Назад
Company hidden
7 часов назад

Security GRC Analyst

Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
junior/middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Security GRC Analyst: Supporting the organization’s Information Security Risk Management program by executing cyber risk functions such as regulatory compliance, third-party risk assessments, and security awareness activities. Focus on ensuring adherence to industry standards like NIST and SOC 2, managing vendor risk lifecycles, and driving program maturity through actionable reporting and cross-functional collaboration.

Location: Remote (US-based)

Company

hirify.global is an organization dedicated to providing financial security and wellbeing solutions, committed to fostering an inclusive and diverse workforce.

What you will do

  • Perform enterprise risk assessments using frameworks such as NIST CSF, NIST 800-53, SOC 2, and CIS.
  • Execute end-to-end cyber third-party risk assessments and manage vendor lifecycle security.
  • Develop and deliver security awareness programs, including training and phishing simulations.
  • Create GRC metrics, dashboards, and executive-level reports to track program effectiveness.
  • Support governance by maintaining policies, standards, and control libraries.
  • Enable audit readiness by managing evidence collection and standardizing responses for external inquiries.

Requirements

  • Bachelor’s degree in Cybersecurity, Information Systems, or a related field.
  • 1–3 years of experience in GRC, risk management, or compliance within cybersecurity.
  • Working knowledge of regulatory frameworks, audit processes, and control environments.
  • Understanding of third-party/vendor risk management (TPRM) and enterprise risk concepts.
  • Proven ability to track and report on GRC program effectiveness using tools like ServiceNow or Archer.
  • Must be eligible to work in the United States as indicated by 401(k) and US-specific benefits.

Nice to have

  • Experience with cloud security compliance (Azure/AWS).
  • Familiarity with tools such as SharePoint, Power BI, or UpGuard.
  • Relevant certifications: CISA, CRISC, GSEC/GISP, CISSP, CISM, CCSP, or Security+.

Culture & Benefits

  • Comprehensive health and financial wellbeing benefits including pension and 401(k) with company matching.
  • Paid time off and paid parental leave.
  • Access to ProHealth Rewards platform for wellbeing and cash incentives.
  • Inclusive work environment with a focus on professional growth and development.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →