Hitachi America

GRC Consultant-68498

Hitachi America$110K — $130K *
US-AnywhereRemote in Texas, US
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5-7 years of experience in GRC, Information Security, IT Risk, or related fields
  • Hands-on experience with security and technology risk assessments
  • Strong knowledge of security frameworks like ISO 27001, SOC 2, NIST
  • Experience with control mapping, testing, evidence collection, and remediation
  • Familiarity with third-party/vendor risk management and cloud environments
  • Bachelor's degree in a related field or equivalent experience

Responsibilities

  • Maintain and update information security policies and standards
  • Track policy exceptions and aid in remediation processes
  • Translate regulatory requirements into operational controls
  • Define, track, and report security metrics to support decision-making
  • Conduct security risk assessments across various business areas
  • Maintain the enterprise risk register and monitor remediation plans
  • Coordinate internal and external audits from start to finish

Benefits

  • Opportunity to work with a collaborative and interdisciplinary team
  • Exposure to various security and compliance frameworks
  • Engagement in advanced technologies like cloud security and AI governance
  • Support for continuous learning and certification
  • Onsite work location to promote teamwork and communication
Full Job Description
Function

Cloud & Data Engineering

Job description

Title: Senior GRC Analyst

Location: Dallas, TX (Onsite)

Experience: 5-7 years

Meet Our Team

Join our Information Security Governance, Risk, and Compliance (GRC) team, where we partner with Security Engineering, IT, Legal, Privacy, Internal Audit, and business teams to strengthen the organization's security and compliance posture.

Our team is responsible for establishing effective security governance, identifying and managing technology risks, maintaining alignment with industry and regulatory frameworks, and supporting internal and external audits.

In this role, you will help embed security and risk management into day-to-day business operations while improving control monitoring, evidence collection, GRC processes, and compliance automation.

What You'll Be Doing
  • Governance: Maintain and update information security policies, standards, procedures, and security-control documentation.
  • Track policy exceptions and support remediation and governance processes.
  • Translate regulatory, security, and compliance requirements into operational controls.
  • Define, track, and report security metrics and KPIs to support leadership visibility and decision-making.
  • Risk Management
  • Conduct security risk assessments across applications, systems, infrastructure, business processes, and vendors.
  • Maintain the enterprise risk register and track identified risks, remediation plans, owners, due dates, and residual risk.
  • Perform third-party/vendor security risk assessments and due diligence.
  • Support business impact analysis and risk-treatment decisions.
  • Partner with stakeholders to identify control gaps and drive remediation activities.
  • Compliance & Audit
  • Map and assess controls against security and compliance frameworks including:
  • ISO 27001
  • SOC 2
  • NIST CSF / NIST 800-53
  • PCI-DSS
  • GDPR, HIPAA, and other applicable privacy/regulatory requirements
  • Coordinate internal and external audits from evidence gathering through findings closure.
  • Manage audit evidence requests, control testing, findings, and remediation tracking.
  • Support continuous control monitoring and evidence-collection initiatives.
  • Support security certification and attestation programs.
  • Collaboration & GRC Operations
  • Partner with Security Engineering, Cloud, Infrastructure, IAM, IT, Legal, and business teams to validate control implementation.
  • Support security awareness, policy adoption, and governance initiatives.
  • Help mature GRC processes and platforms.
  • Identify opportunities to automate manual compliance, control monitoring, and evidence-collection activities.
  • Support emerging governance areas including cloud security and AI governance.


What You'll Bring to the Team:

  • 5-7 years of experience in GRC, Information Security, IT Risk, IT Audit, Cybersecurity Compliance, or related areas.
  • Hands-on experience conducting security and technology risk assessments.
  • Strong experience supporting internal and/or external audits end to end.
  • Working knowledge of at least two major security frameworks, such as ISO 27001, SOC 2, NIST CSF/800-53, or PCI-DSS.
  • Experience with control mapping, control testing, evidence collection, and remediation tracking.
  • Experience maintaining risk registers and managing risk-remediation activities.
  • Familiarity with third-party/vendor risk management.
  • Understanding of security controls across cloud environments such as AWS, Azure, or GCP, as well as identity and infrastructure.
  • Strong documentation, communication, analytical, and stakeholder-management skills.
  • Bachelor's degree in a related field or equivalent professional experience.
  • Preferred Qualifications
  • CISA, CRISC, CISSP, ISO 27001 Lead Implementer/Auditor, or CompTIA Security+ certification.
  • Hands-on experience with GRC platforms such as ServiceNow GRC/IRM, Archer, OneTrust, Vanta, or Drata.
  • Experience with cloud compliance and continuous-control-monitoring tools.
  • Exposure to compliance automation.
  • Awareness of AI governance, AI risk management, or emerging technology governance.


Key Skills:

Risk Assessment • GRC • Information Security • IT Risk • Control Mapping • Control Testing • Audit Management • ISO 27001 • SOC 2 • NIST • PCI-DSS • Risk Register • Policy Development • Vendor Risk Management • Cloud Security • Compliance Monitoring • Remediation Tracking • GRC Tools

#LI-RS2

About Hitachi America

Hitachi America is a subsidiary of Hitachi, Ltd., a Japanese multinational conglomerate. They provide a wide range of products and services, including information technology, power systems, and social infrastructure. They work with clients in a variety of industries, including healthcare, transportation, and finance. They are committed to sustainability and social responsibility, and have implemented various initiatives to reduce their environmental impact.
Learn more about Hitachi America
Size
368,247 employees
Industry
Founded
1959
NASDAQ

Similar Jobs

More Jobs at Hitachi America

More Information Technology Jobs

Find similar GRC Consultant-68498 jobs: