3 дня назад
GRC Analyst (Cybersecurity)
70 000 - 88 000$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
GRC Analyst (Cybersecurity): Managing security awareness programs, vendor risk assessments, controls frameworks, and client governance activities with an accent on cybersecurity compliance, evidence collection, and third-party risk monitoring. Focus on administering phishing simulations, coordinating security audits, completing due diligence questionnaires, and documenting security postures across multiple environments.
Location: Remote across the United States, excluding Massachusetts, New York, and California.
Salary: $70,000–$88,000 per year, depending on experience and work location.
Company
provides managed IT, cybersecurity, cloud, and technology strategy services for growing, highly regulated organizations.
What you will do
- Support vCISO staff with client cybersecurity and governance program management.
- Update policies to align with client practices and maintain controls frameworks.
- Conduct vendor risk assessments and manage third-party risk monitoring programs.
- Coordinate security and compliance due diligence questionnaires across departments.
- Administer security awareness training and phishing simulation campaigns, including content deployment, user enrollment, and progress tracking.
- Collect framework and regulatory evidence, coordinate security audits and projects, and prepare reports on findings and risk assessments.
Requirements
- 3+ years of experience in a GRC role focused on IT or cybersecurity controls, or in an IT role with a cybersecurity focus.
- Previous experience working at a Managed Services Provider.
- Strong analytical, organizational, problem-solving, written, and verbal communication skills.
- Comfort working with technical tools to gather information about systems and settings.
- Ability to manage multiple projects simultaneously while maintaining accuracy, quality, and deadlines.
- High personal and professional ethical standards.
Nice to have
- Cybersecurity or compliance certifications such as Security+, CGRC, CRISC, CISSP, or CISA.
- Hands-on experience with GRC platforms, security awareness tools, and phishing simulation platforms.
- Knowledge of SEC, SOX, or HIPAA requirements in financial services or biotech.
- Experience with vendor management platforms and third-party risk assessment methodologies.
Culture & Benefits
- Remote work environment with benefits adjusted based on location.
- Health, dental, vision, FSA, HRA, HSA, life, and disability insurance.
- 401(k), paid parental leave, holiday pay, flexible vacation, and sick days.
- Twelve holidays, including a birthday and work-anniversary day off.
- Learning and development opportunities, wellness benefits, monthly rewards, spot bonuses, and community events.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
6 дней назад
Compliance Program Manager (Cybersecurity)
100 000 - 120 000$
4 дня назад
Client Assurance & TPRM Manager - Assistant Vice President (Cybersecurity Risk)
100 000 - 140 000$
5 дней назад
Governance, Risk & Compliance (GRC) Analyst (Defense)
120 000 - 150 000$
3 дня назад
Security Governance Manager (Cybersecurity)
83 000 - 100 000€
6 дней назад
Senior Security Analyst, GRC (Fintech)
4 дня назад
Senior GRC Analyst (SaaS)
183 000 - 205 000$