
Search by job, company or skills
About the Role
We are seeking a detai loriented and analytically driven GRC Analyst to support the organization's information security governance, risk management, and compliance program. This role is critical to ensuring alignment with regulatory requirements, industry standards, and internal policies, while enabling effective risk based decision making and continuous control assurance across the enterprise.
Key Responsibilities
Conduct information security risk assessments, including risk identification, analysis, evaluation, and treatment tracking.
Maintain risk registers and support risk reporting to management and key stakeholders.
Partner with system owners to identify control gaps and recommend risk mitigation actions.
Perform control assurance activities, including tests of control design and operating effectiveness.
Support internal and external audits by preparing evidence and responding to audit requests.
Track control deficiencies, remediation plans, and corrective actions through closure.
Support continuous monitoring of security and IT controls to assess ongoing effectiveness.
Monitor control performance, exceptions, and remediation status, and report on control health.
Qualifications
Bachelor's degree in Information Security, Risk Management, Information Systems, or a related field.
5+ years of experience in governance, risk, and compliance, information security, or IT risk management.
Strong working knowledge of ISO/IEC 27001, NIST CSF, and risk management methodologies.
Experience performing control design and operating effectiveness testing.
Familiarity with continuous monitoring concepts, compliance tooling, and GRC platforms.
Strong analytical, documentation, and communication skills.
Job ID: 144629605