Creative Information Technology

GRC Analyst - Rockville, MD

Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cybersecurity, Information Systems, Information Technology, Computer Science, or Business Information Systems.
  • 1 year of experience in InfoSec, IT Governance, Compliance, Risk Management or related fields.
  • Experience using ServiceNow for risk management and policy exception processes.
  • Familiarity with Office 365 suite of products.
  • Basic understanding of Cybersecurity principles, Risk Management, and HIPAA.

Responsibilities

  • Review and verify policy exception requests for completeness.
  • Analyze business impacts and evaluate risk associated with policy exceptions.
  • Maintain and update the County Information Security Risk Register.
  • Coordinate policy exception renewals and closures while tracking their statuses.
  • Interact regularly with IT staff and leadership to ensure effective communication regarding risks.

Benefits

  • Access to professional development resources and certifications.
  • Collaborative work environment with County departments.
  • Use of industry-standard tools like ServiceNow.
Full Job Description
GRC Analyst - Rockville, MD

Roles & Responsibilities:

A. Policy Exception Administration - The contractor shall
  • Review submitted policy exception requests for completeness.
  • Verify required documentation has been submitted.
  • Validate business justifications against County requirements.
  • Request additional information from departments when necessary.
  • Maintain exception records within ServiceNow.
  • Track requests through each stage of the approval process.
  • Monitor exception expiration dates.
  • Coordinate renewals and closures.
  • Produce status reports.


B. Risk Analysis - Using County-approved methodologies, templates and procedures, the Contractor shall:
  • Review policy exception requests.
  • Evaluate business impact.
  • Evaluate likelihood and risk.
  • Identify applicable compensating controls.
  • Prepare written risk analyses.
  • Prepare approval or denial recommendations for CISO review.
  • Document analysis within ServiceNow.


C. Enterprise Risk Register - Maintain the County Information Security Risk Register by:
  • Creating new risk records.
  • Updating existing risk records.
  • Recording risks identified by: o Third-party penetration tests
  • Third-party security assessments
  • Internal risk assessments
  • Vulnerability scanning
  • Policy Exceptions
  • Security incidents
  • Other approved sources


  • Track mitigation activities.
  • Monitor due dates.
  • Update risk status.
  • Maintain supporting documentation.
  • Generate reports.


D. ServiceNow - Utilize ServiceNow IRM to:
  • Process Policy Exceptions
  • Maintain Risk Register records
  • Track approvals
  • Maintain documentation
  • Generate reports
  • Produce dashboards


E. Customer Service - The successful candidate will regularly communicate with:
  • Department IT Staff
  • Department Management
  • Information System Owners
  • County Leadership
  • Office of Enterprise Information Security

Education & Certification:

Bachelor's degree in:
  • Cybersecurity
  • Information Systems
  • Information Technology
  • Computer Science
  • Business Information Systems

Certifications (not required/points awarded)
  • CompTIA Security+ (Sec+)
  • Certified Information Security Manager - Fundamentals (CISM-F)
  • NIST Cybersecurity Framework (NCSF) Practitioner
  • ISACA IT Risk Fundamentals Certificate
  • ISACA Cybersecurity Audit Certificate
  • HIPAA Security Training or Compliance Certificates

Preferred experience
  • One (1) year of professional Information Security, IT Governance, Compliance, Risk Management, Information Technology, Audit, or related experience.
  • Recent graduate with relevant internship or equivalent experience.


  • Experience using ServiceNow.
  • Experience using Office 365 suite of products
  • Experience with Governance, Risk and Compliance (GRC).
  • Experience preparing technical documentation.
  • Experience working in customer service environments.
  • Experience with coordinating projects, tasks and/or workflows.


C. Knowledge

Basic understanding of:
  • Cybersecurity principles
  • Information Security
  • Risk Management
  • NIST Cybersecurity Framework
  • Risk Scoring Systems/Risk Quantitative Frameworks
  • HIPAA

About Creative Information Technology

Creative Information Technology is a software development company that specializes in custom software development, web development, and mobile app development. The company was founded in 1998 and is headquartered in Wilmington, Delaware. Creative Information Technology's clients include small and medium-sized businesses across a range of industries.
Learn more about Creative Information Technology
Size
100 employees
Industry
Founded
1998

Similar Jobs

More Jobs at Creative Information Technology

More Information Technology Jobs

Find similar GRC Analyst - Rockville, MD jobs: