Назад
Company hidden
6 часов назад

Governance, Risk & Compliance (GRC) Analyst (Defense)

120 000 - 150 000$
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
UK/US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Governance, Risk & Compliance (GRC) Analyst (Defense) (NIST, CMMC, ISO): Building and maturing a cybersecurity GRC program for a defense company with an accent on risk assessments, tailored control frameworks, audit coordination, and operational resilience. Focus on designing working controls, managing risk registers and remediation, and translating security requirements across IT, cybersecurity, manufacturing, physical security, legal, and commercial teams.

Location: El Segundo, California, United States; onsite presence required 4 days per week. Travel up to 25% is expected, primarily for control validation at manufacturing and physical security sites.

Salary: $120,000–$150,000 base salary per year, excluding bonus, equity, and benefits.

Company

hirify.global develops defense products powered by Coherent Distributed Networks for warfighters, commercial air operators, and border protection teams.

What you will do

  • Own and mature the cybersecurity governance, risk, and compliance program across multiple business areas.
  • Lead risk assessments and maintain the centralized risk register, including findings, vulnerabilities, remediation plans, ownership, escalation, and business acceptance.
  • Design and maintain a tailored control framework covering security by design, MTD, RPO, and RTO for critical systems.
  • Manage GRC tools and workflows for risk assessments, control monitoring, reporting, and remediation tracking.
  • Coordinate third-party, certification, customer, vendor, supplier, and subcontractor audits from evidence collection through closure.
  • Translate cybersecurity and compliance requirements across IT, cybersecurity, manufacturing, physical security, legal, compliance, commercial, and business teams.

Requirements

  • Bachelor’s degree or equivalent practical experience in computer science, cybersecurity, information security, IT, information assurance, or a related field.
  • At least 5 years of hands-on GRC or compliance experience combined with prior DoD environment experience or military service.
  • Deep knowledge of NIST CSF, NIST RMF, ISO/IEC 27000, UK Cyber Essentials, CMMC/NIST 800-171, and NIST 800-53.
  • Experience selecting, implementing, or administering GRC tooling and workflows, and conducting formal risk assessments using a defined methodology.
  • Experience directly supporting third-party or certification audits, including evidence collection, gap assessment, auditor liaison, and remediation closure.
  • Familiarity with OT/ICS security and the ability to design practical controls tailored to a specific organization.

Nice to have

  • Experience supporting third-party audits in a cloud-centric environment.
  • Experience building or materially contributing to a risk register, control framework, or compliance program.
  • Experience writing policies or procedures that non-security audiences can follow.

Culture & Benefits

  • Medical, dental, and vision benefits fully paid by the company.
  • 401(k) with a 50% company match up to 6% of pay, plus FSA, HSA, and life insurance.
  • Free daily lunch, no-meeting Fridays, unlimited PTO, and a casual dress code.
  • Competitive base salary, pre-IPO stock options, relocation assistance, and planned annual bonuses.
  • Work includes occasional manufacturing-floor access with required PPE and periods of standing or walking.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →