Primary Purpose
Provide reliable operational support across core Security GRC and security awareness activities while preserving accountable decision-making with the Sr. Manager, Security GRC.
Role Summary
- The Security GRC Support Analyst executes recurring governance, risk, compliance, vendor-risk, reporting, and security awareness work. The role organizes evidence, maintains accurate records, prepares first drafts and routine analyses, coordinates follow-up, and escalates exceptions or judgment-intensive matters.
- It is designed to operate effectively as an individual contractor, an offshore resource, or a human role supported by approved AI tools.
Key Responsibilities
- Governance and Policy Lifecycle
- Risk, Vulnerability, and Remediation Tracking
- Third-Party and Technology Risk Support
- Security Awareness and Training
- Metrics, Evidence, and Reporting
- Data Governance and Compliance Support
- These responsibilities include maintaining policy inventories, tracking risks and remediation, coordinating vendor-security reviews, collecting security evidence, supporting awareness campaigns and phishing simulations, preparing KPI/KRI reporting, and supporting Microsoft Purview and other compliance activities.
Required Qualifications
- Working knowledge of security governance, risk, compliance, controls, or audit-support practices.
- Strong written communication, document-quality control, organization, and follow-through.
- Ability to work with structured trackers, ticketing systems, dashboards, questionnaires, and evidence repositories.
- Ability to distinguish routine processing from matters requiring professional judgment or escalation.
- Experience handling confidential business and security information in accordance with access and data-handling requirements.
- Professional fluency in English and the ability to collaborate effectively across time zones and functions.
Preferred Qualifications
- Experience with NIST CSF, ISO/IEC 27001, SOC 2, third-party risk management, vulnerability remediation, or policy lifecycle management.
- Experience supporting security awareness, phishing simulations, training administration, or employee communications.
- Familiarity with tools such as Diligent One, UpGuard, Tenable, ServiceNow, Microsoft Purview, SharePoint, Excel, and reporting dashboards.
- Experience using approved generative AI or workflow-automation tools for drafting, summarization, data preparation, or quality checks.
Key Point to Confirm During Screening
- The candidate should be able to perform evidence collection and organization, tracker maintenance and routine follow-up, first-draft policies/reports/questionnaires/awareness content, data reconciliation and completeness checks, campaign administration and approved communications, and procedure documentation and workflow-improvement suggestions.
- Final risk acceptance, exception approval, control-owner decisions, final vendor or technology approval, legal/privacy/employment/contractual interpretation, material changes to policy requirements or risk ratings, and external commitments or communications without required approval remain with the accountable owner.
90-Day Expectations
- First 30 days: Complete onboarding and access; learn applicable processes and tools; confirm recurring work inventory; begin supervised policy, metrics, and tracking support.
- Days 31–60: Own routine updates and evidence collection; contribute to vendor reviews, remediation coordination, policy revisions, and awareness content; document procedures and escalation paths.
- Days 61–90: Independently manage assigned recurring work; deliver reliable vendor-review packages, awareness and training reporting, dashboards, and status updates; propose measurable efficiency improvements.