About the Role Seeking a practical, organized, and collaborative Cybersecurity Governance, Risk & Compliance (GRC) Analyst to support our cybersecurity governance, risk management, and compliance program. You will work with cybersecurity, infrastructure, business and third-party vendor owners to help keep security requirements on track, documentation current, audit-ready evidence, and identified risks visible to management. Responsibilities Maintain and improve cybersecurity policies, standards, procedures, templates, and supporting documentation. Help coordinate recurring and change-driven cybersecurity compliance activities, including assigning actions, tracking due dates, and following up with responsible teams. Review documentation to control mapping evidence for completeness, accuracy, consistency, and audit readiness. Maintain audit records, including control matrices, roles & responsibilities, risk registers and exception records, and remediation trackers. Work with technical and business teams to interpret security audit requirements and help ensure controls are implemented consistently. Prepare clear compliance status updates covering open gaps, overdue actions, upcoming obligations, exceptions, and remediation progress. Required Qualifications Two or more years of relevant experience in managing cybersecurity governance, audit, third-party risk, security controls, or a related field. Working knowledge of at least one cybersecurity or compliance framework, such as
PCI DSS, ISO
27001, the NIST Cybersecurity Framework, SOC 2, or applicable privacy requirements. General understanding of common IT and cybersecurity controls in at least one of the areas, such as access management, vulnerability management, change management, incident response, data protection, logging, cloud security, and third-party oversight. Strong written communication skills, including the ability to produce clear procedures, assessment results, status reports, and remediation records required for the audit. Strong organizational skills and attention to detail, with the ability to manage multiple activities and follow up on outstanding actions. Ability to work constructively with technical teams, business stakeholders, vendors, auditors, and management. Comfort using spreadsheets, document repositories, ticketing systems, collaboration platforms, or GRC tools. Preferred Qualifications Experience supporting internal audits, PCI
DSS, ISO
27001, privacy, or other regulatory or contractual compliance activities. Experience performing vendor or third-party security reviews. Experience working in a regulated, operationally critical, or highly available environment. Familiarity with GRC platforms, evidence-management tools, or compliance automation tools. Relevant certifications such as Security+, CISA, CRISC, ISO 27001 Foundation, or similar. Location This is a hybrid position. The selected candidate will be expected to work from our office on designated days and may work remotely on other days while collaborating closely with the team. What Success Looks Like A successful analyst in this role will help make cybersecurity obligations easier to understand, track, and demonstrate compliance with. Policies and supporting documentation will remain current; evidence will be organized and defensible; risks and exceptions will have clear ownership; and management will have reliable visibility into gaps and remediation progress. Just as importantly, the analyst will build productive relationships with the teams responsible for implementing controls and will help make compliance activities more consistent and less disruptive over time. We value relevant experience, sound judgment, curiosity, and the ability to learn.
Pay:
$120,000.00 - $170,000.00 per year
Benefits:
401(k) Dental insurance Health insurance Paid time off Vision insurance