Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

GRC Analyst

$189k - $225k

Spire

The GRC Analyst, Federal & Customer Programs is responsible for the hands‑on analysis, documentation, and operational execution of the company's security governance, risk, and compliance obligations. This role sits at the intersection of customer contracts, regulatory frameworks, and the company's security control environment — translating external requirements into clear, traceable internal commitments and evaluating how well current capabilities satisfy them. The GRC Analyst reviews incoming contractual security language, maps obligations to applicable frameworks and existing controls, produces compliance matrices and gap analyses, owns the operational risk assessment process, contributes to governance and policy lifecycle activities, and supports audit, assessment, and customer inquiry activities. A meaningful portion of this role is dedicated to ongoing contract and requirements analysis as new programs are awarded and existing programs evolve. The GRC Analyst serves as the security function's primary reviewer of incoming contractual cybersecurity language and works directly with legal and sourcing on flow‑down negotiation and redlines. Candidates who enjoy careful reading of contractual and regulatory text — and who want this to be a substantial part of their day‑to‑day work — will find this role a strong fit. This is a detail‑oriented, writing‑intensive role requiring strong analytical judgment, fluency across multiple compliance frameworks, and the ability to work effectively with legal, sourcing, program management, engineering, and security operations stakeholders. Key Responsibilities Contract & Requirements Analysis Review customer contracts, statements of work, security annexes, CDRLs, data protection addenda, and flow‑down clauses to identify cybersecurity, privacy, and information handling obligations applicable to the company. Extract and catalog specific security requirements from contractual language, and translate them into structured, testable statements suitable for traceability and control mapping. Compare identified requirements against the company's current product scope, control environment, and certification posture to determine where compliance is already met, partially met, or requires new implementation work. Produce gap analyses, compliance matrices, and Requirements Traceability Matrix (RTM) artifacts that clearly communicate the state of compliance for a given contract, program, or system. Serve as the security function's primary point of contact for legal and sourcing during contract review, redline cycles, and flow‑down negotiation, including review of subcontractor and supplier flow‑down language. Framework Mapping & Interpretation Maintain working proficiency across the frameworks relevant to the company's regulatory and contractual posture, including NIST SP 800‑171, NIST SP 800‑53, NIST CSF, CMMC, ISO 27001, FedRAMP, and applicable European frameworks such as NIS2 and GDPR. Map controls across frameworks to minimize duplicated work and enable consistent responses to overlapping requirements; contribute to a shared control inventory used by compliance, security, and program teams. Interpret framework language and authoritative guidance (NIST publications, DoD guidance, regulator FAQs) in the context of specific company systems and business scenarios and escape ambiguity for formal risk decisions when appropriate. Governance, Policy & ISMS Support Contribute to the maintenance of the company's Information Security Management System (ISMS) documentation set, including keeping control descriptions, evidence references, and scope statements accurate and current. Support the policy and standard lifecycle, including periodic review cycles, version control, exception governance, and clarification of control owner accountability. Produce compliance posture reporting and audit readiness metrics for governance forums and leadership review, including framework coverage, finding aging, and remediation progress. Draft and revise compliance deliverables including System Security Plans (SSP), Plans of Action & Milestones (POA&M), policy and standard content, control narratives, customer security questionnaire responses, and audit artifacts. Author clear, concise written responses to customer, auditor, and regulator inquiries, calibrated to the technical level of the audience and consistent with approved company positioning. Own the operational risk assessment process and the supporting risk register, including conducting periodic and event‑driven risk assessments, documenting current state, identifying deficiencies, and developing risk treatment recommendations. Route risk acceptance and exception decisions to the appropriate decision authority with the underlying analysis and documentation prepared for review; track decisions and ensure follow‑through on conditions or expirations. Track open compliance findings and remediation activities, prepare status updates, and flag aging or high‑severity items for escalation. Third‑Party & Supply Chain Risk Contribute to vendor and supplier security review activities, including evaluating vendor security questionnaires, reviewing supplier control attestations, and assessing residual risk for inclusion in procurement and program decisions. Support assessment of subcontractor and supplier flow‑down compliance, including coordinating with sourcing and program management on supplier security obligations and remediation. Audit & Assessment Support Support internal and external audit, assessment, and certification activities, including C3PAO engagements, ISO 27001 surveillance audits, customer assessments, and regulator inquiries. Coordinate evidence collection with system owners and control operators; validate that evidence is accurate, complete, and appropriately scoped before submission. Participate in assessor and auditor interviews as a subject matter contributor on specific controls and artifacts. Cross‑Functional Collaboration Partner with legal and sourcing on contract review, redlines, and flow‑down language; with security program management on milestones, schedules, and audit coordination; and with security engineering and IT on evidence, control implementation detail, and remediation planning. Serve as a knowledgeable point of contact for internal teams seeking to understand what a given regulatory or contractual requirement means in practice. What Success Looks Like in Year One Established a repeatable contract review intake process with legal and sourcing, including a maintained library of standard cybersecurity flow‑down clauses and review turnaround expectations. Produced an end‑to‑end Requirements Traceability Matrix for at least one active federal program, traceable from contract clauses through framework controls to evidence sources. Stood up the operational risk register and routine risk reporting cadence, with at least one full assessment cycle completed and risk treatment decisions documented. Maintained the ISMS documentation set in audit‑ready condition through at least one external assessment or surveillance cycle. Required Qualifications Five or more years of progressive experience in cybersecurity governance, risk, and compliance; IT audit; or a closely related discipline, with substantial hands‑on exposure to framework interpretation and contract requirement analysis. Demonstrated working knowledge of NIST SP 800‑171 and NIST SP 800‑53, including control families, assessment procedures, and common implementation patterns. Experience contributing to SSP and POA&M artifacts, compliance matrices, or Requirements Traceability Matrices in a regulated environment. Practical experience supporting at least one formal audit, certification, or assessment cycle (for example CMMC, ISO 27001, SOC 2, FedRAMP, or comparable). Strong technical writing skills, including the ability to produce accurate, concise, and audience‑appropriate compliance documentation. Writing samples may be requested as part of the interview process. Demonstrated comfort and interest in reading contractual and regulatory language carefully and translating it into specific, actionable internal requirements. This is a core part of the role, not an occasional task. Comfort working across multiple stakeholder groups — legal, sourcing, engineering, IT, security operations, and program management — and adjusting communication style accordingly. Bachelor's degree in Information Security, Information Systems, Business, a related field, or equivalent practical experience. Preferred Qualifications Direct experience with CMMC 2.0 assessment preparation, including familiarity with DFARS View phone number on click.appcast.io and 48 CFR Part 204. Familiarity with ISO 27001, FedRAMP, SOC 2, NIS2, GDPR data security obligations, or EU dual‑use export control regimes. Experience handling Controlled Unclassified Information (CUI) in accordance with NARA and DoD requirements. Exposure to aerospace, defense, space, or other regulated technology environments. Experience reviewing or negotiating cybersecurity flow‑down language in customer or supplier contracts. Working familiarity with Governance, Risk, and Compliance (GRC) tooling such as ServiceNow GRC, Archer, Hyperproof, Drata, Vanta, or equivalent. Industry certifications such as CISA, CRISC, CISSP, CGRC (formerly CAP), ISO 27001 Lead Implementer / Lead Auditor, CMMC Registered Practitioner (RP), or CMMC Certified Professional / Certified Assessor (CCA / CCP). Active US security clearance, or eligibility to obtain one. Spire operates a hybrid work model, and this position will require you to work a minimum of three days per week in the office. Access to US export‑controlled software and/or technology may be required for this role. If needed, Spire will arrange the necessary licenses—this is not something candidates need to have before applying. The anticipated base salary range for this position is listed below. Final base salary for this role will be based on the location, skills, experience and qualifications. In addition to base compensation, this role may be eligible for annual equity awards and our employee benefits program, including vacation, sick, and personal time off; optional medical, dental, vision, life, and disability coverage; a 401(K) plan; health and wellness reimbursement program; and participation in Spire’s Employee Stock Purchase Plan. Salary Range: $189,000 USD – $225,000 USD About Spire We improve life on Earth with data from space. Spire Global is a space‑to‑cloud analytics company that owns and operates the largest multi‑purpose constellation of satellites. Its proprietary data and algorithms provide the most advanced maritime, aviation, and weather tracking in the world. In addition to its constellation, Spire’s data infrastructure includes a global ground station network and 24/7 operations that provide real‑time global coverage of every point on Earth. Spire is Global and our success draws upon the diverse viewpoints, skills and experiences of our employees. We are proud to be an equal opportunity employer and are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, marital status, disability, gender identity or veteran status. To help maintain a safe and secure workplace for Spire employees, all candidates who receive a conditional offer will be required to complete a background check. This may include criminal history and employment verification. Please take a moment to review Spire’s Global Data Privacy Notice for Employees, Contractors, Candidates and Visitors, as well as Spire’s Privacy Policy. Kindly be advised that communication regarding your application may come from @spire.com, @recruiting.spire.com, or from Candidate.fyi (our scheduling tool). #J-18808-Ljbffr

Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the GRC Analyst in Texas City, TX vacancy
  • Fraud Investigator The Fraud Investigator assists AMOCO in achieving its mission of "serving the financial needs of our members" by investigating and documenting potential fraud and suspicious activities across various types of transactions. The position requires collaboration...
    Suggested

    Amoco Federal Credit Union

    Texas City, TX
    1 day ago
  • INEOS ACETYLS CHEMICALS TEXAS CITY, INC. seeks a Field Safety Specialist responsible for implementing safety policies and programs. The role requires spending up to 80% of time in the field and involves managing safety audits, inspections, and emergency response procedures...
    Suggested

    INEOS ACETYLS CHEMICALS TEXAS CITY, INC.

    Texas City, TX
    4 days ago
  •  ...Overview The opportunity We are seeking a Senior Workday HRIS Analyst with 6+ years of hands-on experience configuring the Workday Compensation and Payroll modules to join our People Technology team. In this role, you will serve as a senior subject matter expert and key... 
    Suggested
    Work at office
    Relocation package

    Unity

    Texas City, TX
    2 days ago
  •  ...meaningful role, you’re in the right place. About you and this role Dowhas an exciting opportunity for an Information Technology Analyst located in Midland, MI or Houston, TX! Please note that we are hiring for various technologies within Information Systems. This... 
    Suggested
    Live in

    Dow Chemical

    Texas City, TX
    1 day ago
  • Minimum Qualifications:A bachelor’s degree and four (4) years of experience in an audit or investigation function are preferable.Job Summary:To audit and/or review complex systems or operations in order to evaluate and report on compliance matters and the adequacy, effectiveness...
    Suggested
    For contractors
    Work at office
    Local area
    Remote work
    Relocation

    The University of Texas Medical Branch

    Galveston, TX
    3 days ago
  • A leading specialty chemicals company in Texas City is seeking an Environmental, Health, Safety & Training Manager to oversee plant safety and environmental performance. The role involves managing EHS-related projects, conducting risk assessments, and ensuring compliance...

    Ashland

    Texas City, TX
    3 days ago
  • Summary:The Vice President and Chief Compliance Officer (VP & CCO) serves as UTMB’s senior executive responsible for enterprise-wide compliance, privacy, conflicts of interest, governance, and regulatory risk management. Reporting with independence to executive leadership...
    For contractors
    Local area

    The University of Texas Medical Branch

    Galveston, TX
    2 days ago
  •  ...Job Overview ISP Technologies Inc. Planning Analyst I – Ashland has an exciting opportunity for a Production Planner to join our Ashland, Inc. business at our Texas City, Texas manufacturing plant. This is a very visible, significant role within the Company and the manufacturing... 
    Full time
    Work at office
    Flexible hours
    Weekend work

    ISP Technologies

    Texas City, TX
    2 days ago
  • The University of Texas Medical Branch is seeking a qualified HR professional to manage leave policies, including Family Medical Leave and Military Leave. This role also involves training managers statewide and ensuring compliance with regulations. The position offers partial...
    Remote work
    Monday to Friday

    The University of Texas Medical Branch

    Galveston, TX
    2 days ago
  •  ...AnalystApplylocations: US-TX-TEXAS CITYtime type: Full timeposted on: Posted Yesterdayjob requisition id: 2026 - 0306ISP Technologies Inc.**PLANNING ANALYST I**Ashland has an exciting opportunity for a Production Planner to join our Ashland, Inc. business at our Texas City, Texas... 

    Ashland

    Texas City, TX
    4 days ago
  •  ...a challenge and meaningful role, youre in the right place. About you and this role Dow has an exciting opportunity for a Sr. IT Analyst on the ED&A Data Technology & Architecture Team located in Midland, MI or Houston, TX. You will: Make significant technical contributions... 
    Permanent employment
    Work experience placement
    Live in
    Visa sponsorship
    Relocation package

    Dow Chemical

    Texas City, TX
    3 days ago
  • Overview Role: Business Analyst Responsibilities Support the collection and consolidation of Objective and Key Results (OKRs), Key Performance Indicators (KPIs), and additional performance metrics in support of Monthly Business Reviews and Quarterly Business Reviews across... 

    Winaxis LLC

    Texas City, TX
    3 days ago
  • $45.52k - $77.18k

    Development of policies, definitions, standards, and processes for costing data. Responsible for managing compliance to policies, definitions, and standards. Drive data change to correspond to master data strategies. Develop and analyze data quality reports and track areas...
    Full time
    Remote work

    Remote Career

    Texas City, TX
    2 days ago
  •  ...quality assurance findings Coordinate research projects and quality improvement activities Supervise the EMS Quality Assurance Analyst and assist with hiring, training, coaching, and performance management Approve timesheets, leave requests, and personnel forms... 
    Full time
    Work at office
    Local area
    Weekend work
    Afternoon shift

    Galveston County Health District

    Texas City, TX
    5 days ago
  •  ...Qualifications:Master’s degree in Human Resources, Business, or related fieldExperience with PeopleSoft HRExperience with Compensation Analyst market pricing softwareA Certified Compensation Professional (CCP) Experience in Healthcare and/or AcademiaJob Summary: Provides... 
    For contractors
    Work at office
    Local area
    Remote work

    The University of Texas Medical Branch

    Galveston, TX
    4 days ago
  • $97.08k - $126.2k

     ...for best practice and enhanced healthcare operations in alignment with UTMB’s mission.Job Duties:A Radiant EHR Clinical Solutions Analyst is responsible for leading the design, development, and optimization of highly complex Epic Radiant (EHR) applications. This role drives... 
    For contractors
    Casual work
    Local area
    Remote work
    Work from home

    The University of Texas Medical Branch

    Galveston, TX
    3 days ago
  •  ...Research new technological solutions, verify, and apply solutions of others and self.Serves as a role model to EHR Clinical Applications Analysts.Apply analysis and documentation to support and understand problems.Understands components within a complex clinical system, as... 
    For contractors
    Local area
    Remote work

    The University of Texas Medical Branch

    Galveston, TX
    1 day ago
  • Minimum Qualifications:Bachelor's degree or equivalent experience and eight (8) years of experience in research administration, along with two (2) years of prior management experience. A strong knowledge of federal regulations governing academic medical center researchPreferred...
    For contractors
    Work at office
    Local area

    The University of Texas Medical Branch

    Galveston, TX
    1 day ago
  •  ...The University of Texas Medical Branch in Galveston, TX is seeking a Radiant EHR Clinical Solutions Analyst to drive design, development, and optimization of Epic Radiant applications. You will collaborate with clinical, operational, and technical teams to deliver scalable... 
    Remote work

    The University of Texas Medical Branch

    Galveston, TX
    1 day ago
  • UTMB Health is seeking a Contract Administrator II to lead complex sourcing initiatives and oversee the full contract lifecycle across a broad portfolio. The role partners with senior stakeholders in category management, value analysis, legal, and clinical leadership to...
    Contract work

    UTMB Health

    Galveston, TX
    3 days ago
  •  ...Investigative Analyst Help As an Investigative Analyst at the GS-1805-9 level, some of your typical work assignments may include: Gathering, researching, and analyzing various types of data from federal, state, local and public agencies. Providing administrative... 
    Local area

    Department of Justice

    Galveston, TX
    1 day ago
  • Clerical & Administrative Support Provides centralized coordination, maintenance, and optimization of clinician scheduling templates and related system configurations across Ambulatory and Ancillary departments. Responsible for managing template change requests, ensuring...
    For contractors
    Local area

    UTMB Health

    Galveston, TX
    1 day ago
  • The University of Texas Medical Branch seeks a Labor Productivity Analyst in Galveston to support efficient labor resource use across departments. This hybrid role includes analyzing workforce performance and developing solutions to enhance staffing and operational decisions... 

    The University of Texas Medical Branch

    Galveston, TX
    2 days ago
  •  ...Dow is seeking a Sr. IT Analyst (ED&A Data Tech & Architecture) to design, implement, and govern data solutions. You will work cross-functionally on SAP integrations, MDG master data, and data migration projects, delivering scalable pipelines and secure data platforms.... 

    Dow Chemical

    Dickinson, TX
    3 days ago
  • $36 per hour

    JOB DESCRIPTION:Under general direction, provides technical analysis and support for maintenance, troubleshooting, and problem resolution of data center facilities, applications, and systems. Provides planning analysis and support for monitoring workflow, methods, and procedures...
    Work at office
    Relocation

    The University of Texas Medical Branch

    Galveston, TX
    1 day ago
  •  ...practitionersDepartment Marketing Statement:UTMB’s new Center for Health and Clinical Outcomes Research (H-COR) invites applications for a Data Analyst to help convert complex clinical and population-health data into decision-grade evidence.The analyst will work closely with H-COR’s... 
    For contractors
    Local area

    The University of Texas Medical Branch

    Galveston, TX
    1 day ago
  • Minimum Qualifications:Bachelor’s degree in healthcare administration, nursing, clinical sciences, or related discipline, and five years of clinical experience, including three years in clinical research.Preferred Licenses, Registrations, or Certifications:Current State...
    For contractors
    Work at office
    Local area

    The University of Texas Medical Branch

    Galveston, TX
    2 days ago
  •  ...Financial Planning Analyst (Work From Home) Company Description At Pro Talent HR, we specialize in empowering businesses with comprehensive HR solutions tailored to drive growth and success. From talent acquisition and employee development to payroll management and... 
    Remote job
    Full time
    Work from home

    Pro Talent HR

    Texas City, TX
    more than 2 months ago
  • Job Description Job Description Description The Rail Coordinator is a logistics department role that supports safe and efficient rail operations by maintaining accurate schedules, managing waybilling and documentation, and ensuring all records are complete and audit...
    Shift work

    Texas International Terminals LTD

    Galveston, TX
    5 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to GRC Analyst. Be the first to apply!

Related searches