Staff Security Analyst - GRC
New
J
JobgetherInformation Security
Remote work within the United States, with a hybrid option available from designated offices.Full-TimeStaff
Salary$150,000–$164,000 annual base salary
Apply NowOpens the employer's application page
Job Details
- Experience
- 8–10+ years
- Required Skills
- AWSGCPAzureHIPAA
Requirements
- 8–10+ years of relevant experience in security, compliance, GRC, or program management.
- Extensive knowledge of ISO 27001, SOC 1, SOC 2, PCI-DSS, and HIPAA frameworks.
- Hands-on experience with GRC tools and building automation in cloud-native environments (AWS, GCP, or Azure).
- Working knowledge of federal frameworks including NIST 800-53, FedRAMP, and CMMC.
- Strong technical proficiency with enterprise SaaS and cloud infrastructure.
- Excellent project management and organizational skills.
- Strong written and verbal communication skills for technical and non-technical stakeholders.
- Ability to navigate ambiguity and make sound decisions in complex environments.
Responsibilities
- Design, implement, and monitor security and compliance controls for SOC 1, SOC 2, ISO 27001, PCI-DSS, and HIPAA frameworks.
- Partner with engineering teams to align system architecture with security and compliance obligations.
- Develop GRC engineering and automation solutions to scale control testing and CI/CD pipeline integration.
- Support federal compliance initiatives including FedRAMP Moderate+, CMMC, DoD IL, and NIST 800-53.
- Manage customer trust activities, including contract reviews and security questionnaires.
- Identify, track, and mitigate compliance and supply chain risks.
- Communicate security capabilities and practices to enterprise customers and auditors.
View Full Description & ApplyYou'll be redirected to the employer's site