GRC Analyst
$189k - $225kInvestedintheMission
About the Role: The GRC Analyst, Federal & Customer Programs is responsible for the hands-on analysis, documentation, and operational execution of the company's security governance, risk, and compliance obligations. This role sits at the intersection of customer contracts, regulatory frameworks, and the company's security control environment — translating external requirements into clear, traceable internal commitments and evaluating how well current capabilities satisfy them. The GRC Analyst reviews incoming contractual security language, maps obligations to applicable frameworks and existing controls, produces compliance matrices and gap analyses, owns the operational risk assessment process, contributes to governance and policy lifecycle activities, and supports audit, assessment, and customer inquiry activities. A meaningful portion of this role is dedicated to ongoing contract and requirements analysis as new programs are awarded and existing programs evolve. The GRC Analyst serves as the security function's primary reviewer of incoming contractual cybersecurity language and works directly with legal and sourcing on flow-down negotiation and redlines. Candidates who enjoy careful reading of contractual and regulatory text — and who want this to be a substantial part of their day-to-day work — will find this role a strong fit. This is a detail-oriented, writing-intensive role requiring strong analytical judgment, fluency across multiple compliance frameworks, and the ability to work effectively with legal, sourcing, program management, engineering, and security operations stakeholders. Key Responsibilities: Contract & Requirements Analysis Review customer contracts, statements of work, security annexes, CDRLs, data protection addenda, and flow-down clauses to identify cybersecurity, privacy, and information handling obligations applicable to the company. Extract and catalog specific security requirements from contractual language, and translate them into structured, testable statements suitable for traceability and control mapping. Compare identified requirements against the company's current product scope, control environment, and certification posture to determine where compliance is already met, partially met, or requires new implementation work. Produce gap analyses, compliance matrices, and Requirements Traceability Matrix (RTM) artifacts that clearly communicate the state of compliance for a given contract, program, or system. Serve as the security function's primary point of contact for legal and sourcing during contract review, redline cycles, and flow-down negotiation, including review of subcontractor and supplier flow-down language. Framework Mapping & Interpretation Maintain working proficiency across the frameworks relevant to the company's regulatory and contractual posture, including NIST SP 800-171, NIST SP 800-53, NIST CSF, CMMC, ISO 27001, FedRAMP, and applicable European frameworks such as NIS2 and GDPR. Map controls across frameworks to minimize duplicated work and enable consistent responses to overlapping requirements; contribute to a shared control inventory used by compliance, security, and program teams. Interpret framework language and authoritative guidance (NIST publications, DoD guidance, regulator FAQs) in the context of specific company systems and business scenarios and elevate ambiguity for formal risk decisions when appropriate. Governance, Policy & ISMS Support Contribute to the maintenance of the company's Information Security Management System (ISMS) documentation set, including keeping control descriptions, evidence references, and scope statements accurate and current. Support the policy and standard lifecycle, including periodic review cycles, version control, exception governance, and clarification of control owner accountability. Produce compliance posture reporting and audit readiness metrics for governance forums and leadership review, including framework coverage, finding aging, and remediation progress. Deliverable Writing & Artifact Contribution Draft and revise compliance deliverables including System Security Plans (SSP), Plans of Action & Milestones (POA&M), policy and standard content, control narratives, customer security questionnaire responses, and audit artifacts. Author clear, concise written responses to customer, auditor, and regulator inquiries, calibrated to the technical level of the audience and consistent with approved company positioning. Risk Assessment & Treatment Own the operational risk assessment process and the supporting risk register, including conducting periodic and event-driven risk assessments, documenting current state, identifying deficiencies, and developing risk treatment recommendations. Route risk acceptance and exception decisions to the appropriate decision authority with the underlying analysis and documentation prepared for review; track decisions and ensure follow-through on conditions or expirations. Track open compliance findings and remediation activities, prepare status updates, and flag aging or high-severity items for escalation. Third-Party & Supply Chain Risk Contribute to vendor and supplier security review activities, including evaluating vendor security questionnaires, reviewing supplier control attestations, and assessing residual risk for inclusion in procurement and program decisions. Support assessment of subcontractor and supplier flow-down compliance, including coordinating with sourcing and program management on supplier security obligations and remediation. Audit & Assessment Support Support internal and external audit, assessment, and certification activities, including C3PAO engagements, ISO 27001 surveillance audits, customer assessments, and regulator inquiries. Coordinate evidence collection with system owners and control operators; validate that evidence is accurate, complete, and appropriately scoped before submission. Participate in assessor and auditor interviews as a subject matter contributor on specific controls and artifacts. Cross-Functional Collaboration Partner with legal and sourcing on contract review, redlines, and flow-down language; with security program management on milestones, schedules, and audit coordination; and with security engineering and IT on evidence, control implementation detail, and remediation planning. Serve as a knowledgeable point of contact for internal teams seeking to understand what a given regulatory or contractual requirement means in practice. What Success Looks Like in Year One Established a repeatable contract review intake process with legal and sourcing, including a maintained library of standard cybersecurity flow-down clauses and review turnaround expectations. Produced an end-to-end Requirements Traceability Matrix for at least one active federal program, traceable from contract clauses through framework controls to evidence sources. Stood up the operational risk register and routine risk reporting cadence, with at least one full assessment cycle completed and risk treatment decisions documented. Maintained the ISMS documentation set in audit-ready condition through at least one external assessment or surveillance cycle. Required Qualifications: Five or more years of progressive experience in cybersecurity governance, risk, and compliance; IT audit; or a closely related discipline, with substantial hands-on exposure to framework interpretation and contract requirement analysis. Demonstrated working knowledge of NIST SP 800-171 and NIST SP 800-53, including control families, assessment procedures, and common implementation patterns. Experience contributing to SSP and POA&M artifacts, compliance matrices, or Requirements Traceability Matrices in a regulated environment. Practical experience supporting at least one formal audit, certification, or assessment cycle (for example CMMC, ISO 27001, SOC 2, FedRAMP, or comparable). Strong technical writing skills, including the ability to produce accurate, concise, and audience-appropriate compliance documentation. Writing samples may be requested as part of the interview process. Demonstrated comfort and interest in reading contractual and regulatory language carefully and translating it into specific, actionable internal requirements. This is a core part of the role, not an occasional task. Comfort working across multiple stakeholder groups — legal, sourcing, engineering, IT, security operations, and program management — and adjusting communication style accordingly. Bachelor's degree in Information Security, Information Systems, Business, a related field, or equivalent practical experience. Preferred Qualifications: Direct experience with CMMC 2.0 assessment preparation, including familiarity with DFARS View phone number on click.appcast.io and 48 CFR Part 204. Familiarity with ISO 27001, FedRAMP, SOC 2, NIS2, GDPR data security obligations, or EU dual-use export control regimes. Experience handling Controlled Unclassified Information (CUI) in accordance with NARA and DoD requirements. Exposure to aerospace, defense, space, or other regulated technology environments. Experience reviewing or negotiating cybersecurity flow-down language in customer or supplier contracts. Working familiarity with Governance, Risk, and Compliance (GRC) tooling such as ServiceNow GRC, Archer, Hyperproof, Drata, Vanta, or equivalent. Industry certifications such as CISA, CRISC, CISSP, CGRC (formerly CAP), ISO 27001 Lead Implementer / Lead Auditor, CMMC Registered Practitioner (RP), or CMMC Certified Professional / Certified Assessor (CCP / CCA). Active US security clearance, or eligibility to obtain one. Spire operates a hybrid work model, and this position will require you to work a minimum of three days per week in the office. Access to US export-controlled software and/or technology may be required for this role. If needed, Spire will arrange the necessary licenses—this is not something candidates need to have before applying. The anticipated base salary range for this position is listed below. Final base salary for this role will be based on the location, skills, experience and qualifications. In addition to base compensation, this role may be eligible for annual equity awards and our employee benefits program, including vacation, sick, and personal time off; optional medical, dental, vision, life, and disability coverage; a 401(K) plan; health and wellness reimbursement program; and participation in Spire’s Employee Stock Purchase Plan. Salary Range: $189,000 USD - $225,000 USD Global Perks Name Your Satellite Program (NYSP) Launch Attendance Generous Time Off Policy Education Assistance Program Employee Assistance Program (EAP) Employee Stock Purchase Program (ESPP) Family Leave Fitness Reimbursement Employee Referral Program Healthy snacks & beverages in every office About Spire We improve life on Earth with data from space. Spire Global is a space-to-cloud analytics company that owns and operates the largest multi-purpose constellation of satellites. Its proprietary data and algorithms provide the most advanced maritime, aviation, and weather tracking in the world. In addition to its constellation, Spire’s data infrastructure includes a global ground station network and 24/7 operations that provide real-time global coverage of every point on Earth. Spire is Global and our success draws upon the diverse viewpoints, skills and experiences of our employees. We are proud to be an equal opportunity employer and are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, marital status, disability, gender identity or veteran status. To help maintain a safe and secure workplace for Spire employees, all candidates who receive a conditional offer will be required to complete a background check. This may include criminal history and employment verification. Please take a moment to review Spire's Global Data Privacy Notice for Employees, Contractors, Candidates and Visitors, as well as Spire's Privacy Policy. Kindly be advised that communication regarding your application may come from @spire.com, @recruiting.spire.com, or from Candidate.fyi (our scheduling tool). #J-18808-Ljbffr
$110k - $140k
Senior GRC Analyst - Accounting - $110,000 - $140,000 You get to build the GRC function from scratch at a nationally recognized, PE-backed company in a major growth phase. This is a greenfield opportunity. There is no inherited mess to untangle, no legacy processes holding...Suggested$46.99k - $122.4k
The Hispanic Alliance for Career Enhancement is seeking a dedicated professional to handle investigations into healthcare fraud, waste, and abuse, focusing on complex cases and cooperation with law enforcement. This full-time position requires a bachelor's degree, with...SuggestedFull time$56.2k - $101k
Centene Management Company LLC is seeking a Fraud Investigator to investigate allegations of healthcare fraud and abuse. The role is remote but prefers candidates from Texas. The investigator will conduct detailed claims investigations, assist with audits, and prepare ...SuggestedRemote work- Centene Corporation is seeking an investigator to tackle healthcare fraud and abuse, essential for transforming health in communities. This remote role requires a bachelor's degree and at least one year of experience in medical claim investigations. You'll conduct thorough...SuggestedRemote workFlexible hours
$85.1k - $141.8k
McKesson is an impact-driven, Fortune 10 company that touches virtually every aspect of healthcare. We are known for delivering insights, products, and services that make quality care more accessible and affordable. Here, we focus on the health, happiness, and well-being...SuggestedRemote workWork from home2 days per week- Clinical Pathology Laboratories, Inc. (CPL) seeks a Healthcare Compliance Specialist for our Legal & Regulatory Compliance department. This role supports development, implementation, and monitoring of policies to ensure adherence to federal and state healthcare regulations...Local area
$135k - $145k
Job Summary The Affordable Housing Compliance Manager ensures the organization’s affordable housing properties comply with all applicable federal, state, and local regulations, including those related to funding sources such as the Low‑Income Housing Tax Credit (LIHTC)...Interim roleWork at officeLocal area- A leading global construction company is seeking a Director, Legal who will serve as the sole in-house legal advisor. Responsibilities include overseeing corporate legal affairs, compliance, and managing external counsel. The ideal candidate will have over 10 years of corporate...Remote work
$3,000 - $4,999 per month
Posting ID 18365 -Posted - Health & Human Services Comm - Benefits Program Integrity - Business and Financial Operations - Eligible for Telework - Other Locations (1) - Additional Shifts available (1) - b. $3000 - $4999 per month Functional Title: Claims Investigator Job...Full timeTemporary workPart timeWork at officeRemote workShift work- SpaceX was founded under the belief that a future where humanity is out exploring the stars is fundamentally more exciting than one where we are not. Today SpaceX is actively developing the technologies to make this possible, with the ultimate goal of enabling human life...Permanent employmentTemporary workFor contractorsLocal areaRelocationWeekend work
$80k - $100k
...ago Houston, TX $80,704.00-$120,000.00 6 days ago Texas, United States $18.00-$20.00 18 hours ago Remote Retirement Plan Compliance Analyst Remote Retirement Plan Compliance Analyst Fort Worth, TX $70,000.00-$100,000.00 1 week ago We’re unlocking community knowledge in a...Full timeRemote work- For nearly 20 years, TheKey has helped clients achieve successful long-term aging at home with comprehensive, concierge-based care. Ensuring the dignity, safety, and independence of its clients, TheKey is committed to changing how the world lives and ages at home. Employee...
