Назад
Company hidden
11 дней назад

GRC Cybersecurity Controls Analyst (Cybersecurity)

88 920 - 176 400$
Формат работы
onsite
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
GRC Cybersecurity Controls Analyst (Cybersecurity): Operating and improving the controls framework, testing control effectiveness, reviewing evidence, and supporting audits across ISO 27001, SOC 2, NIST CSF, and PCI-DSS with an accent on audit readiness, security assurance, and cross-functional control validation. Focus on designing scalable GRC automation, improving evidence workflows, and identifying control gaps across security, privacy, compliance, and regulatory obligations.

Location: Washington, D.C.; fully in-person schedule up to 5 days a week

Salary: $88,920–$176,400 annually

Company

hirify.global operates a data privacy and cybersecurity program focused on protecting U.S. user data, applications, algorithms, and the content ecosystem.

What you will do

  • Maintain and continuously improve the controls framework, including control descriptions, mappings, owners, evidence expectations, testing procedures, and narratives.
  • Perform control design, implementation, and operating-effectiveness testing and validate submitted evidence.
  • Coordinate with control owners, product teams, security, privacy, legal, internal audit, external auditors, and GRC leadership to resolve evidence gaps and improve testing quality.
  • Support audits, certifications, and assessments across ISO 27001, SOC 2, PCI-DSS, NIST CSF, and related obligations.
  • Contribute to GRC automation through workflow automation, control monitoring, dashboards, structured data, evidence recommendations, and scalable testing.
  • Work with engineering and technical teams to identify system-generated evidence and improve control validation.

Requirements

  • Bachelor’s degree in information security, cybersecurity, information technology, risk management, compliance, engineering, data analytics, or a related discipline, or equivalent practical experience.
  • At least 3 years of experience in GRC, IT risk, security controls, audit readiness, control testing, compliance, or security assurance.
  • Experience evaluating control design, implementation, and operating effectiveness, and reviewing technical control evidence.
  • Working knowledge of ISO 27001, NIST CSF, SOC 2, PCI-DSS, or similar frameworks.
  • Strong writing, documentation, analytical, stakeholder-management, and collaboration skills.
  • Familiarity with security domains including identity and access management, vulnerability management, incident management, asset management, logging and monitoring, data security, SDLC, third-party risk, business continuity, disaster recovery, or privacy.

Nice to have

  • Professional certification such as CISA, CISSP, CISM, CRISC, CDPSE, ISO 27001 Lead Auditor, or ISO 27001 Lead Implementer.
  • Experience supporting external audits, security certifications, or regulatory assessments.
  • Experience with GRC automation, control monitoring, evidence automation, dashboarding, workflow design, or data-driven control testing.
  • Familiarity with automation, scripting, SQL, APIs, or data workflows.
  • Experience maintaining control libraries, control mappings, or integrated compliance frameworks.

Culture & Benefits

  • Fully in-person work supports rapid decision-making, alignment, team development, and integrated execution.
  • Medical, dental, and vision insurance from the first day.
  • 401(k) savings plan with company match, paid parental leave, disability coverage, and life insurance.
  • Wellbeing benefits, 10 paid holidays, 10 paid sick days, and 17 days of paid personal time.
  • Inclusive workplace focused on creativity, collaboration, curiosity, humility, and continuous improvement.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →