A growing security program is seeking a Senior GRC Analyst to strengthen and mature its governance, risk, and compliance functions. This role owns core GRC processes—including risk management, control testing, policy development, and audit support—while aligning initiatives to frameworks such as SOC 2, HIPAA, and NIST. The position offers a clear path toward future GRC leadership as the program expands.
Key Responsibilities
- Develop, maintain, and enhance security policies, standards, and procedures aligned with regulatory and industry frameworks.
- Work with technical and business stakeholders to ensure policies are actionable and consistently implemented.
- Prepare documentation, evidence, and responses for external audits and regulatory assessments.
- Maintain the enterprise risk register and coordinate periodic reviews with control owners.
- Map controls to regulatory and operational requirements; conduct control testing to evaluate effectiveness.
- Monitor accepted risks, mitigation plans, and related trends.
- Coordinate evidence collection and maintain continuous audit readiness.
- Support internal and third-party risk assessments.
- Assist with business continuity planning, disaster recovery documentation, and tabletop exercises.
- Build and refine repeatable workflows for compliance, policy management, and risk processes.
- Define and track KPIs related to audit readiness, control health, and GRC maturity.
- Identify opportunities for automation and process optimization.
- Document procedures to support future team scaling and onboarding.
- Demonstrate ownership and high-quality execution across all GRC activities.
- Position oneself for advancement into a formal GRC leadership role.
Qualifications
- Bachelor’s degree in Cybersecurity, Information Systems, Business Administration, or equivalent experience.
- 5–7 years of experience in security, audit, compliance, or risk management, including audit support.
- Familiarity with SOC 2, HIPAA, and NIST frameworks (preferred).
- Strong organizational, communication, and stakeholder-management skills.
- Ability to prioritize and self-direct in a fast-paced environment.
- Strong process orientation with excellent documentation habits.
- Ability to balance strategic thinking with hands-on execution.
- Interest in supporting team growth and moving into future leadership.
Compensation: $110,000-125,000
Salary is based on a range of factors that include relevant experience, knowledge, skills, other job-related qualifications.