Security GRC Analyst
The Security GRC Analyst will manage security risks, policies, audits, control testing, and compliance reporting while partnering with technical and business stakeholders. The role requires 4+ years of GRC or security assurance experience and familiarity with major security frameworks.
About the job
Responsibilities
- Administer and maintain the security risk register, including risks, remediation activities, owners, and reporting.
- Identify, document, assess, and monitor security risks with Security and business stakeholders.
- Draft, review, update, and manage security policies, standards, and procedures.
- Coordinate evidence collection and follow-up activities for the annual SOC 2 Type 2 audit.
- Track and report security awareness training metrics, exceptions, and follow-up actions.
- Execute security control testing aligned with CIS Controls and document findings and remediation recommendations.
- Conduct and support internal security risk assessments.
- Monitor control effectiveness and improve process maturity, consistency, and evidence quality.
- Prepare dashboards, reports, and leadership presentations covering risk, compliance, audit, and awareness programs.
- Track remediation for control gaps, audit findings, and risk treatment actions.
- Contribute to continuous improvement of the GRC framework and operating processes.
Requirements
- 4+ years of experience in security governance, risk, compliance, audit, or security assurance.
- Working knowledge of SOC 2, CIS Controls, ISO 27001, NIST CSF, or similar frameworks.
- Experience supporting audits, assessments, or control testing in a technology or SaaS environment.
- Ability to write practical security policies, standards, and process documentation.
- Experience maintaining risk registers and supporting formal risk assessments.
- Strong organizational, cross-functional communication, and stakeholder information-gathering skills.
- Bachelor’s degree in a relevant field such as Computer Information Systems or Cybersecurity, or equivalent experience.
Nice-to-haves
- Experience supporting SOC 2 Type 2 audits in a cloud-based or high-growth technology environment.
- Familiarity with security awareness program administration and reporting.
- Experience coordinating control testing mapped to recognized frameworks such as CIS Controls.
- Knowledge of identity and access management, logging and monitoring, vulnerability management, endpoint security, and third-party risk.
- Security+, CISA, CRISC, CISSP, or similar certification.
Skills
SOC 2, Cis Controls, ISO 27001, Nist Csf, Risk Registers, Security Audits, Control Testing, Security Policies, Security Awareness, Identity And Access Management, Vulnerability Management, Endpoint Security, Third-Party Risk, Cissp
Similar jobs
Security Engineering jobsDevelops machine-level safety cases, hazard analyses, and safety requirements for autonomous mining and industrial equipment. The role requires hands-on system safety experience, knowledge of ISO 26262, and collaboration across hardware, software, controls, and validation teams.
Investigates and assesses physical security threats involving personnel, executives, events, travel, and operations. The role requires at least five years of relevant intelligence or threat-assessment experience, strong analytical communication, and familiarity with OSINT, behavioral threat methodologies, and technology-enabled investigations.
The Security Engineer will secure AWS and Google Cloud environments, monitor infrastructure, and assess AI/LLM deployments, MCP integrations, and agentic workflows. The role requires 5+ years of security engineering experience, including 2+ years in AI/ML security, plus cloud security and compliance expertise.
The Security Engineer will lead application security across the SDLC, integrating DevSecOps controls, conducting threat modeling and secure code reviews, and managing application vulnerabilities. The role requires 3+ years of application security experience plus hands-on expertise with AWS, Kubernetes, IaC, CI/CD, and mobile or web security.
Conducts end-to-end security risk assessments for vendors, customers, and partners while maintaining risk tiering, remediation, reassessments, and reporting. The role also matures third-party risk processes and uses AI-assisted workflows to scale assessment operations.