> Markdown version of [/jobs/ext/3075655-grc-analyst](https://www.wearedevelopers.com/jobs/ext/3075655-grc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # GRC Analyst - **Company:** Acrisure LLC - **Location:** Valhalla, NY, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Information Systems, Customer Data Management, Information Systems Security Architecture Professional, PCI Data Security Standards, IT General Controls (ITGC), CIS Benchmarks - **Published:** September 25, 2026 - **Apply:** https://startup.jobs/governance-risk-compliance-analyst-acrisure-technology-group-ll-10178927 ## About the Role * Able to work independently and enjoy a high degree of interaction with team members * Ability to contribute to a collaborative environment by consistently demonstrating teamwork, high motivation, positive behavior and effort to achieve goals and objectives * Self-motivated and driven * Maintain a sense of urgency and ability to work with and meet deadlines * Demonstrate effective written and verbal communication, including the ability actively listen, and problem solve with minimal assistance * Demonstrate excellent time management and prioritization skills * Attention to detail and commitment to a high level of accuracy * The ability to multitask, prioritize, work independently, and use discretion surrounding sensitive information * Ability to maintain a professional demeanor and positive attitude Education and Experience: * 2+ years of relevant experience in GRC-focused security activities. * Understanding of security standards and frameworks such as NIST, ISO 27001, CIS Controls, and industry compliance regulations (NYDFS, GDPR, HIPAA, PCI-DSS). * Proven ability to manage complex timelines and deliverables, ensuring alignment with organizational goals and regulatory requirements. * Bachelor's degree (or equal experience) in an Information Systems Assurance or related. * Preferred Certifications: + CRISC (Certified in Risk and Information Systems Control) + CISSP (Certified Information Systems Security Professional) + CISA (Certified Information Systems Auditor) + CEH (Certified Ethical Hacker) #LI-CH1 Candidates should be comfortable with an on-site presence to support collaboration, team leadership, and cross-functional partnership. ## Description We are seeking a detail-oriented and motivated GRC Analyst to join our growing team. The ideal candidate will have 32+ years of experience in supporting governance, risk, and compliance initiatives. This includes assisting with client/prospect compliance questionnaires, user access reviews, SOC1 and SOC2 audits, Sarbanes-Oxley IT general controls audits, and internal risk reviews. You will help maintain awareness of relevant cybersecurity regulations and contribute to implementing audit, governance, risk, and compliance (GRC) frameworks. As a GRC Analyst, you will collaborate across departments to ensure security solutions protect internal systems, vendor environments, and customer data while also aligning with compliance requirements. Join one of the fastest-growing companies in the world, where you'll gain hands-on experience with cybersecurity, compliance, and privacy frameworks, and work alongside industry experts in an environment built for growth, impact, and continuous learning. Responsibilities: * Support governance, risk, and compliance (GRC) activities by assisting with cybersecurity framework implementation and regulatory compliance efforts. * Participate in internal and external audits by coordinating evidence collection, tracking remediation efforts, and supporting readiness for SOC 2, SOX ITGC, and HIPAA assessments. * Performing user access reviews for assigned applications and systems. * Assist in maintaining compliance with regulatory standards including SOX, HIPAA, SOC 2, GDPR, and PCI-DSS, while staying informed about evolving cybersecurity laws and obligations. * Collaborate with cross-functional teams to support security initiatives and communicate effectively with both technical and non-technical stakeholders. ## Related Videos - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [API Platform: From Rest & GraphQL APIs to state-of-the-art standards in seconds](https://www.wearedevelopers.com/videos/1968-api-platform-from-rest-graphql-apis-to-state-of-the-art-standards-in-seconds) - [A practical guide to writing secure Dockerfiles](https://www.wearedevelopers.com/videos/109-a-practical-guide-to-writing-secure-dockerfiles) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [AI Vector Search at Scale - Ewa Szyszka - Ewa Szyszka](https://www.wearedevelopers.com/videos/2161-ai-vector-search-at-scale-ewa-szyszka-ewa-szyszka) - [OPA for the cloud natives](https://www.wearedevelopers.com/videos/713-opa-for-the-cloud-natives) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Data Analyst Salary in Switzerland](https://www.wearedevelopers.com/magazine/276-data-analyst-salary-in-switzerland) - [Coffee with Developers - Maria Apazoglou - Making AI understandable for all in production](https://www.wearedevelopers.com/magazine/475-coffee-with-developers-maria-apazoglou-making-ai-understandable-for-all-in-production) - [The Geometry of Incidents: Connecting User Impact to Architecture](https://www.wearedevelopers.com/magazine/764-the-geometry-of-incidents-connecting-user-impact-to-architecture) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Résumé-Driven Development: How IT trends affect the job market for software developers](https://www.wearedevelopers.com/magazine/59-resume-driven-development-how-it-trends-affect-the-job-market-for-software-developers)