Search

GRC Analyst

PublishedPublished: 6/14/2022
Technology

Job Description

Company - Our client is a cybersecurity services and consulting organization focused on helping enterprises strengthen their security programs through technology, advisory, risk and compliance, and specialized security services. The organization takes a highly consultative, client-centric approach to solving complex cybersecurity challenges.

\n


\n

Job Title - GRC Analyst

\n

Location - Hybrid in Downtown Boston, MA — 3–4 days onsite and 1–2 days remote per week

\n

Role Type - 6-month contract

\n


\n

Must Have Skills:

\n

    \n
  • 3–6 years of relevant GRC/security-risk experience across information security, technology risk, IT audit, operational risk, or a related discipline
  • \n

  • Hands-on client and operational due-diligence experience responding to RFPs, RFIs, DDQs, ODD requests, client security questionnaires, or similar security/technology-risk inquiries
  • \n

  • Control and audit assurance experience supporting SOC 1/SOC 2, SOX, internal/external audits, evidence collection, control-owner coordination, issue management, and remediation
  • \n

  • Strong GRC fundamentals, including risk assessments, control design/testing, policy governance, remediation tracking, third-party risk, and frameworks such as NIST CSF, ISO 27001, COBIT, or CIS Controls
  • \n

  • Independent, highly organized communicator capable of managing multiple concurrent questionnaires, audits, assessments, and remediation activities across technical and business stakeholders.
  • \n

\n


\n

Responsibilities and Job Details:

\n

    \n
  • Manage and respond to client and operational due-diligence requests, translating security and technology controls into clear responses for clients, auditors, and external stakeholders
  • \n

  • Support SOC 1/SOC 2, SOX, internal, and external audit activities, including evidence collection and coordination with control owners
  • \n

  • Conduct and coordinate technology, cybersecurity, information-security, and operational risk assessments
  • \n

  • Maintain risk registers, control inventories, audit findings, policies, standards, exceptions, remediation plans, and supporting evidence
  • \n

  • Partner with Information Security, Technology, Legal and Compliance, Internal Audit, Operations, and client-facing teams
  • \n

  • Perform third-party risk activities, including vendor security assessments, SOC report reviews, risk documentation, and ongoing monitoring
  • \n

  • Support governance and oversight of DLP and information-protection controls
  • \n

  • Track identified issues and remediation activities through completion and coordinate with appropriate stakeholders
  • \n

  • Develop management reporting related to risk, audits, controls, findings, and remediation
  • \n

  • Identify opportunities to automate and streamline GRC, audit, evidence-collection, and due-diligence processes
  • \n

  • Financial services, asset management, institutional investment management, or other regulated-industry experience is strongly preferred
  • \n

  • Relevant certifications such as CISA, CRISC, CISM, CISSP, CIA, Security+, or ISO 27001 are preferred
  • \n

\n


Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...