11 дней назад
GRC Cybersecurity Controls Analyst (Cybersecurity)
88 920 - 176 400$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
GRC Cybersecurity Controls Analyst (Cybersecurity): Operating and improving the controls framework, testing control effectiveness, reviewing evidence, and supporting audits across ISO 27001, SOC 2, NIST CSF, and PCI-DSS with an accent on audit readiness, security assurance, and cross-functional control validation. Focus on designing scalable GRC automation, improving evidence workflows, and identifying control gaps across security, privacy, compliance, and regulatory obligations.
Location: Washington, D.C.; fully in-person schedule up to 5 days a week
Salary: $88,920–$176,400 annually
Company
operates a data privacy and cybersecurity program focused on protecting U.S. user data, applications, algorithms, and the content ecosystem.
What you will do
- Maintain and continuously improve the controls framework, including control descriptions, mappings, owners, evidence expectations, testing procedures, and narratives.
- Perform control design, implementation, and operating-effectiveness testing and validate submitted evidence.
- Coordinate with control owners, product teams, security, privacy, legal, internal audit, external auditors, and GRC leadership to resolve evidence gaps and improve testing quality.
- Support audits, certifications, and assessments across ISO 27001, SOC 2, PCI-DSS, NIST CSF, and related obligations.
- Contribute to GRC automation through workflow automation, control monitoring, dashboards, structured data, evidence recommendations, and scalable testing.
- Work with engineering and technical teams to identify system-generated evidence and improve control validation.
Requirements
- Bachelor’s degree in information security, cybersecurity, information technology, risk management, compliance, engineering, data analytics, or a related discipline, or equivalent practical experience.
- At least 3 years of experience in GRC, IT risk, security controls, audit readiness, control testing, compliance, or security assurance.
- Experience evaluating control design, implementation, and operating effectiveness, and reviewing technical control evidence.
- Working knowledge of ISO 27001, NIST CSF, SOC 2, PCI-DSS, or similar frameworks.
- Strong writing, documentation, analytical, stakeholder-management, and collaboration skills.
- Familiarity with security domains including identity and access management, vulnerability management, incident management, asset management, logging and monitoring, data security, SDLC, third-party risk, business continuity, disaster recovery, or privacy.
Nice to have
- Professional certification such as CISA, CISSP, CISM, CRISC, CDPSE, ISO 27001 Lead Auditor, or ISO 27001 Lead Implementer.
- Experience supporting external audits, security certifications, or regulatory assessments.
- Experience with GRC automation, control monitoring, evidence automation, dashboarding, workflow design, or data-driven control testing.
- Familiarity with automation, scripting, SQL, APIs, or data workflows.
- Experience maintaining control libraries, control mappings, or integrated compliance frameworks.
Culture & Benefits
- Fully in-person work supports rapid decision-making, alignment, team development, and integrated execution.
- Medical, dental, and vision insurance from the first day.
- 401(k) savings plan with company match, paid parental leave, disability coverage, and life insurance.
- Wellbeing benefits, 10 paid holidays, 10 paid sick days, and 17 days of paid personal time.
- Inclusive workplace focused on creativity, collaboration, curiosity, humility, and continuous improvement.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
13 дней назад
Lead Security Analyst - GRC (Cybersecurity)
172 500 - 215 625$
11 дней назад
Security & Compliance Manager (GRC), US-based
190 000 - 220 000$
CrowdStrike
11 дней назад
Senior Governance, Risk, and Compliance Specialist (Cybersecurity)
100 000 - 155 000$
11 дней назад
Senior Lead, Technology Risk and Control
95 600 - 162 400$
11 дней назад
Senior IT Security Specialist (Cybersecurity)
126 862 - 137 269$
12 дней назад
Analyst – IT Infrastructure Audit (Cybersecurity)
71 000 - 121 000$