Назад
Company hidden
3 дня назад

Governance, Risk & Compliance (GRC) Analyst (Cybersecurity)

Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
UK/US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Governance, Risk & Compliance (GRC) Analyst (Cybersecurity) (NIST/ISO/CMMC): Building and maturing a cybersecurity GRC program for a defense company with an accent on risk assessments, tailored control frameworks, audit coordination, and operational resilience. Focus on designing practical controls, managing risk registers and remediation, defining MTD/RPO/RTO requirements, and validating security across manufacturing and physical security environments.

Location: Washington, D.C.; onsite presence required 4 days per week. Travel up to 25% is required, primarily to support manufacturing and physical security control validation across company sites. The role includes occasional access to manufacturing floor environments with required PPE and periods of standing or walking.

Company

Defense technology company developing multi-product systems based on Coherent Distributed Networks for warfighters, commercial air operators, and border protection teams.

What you will do

  • Own and mature the cybersecurity governance, risk, and compliance program across multiple business functions.
  • Lead risk assessments, maintain the centralized risk register, track findings and vulnerabilities, and manage remediation, escalation, and business acceptance.
  • Design and maintain a tailored control framework, including security-by-design practices and MTD, RPO, and RTO requirements for critical systems.
  • Write policies and procedures, manage GRC tooling and workflows, and report risk posture and program maturity to executive stakeholders.
  • Coordinate third-party, certification, customer, vendor, supplier, and subcontractor cybersecurity assessments from evidence collection through remediation closure.
  • Translate security and compliance requirements for IT, cybersecurity, physical security, manufacturing, Legal, Compliance, commercial teams, and business leaders.

Requirements

  • Bachelor’s degree or equivalent practical experience in computer science, cybersecurity, information security, IT, information assurance, or a related field.
  • At least 5 years of hands-on GRC or compliance experience combined with prior DoD environment or military service experience.
  • Deep knowledge of NIST CSF, NIST RMF, ISO/IEC 27000, UK Cyber Essentials, CMMC/NIST 800-171, and NIST 800-53.
  • Experience selecting, implementing, or administering GRC tooling and workflows, and conducting formal risk assessments using a defined methodology.
  • Direct experience supporting third-party or certification audits, including evidence collection, gap assessment, auditor liaison, and closure.
  • Familiarity with OT/ICS security concepts and the ability to design practical controls for a specific organization.

Nice to have

  • Experience supporting third-party audits in a cloud-centric environment.
  • Experience building or materially contributing to a risk register, control framework, or compliance program.
  • Experience writing policies or procedures for non-security audiences.

Culture & Benefits

  • Medical, dental, and vision benefits fully paid by the company.
  • 401(k) with a 50% company match up to 6% of pay, plus FSA, HSA, and life insurance.
  • Unlimited PTO, free daily lunch, no-meeting Fridays, and a casual dress code.
  • Competitive base salary, pre-IPO stock option grants, relocation assistance, and planned annual bonuses.
  • Organization of approximately 350 employees across five global offices.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →