GRC Analyst
NetCov
GRC Analyst
Network Coverage is seeking talented and experienced Analysts to join our growing GRC Team. Candidates will primarily work from home, however occasional dispatch may be required for client-facing meetings, presentations, and consultations and/or training.
Applicants must have 2-4 years of experience in an Information Security role for this position. It is essential to demonstrate a strong working knowledge of Information Security and regulatory standards, especially focusing on CMMC (800-171 rev2) and the CMMC ecosystem. Effective communication with clients and team members, as well as the efficient resolution of time-sensitive issues, are mandatory skills.
A GRC Analyst working within the Network Coverage Governance, Risk and Compliance Team will be expected to work within deadlines and will adjust to ever-changing client needs and scenarios within a fast-paced environment.
Level: Mid-Level
Reports To: GRC Team Lead
Basic Scope and Function:
As a GRC Analyst at Network Coverage, you will be part of the GRC Team, and your expertise will be an integral part of our all-encompassing V-CISO deliverable with a strong focus on CMMC implementation (NIST 800-171 rev2). You be working closely with team members and clients in various locations across the US and overseas and will fulfill the role of subject matter expert, advising upon the on the most effective approach to security, regulatory compliance and continuously developing and helping to implement Network Coverage's targeted approach. As a GRC Analyst, you will be responsible for Security Auditing, Readiness Assessment, Policy Writing, Risk Assessment, client onboarding and coordination of implementation treatment resulting from GAP assessment. As a technical solution provider, you will function as the subject matter expert and deliver a highly comprehensive Plan of Action and Milestones and may be expected to report on a scheduled cadence in a client facing capacity, under the guidance of the GRC Team Leadership.
Due to the nature of the work, flexible work hours may also be required if requested for client onsite or after-hours support of accounts in differing regions.
Primary/Essential Duties and Key Responsibilities:
- Interface with client points of contact as required for onboarding/post sales activity and/or recurring check ins and inquiries.
- Continuously monitor and triage requests flowing through an inbound ticket queue.
- Participate in the design and execution of risk assessments and security audits.
- Participate in the management of employee awareness campaigns for both staff and clients, including phishing simulations and awareness training.
- Perform CMMC Readiness assessment against 110 controls, delivering a comprehensive SSP and POAM with assisted attestation and SPRS reporting.
- Assist clients with their assessments with C3PAOs and 3PAOs.
- Create and Maintain network and data flow diagrams
- Maintain up-to-date detailed knowledge of the IT security industry including awareness of new or revised security solutions, regulatory requirements, improved security processes, and the development of new attacks and threat vectors.
- Document best practices and user guides using available collaboration tools and workspaces.
- Develop and maintain both internal and client-facing documentation, policy libraries and delivery metrics for end-to-end client security and compliance.
- Provide timely, detailed, and complete reports on vulnerabilities, security events and incidents in a client facing setting.
- Triage internal security and permissions requests from staff, including but not limited to systems access and employee terminations.
- Oversee upkeep of internal SOP, ensuring adjustments to protocol are made as tools and methods evolve.
- Perform QA workflow as necessary to improve upon consistency of product and client experience.
- Coordinate resources and/or route audit requests appropriately for high volume or regulated client points of contact.
- Ability to manage a changing and evolving workload and function as decision-maker where needed.
- Provide after-business hours support if requested and as applicable to geographically distributed client base.
- Perform other duties and tasks as assigned.
Knowledge, Skills and Abilities (KSAs) Required:
- Strong problem-solving, analytical skills and the ability to work autonomous.
- Excellent customer service skills, including understanding how to de-escalate, how to soothe and how to deliver the most efficient solution.
- Strong communication skills, both verbal and written.
- Familiarity with regulatory frameworks such as NIST/CMMC, ISO 27001, HIPAA/Hitech, GDPR are a big plus.
- Strong organizational, operational, and inter-personal skills
- Strong familiarity with Windows desktop and server operating systems.
- Strong familiarity with Microsoft Office 365 and Azure Active Directory support and implementation.
- Strong understanding of networking concepts, familiarity with routers, firewalls, access points, IDS/IPS and VPN.
- Familiarity with Email threat protection tools and concepts.
- Familiarity with RMM and asset management tools are a big plus.
- Understanding of tools and processes used in security monitoring and incident response
- Experience with Endpoint Detection & Response (EDR) tools
- Ability to understand vulnerabilities at a technical level and capable of recommending and effectively communicating mitigation strategy
- Ability to communicate and write in English professionally
- Reliable personal transportation for use in traveling to clients' offices is essential.
Minimum Experience and Education Required:
- 2-4 years of experience working in an Information Security capacity.
