Job Description
Company - Our client is a cybersecurity services and consulting organization focused on helping enterprises strengthen their security programs through technology, advisory, risk and compliance, and specialized security services. The organization takes a highly consultative, client-centric approach to solving complex cybersecurity challenges.
\n
\n
Job Title - GRC Analyst
\n
Location - Hybrid in Downtown Boston, MA — 3–4 days onsite and 1–2 days remote per week
\n
Role Type - 6-month contract
\n
\n
Must Have Skills:
\n
- \n
- 3–6 years of relevant GRC/security-risk experience across information security, technology risk, IT audit, operational risk, or a related discipline
- Hands-on client and operational due-diligence experience responding to RFPs, RFIs, DDQs, ODD requests, client security questionnaires, or similar security/technology-risk inquiries
- Control and audit assurance experience supporting SOC 1/SOC 2, SOX, internal/external audits, evidence collection, control-owner coordination, issue management, and remediation
- Strong GRC fundamentals, including risk assessments, control design/testing, policy governance, remediation tracking, third-party risk, and frameworks such as NIST CSF, ISO 27001, COBIT, or CIS Controls
- Independent, highly organized communicator capable of managing multiple concurrent questionnaires, audits, assessments, and remediation activities across technical and business stakeholders.
\n
\n
\n
\n
\n
\n
\n
Responsibilities and Job Details:
\n
- \n
- Manage and respond to client and operational due-diligence requests, translating security and technology controls into clear responses for clients, auditors, and external stakeholders
- Support SOC 1/SOC 2, SOX, internal, and external audit activities, including evidence collection and coordination with control owners
- Conduct and coordinate technology, cybersecurity, information-security, and operational risk assessments
- Maintain risk registers, control inventories, audit findings, policies, standards, exceptions, remediation plans, and supporting evidence
- Partner with Information Security, Technology, Legal and Compliance, Internal Audit, Operations, and client-facing teams
- Perform third-party risk activities, including vendor security assessments, SOC report reviews, risk documentation, and ongoing monitoring
- Support governance and oversight of DLP and information-protection controls
- Track identified issues and remediation activities through completion and coordinate with appropriate stakeholders
- Develop management reporting related to risk, audits, controls, findings, and remediation
- Identify opportunities to automate and streamline GRC, audit, evidence-collection, and due-diligence processes
- Financial services, asset management, institutional investment management, or other regulated-industry experience is strongly preferred
- Relevant certifications such as CISA, CRISC, CISM, CISSP, CIA, Security+, or ISO 27001 are preferred
\n
\n
\n
\n
\n
\n
\n
\n
\n
\n
\n
\n
\n
