> Markdown version of [/jobs/ext/2693267-grc-analyst](https://www.wearedevelopers.com/jobs/ext/2693267-grc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # GRC Analyst - **Company:** Beacon Hill Staffing Group, LLC - **Location:** Houston, TX, United States (Remote available) - **Experience:** Experienced - **Salary:** $145,600.0 - $176,800.0 - **Contract:** Temporary contract - **Skills:** Cyber Security, Executive Information Systems, Supervisory Control and Data Acquisition (SCADA), Identity and Access Management, Information Technology Audit, Software Vulnerability Management, IT General Controls (ITGC), Process Control Systems, RSA Archer Platform, Operational Systems, CIS Benchmarks, Servicenow - **Published:** September 3, 2026 - **Apply:** https://www.jofdav.com/jobs/59521363-grc-analyst ## About the Role * 3+ years of experience in Governance, Risk & Compliance (GRC), cybersecurity compliance, IT audit, information security, or related disciplines. * Strong knowledge of: + NIST Cybersecurity Framework (CSF), * Experience supporting audits, evidence collection, control testing, remediation tracking, and compliance reporting. * Ability to develop and maintain security policies, standards, procedures, and control documentation. * Experience conducting risk assessments, gap assessments, and control reviews. * Familiarity with third-party and vendor risk management processes. * Strong documentation and communication skills with the ability to translate technical concepts into business-friendly language. * Experience working with cross-functional teams across technology and business organizations. * Knowledge of enterprise security controls including identity and access management, vulnerability management, incident response, and change management. * Strong organizational skills and ability to manage multiple initiatives simultaneously., * Experience within energy, utilities, renewable energy, power generation, critical infrastructure, or industrial environments. * Knowledge of NERC CIP, FERC, or similar industry regulations. * Exposure to OT/SCADA environments, substations, generation assets, EMS, DERMS, or industrial control systems. * Certifications such as: + CISA + CISSP + CISM + CRISC + Security+ + ISO 27001 Lead Auditor/Implementer * Experience with GRC platforms such as: + ServiceNow GRC ## Description We are seeking a Governance, Risk & Compliance (GRC) Specialist to join a growing Information Security team supporting a large-scale critical infrastructure environment. This individual will play a key role in strengthening governance, risk management, compliance, and cybersecurity processes across corporate IT, cloud platforms, and operational technology (OT) environments. This is a unique opportunity to help build and mature a cybersecurity governance program from the ground up while partnering closely with security, engineering, infrastructure, legal, procurement, and business stakeholders., * Support and maintain the organization's governance, risk, and compliance program across IT, cloud, and OT environments. * Develop, review, and maintain security policies, standards, procedures, and control documentation. * Coordinate audit evidence collection for internal audits, external audits, compliance reviews, and customer assessments. * Track audit findings, remediation plans, control deficiencies, policy exceptions, and risk acceptance activities. * Perform control testing and compliance validation to ensure security controls are operating effectively. * Assist with risk assessments, gap assessments, compliance readiness activities, and control maturity reviews. * Support vendor and third-party risk management activities, including security questionnaires and risk reviews. * Collaborate with IT, Security Operations, Infrastructure, Engineering, Legal, Procurement, Compliance, and Operations teams. * Map security controls to frameworks including NIST, ISO 27001, SOC 2, and CIS Controls. * Maintain risk registers, compliance calendars, control inventories, and audit repositories. * Prepare compliance reports, dashboards, scorecards, and presentations for leadership. * Monitor remediation efforts and work with control owners to ensure timely issue resolution. * Support continuous improvement initiatives across the information security governance program. * Stay informed on cybersecurity regulations, compliance trends, and industry best practices., + OneTrust + AuditBoard + LogicGate + Drata + Vanta * Experience supporting SOC 2, ISO 27001, SOX ITGC, PCI, or customer security reviews. * Experience creating executive dashboards, compliance scorecards, risk registers, and audit reporting. Why Join? * Opportunity to help build and define a new GRC function. * High visibility within a growing Information Security organization. * Exposure to both traditional enterprise IT and operational technology environments. * Opportunity to contribute to the modernization of cybersecurity, risk, and compliance practices within a critical infrastructure environment. * Strong potential for long-term conversion and career growth. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [A practical guide to writing secure Dockerfiles](https://www.wearedevelopers.com/videos/109-a-practical-guide-to-writing-secure-dockerfiles) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [OPA for the cloud natives](https://www.wearedevelopers.com/videos/713-opa-for-the-cloud-natives) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [A Guide to Green Tech and Green IT Careers](https://www.wearedevelopers.com/magazine/374-a-guide-to-green-tech-and-green-it-careers) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)