Entry Level GRC Analyst
Hotman Group
About the Role
Hotman Group is a boutique cybersecurity and GRC consulting firm doing meaningful work for clients who need GRC done right ranging from Fortune 1000 companies to high-growth startups. We are looking for a driven, detail-obsessed early-career professional who is ready to apply your professional foundation to real GRC consulting work and contribute to real client work from day one.
This is a full-time, remote, contract-to-hire position. Top performers move into permanent roles within 6 months.
What You Will Do
As an Entry Level GRC Analyst at Hotman Group you will work side by side with senior team members and partners to help our clients strengthen their cybersecurity and compliance programs. You will:
- Assess and improve client security and IT controls
- Develop policies, processes, and risk assessments aligned to top frameworks including NIST, ISO 27001, and SOC 2
- Crosswalk and harmonize controls across multiple compliance frameworks
- Document security requirements, support control implementation, and help track remediation progress
- Build risk registers, support assessments, and monitor remediation progress
- Work hands-on with GRC tools and contribute to solutions for complex client challenges
- Translate technical and regulatory requirements into clear, actionable steps for our clients
- Participate in peer review of deliverables before they go to clients — your work will be reviewed and you will review others
You will touch every aspect of cybersecurity and GRC work across multiple industries. Every engagement brings new challenges and new opportunities to grow.
What You Bring
- A Bachelor's or Graduate degree in Cybersecurity, Information Systems, or a related field
- 1 to 2 years of professional work experience -- this does not need to be in GRC or cybersecurity specifically, but it does need to be in a professional office or corporate environment. We are looking for candidates who have demonstrated reliability, communication, and accountability in a workplace setting
- Solid understanding of fundamental security and IT concepts including access controls, data retention, and change management
- Familiarity with major security and privacy frameworks including ISO, NIST, SOC 2, and HIPAA
- Strong critical thinking, organization, and communication skills
- Ability to balance multiple projects and deadlines with exceptional follow-through
- Technical aptitude -- you are curious, you learn fast, and you do not shy away from new tools
- A genuine interest in cybersecurity and a commitment to helping organizations build stronger, safer programs
- A solutions-first attitude -- you show up with curiosity and energy and you are not afraid to dive into the work
- The ability to think critically and execute with precision in a fast-paced, high-trust, low-ego environment
- A high level of ownership and accountability -- you communicate proactively and follow through without being managed closely
- A default toward communication — you keep the team informed, you acknowledge quickly, and you do not go dark on a deliverable or a client
Active pursuit of a relevant certification (Security+, CC, SSCP) is strongly preferred. If you are not currently studying for one, be prepared to explain why.
Requirements
- Located in the USA with permanent work authorization (no sponsorship of any kind now or in the future)
- Able to pass a background check
- A private, dedicated workspace with a door — client calls and confidential work require it
Our Hiring Process
Our process is designed to be straightforward but thorough. In addition to a written questionnaire and video responses, finalists will complete a practical skills assessment before advancing to a panel interview with our delivery team. The assessment is designed to reflect real GRC work. If you are serious about building a career in this field, it is your opportunity to show us what you can do.
Why Hotman Group
At Hotman Group we are not just another consulting firm. You will work alongside people who care about the craft and push each other to do better. No politics, no silos, no hierarchy between you and the people making decisions.
You will touch more GRC frameworks, more industries, and more client situations in one year here than most practitioners see in five. You will grow because the work demands it.
The clients you serve will actually notice your work. You are not a number on a headcount. Your name is on the deliverable.
If you want to do real GRC work, get better at it every day, and work with a team that holds itself to a high standard — this is the place.
No phone calls or emails please.