- No College Education Required.
- CompTIA Security+ or similar.
- High School Diploma or Accredited GED.
- CMMC RP/RPA/CCP will be considered preferentially.
Supervisory/Managerial Experience and Responsibility:
- No supervisory or managerial experience required.
- No supervisory or managerial duties in this role.
Work Environment:
Work is primarily performed in a remote capacity and will require the use of video conferencing software along with a company issued webcam. Work involves operation of computer equipment for 8 hours or more daily.
Network Coverage remote team members must ensure the availability of a stable, reliable, and secure internet connection with adequate bandwidth to support video calls as needed throughout the course of their shift and while performing on-call duties.
Physical Requirements:
- Sitting
- Standing
- Moving of self
- Moving of equipment
- Communicating
- Visual acuity for driving and computer work
- Kneeling
- Crawling
- Reaching
- Stooping
- Lifting
- Pulling
Job Type: Full-time
- The TeamThe Analyst Governance, Risk, and Compliance, a member of the Information Security - Governance, Risk and Compliance (GRC) team, focuses on implementing and maintaining governance frameworks, managing risk remediation activities, and ensuring adherence to regulatory...SuggestedWork experience placementWork at officeLocal area
$138k - $173k
THE POSITIONOur roster has an opening with your name on itFanDuel is seeking a Senior Technology Governance, Risk & Compliance (GRC) Analyst to join its Technology GRC team as a strategic specialist supporting our first line of defense (1LOD) function. This role offers...SuggestedTemporary workWork at officeLocal areaWorldwideShift work- ...customers get the high-quality gear they need to make the most of their adventures. We are BUILT FOR THE WILD.About the RoleThe SAP GRC Analyst will be responsible for GRC administration and segregation of duties (SoD) analysis. You will be responsible for evaluating risks...SuggestedFull timeLocal area
$80.05k - $165k
...end-to-end issue management activities, including intake, validation, prioritization, assignment, remediation tracking, and closure of GRC-related issues in ServiceNow, ensuring timely resolution, appropriate evidence, and alignment with audit, risk, and regulatory...SuggestedFull timeWork at office- ...to its workforce, Kokosing is the winning team.Job Description:We are looking for a Security Governance, Risk, and Compliance (GRC) Analyst to support and mature our security and compliance programs across a large construction organization. This role focuses on maintaining...SuggestedFull timeFor contractors
$130k - $170k
...performance and extend healthspan. The Governance, Risk, and Compliance (GRC) team helps ensure technology and cybersecurity risks are... ...an execution-oriented Senior Governance, Risk, and Compliance Analyst to lead the day-to-day execution and support the ongoing operation...Full timeWork at officeRelocation- ...Security Officer (CISO), to shape long-term cybersecurity strategy.Work in a greenfield environment where you'll help build foundational GRC processes rather than simply maintaining existing programs.Collaborate across Information Security, IT, Legal, Compliance, Privacy,...Contract workFlexible hours
- ...SoftwareClient: WiproContact: Meghana GorusuCompany: SRI Tech SolutionsTitle: GRC AnalystLocation: Portland,ORDuration: Full TimeWe are seeking a detail-oriented and technically proficient Principal GRC Analyst to join our Information Security team, with a focus on validating...Full time
- Job OverviewThe GRC Analyst I is responsible for supporting the organization's Governance, Risk, and Compliance (GRC) program through risk management, policy governance, compliance monitoring, reporting, and continuous improvement activities. This role assists with risk...Full time
- ...ROLE, NOW OR IN THE FUTURE. (e.g., H-1B, STEM OPT, TN, etc.)About the RoleAs a member of the Information Security team, the IS GRC Senior Analyst - Risk & Compliance will be responsible for understanding the firm’s security risk and compliance requirements. You will...Full timeContract workWork experience placementH1bRemote workVisa sponsorshipRelocation packageMonday to Friday
- ...TXEmployment Type: Full TimeIndustry: Computer SoftwareClient: WiproContact: Meghana GorusuCompany: SRI Tech SolutionsJob Title: Technical GRC Analyst with SQL DBDuration: Full timeLocation: Austin TX - Locals onlyJob Description:Skills: Technical GRC Analyst and SQL DBStrong...Local area
- ...Experience Experience in Financial Services domain expertise in one or more of the following areas - Governance, Risk & Compliance (GRC), Regulatory Reporting, Financial Risk. Experience in requirement gathering, process mapping, functional analysis, and Data validation...Full timeTemporary workRelocation
- Job Summary:The IT Governance, Risk, and Compliance (GRC) Lead Analyst serves as a subject matter expert responsible for leading the design, implementation, maturity, and continuous improvement of the organization’s IT governance, risk management, and compliance programs...Full timeWork at office3 days per week
- ...Ruleset Security is offering an exciting internship opportunity for a Governance, Risk, and Compliance (GRC) Analyst. This role is perfect for students or recent graduates looking to gain hands-on experience in cybersecurity, compliance, and risk management. The internship...Full timeInternship
- ...GRC Analyst Join our team as a GRC Analyst and play a key role in regulatory compliance, IT risk management, security. You'll assess risks, support audits, and develop policies that align with industry standards. If you have a solid IT security background, experience...Casual workWork at officeWork from homeHome officeNight shiftWeekend work
- ...raised our Series B and have grown 800% over the last 12 months. The Opportunity Ivo is seeking a detail-oriented and proactive GRC Analyst to support the company's compliance, risk management, and security assurance initiatives. This role will play a key part in...Contract workWork at officeRemote workVisa sponsorshipRelocation packageFlexible hours
- ...continues to expand its technology capabilities and strengthen its security posture. We are seeking a Governance, Risk & Compliance (GRC) Analyst to support critical governance, risk management, compliance, and audit readiness initiatives. This role is ideal for a detail-...
- ...The GRC Cybersecurity Analyst III is a senior level contributor responsible for leading ICCU’s Governance, Risk, and Compliance (GRC) initiatives within the scope of the IT domain. This role provides strategic oversight of cyber and IT operational risk assessments, regulatory...Full timeWork experience placementWork at office
- ...Job Title: Governance, Risk, and Compliance (GRC) Analyst Key Responsibilities: Governance Develop, maintain, and enforce IT security policies, standards, and procedures. Support internal governance frameworks and ensure alignment with industry best...
- ...GRC (3rd Party Risk) Analyst Duration: 12 – 24 Month Project Engagement The GRC Analyst is responsible for managing Client's governance, risk, and compliance functions, with a specific focus on third-party risk management. This role ensures Client operates in a compliant...
- ...be a US Citizen or Green Card holder NO THIRD PARTIES Only local candidates will be contacted We are seeking a highly motivated GRC Analyst to support the modernization and transformation of our Governance, Risk, and Compliance (GRC) program. This role is ideal for someone...Contract workLocal area
- ...audit activities Develops, maintains, and reports on operational compliance metrics General Governance, Risk, and Compliance (GRC) Support: Leads process analysis, development, & improvement efforts Assists in developing, testing, and delivering solutions,...Work experience placementWork at officeRemote work
- ...GRC Analyst The GRC Analyst is responsible for helping to provide compliance and oversight of all our Corporation's Authorization and Accreditation (A&A) requirements as it relates to our government business including but not limited to DIA, DoD, DCSA, etc. Additionally...
- ...the Role Hotman Group is a boutique cybersecurity and GRC consulting firm doing meaningful work for clients who need GRC... ...What You Will Do As an Experienced or Senior GRC Analyst at Hotman Group you will work directly with clients to help them...Permanent employmentFull timeContract workRemote work
- ...Sr. GRC Analyst Sr. GRC Analyst Remote USC or GC only must be in the EST (highly preferred) or CST time zone. Brief Job Description ~6-8 years of experience as a GRC Analyst ~ Will be involved with assisting the clients internal GRC team to help with Third...Remote work
- ...environment, demand excellence, and want to help build the future of finance, we invite you to join us. The Role Rogo is hiring a GRC Analyst to support our customer trust, security assurance, and compliance programs as we scale globally. This role plays a critical part...
$95k - $105k
...Sr. GRC Analyst Remote About Subsplash Subsplash is an exciting award-winning team of 280+ mission-driven people who are committed to our core values of humility, innovation, and excellence. Founded in 2005, we've remained family owned and operated while pioneering...Remote work$134k - $202k
...GRC Analyst Remote - United States About Vercel: Vercel is the agentic infrastructure company. We free people and agents to ship what's next. For more than a decade, Vercel has shaped how the web is built. As the team behind Next.js, v0, and AI SDK, we create...Work at officeRemote workWork from homeWorldwideMonday to FridayFlexible hours- ...regulatory excellence depends on strong governance, risk, and compliance practices and this role sits at the center of that work. As a GRC Analyst, you will manage compliance frameworks, assess organizational risk, and help Zywave maintain the trust of the customers it serves...Remote work
- ...simulations, analysis, and decision-making, accelerating discovery and driving faster innovation. THE POSITION NMC² is hiring a GRC Analyst to join the Information Security team, reporting to the GRC & Privacy Manager and based at our Dallas, TX offices at Victory...Temporary workFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to GRC Analyst. Be the first to apply!


