GRC Analyst
C2 Labs, Inc.
Job Description
Job Description
C2 Labs [ partners with clients on their IT transformation journey via data-driven IT strategic planning, application rationalization and redevelopment, and innovative research and development of new industry standards and technologies. C2 Labs provides specialized products and services that allow our clients to innovate with speed and scale seamlessly while maintaining a robust and effective security posture. C2 has a unique approach to client success enablement that is empowered by ART (Application Rationalization and Transformation) and SCIENCE (Strategic Client Interview and Engineering to assess, design, and implement Cloud Ecosystems) to couple creative new approaches/technologies with proven methodologies that deliver rapid results.
Must Live in the Knoxville, Tennessee metro area and Must be a US Citizen and capable of passing a Public Trust background investigation. For a two year contract.
Job Summary: As a Governance Risk and Compliance (GRC) Analyst at C2 Labs you will work with a team of security analysts and engineers to implement regulatory frameworks such as the Federal Information Security Modernization Act (FISMA), the Federal Risk Authorization Management Program (FedRAMP) and the State Risk Authorization Management Program (StateRAMP). You will leverage GRC tools to develop security authorization package documentation such as the System Security Plan (SSP), Security Assessment Plan (SAP), Security Assessment Report (SAR), and the Plan of Actions & Milestones (POA&M) in human readable and machine-readable formats. You will draft security control implementation statements with enough detail to facilitate the testing of the controls and will develop supporting documentation including the Contingency Plan (CP), Incident Response Plan (IRP), and Configuration Management Plan (CMP). As a GRC Analyst 1 your primary responsibility will be to ensure the timely development of the security authorization package in accordance with C2 Labs quality standards.
Job Responsibilities: Categorize systems in accordance with Federal Information Processing Standards (FIPS) 199 and National Institute of Standards and Technology (NIST) Special Publication (SP) 800-60. Select and tailor security controls by applying scoping guidance in accordance with NIST SP 800-53 and FedRAMP specific guidance. Document the implementation characteristics for security controls with enough detail to permit the testing of the security control by an independent assessor/Third Party Assessment Organization (3PAO).● Develop, review, and update security authorization package documentation to include the System Security Plan (SSP), Security Assessment Plan (SAP), Security Assessment Governance Risk and Compliance (GRC) Analyst 1 Report (SAR), and Plan of Actions and Milestones (POA&M). ● Develop, review, and update supporting documentation including the Contingency Plan (CP), Incident Response Plan (IRP), and Configuration Management Plan (CMP). ● Conduct Security Impact Assessments (SIAs) on changes to information systems
● Create the Control Implementation Summary (CIS)/Customer Responsibility Matrix (CRM) workbook outline Cloud Service Provider (CSP) and customer responsibilities.
● Develop, review, and update policies and procedures to support the implementation of the NIST 800-53 control families.
● Leverage the next generation of Governance Risk and Compliance (GRC) tools to automate the creation of the SSP. ● Review current security assessment and authorization processes and provide recommendations for improvement.
● Develop Risk Assessment Reports (RAR).
● Provide guidance on NIST 800-53, FedRAMP, and StateRAMP control requirements.
● Develop and deliver training to educate stakeholders on the various tasks and activities associated with the RMF.
Qualifications:
● Minimum 1-3 years’ experience in IT consulting specializing in Governance, Risk, and Compliance using the RMF.
● CISSP, CISM, or CAP certification is preferred but not required.
● Excellent communication and interpersonal skills, with the ability to build a rapport and trust with clients.
● Knowledge of the cybersecurity industry to include regulatory frameworks such as the National Institute of Standards in Technology (NIST) Risk Management Framework (RMF), Federal Risk Authorization Management Program (FedRAMP), Department of Defense (DoD) Impact Levels (2-6), and the State Risk Authorization Management Program (StateRAMP). Governance Risk and Compliance (GRC) Analyst 1
● Possesses an in-depth understanding of the FedRAMP authorization process and associated templates and deliverables.
● Must have experience creating security authorization package documentation (i.e., SSP, SAP. SAR, & POA&M) and managing system authorization artifacts for a FedRAMP authorized cloud environment.
Working knowledge of:
● NIST SP 800-53 Security and Privacy Controls for Federal Information Systems and Organizations
● FedRAMP Security Controls Baselines (i.e., Low, Moderate, High, and Li-SaaS)
● StateRAMP Security Control Baselines (i.e., Low Impact Ready, Low Impact Authorized, Moderate Impact Ready, Moderate Impact Authorized)
● NIST SP 800-37 Guide for Applying the Risk Management Framework to Federal Information Systems
● Must have strong technical writing skills.
● Must be able to work independently under only general direction.
● Must be able to interpret and provide consulting expertise on FedRAMP security requirements.
