GRC Security Analyst
ShiftCode Analytics
Mid-Senior Level GRC Security Analyst
We need a mid-senior level Governance, Risk and Compliance (GRC) Security Analyst for a 6+ month contract for a public sector client in Long Beach, CA.
The GRC Security Analyst will plan and implement policies, procedures, standards, and controls to govern the protection of corporate information systems, networks, and data. The GRC security analysts will stay up-to-date on the latest cybersecurity intelligence, including hackers' methodologies, in order to modify standards and controls that govern cybersecurity across the enterprise.
Work is currently performed remotely with the expectation that some work could be performed on-site in Long Beach in the future. Thus, it would be preferable if the resource resides in the Western USA and ideally southern CA.
Essential duties and responsibilities:
- Performing control assessments against cybersecurity framework
- Perform review of policies and supporting procedures/processes
- Perform assessments of adherence to standards
- Work closely with management on security practices
- Assess 3rd party vendors for adherence to standards
- Develop routine reports in accordance with GRC metrics
- Stay on top of changes in the industry as it relates to security
- Other security-related projects that may be assigned according to skills
Required knowledge and attributes:
- Strong preference of consulting background
- Demonstrated experience working in a team environment
- Strong analytical skills
- Great time management
- Demonstrated effective collaboration, comprehension and communication
Required education and experience:
- Bachelor's degree in Computer Engineering, Computer Science, or Information Systems Management or equivalent work experience in the field of Cybersecurity
- Possess current security certifications (e.g., CISM, SANS, CRISC, GSEC, etc.)
- Strong 3-5 years of experience in building an Information Security Risk Management program
- Understanding and familiarity with information system standards
- Understanding and familiarity with cybersecurity frameworks (NIST, ISO, SANS Top 20, HiTrust, COBIT, etc.)
- Assist in maturing the Information Security Risk Management Program by helping to define an IS risk register which includes identifying threats and risks to the organization
- Meet with business stakeholders to identify top security risks
- Assist in performing IS self-assessments to ensure systems and applications are complying with corporate policies, applicable regulatory and legal requirements, and leading industry practices
- Assist in developing and driving the implementation of security best practices and standards to mature the overall IS Risk Management Program which includes defining security system and application standards of control
- Provide solutions to identified issues and risks
- Works with the CISO to determine the acceptable level of risk for enterprise computing platforms
- Liaise with key business divisions such as HR, IM, Communications, Finance, Security Services, Engineering, Risk Management, Maintenance, and others to identify new applications and service providers in use and the associated security controls to secure the data
- Assist in performing Third Party Risk Assessments for new and existing vendor tools, on premise implementations, and third parties with access to the environment
- Assist in maturing the Third Party Risk Management program by defining security controls based on tiers of vendors
- Articulating identified risks to the business for remediation, mitigation and sign off
- Investigate incidents and events that include potential PHI/PII and other data breaches, data leakage, brand reputational risks, malware propagation, system compromises, etc.
- Mature the Data Loss Prevention Program by defining DLP rulesets in existing tools and review outputs to determine the appropriate action required
- Assist in maturing the Data Governance Program which includes defining a Data Classification and Handling Program, identifying Data Owners, and assisting with the design and implementation of a Data Classification, Digital Rights Management and Data Loss Prevention tools
- Assist in developing and maintaining Key Performance Indicators (KPIs) and Key Risk Indicators (KRIs) for the Data Governance Security Program and initiatives
- Assist in the management and maintenance of the enterprise-wide IM Security Awareness Program which includes phishing simulations, computer-based training, proactive communications on latest threats, workshops and newsletters
- Assist in developing enterprise and functional team specific presentations to promote a security mindset
- Work with the CISO to ensure the Information Security team stays abreast of new regulatory, legal and/or compliance data security requirements
- Ensure compliance with applicable legal and regulatory requirements
- Strong documentation and communications skills
- Good communication (oral and written) skills
- Proficiency with Microsoft suite of products (Teams, Word, Outlook, and Excel – required; Access and PowerPoint – preferred)
- Proven success in the past
A video interview will be required and the selected candidate will work remotely.
- ...Ellation, Inc. is seeking a Risk Analyst to enhance its corporate Information Security GRC team. The role focuses on defining processes and implementing technologies to support a comprehensive security program. You will partner across teams to ensure designed technologies...SuggestedFlexible hours
- ...currently Tuesday. What You'll Do Validate and verify Lambda's security controls and practices meet the requirements of ISO 27001, 27701... ...Have a working proficiency with at least one enterprise GRC or TPRM platform: AuditBoard, Vanta, OneTrust, Whistic or equivalent...SuggestedWork at officeLocal areaWork from homeFlexible hours
- ...The Squires Group in Arlington, VA is seeking an experienced SAP Security Analyst to support a major ERP modernization initiative in a federal environment. This position involves implementing and maintaining application security within an SAP S/4HANA landscape, with 7...SuggestedRemote work
- ...BeiGene, Ltd. is hiring a Senior GTS GRC Analyst based in the United States, New York, Town of Poland. This role involves enhancing compliance and security posture while managing risks across various frameworks, including GDPR and ISO standards. The ideal candidate will...SuggestedRemote work
$62k - $87k
...Busey Bank is seeking a GRC Analyst responsible for ensuring effective implementation of information security and cybersecurity controls. This role involves monitoring performance, leading projects, and supporting systems that maintain data integrity. Benefits include...Suggested- ...Title: GRC Security Analyst Client Industry: Oil & Gas Location: Houston, TX Schedule: 100% Onsite Monday through Friday Job Type: Contract until EOY 2025 Daily operational activity will be processing solution risk assessments, communicating...Contract workLocal areaMonday to Friday
$45k - $50k
...complex challenges, improve public health, strengthen national security, and make government services more effective and efficient. Our... ...OverviewThe Entry-Level Cybersecurity Governance, Risk, and Compliance (GRC) Assessor supports cybersecurity compliance and risk management...InternshipLive in- ...MarkMonitor Inc. is looking for a Governance, Risk, and Comp Security Analyst in Meridian, ID. This full-time hybrid role involves leading client... ...have 2-4 years of relevant experience, solid knowledge of GRC processes, and skills in managing multiple workstreams. Join us...Full time
- ...NAVA Software solutions is looking for a Security GRC Analyst Details: Security GRC Analyst Location: San Francisco , CA - Hybrid Duration: 6 months CTH Qualifications: Analyst with 2+ years' experience and with good understanding...
- ...Feitong Buke is seeking a SAP Security Analyst for a 6–12 month role in White Plains, NY. The analyst will support SAP GRC Access, Process Control, and S/4 Hana security management, focusing on troubleshooting and enhancing functionality within various ERP applications...
$89.6k - $194k
...SAP Application Security and GRC Analyst (Sr.) - U.S. Citizenship Required Category: ERP/CRM/Tools Main location: United States, Virginia, Fairfax Alternate Location(s): United States, Louisiana, Lafayette United States, Virginia, Lebanon United States, Tennessee...Full timeContract workWork at officeLocal area2 days per week- ...Title: Information Security GRC Analyst Location: Remote, EST Time Duration: 7+ Months JOB DESCRIPTION Responsibilities: Support the development and implementation of an enterprise-wide business continuity program. Execute tasks associated...Remote work
- ...every day. This role sits within theInformation Security Governance, Risk and Compliance (GRC) team, which reports directly into the CISO organization... ...this role you will: The Information Security GRC Analyst with a Risk and Policy focusis responsible...Contract workImmediate start
$155k - $165k
...Senior Information Security GRC Analyst Remote, US Branch is on a mission to empower workers with financial freedom. We do this by helping companies accelerate payments and providing working Americans with accessible, free financial services. We're committed to...Daily paidRemote workHome officeFlexible hours$88.95k - $150.43k
...Senior Security GRC Analyst and Internal Security Assessor (ISA) At Commerce, our mission is to empower businesses to innovate, grow, and thrive with our open, AI-driven commerce ecosystem. As the parent company of BigCommerce, Feedonomics, and Makeswift, we connect...Work at officeLocal area3 days per week- ...Sr. Information Security GRC Analyst Tire Rack is seeking a Senior Information Security GRC Analyst to support and advance our Information Security Governance, Risk, and Compliance (GRC) program. In this role, you will assess and strengthen IT and security controls...Weekend work
$94.1k - $164.8k
...Job Summary: The Information Security GRC Analyst III managed day to day, short and long term information security risks and ensures activities are within risk tolerance and in compliance with approved risk management policies, procedures and limits. Essential...Temporary workWork experience placementWork at office$90k - $135k
...opportunities, and inclusive programs that enable you to perform at your best. Together we win! THE OPPORTUNITY The Senior GRC Information Security Analyst role will be part of the Information Security Governance, Risk, & Compliance (GRC) team at Banc of California. The...Local areaImmediate startFlexible hours- ...Skills and Qualifications Minimum Years | Skills/Experience 3 - Experience in a GRC, cybersecurity, or compliance role. 3 - Hands-on experience with GRC platforms (Diligent preferred). - Strong understanding of NIST CISF 2.0, HIPPA and state-...
$60 - $65 per hour
...Information Security GRC Analyst Job Type: Contract Contract Length: 6 months Pay Range: $60-$65/hr Start Date: ASAP Location: Remote (EST) About the Opportunity Our client, a leader in the Cloud Infastructure industry, is looking for a skilled Information Security GRC...Contract workFor contractorsImmediate startRemote work$80k - $105k
...Associate GRC Analyst IXL Learning, developer of personalized learning products used by millions of people globally, is seeking an Associate GRC Analyst to join our growing security team. In this role you will support IXL’s internal cybersecurity governance, compliance...Full timeWork at office- ...fundamental components of our information assurance and cyber security program. This position leads the IT security risk and audit... ...requirements (e.g. PCI DSS) and IT best practices. GRC Risk Analyst Skills & Requirements: ? 7-10 years of IT Audit experience...Work experience placement
- HireRight in Nashville, TN is seeking a Cyber Security Auditor to conduct comprehensive security audits and assessments. This position requires strong communication skills and attention to detail, ensuring compliance with ISO standards. The ideal candidate holds a degree...
- ...Archer Administration/Configuration), Preferred 10%2B Years (Enterprise/Government GRC Environments) Job Description Job Description: Seeking an experienced RSA Archer GRC Security Analyst to support enterprise governance, risk, and compliance initiatives through the...
- CFC- Chatham Financial Corporation is seeking an Information Security Governance, Risk and Compliance Analyst with a Risk and Policy focus. You will be responsible for assisting in security risk management, leading risk assessments, and collaborating with stakeholders...Contract work
$130k - $160k
Asana is hiring a Security Risk and Compliance Analyst in San Francisco. This role involves maturing Asana’s compliance programs across various security standards like SOC 2, ISO 27001, and FedRAMP. The successful candidate will support audits, enhance control frameworks...- Florida International University is seeking an IT Security Analyst to support its governance, risk, and compliance program. This role focuses on accessibility compliance and third-party risk management, ensuring the integrity and confidentiality of university systems....
$65k - $70k
Florida International University - Board of Trustees is seeking an IT Security Analyst to support the university’s governance, risk, and compliance program. This role involves evaluating vendor compliance, conducting risk assessments, and ensuring system integrity. Applicants...- HireRight, LLC is seeking a Cyber Security Auditor based in Nashville, TN. This role involves conducting internal audits to ensure compliance with security standards. The ideal candidate will have experience in cyber security and strong communication skills. Key responsibilities...
- Reports To: Business Information Security Officer Department: Information Technology Location... ...apart. Position Overview: The Security Analyst supports the Business Information Security... ...and compliance objectives. Support GRC service delivery, documentation, and vendor...Full timeLocal area
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to GRC Security Analyst. Be the first to apply!
- grc analyst United States
- entry level security analyst United States
- security analyst United States
- junior security analyst United States
- security analyst remote United States
- bond analyst United States
- entry level information security analyst United States
- security operations analyst United States
- work from home security analyst United States
- senior information security analyst United States