- A dynamic cybersecurity firm is looking for a detail-oriented Entry-Level GRC Analyst to join their remote team. In this role, you'll work closely with senior members to strengthen client cybersecurity and compliance programs. You'll be involved in assessing controls, developing...Entry levelRemote job
- A cybersecurity firm is seeking an Entry-Level GRC Analyst in Fort Worth, Texas. This remote position focuses on helping clients strengthen their cybersecurity and compliance programs through various assessments and processes. Ideal candidates should have a relevant degree...Entry levelRemote jobPermanent employment
- ...the RoleAs a member of the Information Security team, the IS GRC Senior Analyst - Risk & Compliance will be responsible for understanding the... ...Conduct and foster an inclusive environment with people at all levels of an organizationAlixPartners has embraced a hybrid work...SuggestedFull timeContract workWork experience placementH1bRemote workVisa sponsorshipRelocation packageMonday to Friday
$80.05k - $165k
...end-to-end issue management activities, including intake, validation, prioritization, assignment, remediation tracking, and closure of GRC-related issues in ServiceNow, ensuring timely resolution, appropriate evidence, and alignment with audit, risk, and regulatory...SuggestedFull timeWork at office$115k - $130k
...130000LocationDes Moines, IA, USAContractPermanentTypeHybridIndustryTechnologyContactEllie ****@*****.*** Senior GRC AnalystAbout the OpportunityJoin a large, well-established financial services organization during a period of significant technology...SuggestedWork at officeRemote work1 day per week- ...The GRC Cybersecurity Analyst III is a senior level contributor responsible for leading ICCU’s Governance, Risk, and Compliance (GRC) initiatives within the scope of the IT domain. This role provides strategic oversight of cyber and IT operational risk assessments, regulatory...Full timeWork experience placementWork at office
- ...GRC Analyst Join our team as a GRC Analyst and play a key role in regulatory compliance, IT risk management, security. You'll assess risks... ...listed below are intended to describe the general nature and level of work performed by employees in this position. They are not...Casual workWork at officeWork from homeHome officeNight shiftWeekend work
- ...Governance, Risk & Compliance (GRC) Analyst (AI Training) About the Role We're partnering with the world's leading AI research labs to build smarter, safer AI - and we need practitioners who know how GRC actually works in the real world. If you've spent time...Hourly payOngoing contractContract workFreelanceRemote work10 hours per weekFlexible hours
- ...Governance, Risk & Compliance (GRC) Analyst (AI Training) About the Role We're looking for experienced GRC professionals to help evaluate and improve AI systems being trained on real-world security, compliance, and risk scenarios. Your practitioner knowledge...Hourly payOngoing contractContract workFreelanceRemote workFlexible hours
- ...raised our Series B and have grown 800% over the last 12 months. The Opportunity Ivo is seeking a detail-oriented and proactive GRC Analyst to support the company's compliance, risk management, and security assurance initiatives. This role will play a key part in...Contract workWork at officeRemote workVisa sponsorshipRelocation packageFlexible hours
$99k - $225k
Enterprise Cybersecurity GRC Governance AnalystThe Opportunity: The Enterprise Cybersecurity (ECS) Governance, Risk, and Compliance (GRC... ...System Security Officer (ISSO) to bridge the gap between high-level policy and technical execution. In this role, you will analyze and...Full timeContract workPart timeWork at officeLocal areaRemote work- ...We are seeking a highly skilled and motivated Senior GRC Analyst to join our Security and Privacy team. In this role, you will own and grow RainFocus's governance, risk, and compliance program — maintaining our control framework, leading risk assessments, supporting...Full time
- ...Job Description Job Description Governance, Risk & Compliance (GRC) Analyst – State Agency – $40-46/hr W2 – Phoenix Hybrid – Contract-to-Hire SunSoftOnline is hiring a GRC / Information Security Analyst for an Arizona state agency's technology division, a 4-month...Permanent employmentFull timeContract workRemote workVisa sponsorshipMonday to Friday
$108k - $130k
...objectives. About the Opportunity Our Information Security team is growing, and we have an immediate opening for a GRC and IT Compliance Analyst to help support and execute Cleerly's security and compliance objectives. Reporting to the Director of Information...Immediate startRemote work$150k - $200k
...the global economy. Join us! Overview We're hiring a GRC Senior Analyst to help build the compliance foundation powering the future of... ...The compensation range provided may span multiple career levels and will be narrowed during the interview process based on factors...Full timeWork at officeRemote work2 days per week- Description The Senior IT GRC Analyst leads policy development and audit execution within CMG's IT Governance, Risk, and Compliance program, with particular emphasis on CMG's upcoming SOC 2 readiness effort. This role works closely with the GRC team and the broader IT...Work at officeRemote work
- ...we can provide the most secure and performant service. As a GRC Analyst at Virtru, you will be the primary point of contact for... ...technical risk and understand how to translate risk to various levels of the organization Have experience training and coaching teams...Full timeFlexible hoursShift work
$95k - $105k
...Job Description Job Description Sr. GRC Analyst About Subsplash Subsplash is an exciting award-winning team of 280+ mission-driven... ...position is between $95,000-$105,000/yr depending on experience level. Essential Functions of This Role: Compliance Program Management...Temporary workCurrently hiringRemote workRelocation- ...Job Description Job Description About the Role Merci Technologies is seeking a GRC Analyst to support the governance, risk, and compliance program for one of our enterprise clients. This role sits at the intersection of security, audit, and business operations,...Full timeContract workRemote work
- ...a boutique cybersecurity and GRC consulting firm doing meaningful... ...high standard. This is not an entry point. We expect you to bring... ...an Experienced or Senior GRC Analyst at Hotman Group you will work... ...when to ask for help A high level of accountability and...Permanent employmentFull timeContract workTemporary workRemote work
- ...Position Overview We are seeking a highly autonomous Senior GRC Analyst to take ownership of core elements within our security and compliance... ...backbone that powers our GovRAMP, FedRAMP, and state-level authorizations. This is a senior, self-directed role designed for...For subcontractorRemote workShift workNight shift
- Governance, Risk, & Compliance (GRC) Analyst Washington, DC Remote Full-Time About This Role As a GRC Analyst, you will help organizations navigate the complex landscape of cybersecurity compliance and risk management. You will work directly with clients to assess their...Full timeRemote work
- Overview The IT GRC Analyst operates within the enterprise Cybersecurity Operations function and supports the Information Technology, Information... ...across the organization. This position may be filled as a Level I, II or III. Additional responsibilities and qualifications...Work at officeRemote work
$55 - $80 per hour
IT GRC Analyst Remote, USA Compensation: $55 - $80 per hour Contract Length: 6-month Contract to Hire Hours: Standard full-time schedule... ...written and verbal communication skills, including executive-level reporting and presentations Ability to prioritize multiple assignments...Hourly payFull timeContract workWork at officeLocal areaImmediate startRemote workFlexible hours- Bloomin' Brands, Inc. is seeking a Sr. GRC Analyst in Tampa, FL to support governance, risk, and compliance efforts across the organization. The role combines onsite and remote work in a hybrid schedule at the Tampa Restaurant Support Center. You will develop policies,...Remote work
$134k - $202k
...customers, growing our community, or shaping our story, you’ll help define what comes next. About the role: We are looking for a GRC Analyst to join our Governance, Risk & Compliance (GRC) team. You will have the opportunity to manage and maintain ongoing compliance with...Work at officeRemote workWorldwideMonday to Friday- Frontier Cybersecurity Consulting in Miami, FL seeks a GRC Analyst for risk assessments, control testing, and gap analyses across HIPAA, SOC 2, ISO 27001 and more. This full-time hybrid role involves onsite client work and remote collaboration. You will gather evidence,...Full timeRemote work
- SkyePoint Decisions is seeking a Governance, Risk & Compliance (GRC) Analyst to support a cybersecurity program and compliance initiatives by managing governance processes, risk management activities, policy compliance efforts, and audit readiness programs. The GRC Analyst...Remote job
- Medasource is seeking an IT GRC Analyst to join the IT Security and Governance team on a 6-month contract-to-hire basis, remote within the USA. The role focuses on governance, risk, and compliance across HIPAA, SOC 2, and NIST, collaborating with IT, Security, Privacy,...Remote jobContract work
- ...development and implementation of the annual strategic plan Develops Board-level reporting Maintains and ensures integration with the company’s... ...compliance metrics General Governance, Risk, and Compliance (GRC) Support Leads process analysis, development, & improvement...Work experience placementWork at officeLocal areaRemote workRelocation
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Entry Level GRC Analyst. Be the first to apply!



