Cybersecurity GRC Analyst
Quidax
Cybersecurity Governance, Risk & Compliance (GRC) Analyst
We're looking for a Cybersecurity Governance, Risk & Compliance (GRC) analyst who will be responsible for maintaining policies, assessing risks, supporting audits, regulatory requirements, third-party reviews, and security awareness. You'll help us carry out audits that help us understand where our risks are, verify that the right controls are operating effectively, and ensure we remain continuously audit-ready — not just when an auditor comes knocking.
You'd also serve as our Data Protection Officer (DPO) leading our privacy programme, ensuring Data Privacy best practices are enforced in the organization, and ensuring compliance with data protection regulations across jurisdictions.
If you're the kind of person who is meticulous, curious, enjoys carrying out audits, documenting policies, processes and bringing them to life, and passionate about cybersecurity governance, risk, compliance and data privacy — you'll fit right in.
What You'll Be Owning
Cybersecurity Governance
Within 60 days: Review all existing information security policies, standards, procedures, and SOPs. Identify gaps, outdated content, and areas for improvement while ensuring alignment with the organization's current technology stack and business operations.
Within 90 days: Update, implement, and communicate approved improvements to security policies, standards, and procedures. Establish a reporting cycle to leadership on Cybersecurity Governance, Risk & Compliance.
Cybersecurity Certifications & External Audits
Within 30 days: Become familiar with Quidax's compliance landscape, including ISO 27001, PCI DSS, NDPA, and other applicable regulatory & certification requirements.
Within 60 days: Coordinate audit readiness activities by ensuring evidence is collated in advance rather than during audit periods, reducing last-minute audit preparation.
Within 90 days: Support internal and external auditors, coordinate stakeholder responses, track audit findings, and ensure remediation activities are completed within agreed timelines.
Security Awareness
Within 30 days: Review the organization's existing security training program and security training policies and identify opportunities to improve employee engagement and effectiveness. Take responsibility of the organization's security awareness program and drive approved improvements.
Within 60 days: Promote a security-first culture by ensuring employees understand their role in protecting customer data and company assets.
Within 180 days: Drive the annual org-wide security culture awareness programme that includes role-based training, data protection and policy awareness.
Third Party Security Review & Evaluation
Within 30 days: Review previous 3rd party security evaluations. Review historical Due Diligence questionnaires completed for partners. Conduct a review of our template for conducting vendor Due Diligence.
Within 60 days: Respond to cybersecurity due diligence questionnaires from partners and regulators. Carry out security reviews on 3rd party applications on-request and create a cadence for scheduled review of the current list of 3rd party apps to verify their eligibility for continued use.
Within 90 days: Ensure all 3rd party services in use must have completed security reviews, and maintain a central repository of 3rd party security evaluations.
Regulatory Engagement
Within 60 days: Build a deep understanding of Quidax regulatory landscape, regulatory obligations and expectations across all operating jurisdictions. Be able to provide responses to regulatory requests, assessments, and evidence collation by collaborating with relevant internal teams. Create a working process for monitoring regulatory developments, recommended changes to policies, controls, and processes to maintain ongoing compliance.
Data Protection
Within 60 days: Audit existing data protection processes, privacy controls, and data handling procedures to identify compliance gaps and opportunities for improvement. Take ownership of data protection processes, controls, data handling procedures, Data Privacy Impact Assessments (DPIAs), and new initiatives involving sensitive data.
Within 90 days: Implement approved improvements to existing data protection processes, privacy controls, and data handling procedures.
Biggest Challenges You'll Tackle
Building enterprise-grade governance in a startup environment. You'll be helping mature our governance, risk, and compliance program while supporting a business that continues to evolve rapidly.
Balancing speed with governance. You'll need to build security processes and controls that enable the business — not slow it down.
Influencing without authority. Success in this role depends on working across Engineering, Product, Legal, Compliance and Operations to drive audit readiness, risk remediation, and certification/regulatory initiatives.
Maintaining continuous compliance instead of audit readiness. Our goal isn't to prepare for audits once a year — it's to build processes that make us audit-ready every day.
Staying ahead of a constantly changing threat and regulatory landscape. Cybersecurity risks, cloud technologies, blockchain ecosystems, and regulatory requirements evolve continuously. You'll need to keep learning and ensure Quidax stays one step ahead.
What We're Looking For
Must-Haves
You have 3 - 6 years of experience in Cybersecurity Governance, Risk & Compliance (GRC), IT Audit, Risk Management, Data Protection or a similar cybersecurity discipline.
You understand security frameworks such as ISO 27001, NIST CSF, CIS, PCI DSS, SOC 2 and know how to apply them in the real world.
Experience implementing or maintaining certifications such as ISO 27001, PCI DSS, SOC 2, or similar compliance programs.
Experience in internal or external audits and understand what good audit evidence looks like.
Familiarity with privacy and data protection regulations such as NDPA, GDPR, UK GDPR, or other international privacy frameworks.
Experience conducting vendor or third-party security risk assessments.
You know how to perform risk assessments, identify control gaps, and help drive remediation efforts from start to finish.
You enjoy writing and maintaining clear, practical security policies, standards, procedures, and documentation that people can actually follow.
You can translate technical risks into language that business stakeholders understand, helping teams make informed decisions.
You're highly organized and can manage multiple audits, risk assessments, and compliance initiatives without losing attention to detail.
You can build strong working relationships across multiple internal teams to move security initiatives forward.
You are naturally curious, ask good questions, and enjoy understanding how systems, technologies, and business processes work.
You take ownership of your work and don't wait to be told what needs improving.
Nice-to-Haves
Understanding of blockchain technology, digital assets, or cryptocurrency security concepts.
Experience working in financial services, fintech, cryptocurrency, blockchain, or other highly regulated industries.
- ...The GRC Cybersecurity Analyst III is a senior level contributor responsible for leading ICCU’s Governance, Risk, and Compliance (GRC) initiatives within the scope of the IT domain. This role provides strategic oversight of cyber and IT operational risk assessments, regulatory...SuggestedFull timeWork experience placementWork at office
$99k - $225k
Enterprise Cybersecurity GRC Governance AnalystThe Opportunity: The Enterprise Cybersecurity (ECS) Governance, Risk, and Compliance (GRC) team is seeking an experienced Information System Security Officer (ISSO) to bridge the gap between high-level policy and technical...SuggestedFull timeContract workPart timeWork at officeLocal areaRemote work- ..., friends, and families in providing best-in-class products and services!Job SummaryThe Governance Risk & Compliance (GRC) Cybersecurity Senior Analyst plays a critical role in ensuring that UGI Utilities Inc. operates within its regulatory, legal, and compliance obligations...SuggestedFor contractors
- ...Cybersecurity GRC Analyst Cleveland Brothers, the largest Cat® dealer in Pennsylvania, northern West Virginia and western Maryland, has an immediate opportunity for a Cybersecurity GRC Analyst onsite at our Harrisburg or New Stanton Branch. The Cybersecurity GRC...SuggestedTemporary workImmediate start
- ...Cybersecurity GRC Analyst We are seeking an experienced Cybersecurity GRC Analyst for a 6-month engagement to support our ongoing security compliance and governance initiatives. The ideal candidate will have strong hands-on experience with ISO 27001, including audit...Suggested
$51 per hour
...Cybersecurity GRC Analyst (Remote) Location: 100% Remote Rate: $51/hour (No PTO) Overview We are seeking a Cybersecurity GRC Analyst to support enterprise-wide cybersecurity risk management, governance, and compliance initiatives. This role is responsible for...Temporary workWork at officeLocal areaRemote work$66.3k - $114.29k
...Cybersecurity GRC Analyst Western National is seeking a Cybersecurity GRC Analyst to join our team! The individual in this role will have the opportunity to strengthen the organization's information security program by supporting regulatory compliance, managing third...Full timeWork at officeLocal areaRemote workWork visaFlexible hours$80k - $100k
...Cybersecurity Compliance Analyst – Orlando, FL Salary: $80,000–$100,000 base + 25% bonus Location: Onsite in Orlando, FL 32810 This role does... ...You Bring: • 6+ years of experience in cybersecurity, GRC, IT compliance, cyber risk, audit, or related environments...Relocation packageShift work$15k - $120k
...Solutions helps build a diverse collection of print and digital resources to support every student. We are currently hiring for Cybersecurity GRC Analyst. This position is an exempt full-time position located in McHenry, IL or remote for the right person. The pay for this...Full timeWork experience placementCurrently hiringWork at officeRemote workWorldwide- A leading utility provider in Pennsylvania seeks a GRC Cybersecurity Senior Analyst to ensure compliance with regulatory obligations. This role involves collaboration with various departments to implement governance and risk management processes. The ideal candidate has...
$115k - $120k
Follett Content Solutions is hiring a Cybersecurity GRC Analyst in McHenry, IL or remote for the right person. This full-time hybrid role offers $115,000-$120,000 annually with 3 days in the office and 2 remote days. The analyst will strengthen governance, risk, and compliance...Remote jobFull timeWork at office- Blue Chip Talent, a Bloomfield Hills, MI-based firm, seeks a Junior/Mid Level IT Governance & Cybersecurity Analyst to strengthen governance, ensure regulatory compliance, and support audit readiness across enterprise IT security and risk management programs. You will review...
- Follett Content Solutions is hiring a Cybersecurity GRC Analyst to strengthen governance, risk, and compliance by formalizing IT policies, operationalizing Microsoft Purview, and ensuring audit readiness. This exempt, full-time role is based in McHenry, IL or remote for...Remote jobFull timeWork at office
$50 - $55 per hour
Georgia Tech Research Institute (GTRI) is seeking a (GRC) Cybersecurity Analyst for a W2 full-time role in Atlanta, GA. The position offers hybrid work and compensation of $50.00 - $55.00 per hour with strong emphasis on governance, risk and compliance in security operations...Hourly payFull time$50 - $55 per hour
Position: (GRC) Cybersecurity Analyst Client: Georgia Tech Research Institute (GTRI) Employment Type: W2 Only Location: Atlanta, GA (Hybrid) Ideal Candidate Profile Experience 5-7+ years in IT/Cybersecurity Technical background (Engineering > GRC preferred) Experience...Hourly pay$70k - $80k
As a GRC Cybersecurity Analyst (CA), you will play a pivotal role securing our clients’ infrastructure, data and software. Beyond helping our clients, you will also make a huge impact and help society as a whole by contributing to our fast moving, passionate efforts to...Full timeWork at office- A leading federal services provider is seeking a Cybersecurity Analyst in Alexandria, VA. This role includes managing governance, risk, and compliance activities to ensure compliance with DoD requirements. The ideal candidate will have at least 10 years of relevant experience...
- Vanguard is seeking a Governance, Risk & Compliance Analyst, Specialist to lead enterprise‑wide information security policies and standards... ...within defined risk controls. You will assess the end‑to‑end GRC framework, monitor policy lifecycles, and use data‑driven methods...
- Follett Content Solutions is seeking a Cybersecurity GRC Analyst in McHenry, IL or remote for the right candidate. The role requires 7-10 years in IT or governance, risk and compliance, with a focus on SOC 2, NIST CSF, and PCI DSS alignment. The position offers a hybrid...Work at officeRemote work
- Follett Content Solutions seeks a Cybersecurity GRC Analyst to strengthen governance, risk, and compliance posture. You will formalize IT policies, operationalize Purview, and support audit readiness in a hybrid role based in McHenry, IL or remote for the right candidate...Remote job
- ...MANTECH seeks an experienced and passionate, career and customer-oriented Cybersecurity Network Analyst to join our team in Fort Meade, MD . Responsibilities include but are not limited to: Maintains the integrity, security and availability of the Insider Threat...Temporary workWork at office
$104k - $166k
ResponsibilitiesPeraton is seeking a Cybersecurity Vulnerability Analyst in our Linthicum, MD office in support of our Department of Defense (DoD) customer as part of a highly talented, highly motivated, and high-performing team. This position offers a unique opportunity...Contract workWork at officeShift work- ...MANTECH seeks a motivated, career and customer-oriented Cybersecurity Analyst - Nights to join our team in Tysons, VA The Cybersecurity Analyst will monitor Air Gapped Security Fabrics through managed SECOPs Tools. Responsibilities include but are...Work at officeLocal areaShift workNight shift
- ...insurance, reinsurance, payroll, benefits, cybersecurity, mortgage services — and more. In the... ...Cybersecurity Vulnerability Governance Analyst is responsible for governing and overseeing... ...management programs. Experience with GRC platforms such as Archer, ServiceNow, MetricStream...Full timeImmediate startFlexible hours
$130k - $160k
...Business System which makes everything possible.The Senior Cybersecurity Risk Analyst is responsible for executing third-party and supplier risk... ...risk including country-of-origin scrutiny.Familiarity with GRC platforms (e.g., OneTrust, ServiceNow IRM, RSA Archer) and...Full timeRemote workWork from homeFlexible hours- ...customers get the high-quality gear they need to make the most of their adventures. We are BUILT FOR THE WILD.About the RoleThe SAP GRC Analyst will be responsible for GRC administration and segregation of duties (SoD) analysis. You will be responsible for evaluating risks...Full timeLocal area
$119k - $140k
...it’s at the airport, stadium, or throughout your everyday life, CLEAR unlocks the magic of frictionless experiences.As a Cybersecurity Risk Analyst II, you'll help strengthen CLEAR's security posture by identifying, assessing, and reducing cyber risk across our products...Casual workWork at officeFlexible hours$130k - $170k
...extend healthspan. The Governance, Risk, and Compliance (GRC) team helps ensure technology and cybersecurity risks are identified, assessed, and communicated... ...-oriented Senior Governance, Risk, and Compliance Analyst to lead the day-to-day execution and support the ongoing...Full timeWork at officeRelocation- ...are looking for a Security Governance, Risk, and Compliance (GRC) Analyst to support and mature our security and compliance programs... ...promote awarenessWhat You Bring5 to 7 years of experience in GRC, cybersecurity, or complianceExperience with CMMC, NIST 800-171, or similar...Full timeFor contractors
$80.05k - $165k
About the Role:Responsible for leading Cybersecurity and IT governance, risk, and compliance efforts, including the establishment and maintenance... ..., assignment, remediation tracking, and closure of GRC-related issues in ServiceNow, ensuring timely resolution, appropriate...Full timeWork at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Cybersecurity GRC Analyst. Be the first to apply!
- cyber security consultant United States
- cyber security specialist United States
- cybersecurity analyst remote United States
- cyber-security operations specialist United States
- senior cybersecurity analyst United States
- grc analyst United States
- cybersecurity specialist United States
- cyber security intern United States
- cybersecurity grc United States
- cyber security United States