$65 - $90 per hour
Crossing Hurdles is offering a remote position as a Permit Expeditor, focused on reviewing and labeling construction documents to ensure compliance with building codes. Ideal candidates should have strong familiarity with permitting workflows, experience coordinating with...Hourly payRemote work$155.9k - $337.6k
...compliance transparency. Leadership & Partnership Lead a global team of diverse skillsets and levels such as managers, process leads, and analysts, fostering a culture of empowerment, accountability, and innovation. Build strong partnerships with business units, ensuring...Temporary workWork experience placementRemote workFlexible hours- ...be expected to be curious, thorough, and proactive. This is an analyst-level position with meaningful ownership. Your work will matter:... ...partnership model Familiarity with compliance management systems or GRC tools CAMS certification or progress toward it College degree in...Work at office
- A growing organization is seeking an experienced compliance professional to support regulatory documentation, adviser disclosures, and compliance program administration. This role will work closely with clients and internal stakeholders to help maintain compliant business...
- Who We Are At Academy Sports + Outdoors our vision is to be the best sports + outdoors retailer in the country — but what truly sets us apart is our people. We’re a passionate, purpose-driven team that’s as committed to each other as we are to our customers. We’ve spent...Work experience placementLocal area
- Job Summary Responsible for supporting Neumo's compliance program, including submerchant onboarding and due diligence, transaction monitoring, compliance operations, vendor oversight, and compliance reporting. Duties and Responsibilities Conduct KYB reviews of government...Work at officeLocal areaRemote workWeekend workAfternoon shift
- USCOR JAS Forwarding (USA), Inc. is seeking an experienced customs entry specialist to manage clearance processes and ensure data accuracy. You will interact with importers, prepare post-entry documentation, and collaborate with CBP and other agencies to resolve issues...
$56.25k
...Senior Credit Risk Analyst - Auto Financing Country: United States of America It Starts Here Santander is a global leader and innovator in the financial services industry and is evolving from a high-impact brand into a technology-driven organization. Our people are at...Hourly payFull timeContract workWork experience placementWork at officeShift work$64.89k - $173.04k
...The Hispanic Alliance for Career Enhancement is seeking a Senior Analyst to join the Periodic Access Review team. This role involves executing complex access reviews, mentoring junior staff, and ensuring compliance with security controls. Strong IT compliance experience...Full time$143.62k - $229.79k
Job Description As a Consulting Actuary - ACA Risk Adjustment, you will play a pivotal role in delivering a wide array of actuarial and analytical services for our organization. Responsibilities include leading pricing strategies and actuarial initiatives for business ...$139.4k - $291.8k
Job Summary As Director of Compliance & Property Management you will lead the administrative, governance, and regulatory management of Oracle Cloud Infrastructure’s growing hyperscale data center property portfolio. This role owns property‑related strategy and execution...Full timeContract workTemporary workWork at officeLocal areaRelocationRelocation packageFlexible hours- As Director of Compliance & Property Management you will lead the administrative, governance, and regulatory management of Oracle Cloud Infrastructure’s growing hyperscale data center property portfolio. This role owns property-related strategy and execution across land...Contract work
$110k - $135k
What You’ll Do As an Associate Actuary at Imagine Pediatrics, you will leverage your actuarial expertise to conduct and present analytics on several fronts. Key projects will include forecasting, budgeting, and analyzing the financial and clinical value proposition that...Temporary work$20 - $28 per hour
Job Description Job Description Pay Range: $20.00–$28.00 per hour (production-based) Insurance Property Inspector Flexible Remote & Field-Based Opportunity | Part-Time Independent Contractor (1099) Earn $20–$28+ per Hour (Production-Based Pay) Do you enjoy...Hourly payPart timeFor contractorsLocal areaRemote workWork from homeFlexible hours- ...Senior Relativity Archiving Analyst Employment Type: Full-Time, Experienced Department: Information Technology Overview Senior Relativity Archiving Analyst will be responsible for vetting Relativity workspaces and file share folders, archiving or purging them. File shares...Full timeFlexible hours
- JOB DESCRIPTION:Assist with ongoing land operations, acquisitions activities and strategies in the Land Department.JOB RESPONSIBILITIESPrepare, maintain and process land related filesReview title opinions. Assist with curative with direction from title attorney and/or ...Work experience placement
- ...Senior FOIA Analyst Employment Type: Full Time, Mid-Level Department: Information Technology Responsibilities Receive, review, and analyze new and backlogged Freedom of Information Act (FOIA) requests. Intake incoming requests and prepare FOIA request folders. Enter request...Full timeFor contractorsWork at officeFlexible hours
- JOB DESCRIPTION:This position is responsible for the proper establishment and maintenance of division of interest ownership records.Education and Experience:5+ years related experience including Oil and Gas land contracts.Mineral, royalty and acquisition related land experienceSolid...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to GRC Analyst. Be the first to apply!


