> Markdown version of [/jobs/ext/584826-grc-analyst](https://www.wearedevelopers.com/jobs/ext/584826-grc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # GRC Analyst - **Company:** M\u002FA Com Technolgy Solutions - **Location:** Lowell, MA, United States - **Experience:** Starter - **Salary:** $78,000.0 - $125,000.0 - **Contract:** Internship / Graduate position - **Skills:** Cyber Security, Smartsuite, Servicenow - **Published:** June 12, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=4c6b0dd1738cbb87 ## About the Role Do you have experience in Vendor compliance audits?, Do you have a Bachelor's degree?, We are seeking a motivated and detail-oriented GRC Analyst to join our Information Security team. This role will support the organization's governance, risk, and compliance initiatives, focusing on regulatory and framework alignment, third-party risk management, risk lifecycle processes, and policy governance. The ideal candidate will have foundational knowledge of information security principles, strong analytical skills, and a willingness to learn and grow within the GRC space, especially in platforms such as ServiceNow GRC., * Bachelor's degree in Information Security, Cybersecurity, IT, or related field (or equivalent experience) * 1-3 years of experience in information security, risk, compliance, or audit (internships acceptable) * Basic understanding of security frameworks and regulatory requirements * Strong analytical, organizational, and documentation skills * Excellent written and verbal communication skills Preferred * Exposure to frameworks such as NIST, ISO 27001, SOC 2, or CIS * Security or compliance certifications (e.g., CISM, CRISC, CISSP, CGEIT, or CISA). * Experience with third-party risk management processes * Familiarity with risk management concepts and methodologies * Exposure to GRC tools (ServiceNow GRC preferred, but not required) Key Competencies * Detail-oriented with strong follow-through * Ability to manage multiple priorities and deadlines * Collaborative mindset with cross-functional teams * Curiosity and willingness to learn new tools and frameworks * Strong problem-solving and critical-thinking skills Why Join Us * Opportunity to grow within a maturing GRC program * Exposure to a wide range of security, compliance, and risk disciplines * Hands-on experience with industry-standard tools like ServiceNow GRC * Collaborative and supportive team environment ## Description Compliance & Framework Support * Assist in the implementation, maintenance, and monitoring of compliance frameworks (e.g., NIST, ISO 27001, SOX, SOC2, CIS, etc.) * Support internal and external audit activities, including evidence collection and control validation * Track and report on compliance status, gaps, and remediation efforts Third-Party Risk Management (TPRM) * Conduct vendor risk assessments and due diligence reviews * Analyze third-party security posture and identify potential risks * Maintain vendor inventory and track risk treatment activities * Collaborate with business owners to ensure appropriate risk mitigation Risk Management * Support the execution of the Information Security risk management lifecycle * Assist with risk identification, assessment, documentation, and tracking * Help maintain risk registers and ensure risks are properly escalated and monitored * Partner with stakeholders to support risk remediation planning Policy Governance * Assist in drafting, reviewing, and maintaining information security policies, standards, and procedures * Facilitate policy review cycles, approvals, and documentation updates * Ensure alignment with regulatory requirements and industry best practices GRC Tooling & Process Support * Support and learn the administration and use of ServiceNow GRC * Assist in configuring workflows, tracking activities, and improving GRC processes * Help identify opportunities for automation and process optimization ## Related Videos - [Great DevEx and Regulatory Compliance - Possible?](https://www.wearedevelopers.com/videos/1426-great-devex-and-regulatory-compliance-possible) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Robots are coming into the wild! Full-Stack Robotics Engineers, be ready!](https://www.wearedevelopers.com/videos/479-robots-are-coming-into-the-wild-full-stack-robotics-engineers-be-ready) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023) - [The Glassdoor Dilemma: Unveiling the Truth Behind Company Reviews](https://www.wearedevelopers.com/magazine/273-the-glassdoor-dilemma-unveiling-the-truth-behind-company-reviews) - [Quick guide: How to write a Software Developer CV](https://www.wearedevelopers.com/magazine/37-quick-guide-how-to-write-a-software-developer-cv) - [Résumé-Driven Development: How IT trends affect the job market for software developers](https://www.wearedevelopers.com/magazine/59-resume-driven-development-how-it-trends-affect-the-job-market-for-software-developers) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know)