Coordinate third-party and vendor security assessments, questionnaires, supporting documentation, and evidence
Review contractual, regulatory, customer, and audit requirements to identify required controls and documentation
Support SOC 2, SOX, and other internal or external audit activities
Coordinate evidence collection, control walkthroughs, issue tracking, and remediation follow-up
Develop repeatable audit procedures, workpapers, processes, and supporting documentation
Prepare risk and compliance metrics and updates for leadership and other stakeholders
Work cross-functionally to identify control gaps, document findings, assign remediation ownership, and drive items through completion
Support identity and access control reviews when necessary, while maintaining a broader focus on governance, compliance, policies, procedures, and risk management
BACKGROUND PROFILE
3+ years of experience within Governance, Risk & Compliance, IT Audit, Risk Management, Information Security Compliance, or a related discipline
Working knowledge of a recognized security or control framework such as NIST Cybersecurity Framework or CIS Controls
Experience supporting internal or external audits and collecting and organizing supporting evidence
Strong understanding of risk assessments, control design, control testing, remediation tracking, and policy documentation
Experience with third-party or vendor risk management is highly valuable
Exposure to SOC 2, SOX, or similar compliance environments preferred
Ability to interpret technical security information and communicate findings to both technical and business stakeholders
Experience with GRC, ticketing, workflow, or audit-management technologies such as ServiceNow GRC, Archer, Jira, or similar platforms
Familiarity with Active Directory and Microsoft Entra ID is beneficial, particularly around access reviews and audit evidence
Strong documentation, organization, analytical, and follow-through skills
Experience in a regulated or critical-infrastructure environment is beneficial but not required
Certifications such as CISA, CRISC, Security+, or ISO 27001 are valuable but not required