Security GRC Analyst

Stellenbeschreibung:

  • Perform and mature enterprise risk assessments using frameworks such as NIST CSF, NIST 800-53, SOC 2, and CIS
  • Analyze vulnerability assessment reports to support troubleshooting, remediation, and risk reduction initiatives
  • Develop and execute security awareness programs, including training, phishing simulations
  • Deliver actionable reporting and insights, including assessment results and GRC metrics
  • Perform end-to-end cyber third-party risk assessments
  • Drive process and tooling optimization
  • Support governance and control management
  • Enable audit readiness and due diligence
  • Stay current on evolving regulations, frameworks, and industry trends
  • Manage priorities and execution using Agile methodologies

Requirements

  • Bachelor’s degree in Cybersecurity, Information Systems, or related field. 1–3 years of experience in GRC, risk management, or compliance within cybersecurity.
  • Working knowledge of regulatory frameworks, audit processes, and control environments
  • Understanding of third-party/vendor risk management (TPRM) processes and enterprise risk concepts
  • General knowledge of security tools and controls across domains such as network security, endpoint protection
  • Proven ability to track, measure, and report on IS GRC program effectiveness using tools such as ServiceNow, Archer, SharePoint, and Power BI
  • Experience contributing to continuous improvement of GRC programs
  • Experience developing and delivering training materials
  • Strong organizational, analytical, and multitasking abilities

Core Competencies

Demonstrates expertise in enterprise risk assessments and governance, risk, and compliance (GRC) frameworks, with a strong focus on NIST CSF, NIST 800-53, and SOC 2. Proficient in developing security awareness programs and managing third-party risk assessments while utilizing Agile methodologies for effective execution.

Highest-signal resume keywords

  • Enterprise Risk Assessment
  • Governance, Risk, And Compliance (GRC)
  • Third-Party Risk Management (TPRM)
  • Security Awareness Program Development
  • Agile Methodologies

Hard Skills

  • NIST CSF
  • NIST 800-53
  • SOC 2
  • CIS
  • Vulnerability Assessment
  • Risk Management
  • Audit Processes
  • Security Tools
  • IS GRC Program Effectiveness
  • Control Environments

Soft Skills

  • Organizational Abilities
  • Analytical Skills
  • Multitasking Abilities

Industry Keywords

  • Cybersecurity
  • Compliance
  • Regulatory Frameworks
  • Risk Reduction Initiatives
  • Continuous Improvement

Tools & Technologies

  • ServiceNow
  • Archer
  • SharePoint
  • Power BI

#J-18808-Ljbffr
NOTE / HINWEIS:
EnglishEN: Please refer to Fuchsjobs for the source of your application
DeutschDE: Bitte erwähne Fuchsjobs, als Quelle Deiner Bewerbung

Stelleninformationen

  • Veröffentlichungsdatum:

    04 Sep 2026
  • Standort:

    WorkFromHome
  • Typ:

    Vollzeit
  • Arbeitsmodell:

    Vor Ort
  • Kategorie:

  • Erfahrung:

    2+ years
  • Arbeitsverhältnis:

    Angestellt

KI Suchagent

AI job search

Möchtest über ähnliche Jobs informiert werden? Dann beauftrage jetzt den Fuchsjobs KI Suchagenten!