Security GRC Analyst

Jobtailor

Deutschland

Remote

EUR 42.000 - 64.000

Vollzeit

14 Tage+

Erhalte mehr Antworten von Arbeitgebern

Versende in nur wenigen Minuten einen passgenauen Lebenslauf.

Zusammenfassung

Jobtailor in Germany seeks a dedicated GRC Analyst to drive enterprise risk assessments using NIST CSF, NIST 800-53, SOC 2, and CIS, and to analyze vulnerability reports for remediation and risk reduction. You will develop security awareness programs, deliver insightful GRC metrics, and support third-party risk evaluations.

The role emphasizes continuous improvement of GRC programs, audit readiness, and agile prioritization, with a focus on regulatory awareness and cross-functional collaboration.

Qualifikationen

  • Bachelor’s degree in Cybersecurity, Information Systems, or related field.
  • 1–3 years of experience in GRC, risk management, or compliance within cybersecurity.
  • Working knowledge of regulatory frameworks, audit processes, and control environments.
  • Understanding of third-party/vendor risk management (TPRM) processes and enterprise risk concepts.
  • General knowledge of security tools and controls across domains such as network security, endpoint protection.
  • Proven ability to track, measure, and report on IS GRC program effectiveness using tools such as ServiceNow, Archer, SharePoint, and Power BI.
  • Experience contributing to continuous improvement of GRC programs.
  • Experience developing and delivering training materials.
  • Strong organizational, analytical, and multitasking abilities.

Aufgaben

  • Perform and mature enterprise risk assessments using frameworks such as NIST CSF, NIST 800-53, SOC 2, and CIS.
  • Analyze vulnerability assessment reports to support troubleshooting, remediation, and risk reduction initiatives.
  • Develop and execute security awareness programs, including training, phishing simulations.
  • Deliver actionable reporting and insights, including assessment results and GRC metrics.
  • Perform end-to-end cyber third-party risk assessments.
  • Drive process and tooling optimization.
  • Support governance and control management.
  • Enable audit readiness and due diligence.
  • Stay current on evolving regulations, frameworks, and industry trends.
  • Manage priorities and execution using Agile methodologies.

Kenntnisse

NIST CSF
NIST 800-53
SOC 2
CIS
Vulnerability Assessment
Risk Management
Audit Processes
Security Tools
IS GRC Program Effectiveness
Control Environments
Agile Methodologies

Ausbildung

Bachelor’s degree in Cybersecurity/Information Systems or related field

Tools

ServiceNow
Archer
SharePoint
Power BI

Jobbeschreibung

  • Perform and mature enterprise risk assessments using frameworks such as NIST CSF, NIST 800-53, SOC 2, and CIS
  • Analyze vulnerability assessment reports to support troubleshooting, remediation, and risk reduction initiatives
  • Develop and execute security awareness programs, including training, phishing simulations
  • Deliver actionable reporting and insights, including assessment results and GRC metrics
  • Perform end-to-end cyber third-party risk assessments
  • Drive process and tooling optimization
  • Support governance and control management
  • Enable audit readiness and due diligence
  • Stay current on evolving regulations, frameworks, and industry trends
  • Manage priorities and execution using Agile methodologies
Requirements
  • Bachelor’s degree in Cybersecurity, Information Systems, or related field. 1–3 years of experience in GRC, risk management, or compliance within cybersecurity.
  • Working knowledge of regulatory frameworks, audit processes, and control environments
  • Understanding of third-party/vendor risk management (TPRM) processes and enterprise risk concepts
  • General knowledge of security tools and controls across domains such as network security, endpoint protection
  • Proven ability to track, measure, and report on IS GRC program effectiveness using tools such as ServiceNow, Archer, SharePoint, and Power BI
  • Experience contributing to continuous improvement of GRC programs
  • Experience developing and delivering training materials
  • Strong organizational, analytical, and multitasking abilities
Core Competencies

Demonstrates expertise in enterprise risk assessments and governance, risk, and compliance (GRC) frameworks, with a strong focus on NIST CSF, NIST 800-53, and SOC 2. Proficient in developing security awareness programs and managing third-party risk assessments while utilizing Agile methodologies for effective execution.

Highest-signal resume keywords
  • Enterprise Risk Assessment
  • Governance, Risk, And Compliance (GRC)
  • Third-Party Risk Management (TPRM)
  • Security Awareness Program Development
  • Agile Methodologies
Hard Skills
  • NIST CSF
  • NIST 800-53
  • SOC 2
  • CIS
  • Vulnerability Assessment
  • Risk Management
  • Audit Processes
  • Security Tools
  • IS GRC Program Effectiveness
  • Control Environments
Soft Skills
  • Organizational Abilities
  • Analytical Skills
  • Multitasking Abilities
Industry Keywords
  • Cybersecurity
  • Compliance
  • Regulatory Frameworks
  • Risk Reduction Initiatives
  • Continuous Improvement
Tools & Technologies
  • ServiceNow
  • Archer
  • SharePoint
  • Power BI
Hol dir deinen kostenlosen, vertraulichen Lebenslauf-Check.
oder ziehe deine Datei hierhin.
Similar jobs

Ähnliche Jobs, die dir auch gefallen könnten

Information Security Consultant
Information Security Consultant

Jobtailor • Lübeck

Vor Ort
EUR 60.000 - 80.000
Cybersecurity Assessment Data Analyst
Cybersecurity Assessment Data Analyst

Jobtailor • Deutschland

Hybrid
EUR 90.000 - 120.000
Cyber Security GRC Consultant
Cyber Security GRC Consultant

MeJuvante GmbH • Frankfurt

Vor Ort
EUR 65.000 - 95.000
GRC Cybersecurity Analyst
GRC Cybersecurity Analyst

Fractional CISO • Sevenig (Our)

Hybrid
EUR 95.000 - 147.000
Senior Security Agent / AI Red Team Engineer
Senior Security Agent / AI Red Team Engineer

Jobtailor • Deutschland

Hybrid
EUR 103.000 - 142.000
Cybersecurity Analyst
Cybersecurity Analyst

Jobtailor • Deutschland

Vor Ort
EUR 65.000 - 90.000
Senior Analyst IT Governance, Risk & Compliance
Senior Analyst IT Governance, Risk & Compliance

Embedded Shishya • Deutschland

Remote
EUR 90.000 - 120.000
SNOC Engineer II
SNOC Engineer II

Jobtailor • Deutschland

Remote
EUR 52.000 - 72.000
Specialist - Information Security
Specialist - Information Security

Everise • Deutschland

Hybrid
EUR 65.000 - 95.000
Senior Security Engineer – Cloud Security
Senior Security Engineer – Cloud Security

Jobtailor • Deutschland

Hybrid
EUR 90.000 - 130.000