● Must have extensive knowledge in reviewing, analyzing, and documenting the secure implementation of logical controls, physical controls, environmental controls, personnel security, and incident handling.
● Experience preparing monthly continuous monitoring deliverables (e.g., vulnerability scans, POA&Ms, and asset inventory) for submission to the FedRAMP PMO.
● Must be a US Citizen and capable of passing a Public Trust background investigation.
EEO Statement
We are an equal opportunity employer. All qualified applicants will be considered without discrimination based on race, color, religion, sex, national origin, age, disability, or protected veteran status. Employment offers will be contingent on passing a pre-employment drug screen.
Practical AI Application
- Applies AI tools to streamline workflows, enhance decision-making, and improve outcomes
- Understands the strengths and limitations of AI systems and exercises sound judgment in their use
- Continuously explores new AI capabilities and integrates them into day-to-day work where appropriate
- Uses AI in alignment with company and customer-specific policies, data privacy standards, and ethical guidelines
- Exercises discretion when using AI with sensitive or proprietary information
- Demonstrates awareness of bias, accuracy, and risk considerations when leveraging AI tools
- ...passing a Public Trust background investigation. For a two year contract. Job Summary: As a Governance Risk and Compliance (GRC) Analyst at C2 Labs you will work with a team of security analysts and engineers to implement regulatory frameworks such as the Federal...SuggestedContract workLive in
$95k - $105k
...Job Description Job Description Sr. GRC Analyst About Subsplash Subsplash is an exciting award-winning team of 280+ mission-driven people who are committed to our core values of humility, innovation, and excellence. Founded in 2005, we've remained family owned and...SuggestedTemporary workCurrently hiringRemote workRelocation$136.85k - $161k
...BGS) has created this Evergreen Talent Pool post for gathering qualified candidates for a position relating to Risk and Compliance Analyst to support our clients in various locations across the US. BGS is an engineering, technology, and security firm helping to advance...SuggestedFull timeContract workTemporary workRemote workMonday to FridayNight shift- ...Risk Analyst CGI is seeking a Risk Analyst to support governance, risk, and controls initiatives within a highly regulated financial services environment. This role serves as a bridge between business and technology teams, helping document processes, assess risks, develop...Suggested
- Job Description Job Description *THIS IS NOT A REMOTE POSITION* Position Summary: The Compliance Manager will be responsible for developing, implementing, and managing a comprehensive compliance program to ensure adherence to federal and state healthcare laws and...SuggestedWork at office
- Job Description The Alcohol Compliance Supervisor is responsible for ensuring the safe and legal service of alcohol within the venue. This role plays a key part in upholding local and state alcohol regulations, supporting staff in responsible alcohol service, and mitigating...Local areaFlexible hoursShift workAfternoon shift
$85.1k - $123.8k
...order - J0826-0524 - Permanent Full Time Title Risk & Controls Analyst Category Software Development/ Engineering City Various, , United... ...role . 5+ years of experience within Governance, Risk & Controls (GRC), Operational Risk Management, or similar areas such as Audit,...Permanent employmentFull timeWork at officeLocal area- OverviewCoding Analyst, Centralized Coding OutpatientFull Time, 80 Hours Per Pay Period, Day ShiftCovenant Health Overview:Covenant Health is the region’s top-performing healthcare network with 10 hospitals, outpatient and specialty services, and Covenant Medical Group,...Work experience placementInterim roleWork at office
- OverviewBusiness Support Analyst, IT Rev Cycle SupportFull Time, 80 Hours Per Pay Period, Day shiftThis position participates in an after-hours on-call rotation supporting critical business applications.Covenant Health Overview:Covenant Health is the region’s top-performing...Work experience placementWork at office
- ## Compliance AnalystApplylocations: Knoxville-Bearden: Chattanooga-Miller Plaza: Sevierville-Downtowntime type: Full timeposted on: Posted Yesterdayjob requisition id: JR100123Looking to join a Great Place to Work Employer and become a valued member of our growing team...Local area
- ...IT project managementexperience.Licensure Requirement Professional/clinical licensure (RN, ARRT, etc.) may be required based on assigned applications.Job SummaryJob Title: APPL ANALYST SRID: 4590891Facility: Covenant Health CorporateDepartment Name: IT CARE MGR SUPPORT
$70.89k - $83.4k
At U.S. Bank, we’re on a journey to do our best. Helping the customers and businesses we serve to make better and smarter financial decisions, enabling the communities we support to grow and succeed in the right ways, all more confidently and more often—that’s what we call...Full timeWork at officeLocal areaRemote workFlexible hours3 days per week$52 - $63 per hour
Insurance Field Inspector Knoxville & Surrounding We are a regional insurance inspection firm servicing the southeastern United States. At the request of a few clients we opened the state of TN. Our current Knoxville rep is down with a broken foot and looking to shrink ...Local areaWork from home- Covenant Health is looking for a Credentialing Specialist to manage Payer Enrollment and Hospital credentialing tasks in Knoxville, TN. This full-time position involves acting as a liaison, processing applications, and maintaining credentialing databases with confidentiality...Full time
- Overview Application Analyst, IT Care Manager SupportFull Time, 80 Hours Per Pay Period, Day ShiftCovenant Health Overview:Covenant Health is the region’s top-performing healthcare network with 10 hospitals, outpatient and specialty services, and Covenant Medical Group...
- Job Title:Critical Power and Electromagnetic Threats - Simulation and Data AnalystLocation:Knoxville, TNJob Summary and Description:The position is for a senior level engineer with expertise in power system simulation, data analysis, and design. The candidate will provide...Full timeFlexible hours
$53.92k - $67.01k
...Title: Analyst I Number of Positions: 1 Department: Application Programing Support Classification: 2 - Hybrid Pay Rate: $$53,920 - $67,010/per year. Pay will be determined based on related work experience above required. To be considered...Full timeTemporary workPart timeWork experience placementWork at office- ...Investigative Analyst Help As an Investigative Analyst at the GS-1805-9 level, some of your typical work assignments may include: Gathering, researching, and analyzing various types of data from federal, state, local and public agencies. Providing administrative...Local area
$165k - $185k
THIS POSITION IS 100% ON-SITE IN GERMANTOWN, MARYLAND. This position provides relocation support to the Germantown area. Global Engineering & Technology (GET) is seeking qualified individuals for the position of Nuclear Weapons Subject Matter Expert (SME) in ...Full timeTemporary workWork at officeRelocation package- Job Title: Security Compliance Program Coordinator Location: Knoxville, TN Employment Type: Full-Time Who We Are Management Solutions, LLC (MSLLC) is an award-winning management consulting firm delivering solutions for our partners’ most complex challenges...Full timeContract workTemporary workFor contractorsWork at officeLocal areaImmediate startRemote workHome officeFlexible hours
- ...Cellular Sales Revenue Reconciliation Analyst Classification Non-Exempt Reports To Revenue Reconciliation Manager JOB DESCRIPTION Summary Responsible for transaction-level reconciliation of revenue activity across multiple systems within the Revenue accounting & reconciliation...Full timeMonday to Friday
- Job Description Job Description Description: University Physicians' Association, Inc. is seeking a qualified full-time Certified Medical Assistant (CMA) or Licensed Practical Nurse (LPN) candidate for HIGH-RISK OB CONSULTANTS , a fast paced, high-risk obstetrical...Full timeWork at officeImmediate startShift work
- Job Description Job Description Signature is looking to add a Field Consultant to cover the following counties in Tennessee: Knox, Roane, Loudon, Blount, Sevier Are you looking for a new career that allows you to work independently, is flexible, and challenging...For contractorsWork from homeHome officeFlexible hours
- Chief Risk Officer (CRO) About the Company Respected banking organization Industry Banking Type Privately Held About the Role The Company is in search of a Chief Risk Officer to lead the strategic planning and oversight of its enterprise-wide risk...
- ...POSITION: Legal Research Analyst FLSA STATUS: Non-Exempt DEPARTMENT: Client Solutions Group SUPERVISOR: Director of Knowledge Management and Research SUMMARY The Legal Research Analyst serves as a trusted expert resource at the intersection of legal knowledge, information...Work at officeWeekend work
$30 per hour
...Store, Oracle Software Delivery Cloud, License Key Provisioning and internal distribution of Employee Laptops. Customer Service analysts deliver service and support that represents the highest level of customer service and quality. To do this, the analyst will:...Hourly payTemporary workWork experience placementInternshipWorldwideFlexible hours- You were made to create Better Care for a Better World. As a person, you’re a problem-solver - a connector - someone who thrives on creating order from complexity and driving continuous improvement. You see the big picture while mastering the details, ensuring that every...Full timeInternshipLocal areaImmediate startRelocation package
$70.89k - $83.4k
At U.S. Bank, we’re on a journey to do our best. Helping the customers and businesses we serve to make better and smarter financial decisions, enabling the communities we support to grow and succeed in the right ways, all more confidently and more often—that’s what we call...Temporary workWork experience placementWork at officeLocal areaRemote workFlexible hours3 days per week- National Contracting Center (NCC) is looking for a detail-driven Commissions Data Specialist to join our growing team. In this role, you will work with large, multi-source commission datasets to ensure accurate reporting and timely payments to our independently contracted...Full timeImmediate start
- Job Responsibilities Responsible for on-site and/or remote installation, implementation, maintenance, troubleshooting and/or repair of desktops, notebooks, and associated peripherals. Windows troubleshooting, diagnosing, imaging/deployment and software installation. ...Remote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to GRC Analyst. Be the first to apply!




