GRC Analyst

Jobtailor

Deutschland

Vor Ort

EUR 90.000 - 130.000

Vollzeit

Vor 9 Tagen

Erhalte mehr Antworten von Arbeitgebern

Versende in nur wenigen Minuten einen passgenauen Lebenslauf.

Zusammenfassung

Jobtailor is seeking a security/compliance leader to advance the GRC program and ensure adherence to NIST, SOC 2, and GovRAMP across cloud and on‑prem environments.

You will drive risk assessments, maintain policies, support audits, and collaborate with engineering and growth teams on government and procurement initiatives.

Qualifikationen

  • 3–5+ years of experience in GRC, security compliance, information security, or internal audit.
  • Experience in federal, regulated, or cloud-based tech environments.
  • Hands‑on participation in at least one complete audit/authorization cycle (SOC 2, FedRAMP, GovRAMP, ISO 27001, etc.).
  • Working knowledge of NIST SP 800‑53, SOC 2, and GovRAMP requirements.
  • Technical understanding of cloud and/or on‑prem environments.
  • IAM, encryption, logging/monitoring, network, SDLC, change management knowledge.
  • Familiarity with AI tools for research, drafting, documentation, evidence management.
  • Strong cross‑functional written and verbal communication skills.
  • Evidence‑first mindset for collecting, organizing, and validating control evidence.

Aufgaben

  • Support development/administration of the GRC program.
  • Maintain compliance with NIST SP 800‑53, CJIS, SOC 2, GovRAMP.
  • Maintain risk register and assist with risk assessments.
  • Monitor control performance and identify remediation areas.
  • Develop and maintain security/compliance policies and procedures.
  • Manage policy version control, approvals, annual reviews, attestations.
  • Assist with SOC 2 and GovRAMP audits and authorizations.
  • Collect, organize, validate, and maintain audit evidence.
  • Coordinate with engineering on compliance requirements.
  • Act as primary contact for customer security questionnaires and vendor assessments.
  • Maintain questionnaire responses, evidence, and customer security materials.
  • Monitor contractual security/privacy/compliance and service obligations.
  • Coordinate reports, SLA docs, insurance certs, certifications.
  • Partner with Growth on government/public-sector RFPs and proposals.
  • Develop/edit security/tech/management proposal sections.
  • Support proposal amendments, customer questions, post‑award activities.
  • Create reusable proposal content and translate security capabilities.

Kenntnisse

GRC
Security compliance
Audit management
Cross‑functional comms
Evidence collection

Tools

Vanta
Drata
AI tools

Jobbeschreibung

  • Support the ongoing development and administration of the organization's GRC program
  • Maintain compliance with NIST SP 800-53, CJIS Security Policy, SOC 2, and GovRAMP requirements
  • Maintain the enterprise risk register and assist with periodic risk assessments
  • Monitor control performance and identify remediation or improvement areas
  • Develop, update, organize, and maintain security and compliance policies and procedures
  • Manage policy version control, approvals, annual reviews, and employee attestations
  • Support SOC 2 and GovRAMP audit and authorization activities
  • Assist with gap assessments and track remediation efforts through completion
  • Collect, organize, validate, and maintain audit evidence
  • Work with engineering and technical teams to complete compliance-related requirements
  • Act as a primary contact for customer security questionnaires, vendor assessments, and compliance reviews
  • Maintain approved questionnaire responses, supporting documentation, and customer-facing security materials
  • Monitor contractual security, privacy, compliance, reporting, and service obligations
  • Maintain a calendar of recurring contractual deliverables and deadlines
  • Coordinate reports, SLA documentation, insurance certificates, certifications, and other required compliance materials
  • Partner with the Growth team on government and public-sector RFPs, solicitations, and proposal opportunities
  • Develop and edit security, technical, compliance, and management proposal sections
  • Support proposal amendments, customer questions, formal responses, and post-award activities
  • Create reusable proposal content and translate technical security capabilities for procurement and government stakeholders
Requirements
  • 3–5+ years of experience in GRC, security compliance, information security, internal audit, or a related discipline
  • Experience in a federal, regulated, or cloud-based technology environment
  • Hands‑on participation in at least one complete audit or authorization cycle involving SOC 2, FedRAMP, StateRAMP/GovRAMP, ISO 27001, CMMC, or a comparable framework
  • Working knowledge of NIST SP 800‑53, SOC 2, and GovRAMP requirements
  • Technical understanding of cloud and/or on‑premises environments
  • Knowledge of identity and access management, encryption, security logging and monitoring, network architecture, software development lifecycle, and change management
  • Practical experience using AI tools for research, drafting, documentation, analysis, or evidence management
  • Strong cross‑functional written and verbal communication skills
  • Evidence‑first mindset and ability to identify, collect, organize, and validate control evidence
  • Ability to create scalable workflows where processes are evolving
  • Organization and execution skills to manage multiple priorities, stakeholders, and deadlines
  • Strategic thinking combined with hands‑on execution skills
  • Adaptability, independent problem‑solving, and ownership
  • Demonstrated ability to coordinate concurrent initiatives while meeting firm external deadlines
  • Ability to work independently and establish processes without extensive direction
  • Must live in the United States
  • Must be a US Citizen or Green Card Holder
  • Must be able to work without sponsorship
  • Preferred: experience with CJIS Security Policy, FBI NGI, or criminal justice information systems
  • Preferred: experience supporting government or public‑sector RFPs and proposal development
  • Preferred: familiarity with Vanta, Drata, or similar compliance automation platforms
  • Preferred: experience working directly with government agencies or organizations subject to federal security requirements
Core Competencies

Demonstrates expertise in GRC program development and administration, with a strong focus on compliance with NIST SP 800-53, SOC 2, and GovRAMP requirements. Proven ability to manage audits, develop security policies, and coordinate compliance-related initiatives in federal and regulated environments.

Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Lead Compliance Analyst
Lead Compliance Analyst

HubSpot • Deutschland

Remote
EUR 70.000 - 110.000
Senior Manager, Information Security Architecture – Engineering
Senior Manager, Information Security Architecture – Engineering

Jobtailor • Deutschland

Remote
EUR 120.000 - 150.000
Corporate Governance, Risk and Compliance Analyst
Corporate Governance, Risk and Compliance Analyst

Jobtailor • Deutschland

Remote
EUR 90.000 - 130.000
Product GRC SME
Product GRC SME

Vanta • Deutschland

Hybrid
EUR 70.000 - 90.000
IS Principal Security Architect
IS Principal Security Architect

Jobtailor • Deutschland

Hybrid
EUR 130.000 - 190.000
GRC Program Architect (Fully Remote)
GRC Program Architect (Fully Remote)

Onebrief • Deutschland

Remote
EUR 90.000 - 130.000
IT Security Analyst – Level 1
IT Security Analyst – Level 1

Jobtailor • Deutschland

Hybrid
EUR 45.000 - 65.000
(Senior) Information Security Officer (German)
(Senior) Information Security Officer (German)

United States Digital Space LLC • München

Vor Ort
EUR 90.000 - 130.000
Cloud Security Engineer
Cloud Security Engineer

Jobtailor • Deutschland

Vor Ort
EUR 90.000 - 130.000
Security training
Security Engineer
Security Engineer

Jobtailor • Deutschland

Vor Ort
EUR 80.000 - 110.000