GRC Security Analyst
ShiftCode Analytics
Mid-Senior Level GRC Security Analyst
We need a mid-senior level Governance, Risk and Compliance (GRC) Security Analyst for a 6+ month contract for a public sector client in Long Beach, CA.
The GRC Security Analyst will plan and implement policies, procedures, standards, and controls to govern the protection of corporate information systems, networks, and data. The GRC security analysts will stay up-to-date on the latest cybersecurity intelligence, including hackers' methodologies, in order to modify standards and controls that govern cybersecurity across the enterprise.
Work is currently performed remotely with the expectation that some work could be performed on-site in Long Beach in the future. Thus, it would be preferable if the resource resides in the Western USA and ideally southern CA.
Essential duties and responsibilities:
- Performing control assessments against cybersecurity framework
- Perform review of policies and supporting procedures/processes
- Perform assessments of adherence to standards
- Work closely with management on security practices
- Assess 3rd party vendors for adherence to standards
- Develop routine reports in accordance with GRC metrics
- Stay on top of changes in the industry as it relates to security
- Other security-related projects that may be assigned according to skills
Required knowledge and attributes:
- Strong preference of consulting background
- Demonstrated experience working in a team environment
- Strong analytical skills
- Great time management
- Demonstrated effective collaboration, comprehension and communication
Required education and experience:
- Bachelor's degree in Computer Engineering, Computer Science, or Information Systems Management or equivalent work experience in the field of Cybersecurity
- Possess current security certifications (e.g., CISM, SANS, CRISC, GSEC, etc.)
- Strong 3-5 years of experience in building an Information Security Risk Management program
- Understanding and familiarity with information system standards
- Understanding and familiarity with cybersecurity frameworks (NIST, ISO, SANS Top 20, HiTrust, COBIT, etc.)
- Assist in maturing the Information Security Risk Management Program by helping to define an IS risk register which includes identifying threats and risks to the organization
- Meet with business stakeholders to identify top security risks
- Assist in performing IS self-assessments to ensure systems and applications are complying with corporate policies, applicable regulatory and legal requirements, and leading industry practices
- Assist in developing and driving the implementation of security best practices and standards to mature the overall IS Risk Management Program which includes defining security system and application standards of control
- Provide solutions to identified issues and risks
- Works with the CISO to determine the acceptable level of risk for enterprise computing platforms
- Liaise with key business divisions such as HR, IM, Communications, Finance, Security Services, Engineering, Risk Management, Maintenance, and others to identify new applications and service providers in use and the associated security controls to secure the data
- Assist in performing Third Party Risk Assessments for new and existing vendor tools, on premise implementations, and third parties with access to the environment
- Assist in maturing the Third Party Risk Management program by defining security controls based on tiers of vendors
- Articulating identified risks to the business for remediation, mitigation and sign off
- Investigate incidents and events that include potential PHI/PII and other data breaches, data leakage, brand reputational risks, malware propagation, system compromises, etc.
- Mature the Data Loss Prevention Program by defining DLP rulesets in existing tools and review outputs to determine the appropriate action required
- Assist in maturing the Data Governance Program which includes defining a Data Classification and Handling Program, identifying Data Owners, and assisting with the design and implementation of a Data Classification, Digital Rights Management and Data Loss Prevention tools
- Assist in developing and maintaining Key Performance Indicators (KPIs) and Key Risk Indicators (KRIs) for the Data Governance Security Program and initiatives
- Assist in the management and maintenance of the enterprise-wide IM Security Awareness Program which includes phishing simulations, computer-based training, proactive communications on latest threats, workshops and newsletters
- Assist in developing enterprise and functional team specific presentations to promote a security mindset
- Work with the CISO to ensure the Information Security team stays abreast of new regulatory, legal and/or compliance data security requirements
- Ensure compliance with applicable legal and regulatory requirements
- Strong documentation and communications skills
- Good communication (oral and written) skills
- Proficiency with Microsoft suite of products (Teams, Word, Outlook, and Excel – required; Access and PowerPoint – preferred)
- Proven success in the past
A video interview will be required and the selected candidate will work remotely.
$209.25k - $271.71k
...challenges at scale, and helping to create safer, more civil shared experiences for everyone.As a member of the Roblox Security Governance, Risk, and Compliance (GRC) team, you will play a key role in supporting the Security team’s mission. The GRC team is at the heart of...SuggestedFull timeWork experience placementH1bWork at officeLocal areaVisa sponsorshipMonday to Friday$114k - $139k
Reno, NV / Remote - USAdministration - Enterprise Information Security /Full-Time /RemoteAs a GRC Security Analyst, you will serve as a fully qualified, experienced professional responsible for ensuring Clear Capital adheres to all relevant security standards, regulations...SuggestedFull timeTemporary workWork experience placementRemote work$117.2k - $176.7k
...place! Agentforce is the future of AI, and you are the future of Salesforce.The ExperienceLocation: San Francisco, CAThe Senior Security GRC Analyst role is part of our Assurance team, sitting at the intersection of internal operations and external audit relationships....SuggestedFull timeWork at office- A leading energy company is seeking an SAP Security support professional to manage security applications across multiple SAP environments. You will ensure compliance with security guidelines, advocate for standard solutions, and maintain user security management. Ideal...SuggestedFlexible hours
- ...RSA Archer Administration/Configuration), Preferred 10+ Years (Enterprise/Government GRC Environments) Job Description: Seeking an experienced RSA Archer GRC Security Analyst to support enterprise governance, risk, and compliance initiatives through the...Suggested
- The Information Security GRC Analyst, will report to the Director, IT Compliance. This role will interact with multiple departments, manage compliance readiness, provide support for our central GRC repository, and conduct risk/gap assessments based on industry leading...Full timeCasual workWork at officeLocal areaMonday to FridayAfternoon shift
$89.6k - $194k
Position Description CGI is seeking a Senior SAP GRC and Application Security Analyst to join an SAP S/4HANA Greenfield implementation project for a large government contract. As a senior-level SAP GRC and Application Security Consultant, you will be involved in every...Contract workWork at officeLocal area2 days per week- Senior GRC Information Security Systems Analyst Location: Minneapolis, MN (Preferred) or one of the following office locations: Anchorage, AK Boise, ID Chicago, IL Costa Mesa, CA Dallas, TX Denver, CO Des Moines, IA Minneapolis, MN Missoula, MT New York, NY Palo Alto...Full timeContract workWork at office
- • Work from remotely or from home • Complete back office support • Zero micro-management We're a perfect fit for top account managers and existing entrepreneurs. Be your own boss, but have the power of a thriving startup. We're a next-generation platform. We are ...Full timeRemote workWork from homeFlexible hoursWeekday work
- ...The Compliance Analyst is responsible for completing and maintaining system security plans (SSP) for new and existing systems. The system security plans are documented in the Governance, Risk, Compliance tool. This requires close coordination with IT project teams, tech...Full timeWork at officeLocal areaRemote workMonday to Friday2 days per week1 day per week
- ...Insurance. Job Description Position Details: Industry Manufacturing Work Location Moline IL 61265 Job Title IT Security Analyst Duration 3 Years (Strong possibility of extension) Job Description: • Duties: Learns how to identify, analyze and...Full time
$29.94 - $32.04 per hour
...The IT Security Analyst will assist the Enterprise IT Security Risk Management Team in monitoring, analyzing, and responding to security events to safeguard the confidentiality, integrity, and availability of our healthcare systems and data. This position will work...Full timeWork at officeMonday to Friday$80k - $100k
...backed by leading institutional investors GTCR, Genstar Capital, and Blackstone. Learn more at . Mission Statement The IT Security Analyst supports the organization’s cybersecurity operations by monitoring security alerts, analyzing potential threats, and assisting...Hourly payFull timeWork at office$95k - $105k
...Magnetic Technologies, please visit: . Basic Purpose and Objective of the Position: We are seeking a skilled Information Security Analyst to identify, investigate, and mitigate potential security risks to protect our company’s information systems and computer...Permanent employmentFull timeTemporary workWork experience placementFlexible hours$90k - $115k
...position due to Department of Defense restrictions. Our Senior Security Policy Analyst is responsible for developing, implementing, and... ...with hands-on experience in governance, risk, and compliance (GRC) operations, and excels at clear communication and high-quality...Full timeContract workFor contractorsWork at officeLocal areaImmediate startRemote work3 days per week- ...Summary of Purpose: The Senior IT Security Analyst serves as INPO's primary cybersecurity risk authority, providing oversight and guidance... ...management tools (e.g. Qualys) and Governance, Risk and Compliance (GRC) platforms (e.g. ServiceNow GRC, X-Analytics) Performs other...Full timeWork experience placement
