CoStar Group

Associate GRC Analyst

CoStar Group$75K — $101K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor’s Degree from an accredited institution
  • 1–3 years of experience in IT, audit, compliance, or information security
  • Demonstrated curiosity about technology and cybersecurity
  • Excellent written communication with attention to detail
  • Familiarity with core security concepts such as the CIA triad and attack types
  • Strong organizational and time-management skills
  • Collaborative style and willingness to engage with diverse stakeholders

Responsibilities

  • Perform routine governance operations including user access reviews and audit support
  • Support third-party risk assessments by reviewing security questionnaires and SOC reports
  • Draft clear summaries of assessments and recommendations for various audiences
  • Maintain GRC tooling and vendor inventories to ensure audit readiness
  • Contribute to security awareness materials that enhance company culture
  • Adopt a continuous learning mindset to grow in Cybersecurity

Benefits

  • Comprehensive healthcare coverage including medical, vision, dental, and prescription drugs
  • Life insurance and legal assistance
  • Virtual and in-person mental health counseling services
  • Commuter and parking benefits
  • 401(K) retirement plan with matching contributions
  • Tuition reimbursement for professional and academic growth
  • Access to on-site fitness center or reimbursement for gym memberships
  • Employee Resource Groups for community and networking
  • Complimentary healthy snacks and beverages
Full Job Description
Associate GRC Analyst


Job Description


Overview

We are seeking an Associate GRC Analyst to help evolve and grow CoStar’s cybersecurity and information technology governance program. As an Associate on the CoStar Group IT Governance, Risk, and Compliance Team, you will learn and assist in day-to-day governance operations, and progress toward developing ownership and establishing expertise in areas of GRC engagement. You will work alongside and under the guidance of experienced team members, supporting functions such as our third-party risk and compliance programs, security awareness and marketing initiatives, audit and assurance support, and controls governance. In the course of your work, you will collaborate with stakeholders across Cybersecurity, Information Technology Operations, Product & Development, Human Resources, Finance, and Sales. 

This position is located in Richmond, VA and is in office Monday through Thursday and work from home on Friday.

Responsibilities

  • Perform routine governance operations such as periodic user access reviews, triage of anomalous control alerts, and audit support.
  • Support third-party risk assessments for new and existing vendors — distributing and reviewing security questionnaires and performing initial reviews of SOC reports or equivalent control attestations.
  • Draft clear, well-organized written summaries of assessments, risk findings and recommendations for both technical and non-technical audiences.
  • Help maintain our GRC tooling and records — keeping vendor inventories, assessment trackers, and supporting documentation current, organized, and audit-ready.
  • Contribute to security-awareness efforts across the company, generating bespoke and culture-relevant information security awareness materials and communications that help build and reinforce a healthy security culture.
  • Arrive ready to learn, grow, and develop your career within Cybersecurity, adopting a continuous learning mindset.  

Basic Qualifications

  • Bachelor’s Degree required from an accredited, not for profit, in person, university or college.  
  • A track record of commitment to prior employers 
  • 1–3 years of experience in an adjacent field such as IT, audit, compliance, information security, or a related analytical or operational role.
  • A genuine and demonstrated curiosity about technology and cybersecurity, paired with the self-motivation to take on unfamiliar challenges and see them through.
  • Excellent written communication with meticulous attention to detail — you take pride in accurate, well-organized, polished work.
  • Familiarity with core security concepts — for example, least privilege, defense in depth, the CIA triad (confidentiality, integrity, and availability), authentication versus authorization, encryption in transit and at rest, and common attack types such as phishing and social engineering.
  • Strong organizational and time-management skills, with the ability to track many moving pieces without dropping detail.
  • A collaborative, approachable style and a willingness to engage with people across the business.

Preferred Qualifications and Skills

  • Excellent verbal communication and presentation skills, with a proven track record of communicating clearly to diverse audiences, including both non-technical and highly technical stakeholders.
  • Entry-level certifications, or demonstrable progress toward them, such as CompTIA Security+ or ISC2 Certified in Cybersecurity (CC).
  • Experience in a service-oriented technology role, such as an IT help desk or technical customer support function.
  • Exposure to ticketing and workflow tools.
  • Experience in developing automation – whether it is through standard scripting languages such as Python, PowerShell, or through applications such as Power Automate.
  • Experience reading or summarizing SOC reports, security questionnaires (SIG, CSA CAIQ), or other vendor documentation.
  • Hands-on experience applying AI to accomplish real work — for example, building or orchestrating agentic workflows, automating multi-step tasks, or integrating AI tools into business processes — rather than using AI as a substitute for a search engine.

What’s in it for You

When you join CoStar Group, you’ll experience a collaborative and innovative culture working alongside the best and brightest to empower our people and customers to succeed.

We offer you generous compensation and performance-based incentives. CoStar Group also invests in your professional and academic growth with internal training, and tuition reimbursement.

Our benefits package includes (but is not limited to):

  • Comprehensive healthcare coverage: Medical / Vision / Dental / Prescription Drug
  • Life, legal, and supplementary insurance
  • Virtual and in person mental health counseling services for individuals and family
  • Commuter and parking benefits
  • 401(K) retirement plan with matching contributions
  • Employee stock purchase plan
  • Paid time off
  • Tuition reimbursement
  • On-site fitness center and/or reimbursed fitness center membership costs (location dependent)
  • Access to CoStar Group’s Employee Resource Groups
  • Complimentary gourmet coffee, tea, hot chocolate, fresh fruit, and other healthy snacks

The final salary or hourly rate offered for this role will fall within the range set forth below based on avariety of factors, including but not limited to, geographic location, skills, and competencies.


Base Compensation: $75,000 6 $101,000 Annually

We welcome all qualified candidates who are currently eligible to work full-time in the United States to apply. However, please note that CoStar Group is not able to provide visa sponsorship for this position.

#LI-AR


About CoStar Group

CoStar Group is a provider of information, analytics and marketing services to the commercial property industry in the United States, Canada, the United Kingdom, France, Germany, and Spain. Founded in 1987 by Andrew C. Florance, the company has grown to include online database CoStar and many online marketplaces, including Apartments.com, LoopNet, Lands of America, and BizBuySell. CoStar Group was founded in 1987 by Andrew C. Florance in Washington, D.C. In 1998, the company became a public company via an initial public offering on the NASDAQ, raising $22.5 million. In 2004, CoStar Group, Inc. v. LoopNet, Inc. became a landmark case in copyright law. In October 2009, the company acquired a building in Washington, D.C., now its headquarters, from the Mortgage Bankers Association for $41.3 million. The building had sold 2 years earlier for $79 million and the company claims it used its analytics data to know the right time to buy. In April 2012, CoStar Group acquired LoopNet for $860 million. In April 2014, the company acquired Apartments.com for $585 million. In April 2015, the company acquired Apartment Finder for $170 million. In July, the company acquired Belbex an online marketplace and information provider for commercial property based in Spain. In February 2017, the company acquired Westside Rentals. In February 2018, the company acquired ForRent.com from Dominion Enterprises for $350 million in cash and $35 million in stock. In October, the company acquired Realla.co an online marketplace for commercial property based in the United Kingdom. In November, the company acquired Cozy Services for $68 million.
Learn more about CoStar Group
Size
4,742 employees
Market Cap
$31.3 billion
Industry
Net Income
$227.1 million
Founded
1987
5 Year Trend
+18.3%
Revenue
$1.6 billion
NASDAQ

Similar Jobs

More Jobs at CoStar Group

More Information Technology Jobs

Find similar Associate GRC Analyst jobs: