997,024open jobs
59,481companies
165,643added this week
Browse all
Salary
≈ $58k – $135k per year (Estimated)
Location
Remote (location not specified, PT hours)
Seniority
Junior · 2+ years exp
Employment
Full-Time

Confirmed on the employer's own hiring board on Oct 1, 2026. First seen by Alion on Jul 15, 2025. Bright Defense scores B on the Alion truth index.

Overview
Company
Impact
Profile match
We provide managed SOC 2, ISO 27001, HIPAA, and CMMC compliance services for small and mid-size businesses through CISSP certified experts.

Bright Defense · Governance Team · Now Hiring

GRC Analyst II

Governance - Security Policy, Risk & Compliance

Full-TimeRemoteGovernance2-3 Years Experience

You’ll play a critical role in helping our customers establish and implement robust security governance programs - serving as their trusted point of contact for policy development, gap reviews, compliance readiness, and clear communication of security requirements from day one.

About the role

As a GRC Analyst II on our Governance Team, you’ll work directly with clients to support customer onboarding, policy development, gap reviews, and compliance readiness. You’ll explain governance frameworks and security requirements clearly to non-technical stakeholders, coordinate cross-functional handoffs with SecOps and Offensive Security, and help clients build the governance foundation they need to pass audits and maintain strong security postures.

Key responsibilities

Governance & policy

  • Support customer onboarding and kick-off, ensuring clients understand their security program roadmap and governance objectives
  • Draft, review, and maintain information security policies, procedures, and controls
  • Clearly communicate and explain governance frameworks and policy requirements to non-technical stakeholders
  • Develop and track risk registers, mitigation plans, and corrective action plans

Gap assessment & audit readiness

  • Perform gap assessments to identify areas for improvement against ISO 27001, SOC 2, NIST CSF, and other relevant frameworks
  • Support clients through audit readiness and defense - collecting evidence, tracking findings, and remediating gaps
  • Prepare clear, high-quality documentation and status reports for customers
  • Participate in regular customer status meetings and provide input on governance milestones and deliverables

Cross-functional coordination

  • Coordinate handoffs between governance activities and technical teams - Offensive Security, SecOps, and beyond
  • Serve as the trusted governance point of contact for assigned client accounts
  • Align policy and risk activities with the broader security program strategy for each client
  • Contribute to continuous improvement of governance procedures, templates, and documentation standards

Cross-functional collaboration

Security Consultants

SecOps Team

Offensive Security

Client Stakeholders

Requirements

Experience & frameworks

  • 2-3 years of relevant experience in information security, compliance, or risk management
  • Solid understanding of ISO 27001, SOC 2, NIST CSF, and other common security frameworks
  • Proven experience developing and implementing security policies and controls
  • Strong attention to detail and ability to manage multiple client deliverables simultaneously

Communication & availability

  • Exceptional written and verbal communication skills are mandatory - you must confidently explain security policies and governance requirements to diverse audiences
  • Collaborative, customer-focused mindset - you thrive in a cross-functional team environment
  • Must support US Eastern and Pacific time zones, 9AM-6PM

Nice to have

  • ISO 27001 Lead Implementer, CISA, CISSP (Associate), Security+, or similar certification
  • Experience working with clients in regulated industries - finance, healthcare, or SaaS
  • Exposure to GRC or risk and compliance management tools

Tools & platforms

  • GRC platforms - Drata, Vanta, Thoropass, or equivalent
  • Asana or similar PM tools for task and deliverable tracking
  • Google Workspace or Microsoft 365 proficiency
  • Documentation and evidence management tooling experience

Relevant certifications

ISO 27001 Lead ImplementerCISACISSP (Associate)CompTIA Security+CISMCC (Certified in Cybersecurity)ISACA Cybersecurity Fundamentals

Why you’ll love this role

Directly help customers build trust and strengthen their security governance posture from day one

Develop hands-on expertise with real-world frameworks, audits, and compliance practices across diverse client verticals

Be part of a supportive team that values strong communication, clear documentation, and continuous learning

Compensation & perks

  • Competitive base salary - range shared during screening
  • Remote-first with flexible hours within the ET/PT coverage window (9AM-6PM)
  • Certification reimbursement - ISO 27001 Lead Implementer, CISA, CISSP, Security+, and more
  • Direct collaboration with Bright Defense co-founders and Governance leadership
  • Broad client exposure across defense, healthcare, fintech, and SaaS verticals
  • Clear growth path toward GRC Analyst III and Senior GRC roles

Bright Defense is an equal opportunity employer. We build diverse, high-trust teams. | brightdefense.com

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
997,024 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Security
Similar stack
Same company
In your city
≈ $36k – $103k per year (Estimated) • Remote (likely EAEU) • 2+ years exp • Bachelor's Degree • Tbilisi
DevOps
Azure
Cybersecurity
Active Directory
Apply
≈ $11k – $31k per year (Estimated) • Remote (likely EAEU) • 2+ years exp • Bachelor's Degree • Almaty
DevOps
Azure
Cybersecurity
Active Directory
Apply
≈ $89k – $167k per year (Estimated) • Remote (United States) • Full-Time
Python
PowerShell
Bash
DevOps
GCP
Azure
AWS
Docker
Kubernetes
IAM
Windows
Cybersecurity
Nmap
Nessus
OpenVAS
SIEM
DLP
Apply
≈ $15k – $31k per year (Estimated) • Remote (EAEU) • 1+ year exp • Moscow
DevOps
Linux
Cybersecurity
SIEM
DLP
Apply
≈ $56k – $130k per year (Estimated) • Remote (location not specified) • 1+ year exp • Bachelor's Degree
Python
JavaScript
DevOps
SLI/SLO/SLA
Cybersecurity
Crowdstrike
Qualys Cloud Platform
Microsoft Defender
CVSS
Management
ServiceNow
Apply
≈ $97k – $211k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Jakarta
AI/ML
Red Teaming
DevOps
GCP
CI/CD
AWS
IAM
Cybersecurity
ISO 27001
NIST CSF
PCI DSS
SOC 2
GDPR
Zero Trust
SIEM
Apply
≈ $61k – $158k per year (Estimated) • In office • Full-Time • 8+ years exp • Cairo
Python
PowerShell
Bash
Databases
Oracle
DevOps
Terraform
Puppet
Ansible
Red Hat
Podman
Chef
Datadog
Prometheus
CI/CD
Windows Server
Docker
Grafana
SaltStack
Configuration Management
Incident Management
Linux
Windows
DNS
DHCP
VPN
Cybersecurity
ISO 27001
Microsoft Defender
CIS Benchmarks
PCI DSS
SOC 2
Active Directory
Cryptography
Vault
Management
ServiceNow
ITIL
ITSM
Apply
In office
DevOps
Incident Management
Cybersecurity
ISO 27001
Apply
≈ $16k – $39k per year (Estimated) • Hybrid • Full-Time • 3+ years exp • Bachelor's Degree • Bengaluru
DevOps
Azure
AWS
Incident Management
Cybersecurity
ISO 27001
PCI DSS
GDPR
HIPAA
Management
ITIL
Apply
In office
DevOps
SLI/SLO/SLA
Cybersecurity
ISO 27001
CAPA
Management
Agile
Apply
≈ $75k – $161k per year (Estimated) • Remote (United States) • Full-Time • 3+ years exp
DevOps
GCP
Azure
AWS
SLI/SLO/SLA
Cybersecurity
ISO 27001
NIST CSF
PCI DSS
SOC 2
HIPAA
Management
Asana
Slack
Google Workspace
Apply
Remote (location not specified, PT hours) • Full-Time
Cybersecurity
ISO 27001
NIST CSF
SOC 2
Management
Asana
Google Workspace
Apply
≈ $76k – $165k per year (Estimated) • Remote (likely United States) • Full-Time • 5+ years exp • Bachelor's Degree
DevOps
IAM
Cybersecurity
ISO 27001
PCI DSS
SOC 2
HIPAA
NIST 800-53
NIST 800-171
Apply
≈ $74k – $164k per year (Estimated) • Remote (location not specified) • Full-Time • 5+ years exp
Python
PowerShell
AI/ML
LLM
Red Teaming
LLM Guardrails
Frontend
GraphQL
DevOps
Rest API
GCP
Azure
CI/CD
AWS
Cybersecurity
Burp Suite
Metasploit
Nmap
ISO 27001
OWASP Top 10
PCI DSS
SOC 2
HIPAA
Threat Modeling
MobSF
Frida
Objection
OWASP
Apply
See all jobs
This is one of many
997,024 more open roles from verified company boards, updated every day.