Information Security GRC Analyst

Concordant LLC
United States
about 1 month ago

Role details

Contract type
Temporary to permanent
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Compensation
$92,160.0 - $105,600.0
Working hours
Regular working hours
Job source

Tech stack

Software Documentation Cyber Security PCI Data Security Standards Information Security Management System

Job description

This position supports the execution of a statewide information security program, helping organizations develop and mature their information security programs through direct, hands-on implementation assistance, compliance assessment, and program documentation., * Support organizations during their development of information security programs with direct tactical implementation assistance

  • Develop and track information security implementation plans
  • Interview administrators, managers, and third parties to aid in development of program artifacts
  • Conduct high-level assessments of information security work to ensure progress is being made
  • Provide high-level analysis of processes and procedures to ensure compliance with established standards
  • Interview business and technical owners to determine policies and procedures used for each organizational process
  • Develop and track information security implementation plan progress
  • Document information gathered during interviews and document reviews to assist with developing formal processes and procedures
  • Assess documentation to ensure adequate approaches are used to comply with required controls

Requirements

Do you have experience in Regulatory compliance analysis?, Do you have a Bachelor’s degree?, * 10+ years of experience in information security and compliance

  • 2+ years of experience with security audits based on a standard control set, as an auditor or responding information system security officer
  • Strong working knowledge of NIST 800-53 (2+ years of experience)
  • Prior experience with POA&M or CAP
  • Strong communication skills
  • Experience using a GRC tool (Archer or similar) (3+ years of experience)

Preferred Skills

  • Experience completing an information security plan or system security plan notebook
  • Ability to simultaneously manage multiple information security work efforts
  • Knowledge of IRS 1075, HIPAA, CJIS, MARS-E, and/or PCI-DSS
  • Government sector experience

Additional Skills

  • Ability to identify, map, and re-engineer business processes
  • Strong schedule management and resource planning skills
  • Ability to work at a high volume and fast pace
  • Strong collaborator with a strong ability to meet deadlines

Required Education

Bachelor’s degree

Preferred Certifications

CISA, GSLC, or equivalent certification, Candidates must pass a 7-year background check, credit history check, driving record (MVR) check, E-Verify, and SLED check. CJIS certification will be required for this position and processed after start., * Bachelor’s (Required)

Experience:

  • Information Security & Compliance: 10 years (Required)
  • audits as an auditor or ISSO: 2 years (Required)
  • NIST 800-53 : 2 years (Required)
  • POA&M or CAP: 1 year (Required)
  • GRC tool (Archer or similar): 3 years (Required)

Benefits & conditions

$92,160 - $105,600 a year - Full-time, Contract

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

2:03 min

Platform compliance and security certifications for sensitive data

Chad Carlson · WWC 2021

1:58 min

Measuring productivity gains from agent-assisted code refactoring

Dr. Alexander Wachtel Dr. Alexander Wachtel +1 · WWC 2025

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · WWC Europe 2026

1:32 min

The danger of unverified assumptions in critical systems

Luís Ventura Luís Ventura · WWC 2024

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all