Senior Information Security GRC Analyst

New
REMOTE within the United States of AmericaFull-TimeSenior
Salary155,000 - 165,000 USD per year
Apply NowOpens the employer's application page

Job Details

Experience
5-7 years

Requirements

  • 5-7 years of experience in a similar role.
  • 3+ years of expertise conducting audits (SOC 2, PCI or ISO 27001) and handling audit responses.
  • Excellent communication skills for both internal employees and leadership.
  • Experience creating and maintaining documentation for GRC initiatives.
  • Knowledge of GRC tool techniques (Drata, HyperProof, AuditBoard, OneTrust).
  • Familiarity with security and compliance requirements for SOC 2, PCI, NIST CSF, ISO 27001, CCPA.
  • CISA, CISM or working toward certification.

Responsibilities

  • Manage and maintain the Branch Information Security Program, security function programs and processes.
  • Perform control mapping to align internal controls with regulatory and compliance frameworks (e.g., PCI, SOC 2, ISO 27001, NIST CSF, CCPA).
  • Conduct comprehensive gap analysis to identify deficiencies in existing controls.
  • Manage risk and vulnerability assessments, validation testing, compliance reviews, and audits.
  • Manage Branch’s Drata GRC platform, including evidence collection and validation.
  • Collaborate with stakeholders to ensure security practices are integrated into daily operations.
  • Manage the end-to-end third-party vendor management lifecycle.
  • Manage the security training and awareness program.
  • Support the planning of penetration tests and coordination of remediation efforts.
View Full Description & ApplyYou'll be redirected to the employer's site
155,000 - 165,000 USD per year
Apply Now