Назад
Company hidden
4 дня назад

GRC Cybersecurity Controls Analyst (Cybersecurity)

98 800 - 196 000$
Формат работы
onsite
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
GRC Cybersecurity Controls Analyst (Cybersecurity): Operating and improving cybersecurity controls frameworks, testing control effectiveness, and supporting audit readiness across ISO 27001, SOC 2, NIST CSF, and PCI with an accent on evidence assessment, control narratives, and cross-functional coordination. Focus on automating control monitoring and testing, identifying design and evidence gaps, and building scalable GRC workflows with technical teams.

Location: New York, United States; fully in-person up to 5 days a week

Salary: $98,800–$196,000 annually, plus potential discretionary bonuses, incentives, and restricted stock units.

Company

hirify.global operates a data privacy and cybersecurity program focused on protecting U.S. user data, applications, algorithms, and the content ecosystem.

What you will do

  • Maintain and continuously improve the controls framework, including control descriptions, mappings, owners, evidence expectations, testing procedures, and narratives.
  • Perform control design, implementation, and operating-effectiveness testing and validation.
  • Review technical evidence from control owners and product teams, identify gaps, and improve testing quality.
  • Support internal and external audits, certifications, and assessments across ISO 27001, SOC 2, PCI, NIST CSF, and related obligations.
  • Coordinate with security, privacy, legal, audit, product, engineering, and GRC stakeholders to resolve issues and communicate risks.
  • Help develop GRC automation through workflow automation, control monitoring, dashboards, structured data, and scalable testing.

Requirements

  • Bachelor’s degree in information security, cybersecurity, information technology, risk management, compliance, engineering, data analytics, or a related field, or equivalent practical experience.
  • 3+ years of experience in GRC, IT risk, security controls, audit readiness, control testing, compliance, or security assurance.
  • Experience evaluating control design, implementation, operating effectiveness, and technical control evidence.
  • Working knowledge of ISO 27001, NIST CSF, SOC 2, PCI-DSS, or similar frameworks.
  • Strong writing, documentation, analytical, collaboration, and stakeholder-management skills.
  • Ability to manage multiple workstreams, follow up on open items, identify blockers, and communicate risks clearly.

Nice to have

  • Professional certification such as CISA, CISSP, CISM, CRISC, CDPSE, or ISO 27001 Lead Auditor/Lead Implementer.
  • Experience with external audits, security certifications, regulatory assessments, or national security and data protection obligations.
  • Experience with GRC automation, control monitoring, evidence automation, dashboarding, workflow design, scripting, SQL, APIs, or data workflows.
  • Experience maintaining control libraries, control mappings, or integrated compliance frameworks.

Culture & Benefits

  • Fully in-person work supports rapid decision-making, alignment, team development, and integrated execution.
  • Medical, dental, and vision insurance from day one, plus a 401(k) savings plan with company match.
  • Paid parental leave, disability coverage, life insurance, and wellbeing benefits.
  • 10 paid holidays, 10 paid sick days, and 17 days of paid personal time, with accruals increasing by tenure.
  • Inclusive workplace with reasonable accommodations available during recruitment.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →