Governance and Compliance Analyst

Gravity IT Resources

Deerfield Beach (FL)

Hybrid

USD 90,000 - 130,000

Part time

4 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

Gravity IT Resources seeks a Governance and Compliance Analyst to support the information security department by providing IT governance and compliance as a service. You will manage assessments, compliance program management, and assurance activities, collaborating with business areas to meet standards like SOC 1 Type 2, MAR, NY DFS 500, CCPA and HIPAA as well as contractual security requirements.

Strong communication is essential.

Qualifications

  • Working knowledge of governance and compliance, including policy, process, controls frameworks, and regulatory environments.
  • Experience evaluating, building, and optimizing security program elements (e.g., logical access control, application security, vendor risk management, network security, privacy).
  • Strong organizational skills to thrive in a sense-of-urgency environment and leverage best practices.
  • Excellent written and verbal communication skills for interfacing across all levels of the organization.
  • Strong analytical, problem solving, and decision-making skills with a solution-focused attitude.
  • Self-directed work habits demonstrating initiative, drive, creativity, professionalism, and maturity.
  • Experience working with auditors.

Responsibilities

  • Ensure compliance with regulatory requirements and internal controls through proactive validation of controls.
  • Review regulatory and compliance matters related to information technology and perform gap analysis.
  • Implement and maintain IT, security, and privacy controls framework.
  • Develop and maintain IT policies, standards, and procedures.
  • Act as an advocate for information security practices.
  • Engage control owners and key stakeholders across the enterprise to collect, test evidence, and assess compliance.
  • Maintain relationships and trust with key partners throughout the company.
  • Manage compliance and risk initiatives in a GRC platform.
  • Facilitate IT audits and assessments, including remediation of findings.
  • Understand contractual security requirements for third parties and speak knowledgeably on contractual security aspects.
  • Stay informed about new security standards and governance through industry and government sources.
  • Establish governance around disaster recovery, developing standards and action plans in collaboration with business and IT leaders.
  • Conduct periodic internal assessments for security risk and compliance as directed.

Skills

Governance & compliance
Regulatory frameworks
IT security concepts
Vendor risk management
Auditing cooperation
Communication skills
Policy development

Tools

GRC platform

Job description

Job Title: Governance and Compliance Analyst

Location Requirements: Hybrid

Job Type: Contract

Role Overview:
You will support the information security department by providing IT governance and compliance as a service. Your role involves managing assessments, compliance program management, and assurance activities. You will operationalize and communicate compliance initiatives across the enterprise, working closely with business areas to ensure standards like SOC 1 Type 2, MAR, NY DFS 500, CCPA, and HIPAA are met. Collaboration and relationship-building are key to your success.

Responsibilities:

  • Ensure compliance with regulatory requirements and internal controls through proactive validation of controls
  • Review regulatory and compliance matters related to information technology and perform gap analysis
  • Implement and maintain IT, security, and privacy controls framework
  • Develop and maintain IT policies, standards, and procedures
  • Act as an advocate for information security practices
  • Engage control owners and key stakeholders across the enterprise to collect, test evidence, and assess compliance
  • Maintain relationships and trust with key partners throughout the company
  • Manage compliance and risk initiatives in a GRC platform
  • Facilitate IT audits and assessments, including remediation of findings
  • Understand contractual security requirements for third parties and speak knowledgeably on contractual security aspects
  • Stay informed about new security standards and governance through industry and government sources
  • Establish governance around disaster recovery, developing standards and action plans in collaboration with business and IT leaders
  • Conduct periodic internal assessments for security risk and compliance as directed

Required Qualifications:

  • Working knowledge of governance and compliance, including policy, process, controls frameworks, and regulatory environments
  • Experience evaluating, building, and optimizing security program elements (e.g., logical access control, application security, vendor risk management, network security, privacy)
  • Strong organizational skills to thrive in a sense-of-urgency environment and leverage best practices
  • Excellent written and verbal communication skills for interfacing across all levels of the organization
  • Strong analytical, problem solving, and decision-making skills with a solution-focused attitude
  • Self-directed work habits demonstrating initiative, drive, creativity, professionalism, and maturity
  • Experience working with auditors

Additional certifications such as CISSP, CISA, CISM, CIPP, GIAC are a plus.

Equal Employment Opportunity Statement

Gravity IT Resources is an Equal Opportunity Employer. We are committed to creating an inclusive environment for all employees and applicants. We do not discriminate on the basis of race, color, religion, sex (including pregnancy, sexual orientation, or gender identity), national origin, age, disability, genetic information, veteran status, or any other legally protected characteristic. All employment decisions are based on qualifications, merit, and business needs.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Hybrid Governance & Compliance Analyst
Hybrid Governance & Compliance Analyst

Gravity IT Resources • Deerfield Beach (FL)

Hybrid
USD 90,000 - 130,000
IT AUDITING (Governance and Compliance)
IT AUDITING (Governance and Compliance)

3Core Systems, Inc • Deerfield Beach (FL)

Hybrid
USD 95,000 - 125,000
Governance, Risk & Compliance Analyst I
Governance, Risk & Compliance Analyst I

Geographic Solutions, Inc. • Dunedin (FL)

On-site
USD 60,000 - 100,000
Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

Delta-Denta • St. Louis (MO)

Hybrid
USD 75,000 - 110,000
Info. Governance and Compliance Analyst
Info. Governance and Compliance Analyst

INSPYR Solutions • Deerfield Beach (FL)

Hybrid
USD 69,000 - 83,000
Comprehensive medical benefits
401(k)
Retirement plan
GOVERNANCE, RISK, AND COMPLIANCE ANALYST
GOVERNANCE, RISK, AND COMPLIANCE ANALYST

Access Data Consulting Corporation • Phoenix (AZ)

Hybrid
USD 80,000 - 100,000
Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

Delta Dental of Missouri • Missouri

Hybrid
USD 80,000 - 100,000
Sr. Security Governance, Risk & Compliance Specialist
Sr. Security Governance, Risk & Compliance Specialist

clarioclinical • United States

On-site
USD 120,000 - 180,000
Governance Risk and Compliance Analyst Intermediate
Governance Risk and Compliance Analyst Intermediate

Cone Health • Greensboro (NC)

On-site
USD 110,000 - 140,000
Governance, Risk and Compliance Analyst Senior
Governance, Risk and Compliance Analyst Senior

Cone Health • Greensboro (NC)

On-site
USD 90,000 - 130,000