Job Summary:
We are seeking a detail-oriented and motivated GRC Analyst to join our growing team. The ideal candidate will have 32+ years of experience in supporting governance, risk, and compliance initiatives. This includes assisting with client/prospect compliance questionnaires, user access reviews, SOC1 and SOC2 audits, Sarbanes-Oxley IT general controls audits, and internal risk reviews. You will help maintain awareness of relevant cybersecurity regulations and contribute to implementing audit, governance, risk, and compliance (GRC) frameworks.
As a GRC Analyst, you will collaborate across departments to ensure security solutions protect internal systems, vendor environments, and customer data while also aligning with compliance requirements.
Responsibilities:
- Support governance, risk, and compliance (GRC) activities by assisting with cybersecurity framework implementation and regulatory compliance efforts.
- Participate in internal and external audits by coordinating evidence collection, tracking remediation efforts, and supporting readiness for SOC 2, SOX ITGC, and HIPAA assessments.
- Performing user access reviews for assigned applications and systems.
- Assist in maintaining compliance with regulatory standards including SOX, HIPAA, SOC 2, GDPR, and PCI-DSS, while staying informed about evolving cybersecurity laws and obligations.
- Collaborate with cross-functional teams to support security initiatives and communicate effectively with both technical and non-technical stakeholders.
Requirements:
- Able to work independently and enjoy a high degree of interaction with team members
- Ability to contribute to a collaborative environment by consistently demonstrating teamwork, high motivation, positive behavior and effort to achieve goals and objectives
- Self-motivated and driven
- Maintain a sense of urgency and ability to work with and meet deadlines
- Demonstrate effective written and verbal communication, including the ability actively listen, and problem solve with minimal assistance
- Demonstrate excellent time management and prioritization skills
- Attention to detail and commitment to a high level of accuracy
- The ability to multitask, prioritize, work independently, and use discretion surrounding sensitive information
- Ability to maintain a professional demeanor and positive attitude
Education and Experience:
- 2+ years of relevant experience in GRC-focused security activities.
- Understanding of security standards and frameworks such as NIST, ISO 27001, CIS Controls, and industry compliance regulations (NYDFS, GDPR, HIPAA, PCI-DSS).
- Proven ability to manage complex timelines and deliverables, ensuring alignment with organizational goals and regulatory requirements.
- Bachelor’s degree (or equal experience) in an Information Systems Assurance or related.
- Preferred Certifications:
- CRISC (Certified in Risk and Information Systems Control)
- CISSP (Certified Information Systems Security Professional)
- CISA (Certified Information Systems Auditor)
- CEH (Certified Ethical Hacker)
#LI-CH1
Candidates should be comfortable with an on-site presence to support collaboration, team leadership, and cross-functional partnership.
Employee Benefits
We also offer our employees a comprehensive suite of benefits and perks, including:
Physical Wellness: Comprehensive medical insurance, dental insurance, and vision insurance; life and disability insurance; fertility benefits; wellness resources; and paid sick time.
Mental Wellness: Generous paid time off and holidays; Employee Assistance Program (EAP); and a complimentary Calm app subscription.
Financial Wellness: Immediate vesting in a 401(k) plan; Health Savings Account (HSA) and Flexible Spending Account (FSA) options; commuter benefits; and employee discount programs.
Family Care: Paid maternity leave and paid paternity leave (including for adoptive parents); legal plan options; and pet insurance coverage.
… and so much more!
This list is not exhaustive of all available benefits. Eligibility and waiting periods may apply to certain offerings. Benefits may vary based on subsidiary entity and geographic location.