Назад
Company hidden
1 час назад

Security Governance Risk & Compliance (GRC) Analyst (Cybersecurity)

130 000 - 170 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Governance Risk & Compliance (GRC) Analyst (Cybersecurity): Building and maintaining a security compliance program across CMMC, FedRAMP, SOC 2, PCI DSS, and privacy frameworks with an accent on cloud controls, automated evidence collection, and risk management. Focus on conducting gap analyses, developing compliance roadmaps, supporting incident response, and evaluating third-party security risks.

Location: Washington, DC, United States — Remote

Salary: $130,000–$170,000 per year

Company

hirify.global develops data protection applications and an open Trusted Data Format platform that enables secure data sharing, collaboration, and control for enterprises and government agencies.

What you will do

  • Manage and implement complex security controls frameworks across cloud infrastructure and SaaS services, including AWS, GCP, GitHub, and Okta.
  • Design and develop automation for evidence collection across cloud infrastructure, endpoints, and SaaS services.
  • Conduct risk assessments, identify findings, and recommend remediation and mitigation strategies across business units.
  • Participate in incident response activities by providing risk analysis and remediation support.
  • Lead CMMC compliance efforts, including gap analyses, roadmap development, certification, and ongoing monitoring.
  • Support FedRAMP, SOC 2, and PCI DSS compliance and facilitate third-party vendor security reviews.

Requirements

  • 5+ years of experience in information security, IT audit, IT risk management, or GRC analysis and engineering.
  • Deep understanding of several frameworks, including CMMC, NIST 800-53, NIST 800-171, FedRAMP, SOC 2, PCI DSS, or global privacy compliance frameworks.
  • Strong understanding of modern cloud technologies such as AWS, GCP, and Azure.
  • Familiarity with GRC tools such as Hyperproof, Vanta, and Drata, and SIEM tools such as Datadog and Splunk.
  • Experience translating technical and business risk for stakeholders, training and coaching teams, and driving remediation to completion.
  • Ability to work independently on an autonomous agile team and adapt to shifting priorities.

Culture & Benefits

  • Flexible PTO plus 14 holidays and a high degree of day-to-day flexibility.
  • $1,500 annual learning and development stipend.
  • Medical, dental, vision, parental, bereavement, and employee assistance benefits.
  • Headspace access, retirement contribution, and stock options.
  • Team celebrations, structured semi-annual 360-degree performance reviews, and an inclusive workplace focused on psychological safety.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →