This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a GRC Analyst based in United States.
This is a governance, risk, and compliance role supporting cybersecurity programs across diverse client environments. You will help strengthen security postures through policy management, vendor risk assessments, compliance activities, and security awareness initiatives. The role combines analytical investigation, technical information gathering, project coordination, and clear documentation. You will collaborate with cybersecurity specialists, clients, and internal teams to assess risks and maintain alignment with relevant controls and regulatory expectations. Success requires strong attention to detail, sound judgment, and the ability to manage multiple priorities without compromising quality. The position offers a remote environment with opportunities to deepen your expertise across cybersecurity, compliance, and third-party risk management.
Accountabilities:
- Support virtual CISO and cybersecurity teams with the ongoing management and execution of client governance, risk, and compliance programs, helping ensure security initiatives remain organized, measurable, and aligned with client objectives.
- Review and update information security policies and related documentation to ensure they accurately reflect client practices, applicable controls, and evolving security and compliance requirements.
- Conduct comprehensive vendor and third-party risk assessments, evaluate security information, document findings, and support ongoing monitoring programs to identify and manage supplier-related risks.
- Collaborate with multiple departments and stakeholders to complete security and compliance due diligence questionnaires on behalf of clients, ensuring responses are accurate, well-supported, and delivered within required timelines.
- Administer security awareness training and phishing simulation programs, including content deployment, user enrollment, campaign coordination, participation tracking, and reporting on program progress.
- Collect, organize, and maintain evidence required to demonstrate compliance with relevant cybersecurity frameworks, controls, standards, and regulatory requirements.
- Coordinate and track client security projects, audits, and compliance activities, maintaining visibility into milestones, responsibilities, deadlines, risks, and outstanding actions.
- Prepare clear and detailed reports covering governance activities, security findings, vendor assessments, risk observations, awareness initiatives, and other cybersecurity program metrics.
- 3+ years of experience in a governance, risk, and compliance role focused on IT or cybersecurity controls, or 3+ years of IT experience with a significant cybersecurity focus.
- Previous experience working within a Managed Services Provider environment, with an understanding of supporting multiple clients, environments, priorities, and security requirements.
- Strong analytical, organizational, and problem-solving skills, with the ability to evaluate complex information, identify risks, and translate findings into clear documentation and practical actions.
- Strong written and verbal communication skills, including the ability to communicate security and compliance concepts clearly with both technical and non-technical stakeholders.
- Comfortable working with a variety of technical and security tools to gather information about systems, configurations, settings, controls, and security practices.
- Highly detail-oriented, with a strong commitment to accuracy, documentation quality, confidentiality, and meeting deadlines.
- Proven ability to manage multiple projects and competing priorities simultaneously while maintaining consistent quality and follow-through.
- High personal and professional ethical standards, with sound judgment when handling sensitive security, compliance, and client information.
- Cybersecurity or compliance certifications such as CompTIA Security+, CGRC, CRISC, CISSP, or CISA are preferred.
- Hands-on experience with GRC platforms, security awareness training systems, and phishing simulation tools is preferred.
- Familiarity with regulatory requirements relevant to financial services or biotechnology and life sciences, including SEC, SOX, and HIPAA, is advantageous.
- Experience with vendor management platforms and third-party risk assessment methodologies is preferred.
- Salary range of $70,000-$88,000 USD, depending on experience, skills, education, training, and work location. The stated range applies across U.S. locations except Massachusetts, New York, and California.
- Medical, dental, and vision insurance.
- Flexible Spending Account (FSA), Health Reimbursement Account (HRA), and Health Savings Account (HSA) options.
- 401(k) retirement plan.
- Life insurance and disability insurance.
- Paid parental leave.
- Holiday pay, including 12 holidays throughout the year.
- Flexible vacation and sick days designed to support work-life balance.
- Birthday and work-anniversary days off.
- Monthly rewards and spot bonuses recognizing demonstrated excellence.
- Community and social events supporting connection and collaboration.
- Learning and development opportunities to support continued career growth.
- Flexible working arrangements suited to a remote workforce.
- $100 well-being allowance and additional health and wellness perks.
Requirements:
Benefits:

