Information Security
GRC Analyst
Remotefull timeonsite
About the Role
Looking for a meticulous and proactive Governance, Risk, and Compliance (GRC) Analyst to support the company’s information security, risk management, and compliance programs.
Key Responsibilities
- Support the development, implementation, and maintenance of the information security governance framework.
- Ensure all departments understand and adhere to security policies and control requirements.
- Maintain a central repository of policies, standards, and supporting documentation.
- Conduct risk assessments to identify and evaluate operational, technical, and compliance risks.
- Collaborate with technical and business teams to define risk mitigation plans and monitor implementation.
- Perform third-party/vendor risk assessments and follow up on remediation activities.
- Assist in maintaining compliance with standards such as ISO 27001, NIST
- Coordinate internal and external audits, including evidence collection and control verification.
- Track remediation efforts from audit findings and compliance gaps.
- Support management reporting by providing compliance status updates and metrics.
- Prepare regular reports on governance, risk, and compliance activities for management and stakeholders.
- Assist in conducting security awareness and training initiatives across departments.
- Contribute to developing a compliance dashboard or other visualization tools to track GRC performance.
Requirements
- Bachelor’s degree in Information Security, Risk Management, Business Administration, or a related field.
- 2–4 years of experience in governance, risk, or compliance functions.
- Strong understanding of information security frameworks and regulatory standards (ISO 27001, NIST)
- Experience with risk assessment methodologies and compliance management processes.
- Excellent attention to detail, documentation, and analytical skills.
- Ability to communicate effectively across technical and non-technical teams.
