobs/ext/2681795-grc-analyst](https://www.wearedevelopers.com/jobs/ext/2681795-grc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # GRC Analyst - **Company:** Covenant LLC - **Location:** Boston, MA, United States - **Experience:** Experienced - **Contract:** Temporary contract - **Skills:** Control Objectives for Information and Related Technology (COBIT), Cyber Security, Information Technology Audit, CIS Benchmarks - **Published:** August 31, 2026 - **Apply:** https://www.disabledperson.com/jobs/74609765-grc-analyst ## About the Role * 3-6 years of relevant GRC/security-risk experience across information security, technology risk, IT audit, operational risk, or a related discipline * Hands-on client and operational due-diligence experience responding to RFPs, RFIs, DDQs, ODD requests, client security questionnaires, or similar security/technology-risk inquiries * Control and audit assurance experience supporting SOC 1/SOC 2, SOX, internal/external audits, evidence collection, control-owner coordination, issue management, and remediation * Strong GRC fundamentals, including risk assessments, control design/testing, policy governance, remediation tracking, third-party risk, and frameworks such as NIST CSF, ISO 27001, COBIT, or CIS Controls * Independent, highly organized communicator capable of managing multiple concurrent questionnaires, audits, assessments, and remediation activities across technical and business stakeholders. ## Description * Manage and respond to client and operational due-diligence requests, translating security and technology controls into clear responses for clients, auditors, and external stakeholders * Support SOC 1/SOC 2, SOX, internal, and external audit activities, including evidence collection and coordination with control owners * Conduct and coordinate technology, cybersecurity, information-security, and operational risk assessments * Maintain risk registers, control inventories, audit findings, policies, standards, exceptions, remediation plans, and supporting evidence * Partner with Information Security, Technology, Legal and Compliance, Internal Audit, Operations, and client-facing teams * Perform third-party risk activities, including vendor security assessments, SOC report reviews, risk documentation, and ongoing monitoring * Support governance and oversight of DLP and information-protection controls * Track identified issues and remediation activities through completion and coordinate with appropriate stakeholders * Develop management reporting related to risk, audits, controls, findings, and remediation * Identify opportunities to automate and streamline GRC, audit, evidence-collection, and due-diligence processes * Financial services, asset management, institutional investment management, or other regulated-industry experience is strongly preferred * Relevant certifications such as CISA, CRISC, CISM, CISSP, CIA, Security+, or ISO 27001 are preferred ## Related Videos - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [A practical guide to writing secure Dockerfiles](https://www.wearedevelopers.com/videos/109-a-practical-guide-to-writing-secure-dockerfiles) - [Fireside Chat: AI and Sustainability - Thorsten Jonas](https://www.wearedevelopers.com/videos/1769-fireside-chat-ai-and-sustainability-thorsten-jonas) - [OPA for the cloud natives](https://www.wearedevelopers.com/videos/713-opa-for-the-cloud-natives) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Should senior developers refuse interview coding challenges?](https://www.wearedevelopers.com/magazine/29-should-senior-developers-refuse-interview-coding-challenges) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Résumé-Driven Development: How IT trends affect the job market for software developers](https://www.wearedevelopers.com/magazine/59-resume-driven-development-how-it-trends-affect-the-job-market-for-software-developers) - [Best US AI Conferences for CTOs in 2026: Build vs. Buy, Vendor Evaluation, and Peer Intelligence](https://www.wearedevelopers.com/magazine/736-best-us-ai-conferences-for-ctos-in-2026-build-vs-buy-vendor-evaluation-and-peer-intelligence) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking)