Назад
Company hidden
3 дня назад

GRC Analyst (Cybersecurity)

70 000 - 88 000$
Формат работы
remote (только USA)
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
GRC Analyst (Cybersecurity): Managing security awareness programs, vendor risk assessments, controls frameworks, and client governance activities with an accent on cybersecurity compliance, evidence collection, and third-party risk monitoring. Focus on administering phishing simulations, coordinating security audits, completing due diligence questionnaires, and documenting security postures across multiple environments.

Location: Remote across the United States, excluding Massachusetts, New York, and California.

Salary: $70,000–$88,000 per year, depending on experience and work location.

Company

hirify.global provides managed IT, cybersecurity, cloud, and technology strategy services for growing, highly regulated organizations.

What you will do

  • Support vCISO staff with client cybersecurity and governance program management.
  • Update policies to align with client practices and maintain controls frameworks.
  • Conduct vendor risk assessments and manage third-party risk monitoring programs.
  • Coordinate security and compliance due diligence questionnaires across departments.
  • Administer security awareness training and phishing simulation campaigns, including content deployment, user enrollment, and progress tracking.
  • Collect framework and regulatory evidence, coordinate security audits and projects, and prepare reports on findings and risk assessments.

Requirements

  • 3+ years of experience in a GRC role focused on IT or cybersecurity controls, or in an IT role with a cybersecurity focus.
  • Previous experience working at a Managed Services Provider.
  • Strong analytical, organizational, problem-solving, written, and verbal communication skills.
  • Comfort working with technical tools to gather information about systems and settings.
  • Ability to manage multiple projects simultaneously while maintaining accuracy, quality, and deadlines.
  • High personal and professional ethical standards.

Nice to have

  • Cybersecurity or compliance certifications such as Security+, CGRC, CRISC, CISSP, or CISA.
  • Hands-on experience with GRC platforms, security awareness tools, and phishing simulation platforms.
  • Knowledge of SEC, SOX, or HIPAA requirements in financial services or biotech.
  • Experience with vendor management platforms and third-party risk assessment methodologies.

Culture & Benefits

  • Remote work environment with benefits adjusted based on location.
  • Health, dental, vision, FSA, HRA, HSA, life, and disability insurance.
  • 401(k), paid parental leave, holiday pay, flexible vacation, and sick days.
  • Twelve holidays, including a birthday and work-anniversary day off.
  • Learning and development opportunities, wellness benefits, monthly rewards, spot bonuses, and community events.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →