Information Security Governance, Risk & Compliance (GRC) Analyst
ASSYST, Inc.
Job Description
Job Description
ASSYST is seeking an Information Security Governance, Risk & Compliance (GRC) Analyst to support our client in administering and maintaining an established enterprise Information Security Governance, Risk, and Compliance (GRC) program. This role will focus on managing Information Security Policy Exceptions and maintaining the Enterprise Information Security Risk Register using the ServiceNow Integrated Risk Management (IRM) platform.
The ideal candidate will work under the guidance of Information Security leadership to execute established governance processes, document and track information security risks, and support enterprise risk management activities. This position provides an excellent opportunity to gain hands-on experience with enterprise cybersecurity governance, information security risk management, ServiceNow IRM, and policy exception management while collaborating with experienced information security professionals.
Note: This position focuses on governance, documentation, and risk management activities. It does not involve performing security assessments, penetration testing, vulnerability assessments, audits, or compliance revie ws.
Roles & Responsibilities:
- Administer and support the Information Security Policy Exception Program.
- Maintain and update the Enterprise Information Security Risk Register using the ServiceNow Integrated Risk Management (IRM) platform.
- Execute established governance processes, standardized risk assessment methodologies, workflows, templates, and reporting procedures.
- Review policy exception requests and document findings.
- Perform information security risk analyses and provide approval or denial recommendations.
- Document, track, and maintain identified information security risks within the enterprise Risk Register.
- Prepare and maintain accurate policy exception tracking records.
- Produce monthly metrics, quarterly reports, executive dashboards, and ServiceNow documentation.
- Coordinate assigned tasks, workflows, and activities while ensuring timely completion.
- Prepare clear and accurate technical documentation related to governance and risk management processes.
- Collaborate with internal stakeholders to support enterprise information security governance initiatives.
- Maintain high standards of documentation accuracy, consistency, and data integrity.
- Provide excellent customer service while supporting governance and risk management activities.
- Work independently while effectively managing multiple priorities and deadlines.
Required Skills & Qualifications:
Minimum Qualifications:
- Professional experience in Information Security, IT Governance, Compliance, Risk Management, Information Technology, Audit, or a related field.
- Basic understanding of Information Security Governance, Risk Management, and Cybersecurity principles.
- Strong analytical and critical thinking skills.
- Excellent written and verbal communication skills.
- Strong organizational skills with exceptional attention to detail.
- Ability to manage multiple priorities in a fast-paced environment.
- Ability to quickly learn new technologies and business processes.
- Demonstrated professionalism and ability to work independently.
Preferred Qualifications:
- Experience using ServiceNow, preferably Integrated Risk Management (IRM).
- Experience with Governance, Risk, and Compliance (GRC) programs or platforms.
- Experience using Microsoft Office 365 applications.
- Experience preparing technical documentation and reports.
- Experience coordinating projects, tasks, or workflow activities.
- Experience working in customer service or stakeholder-facing environments.
Knowledge & Technical Skills:
- Cybersecurity Principles
- Information Security Governance
- Governance, Risk & Compliance (GRC)
- Enterprise Risk Management
- Risk Assessment Methodologies
- Risk Register Management
- ServiceNow Integrated Risk Management (IRM)
- NIST Cybersecurity Framework (NIST CSF)
- Risk Scoring Systems and Quantitative Risk Frameworks
- HIPAA
- Technical Documentation
- Workflow Coordination
- Microsoft Office 365
ASSYST is an Equal Opportunity Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, disability, military status, national origin or any other characteristic protected under federal, state, or applicable local law.
- ...Cyber And It Security Risk Analyst Location: Bethesda, MD Contract: 12 Months Position... ...Summary We are seeking a Cyber and Information Security Risk Analyst to join our growing... ...internal and external audits and compliance efforts. Document implementation...SuggestedContract workFor contractors
- ...The Compliance and Risk Analyst assists the IT Program Manager in the registration of all Application and Database Management Systems (DADMS) for inclusion into the investment portfolio. Responsibilities Use the IT portfolio tool to manage the compliance of Secretariat...SuggestedTemporary workWork at officeFlexible hours
$176.97k - $303.37k
...days per week. Responsibilities Reporting to the Chief Risk Officer, the Chief Compliance Officer is a senior leadership position responsible... ...closely with business leaders, risk management, legal, information security, and audit functions to foster a strong culture of...SuggestedWork at officeRemote workFlexible hours- ...September 23, 2025: Solifi, a global leader in secured finance technology, today announced the... ...in wholesale finance and inventory risk management. About DataScan:... ...inventory status by recording detailed information in our Onsite mobile audit application and...SuggestedWork at officeLocal areaImmediate startFlexible hoursNight shift
$96.5k - $110.1k
...Overview Senior Risk Specialist | Retail Bank The Conduct... ...MPG (Monitoring, Process, & Governance) mission is a passionate and... ...with select business, Compliance, Human Resources and Risk stakeholders... ...note that this salary information is solely for candidates...SuggestedPermanent employmentFull timePart timeWork at officeLocal area$170k - $200k
...Chief Compliance Officer The Chief Compliance Officer (CCO) is responsible... ...to maintain a robust, risk-based compliance framework,... ...Compliance Framework & Governance Own, design, and continuously... ...trust our expertise to make informed decisions for their stakeholders...Local areaWorldwideFlexible hours$164.8k - $188.1k
...Data Analyst Manager - Model Risk Office At Capital One, data is at the center... ...decision making. The Model Risk Governance - Reporting and... ...at specific and crucial information for the organization Identifying... ...to non‑discrimination in compliance with applicable federal,...Full timePart timeWork experience placementWork at officeLocal area- ...support for researching and determining the likelihood of financial risk to the organization, reviewing actuarial documentation for... ...and effective relationships with others by sharing resources, information, and knowledge with coworkers and customers; listening, responding...
$90k - $95k
Technical Business Analyst Imagineeer, LLC — North... ...health, defense, homeland security, and transportation.... ...without breaking governance, compliance, or mission continuity... ...delivery and reduces risk. If real delivery... ...technical analysts, information technology analysts,...Work experience placementLocal area$120.8k - $137.9k
...Principal Risk Specialist | Enterprise Payments Do you like... ...one or more of our Payment Governance teams. You'll play a key role... ...Please note that this salary information is solely for candidates hired... ...to non-discrimination in compliance with applicable federal, state...Full timePart timeWork at officeLocal area$120.8k - $137.9k
...Principal Risk Specialist As a Principal Risk Associate at Capital One you’ll be responsible... ...across stakeholders to document compliance with applicable laws and regulations related... ...@capitalone.com. All information you provide will be kept confidential and...Full timePart timeWork at officeLocal area$117.3k - $133.9k
...Principal, Risk Specialist Does the idea of working with and guiding professional, highly... ...location. Please note that this salary information is solely for candidates hired to... ...vet) committed to non-discrimination in compliance with applicable federal, state, and local...Full timePart timeLocal area$120.8k - $137.9k
...Principal Risk Specialist As a Principal Risk Associate at Capital One you'll be... ...stakeholder groups to ensure documentation of compliance with applicable laws and regulations as... ...location. Please note that this salary information is solely for candidates hired to...Full timePart timeWork at officeLocal area$120.8k - $137.9k
...Principal Risk Specialist | Enterprise Payments Do you like... ...one or more of our Payment Governance teams. You’ll play a key role... ...Please note that this salary information is solely for candidates hired... ...to non-discrimination in compliance with applicable federal, state...Full timePart timeWork at officeLocal area$120.8k - $137.9k
...Principal Risk Specialist | Enterprise Payments Do you like... ...one or more of our Payment Governance teams. You'll play a key role... ...note that this salary information is solely for candidates hired... ...committed to non-discrimination in compliance with applicable federal,...Full timePart timeWork at officeLocal area- ...Senior Risk Analyst Immediate need for a talented Senior Risk Analyst with experience in the Banking & Financial Industry. This is a 06+ Months Contract opportunity with long-term potential and is located in McLean, VA. Please review the job description below. Key...Contract workImmediate start
- ...Wise Consulting, LLC is seeking an Identity Access Management Analyst to join their team in Maryland. The role involves reviewing IAM... ...standards, and engaging with various stakeholders to enhance identity security. The ideal candidate should possess a Bachelor's degree in IT...Remote work
- Director Compliance Advisory - Personal Loans Corporate Compliance... ...corners to identify tomorrow’s risks, and able to integrate... ..., Legal, Compliance Central Governance, and the US Card Business Risk... ...Compliance Manager (CRCM), Certified Information Privacy Professional (CIPP),...Full timeWork at officeLocal areaFlexible hours
- ...Provides direction on benefit plan analysis, design, cost avoidance, risk and funding strategies Contributes to vendor financial... ...~ Proven ability to identify and resolve issues with limited information and experience ~ Strong written and verbal communication skills...Temporary workWork at officeLocal areaRemote workVisa sponsorshipWork visaFlexible hours
$38 - $42 per hour
...$38.00/hr - $42.00/hr Information Assurance Analyst / Engineer Razor is looking... ...a long‑term federal government contract supporting a large... ...vulnerabilities, risks, and security requirements in accordance... ...to identify and document compliance Capable of providing thoughtful...Long term contractContract workRemote work- ...Title: Financial Risk Program Manager Direct hire Onsite 5 days/week in McLean, VA Cherry Bekaert is recruiting for a Risk Program... ...project tracking to drafting executive-level materials for senior government and industry audiences. Key Responsibilities Program Management...
$151.9k - $173.4k
...Overview Compliance Privacy Advisor, Manager The Capital One... ...passion for mitigation privacy risks at a tech focused finance... ...audit. ~ CIPP (Certified Information Privacy Professional) certification... ..., or AIGP (Certified AI Governance Professional). At...Full timeTemporary workPart timeLocal area$140k - $195k
...ask you to provide payment information as part of the recruiting process... ...for supporting Plant Security management in the development... ...of fuel. Additionally, the Analyst will assist in maintaining and... ...operational facility, ensuring compliance with applicable security...Full timeFor contractorsWork at officeLocal area- ...protected veteran status, or any other category protected byapplicable federal, state or local laws. The attached link contains further information regarding KPMG's compliancewith federal, state and local recruitment and hiring laws. No phone calls oragencies please. KPMG...Local area
$198k - $368k
...join our team. KPMG is currently seeking a Director, Security Compliance to join our Digital Security team. Responsibilities... ...Apply a comprehensive specialist-level knowledge of risk, compliance, and information security controls to develop and execute a multi-disciplined...Temporary workH1bLocal area- Senior Analyst, Actuary The Sr. Analyst, Actuary role requires evaluating complex risks and assessing potential financial consequences in the healthcare space. Utilize mathematics, statistics, and financial theory to evaluate risk, help develop business plans that minimize...Contract workFlexible hours
- ...Solutions is hiring a mid-level Regulatory Analyst. This is a contract role in Rockville.... ...of rules, regulations, statutes, and compliance policies that are relevant and applicable... ...rules, regulations, statutes, and policies governing filings.* Demonstrates the culture of...Contract work
$69.8k - $100.05k
...version control, and compliance of documentation. Maintain... ..., inconsistencies, risks, and timeline issues;... ..., biotechnology, CRO, government contractor, or related... ...obtain and maintain a security clearance. Preferred Qualifications... ...condition, genetic information, pregnancy, family...Full timeContract workPart timeFor contractorsWork at office- ...Quality Assurance Auditor Performs audits necessary to ensure the compliance of manufacturing procedures to in-house specifications and government regulation. Establishes auditing requirements, quality standards and test methods in accordance with FDA and GMP requirements...Contract work
$160k - $195k
JustinBradley’s client is a non‑profit organization that brings members of U.S. financial sector, government organizations and key stakeholders together to address and mitigate risk relating to critical financial systems across the country. Our client is seeking a Financial...Work experience placement
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Information Security Governance, Risk & Compliance (GRC) Analyst. Be the first to apply!

