Analyst

Insight Security

Northern (KY)

Hybrid

USD 68,000 - 95,000

Full time

11 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Health, dental, and vision insurance
Fully remote work
Unlimited PTO
Home office stipend
401(k) with company match

Job summary

Insight Security is seeking a GRC Analyst to guide clients through compliance and risk programs from a fully remote location in the United States. You will assess frameworks like SOC 2, ISO 27001, and HIPAA, identify gaps, and help build practical programs that satisfy auditors without adding busywork.

You will collaborate with clients to tailor controls to their business, prepare for audits, respond to security questionnaires, and manage vendor risk while creating documentation that runs

Qualifications

  • 2+ years of experience in GRC, compliance, or security program management.
  • Familiarity with SOC 2, ISO 27001, NIST CSF, and HIPAA.
  • Experience with audit preparation and working with external auditors.
  • Strong writing skills and attention to detail.
  • Ability to explain compliance requirements in plain language to non-security audiences.
  • Comfort working with multiple clients and managing competing priorities.

Responsibilities

  • Conduct gap assessments against SOC 2, ISO 27001, HIPAA, and other security frameworks.
  • Help clients build and maintain policies, procedures, and control documentation.
  • Prepare clients for audits and manage the audit process from start to finish.
  • Respond to customer security questionnaires and RFPs.
  • Assess third-party vendor risk and help clients build vendor management programs.
  • Build and maintain risk registers and help clients prioritize remediation efforts.
  • Create training materials and help clients build security awareness programs.
  • Work with our consulting team to deliver client engagements on time and on budget.

Skills

GRC experience
Security frameworks
Audit preparation
Clear writing
Plain-language explanations
Vendor risk management

Tools

Vanta
Drata

Job description

We're looking for someone who can help our clients navigate compliance, build risk programs, and turn security frameworks into something that actually works for their business.

As a GRC Analyst at Insight Security, you'll help clients make sense of the compliance and risk landscape. You'll assess where they stand against frameworks like SOC 2, ISO 27001, and HIPAA, identify gaps, and help them build programs that satisfy auditors without creating busywork.

This isn't about checking boxes on a spreadsheet. You'll work closely with clients to understand their business, figure out what controls actually make sense for their situation, and help them build security programs that are practical and sustainable. When audit time comes, you'll be the one helping them prepare and making sure nothing falls through the cracks.

You'll also help clients respond to security questionnaires, manage vendor risk, and build the documentation that makes everything run smoothly. It's detail-oriented work, but it matters. The companies we work with are often dealing with compliance for the first time, and they need someone who can guide them through it without making it more complicated than it needs to be.

What you'll do
  • Conduct gap assessments against SOC 2, ISO 27001, HIPAA, and other security frameworks
  • Help clients build and maintain policies, procedures, and control documentation
  • Prepare clients for audits and manage the audit process from start to finish
  • Respond to customer security questionnaires and RFPs
  • Assess third-party vendor risk and help clients build vendor management programs
  • Build and maintain risk registers and help clients prioritize remediation efforts
  • Create training materials and help clients build security awareness programs
  • Work with our consulting team to deliver client engagements on time and on budget
What we're looking for
  • 2+ years of experience in GRC, compliance, or security program management
  • Familiarity with common security frameworks (SOC 2, ISO 27001, NIST CSF, HIPAA)
  • Experience with audit preparation and working with external auditors
  • Strong writing skills and attention to detail
  • Ability to explain compliance requirements in plain language to non-security audiences
  • Comfort working with multiple clients and managing competing priorities
  • A practical approach that focuses on what actually reduces risk, not just what looks good on paper
Nice to have
  • Experience working in a consulting environment
  • Familiarity with GRC tools like Vanta, Drata, or similar platforms
  • Experience with privacy frameworks (GDPR, CCPA)
  • Background in IT or technical roles before moving to GRC
  • Relevant certifications (CISA, CRISC, etc.) are helpful but not required
What we offer
  • Competitive salary and equity
  • Fully remote work
  • Health, dental, and vision insurance
  • Unlimited PTO (and we actually use it)
  • Home office stipend
  • 401(k) with company match

We build security programs for growing companies.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Governance, Risk, & Compliance (GRC) Analyst
Governance, Risk, & Compliance (GRC) Analyst

Districttechgroup • Washington

Hybrid
USD 80,000 - 100,000
Fully remote work environment
Competitive salary and performance bonuses
Health, dental, and vision insurance
+2
Cybersecurity GRC Professional
Cybersecurity GRC Professional

duvari group • United States

On-site
USD 120,000 - 190,000
Staff Security Analyst - GRC
Staff Security Analyst - GRC

Jobgether • United States

Hybrid
USD 150,000 - 164,000
Remote work within the United States
Hybrid option with designated offices
Remote GRC Analyst: Build Practical Compliance Programs
Remote GRC Analyst: Build Practical Compliance Programs

Insight Security • Northern (KY)

Hybrid
USD 68,000 - 95,000
Health, dental, and vision insurance
Fully remote work
Unlimited PTO
+2
Sr. GRC Analyst
Sr. GRC Analyst

TriCom Technical Services • Overland Park (KS)

On-site
USD 100,000 - 140,000
Low-cost employee benefits
Paid time off
Paid Holidays
+1
GRC Analyst – SecOps
GRC Analyst – SecOps

Bright Defense, LLC. • United States

On-site
USD 70,000 - 90,000
Senior GRC Analyst
Senior GRC Analyst

Averity • New York (NY)

On-site
USD 90,000 - 140,000
Sr. Security Engineer/Analyst (GRC)
Sr. Security Engineer/Analyst (GRC)

Insight Global • United States

Hybrid
USD 120,000 - 160,000
Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

Delta-Denta • St. Louis (MO)

Hybrid
USD 75,000 - 110,000
GRC Auditor
GRC Auditor

Silpa Consulting LLC • Houston (TX)

Remote
USD 90,000 - 150,000
Flexible work options
Engagement with executive stakeholders
Long-term relationships with clients