We are looking for a detail-oriented Governance, Risk & Compliance (GRC) Analyst to support information security governance, risk management, compliance assessments, audits, and security control activities. The ideal candidate will have hands-on experience with frameworks such as ISO 27001, NIST, SOC 2, PCI-DSS, and GDPR.
Key Responsibilities
- Conduct IT security, enterprise, and third-party/vendor risk assessments.
- Maintain risk registers, control libraries, compliance documentation, and remediation plans.
- Support implementation and maintenance of ISO 27001, NIST, SOC 2, PCI-DSS, GDPR, and other applicable frameworks.
- Develop, review, and maintain information security policies, standards, procedures, and guidelines.
- Perform control assessments and identify compliance gaps and security risks.
- Coordinate internal and external audits and manage audit evidence collection.
- Track audit findings, corrective actions, exceptions, and remediation activities through closure.
- Perform third-party/vendor security and compliance assessments.
- Maintain compliance evidence repositories and ensure documentation is audit-ready.
- Prepare GRC dashboards, compliance reports, risk metrics, and management presentations.
- Monitor regulatory and industry changes and assess their impact on organizational compliance.
- Collaborate with Information Security, IT, Legal, Privacy, Procurement, Internal Audit, and business teams.
Required Skills
- 6+ years of experience in GRC, Information Security, IT Risk, Audit, or Compliance.
- Strong knowledge of ISO 27001, NIST CSF, SOC 2, PCI-DSS, GDPR, and security controls.
- Experience with risk assessments, control testing, audit preparation, and remediation tracking.
- Experience with Third-Party Risk Management (TPRM).
- Strong documentation, analytical, communication, and stakeholder-management skills.
- Familiarity with GRC platforms such as ServiceNow GRC, Archer, OneTrust, AuditBoard, or similar tools is preferred.
Preferred Certifications
- CISA
- CRISC
- CISM
- CISSP
Nice to Have
- Experience supporting SOC 1/SOC 2 or ISO 27001 audits.
- Knowledge of cloud security and cloud compliance.
- Experience with security questionnaires and customer audits.
- Knowledge of privacy regulations such as GDPR, HIPAA, or applicable data-protection requirements.