- ...and cultures. At IRI, we know that our success is directly tied to our clients’ success. Job Description Position: IT Security Analyst Duration: 1 Year Location: Hancocks Bridge, New Jersey (Alloway Creek Neck Road) Direct client: Immediate Interview...Full timeFor contractorsWork experience placementWork at officeImmediate start
- ...IT Security Analyst needs 3+ years of experience in IT or IS or Compliance, health sector IT Security Analyst requires: SOC 1-2, ISO 27001/2, PCI DSS, HITRUST, SANS, NIST IT degree Strong Project management Familiarity and understanding of broad range...Full time
- ...background in threat detection, incident response, and the Microsoft security suite. This role requires a blend of technical expertise,... ...technical teams. ~ Proficiency with compliance tracking tools, GRC platforms, and project management tools a plus. ~ Willingness...Permanent employmentFull timeContract work
- ...Reedsburg Area Medical Center is looking for an IT Security Analyst to help safeguard our technology, support innovative security solutions, and play a key role in protecting the information that keeps our organization running. This position will be 100% onsite in...Full time
- ...The Sr. Information Security Analyst is responsible for assessing information risk and facilitates remediation of identified vulnerabilities for IT security and IT risk across the enterprise. Assesses information risk and facilitates remediation of identified vulnerabilities...Full time
- IT Security Analyst Location: Remote - U.S. Only (or Hybrid in Denver, CO) Type: Full-Time Clearance: Must pass FBI fingerprint and background check in multiple states About GovWorx GovWorx is helping public safety rise to today's greatest challenge: the loss of experience...Remote jobFull time
$110k - $130k
...universal life, critical illness, accident insurance, and even pet insurance Purpose Responsible for performing risk assessment, security analysis, and developing remediation plans Essential Duties & Responsibilities IT Security Administration: The primary...Full timeRemote workFlexible hours- ...DescriptionWants:Ø In-depth knowledge and understanding of information risk concepts and principles, as a means of relating business needs to security controlsØ Knowledge of an experience in developing and documenting security controls and test plans/scripts.Ø Experience with SOX...Work experience placement
$96.4k - $144.6k
...Castle, Delaware, United StatesSalary: $96,400.00 - $144,600.00Category: Technology, Technology ManagementCompany: CitiThe Security Technology Analyst is a seasoned security systems professional role. Applies in-depth disciplinary knowledge, contributing to the...Full time- ...doors a fair shot at reaching his or her potential.Success Academy is growing rapidly and security is at the forefront of enabling that growth. We are seeking a Senior Security Analyst to join our Information Security & Privacy team. This individual will serve as a senior...Work at officeImmediate startVisa sponsorship3 days per week
$102k - $112k
...as electrical, mechanical, lighting, air conditioning, heating, security, fire protection, and power generation systems—in virtually... ...government. Job Summary EMCOR Group, Inc. seeks a Security Analyst for Identity and Access Management (IAM) who will support EMCOR...Flexible hours$75k - $137.5k
...culture where all of our employees feel respected, valued and have an opportunity to contribute to the company’s success. As a Security Analyst within PNC’s Technology organization, you will be based in Pittsburgh, PA; Cleveland, OH; or Birmingham, AL. The work shift...Full timeTemporary workPart timeWork experience placementWork at officeShift work- ...environment that is respectful and inclusive for everyone.As a Security Analyst at Lucid Software, you will protect our corporate assets,... ...and employees. You will focus on the execution of day-to-day GRC (Governance, Risk, and Compliance) operations, third-party risk...Remote work
$110k - $120k
...advanced manufacturing and engineering organization is seeking a Security Analyst to help strengthen and mature its enterprise cybersecurity... ...environments.Experience with governance, risk, and compliance (GRC) platforms and compliance tracking tools.Knowledge of cybersecurity...Remote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to GRC Security Analyst. Be the first to apply!
- grc analyst United States
- application security analyst United States
- entry level information security analyst United States
- entry level security analyst United States
- information security analyst United States
- senior security analyst United States
- rate analyst United States
- IT security analyst United States
- national security analyst United States
- work from home security analyst United States


