> Markdown version of [/jobs/ext/735310-information-security-grc-analyst](https://www.wearedevelopers.com/jobs/ext/735310-information-security-grc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security GRC Analyst - **Company:** Concordant LLC - **Location:** United States (Remote available) - **Experience:** Experienced - **Salary:** $92,160.0 - $105,600.0 - **Contract:** Temporary to permanent - **Skills:** Software Documentation, Cyber Security, PCI Data Security Standards, Information Security Management System - **Published:** June 29, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=a477ee7b3982fdae ## About the Role Do you have experience in Regulatory compliance analysis?, Do you have a Bachelor's degree?, * 10+ years of experience in information security and compliance * 2+ years of experience with security audits based on a standard control set, as an auditor or responding information system security officer * Strong working knowledge of NIST 800-53 (2+ years of experience) * Prior experience with POA&M or CAP * Strong communication skills * Experience using a GRC tool (Archer or similar) (3+ years of experience) Preferred Skills * Experience completing an information security plan or system security plan notebook * Ability to simultaneously manage multiple information security work efforts * Knowledge of IRS 1075, HIPAA, CJIS, MARS-E, and/or PCI-DSS * Government sector experience Additional Skills * Ability to identify, map, and re-engineer business processes * Strong schedule management and resource planning skills * Ability to work at a high volume and fast pace * Strong collaborator with a strong ability to meet deadlines Required Education Bachelor's degree Preferred Certifications CISA, GSLC, or equivalent certification, Candidates must pass a 7-year background check, credit history check, driving record (MVR) check, E-Verify, and SLED check. CJIS certification will be required for this position and processed after start., * Bachelor's (Required) Experience: * Information Security & Compliance: 10 years (Required) * audits as an auditor or ISSO: 2 years (Required) * NIST 800-53 : 2 years (Required) * POA&M or CAP: 1 year (Required) * GRC tool (Archer or similar): 3 years (Required) ## Description This position supports the execution of a statewide information security program, helping organizations develop and mature their information security programs through direct, hands-on implementation assistance, compliance assessment, and program documentation., * Support organizations during their development of information security programs with direct tactical implementation assistance * Develop and track information security implementation plans * Interview administrators, managers, and third parties to aid in development of program artifacts * Conduct high-level assessments of information security work to ensure progress is being made * Provide high-level analysis of processes and procedures to ensure compliance with established standards * Interview business and technical owners to determine policies and procedures used for each organizational process * Develop and track information security implementation plan progress * Document information gathered during interviews and document reviews to assist with developing formal processes and procedures * Assess documentation to ensure adequate approaches are used to comply with required controls ## Related Videos - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [GitOps keeps focus on apps, not on infrastructure](https://www.wearedevelopers.com/videos/182-gitops-keeps-focus-on-apps-not-on-infrastructure) - [Humanizing Your Documentation](https://www.wearedevelopers.com/videos/476-humanizing-your-documentation) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know)