{"id":1539374,"url":"https://alion.io/job/bright-defense-grc-analyst-secops","title":"GRC Analyst – SecOps","company":{"id":1850073,"name":"Bright Defense","domain":"brightdefense.com","url":"https://alion.io/company/brightdefense","size_band":"11-50","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Schema","truth_index":{"grade":"B","score":75,"open_postings":4,"ghost_share":0,"stale_share":1,"repost_share":0,"time_to_fill_p50_days":null,"computed_at":"2026-10-01T05:45:00Z"}},"role":"Security","role_family":"Security","seniority":"junior","employment_type":"full_time","work_mode":"remote","remote_scope":"unspecified","remote_scope_basis":null,"remote_working_hours":{"label":"PT","utc_offset_min":-8,"utc_offset_max":-8},"hiring_geo_confidence":"inferred","locations":[],"countries":[],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":58000,"max_usd":135000,"period":"year","method":"global_role_seniority_cell","sample_n":309},"experience_years_min":2,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"ISO 27001","optional":false},{"name":"NIST CSF","optional":false},{"name":"SOC 2","optional":false},{"name":"Asana","optional":true},{"name":"Google Workspace","optional":true}],"status":"live","first_seen_at":"2025-07-15T03:04:39Z","employer_posted_date":"2026-04-12","last_verified_at":"2026-10-01T07:17:58Z","board_verified":true,"closed_at":null,"days_open":443,"trust":{"level":"stale","repost_count":0,"flags":["stale"],"days_open":443},"description":"Bright Defense · Governance Team · Now Hiring\nGRC Analyst II\nGovernance - Security Policy, Risk & Compliance\nFull-TimeRemoteGovernance2-3 Years Experience\nYou’ll play a critical role in helping our customers establish and implement robust security governance programs - serving as their trusted point of contact for policy development, gap reviews, compliance readiness, and clear communication of security requirements from day one.\nAbout the role\nAs a GRC Analyst II on our Governance Team, you’ll work directly with clients to support customer onboarding, policy development, gap reviews, and compliance readiness. You’ll explain governance frameworks and security requirements clearly to non-technical stakeholders, coordinate cross-functional handoffs with SecOps and Offensive Security, and help clients build the governance foundation they need to pass audits and maintain strong security postures.\nKey responsibilities\nGovernance & policy\nSupport customer onboarding and kick-off, ensuring clients understand their security program roadmap and governance objectives\nDraft, review, and maintain information security policies, procedures, and controls\nClearly communicate and explain governance frameworks and policy requirements to non-technical stakeholders\nDevelop and track risk registers, mitigation plans, and corrective action plans\nGap assessment & audit readiness\nPerform gap assessments to identify areas for improvement against ISO 27001, SOC 2, NIST CSF, and other relevant frameworks\nSupport clients through audit readiness and defense - collecting evidence, tracking findings, and remediating gaps\nPrepare clear, high-quality documentation and status reports for customers\nParticipate in regular customer status meetings and provide input on governance milestones and deliverables\nCross-functional coordination\nCoordinate handoffs between governance activities and technical teams - Offensive Security, SecOps, and beyond\nServe as the trusted governance point of contact for assigned client accounts\nAlign policy and risk activities with the broader security program strategy for each client\nContribute to continuous improvement of governance procedures, templates, and documentation standards\nCross-functional collaboration\nSecurity Consultants\nSecOps Team\nOffensive Security\nClient Stakeholders\nRequirements\nExperience & frameworks\n2-3 years of relevant experience in information security, compliance, or risk management\nSolid understanding of ISO 27001, SOC 2, NIST CSF, and other common security frameworks\nProven experience developing and implementing security policies and controls\nStrong attention to detail and ability to manage multiple client deliverables simultaneously\nCommunication & availability\nExceptional written and verbal communication skills are mandatory - you must confidently explain security policies and governance requirements to diverse audiences\nCollaborative, customer-focused mindset - you thrive in a cross-functional team environment\nMust support US Eastern and Pacific time zones, 9AM-6PM\nNice to have\nISO 27001 Lead Implementer, CISA, CISSP (Associate), Security+, or similar certification\nExperience working with clients in regulated industries - finance, healthcare, or SaaS\nExposure to GRC or risk and compliance management tools\nTools & platforms\nGRC platforms - Drata, Vanta, Thoropass, or equivalent\nAsana or similar PM tools for task and deliverable tracking\nGoogle Workspace or Microsoft 365 proficiency\nDocumentation and evidence management tooling experience\nRelevant certifications\nISO 27001 Lead ImplementerCISACISSP (Associate)CompTIA Security+CISMCC (Certified in Cybersecurity)ISACA Cybersecurity Fundamentals\nWhy you’ll love this role\nDirectly help customers build trust and strengthen their security governance posture from day one\nDevelop hands-on expertise with real-world frameworks, audits, and compliance practices across diverse client verticals\nBe part of a supportive team that values strong communication, clear documentation, and continuous learning\nCompensation & perks\nCompetitive base salary - range shared during screening\nRemote-first with flexible hours within the ET/PT coverage window (9AM-6PM)\nCertification reimbursement - ISO 27001 Lead Implementer, CISA, CISSP, Security+, and more\nDirect collaboration with Bright Defense co-founders and Governance leadership\nBroad client exposure across defense, healthcare, fintech, and SaaS verticals\nClear growth path toward GRC Analyst III and Senior GRC roles\nBright Defense is an equal opportunity employer. We build diverse, high-trust teams. | brightdefense.com","description_format":"text","description_chars":4598,"description_truncated":false,"requirements":{"experience_years_min":2,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":["Certification reimbursement","Continuous learning"],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Cybersecurity","Information Security","Security Compliance"],"lifecycle":[{"event":"open","at":"2026-09-30T20:25:24Z"}],"liveness":{"score":3,"band":"cold","label":"Long shot","p_open":1,"p_active":0.109,"p_room":0.28,"age_days":443,"expected_fill_days":7,"reasons":["conf:9","win:tail","crowd:junior"],"computed_at":"2026-10-01T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/bright-defense-grc-analyst-secops","json_url":"https://alion.io/job/bright-defense-grc-analyst-secops.json","meta":{"generated_at":"2026-10-02T01:11:03Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":1277,"day_limit":5000,"remaining_today":3723,"minute_limit":60,"resets_at":"2026-10-03T00:00:00Z"}}}