> Markdown version of [/jobs/ext/2695479-grc-analyst-ii-remote](https://www.wearedevelopers.com/jobs/ext/2695479-grc-analyst-ii-remote). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # GRC Analyst II (REMOTE) - **Company:** Dick's Sporting Goods Inc - **Location:** Coraopolis, PA, United States (Remote available) - **Experience:** Starter - **Salary:** $67,100.0 - $109,000.0 - **Contract:** Permanent contract - **Skills:** Cyber Security, Information Technology Audit, PCI Data Security Standards, Information Technology - **Published:** September 3, 2026 - **Apply:** https://www.dickssportinggoods.jobs/jobs/19946961/grc-analyst-ii-remote-remote/?utm_medium=%22mcloud%2Djobads%22&utm_campaign=&utm_content=GRC%20Analyst%20II%20%28REMOTE%29&utm_term=202402877 ## About the Role * 1-3 years of experience in cybersecurity, GRC, or technology audit * Some working knowledge and experience with cybersecurity controls frameworks such as the NIST CSF is preferred * Previous experience with cybersecurity policy lifecycle, control statements, standards, and guidelines is preferred * Some knowledge of PCI-DSS and SOX technology control requirements * Some knowledge of security awareness techniques and processes * Effective communication skills that can be adjusted to relevant audiences * Analytic and problem solving skills * Ability to work effectively in a team and remote work environment * Bachelors in Cybersecurity, MIS, Computer Science, or related field is preferred but not required ## Description We are seeking a highly motivated GRC Analyst II to help us maintain a robust cybersecurity governance, risk, and compliance program. The ideal candidate will play a pivotal role in reducing cybersecurity risk and maintaining technology compliance while enabling the business to serve our athletes and teammates. This position is ideal for candidates who are looking to further their career in the cybersecurity field. Policy/Standard/Control Statement Development and Maintenance: * Contribute to the creation and maintenance of cybersecurity control statements, policies, standards, and guidelines. * Ensure policies are up-to-date and align with industry best practices and frameworks. * Communicate policy changes and updates to relevant stakeholders. Security Awareness Training: * Assist in the development of security awareness training programs and materials. * Assist with the planning and execution of cybersecurity awareness events and communication campaigns. * Organize and deliver training sessions to teammates on security best practices. * Monitor and report on the effectiveness of security awareness initiatives. Technology Risk Assessment: * Assist with the collection, analysis, and presentation of cybersecurity program performance metrics and key risk indicators (KRIs). * Conduct regular assessments of technology-related risks within applications, platforms, and processes. * Identify risks and assist in the development of mitigation strategies and risk management plans. * Provide policy, risk, and compliance input on the design of required security measures. PCI and SOX Compliance: * Serve as a second line of defense to ensure appropriate design and operating effectiveness of PCI DSS and SOX controls. * Collaborate with cross-functional teams to implement necessary controls. * Maintain compliance documentation and reporting. ## Related Videos - [Forecasting Cyber Attacks with Glassdoor Reviews - Lianne Potter](https://www.wearedevelopers.com/videos/2143-forecasting-cyber-attacks-with-glassdoor-reviews-lianne-potter) - [GitOps keeps focus on apps, not on infrastructure](https://www.wearedevelopers.com/videos/182-gitops-keeps-focus-on-apps-not-on-infrastructure) - [Enabling intelligent logistics automation: home-grown Industrial IoT platform at Austrian Post](https://www.wearedevelopers.com/videos/2018-enabling-intelligent-logistics-automation-home-grown-industrial-iot-platform-at-austrian-post) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Why Your Next Best Talent Might Not Be in Your Neighborhood](https://www.wearedevelopers.com/videos/1861-why-your-next-best-talent-might-not-be-in-your-neighborhood) ## Related Articles - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Remote Jobs](https://www.wearedevelopers.com/magazine/255-best-paying-remote-jobs) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Job Boards for Remote Work for Developers](https://www.wearedevelopers.com/magazine/290-best-job-boards-for-remote-work-for-developers)