> Markdown version of [/jobs/ext/616282-remote-senior-information-security-grc-analyst](https://www.wearedevelopers.com/jobs/ext/616282-remote-senior-information-security-grc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Remote- Senior Information Security GRC Analyst - **Company:** E-Solutions - **Location:** Columbia, United States (Remote available) - **Experience:** Expert - **Contract:** Temporary to permanent - **Skills:** Cyber Security, PCI Data Security Standards, Information Security Management System - **Published:** June 24, 2026 - **Apply:** https://www.dice.com/job-detail/575b867d-3185-44f5-ba15-9e2a3e07019c ## About the Role Required skills (must include years of experience, in order of importance) * 10+ Years of Experience in Information Security and Compliance. * 2+ Years of Experience with security audits based on a standard control set as an auditor or responding information system security officer * Must Have a Strong Working Knowledge of NIST 800-53 (2 Years of Experience) * Prior Experience POA&M or CAP. * Strong Communication Experience. Experience With Using A GRC Tool (Archer or Similar) (3 Years of Experience) Preferred Skills (Rank in order of Importance): * Have completed an information security plan or system security plan notebook. * Simultaneously, manage multiple infosec work efforts. * Knowledge of IRS 1075, HIPAA, CJIS, MARS-E and/or PCI-DSS. * Government sector experience Required Education: Bachelor's Degree Preferred Certifications: CISA, GSLC, or equivalent certification Senior Information Security GRC Analyst1Information Security,archerN/AC2CUnited States ## Description Work Location: The role is 100% remote. Preference will be given to local candidates who can come to the office as needed for client and departmental meetings, trainings, and other onsite activities. Candidate location: All travel-related costs for onsite work will be the responsibility of the resource no matter the frequency of onsite work. Scope of the project: This position with be perform duties as part of DIS execution of its responsibilities under the statewide information security program. DIS responsibilities include the following: * Supporting agencies during their development of the information security program with direct tactical implementation assistance. * Developing and tracking agency information security implementation plans. * Interview administrators, managers and third parties to aid in development of program artifacts. * Ensuring high-level assessments of agencies' infosec work to ensure progress is made. Providing high-level analysis of process and procedures work to ensure compliance with state standards. Daily Duties / Responsibilities: Duties include, but are not limited to: * Interviewing business and technical owners to determine policies and procedures used for each agency process. * Developing and tracking infosec implementation plan progress. * Documenting information gathered during both interviews and * Document reviews to assist with developing formal process and procedures. Assessing agency documentation to ensure adequate approaches are used to comply with controls. ## Related Videos - [Communicate efficiently with Software Architecture Diagrams](https://www.wearedevelopers.com/videos/379-communicate-efficiently-with-software-architecture-diagrams) - [GitOps keeps focus on apps, not on infrastructure](https://www.wearedevelopers.com/videos/182-gitops-keeps-focus-on-apps-not-on-infrastructure) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) ## Related Articles - [Best Paying Remote Jobs](https://www.wearedevelopers.com/magazine/255-best-paying-remote-jobs) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)