GRC Analyst

Beacon Hill Staffing Group, LLC

Concord (NH)

Hybrid

USD 90,000 - 120,000

Full time

11 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Beacon Hill Technologies is seeking a Governance, Risk & Compliance (GRC) Specialist to join a growing Information Security team supporting a large-scale critical infrastructure environment. You will strengthen governance, risk management, compliance, and cybersecurity processes across IT, cloud platforms, and OT environments.

This role offers the chance to build a mature cybersecurity governance program from the ground up while coordinating with security, engineering, infrastructure, legal,

Qualifications

  • 3+ years of experience in Governance, Risk & Compliance (GRC), cybersecurity compliance, IT audit, information security, or related disciplines.
  • Strong knowledge of NIST CSF, NIST 800-53, NIST 800-171, ISO 27001, SOC 2, CIS Controls.
  • Experience supporting audits, evidence collection, control testing, remediation tracking, and compliance reporting.
  • Ability to develop and maintain security policies, standards, procedures, and control documentation.
  • Experience conducting risk assessments, gap assessments, and control reviews.
  • Familiarity with third-party and vendor risk management processes.
  • Strong documentation and communication skills with the ability to translate technical concepts into business-friendly language.
  • Experience working with cross-functional teams across technology and business organizations.
  • Knowledge of enterprise security controls including identity and access management, vulnerability management, incident response, and change management.

Responsibilities

  • Support and maintain the organization's governance, risk, and compliance program across IT, cloud, and OT environments.
  • Develop, review, and maintain security policies, standards, procedures, and control documentation.
  • Coordinate audit evidence collection for internal audits, external audits, compliance reviews, and customer assessments.
  • Track audit findings, remediation plans, control deficiencies, policy exceptions, and risk acceptance activities.
  • Perform control testing and compliance validation to ensure security controls are operating effectively.
  • Assist with risk assessments, gap assessments, compliance readiness activities, and control maturity reviews.
  • Support vendor and third-party risk management activities, including security questionnaires and risk reviews.
  • Collaborate with IT, Security Operations, Infrastructure, Engineering, Legal, Procurement, Compliance, and Operations teams.
  • Map security controls to frameworks including NIST, ISO 27001, SOC 2, and CIS Controls.
  • Maintain risk registers, compliance calendars, control inventories, and audit repositories.
  • Prepare compliance reports, dashboards, scorecards, and presentations for leadership.
  • Monitor remediation efforts and work with control owners to ensure timely issue resolution.
  • Support continuous improvement initiatives across the information security governance program.
  • Stay informed on cybersecurity regulations, compliance trends, and industry best practices.

Skills

GRC frameworks
Audit support
Policy development
Risk assessments
Third-party risk
Documentation & reporting
Cross-functional collaboration
Security controls

Tools

ServiceNow GRC
Archer
OneTrust
AuditBoard
LogicGate
Drata
Vanta

Job description

Beacon Hill was founded to set a new standard in search, career placement and flexible staffing.

Governance, Risk & Compliance (GRC) Specialist

Location: Houston, TX (Hybrid: 3 days onsite, 2 remote) OR Chicago, IL (Remote)
Duration: 6-Month Contract (Strong Extension/Conversion Potential)
Start Date: Approximately 3 Weeks from Offer

Overview

We are seeking a Governance, Risk & Compliance (GRC) Specialist to join a growing Information Security team supporting a large-scale critical infrastructure environment. This individual will play a key role in strengthening governance, risk management, compliance, and cybersecurity processes across corporate IT, cloud platforms, and operational technology (OT) environments. This is a unique opportunity to help build and mature a cybersecurity governance program from the ground up while partnering closely with security, engineering, infrastructure, legal, procurement, and business stakeholders.

Key Responsibilities
  • Support and maintain the organization's governance, risk, and compliance program across IT, cloud, and OT environments.
  • Develop, review, and maintain security policies, standards, procedures, and control documentation.
  • Coordinate audit evidence collection for internal audits, external audits, compliance reviews, and customer assessments.
  • Track audit findings, remediation plans, control deficiencies, policy exceptions, and risk acceptance activities.
  • Perform control testing and compliance validation to ensure security controls are operating effectively.
  • Assist with risk assessments, gap assessments, compliance readiness activities, and control maturity reviews.
  • Support vendor and third-party risk management activities, including security questionnaires and risk reviews.
  • Collaborate with IT, Security Operations, Infrastructure, Engineering, Legal, Procurement, Compliance, and Operations teams.
  • Map security controls to frameworks including NIST, ISO 27001, SOC 2, and CIS Controls.
  • Maintain risk registers, compliance calendars, control inventories, and audit repositories.
  • Prepare compliance reports, dashboards, scorecards, and presentations for leadership.
  • Monitor remediation efforts and work with control owners to ensure timely issue resolution.
  • Support continuous improvement initiatives across the information security governance program.
  • Stay informed on cybersecurity regulations, compliance trends, and industry best practices.
Required Qualifications
  • 3+ years of experience in Governance, Risk & Compliance (GRC), cybersecurity compliance, IT audit, information security, or related disciplines.
  • Strong knowledge of NIST Cybersecurity Framework (CSF), NIST 800-53, NIST 800-171, ISO 27001, SOC 2, CIS Controls.
  • Experience supporting audits, evidence collection, control testing, remediation tracking, and compliance reporting.
  • Ability to develop and maintain security policies, standards, procedures, and control documentation.
  • Experience conducting risk assessments, gap assessments, and control reviews.
  • Familiarity with third-party and vendor risk management processes.
  • Strong documentation and communication skills with the ability to translate technical concepts into business-friendly language.
  • Experience working with cross-functional teams across technology and business organizations.
  • Knowledge of enterprise security controls including identity and access management, vulnerability management, incident response, and change management.
  • Strong organizational skills and ability to manage multiple initiatives simultaneously.
Preferred Qualifications
  • Experience within energy, utilities, renewable energy, power generation, critical infrastructure, or industrial environments.
  • Knowledge of NERC CIP, FERC, or similar industry regulations.
  • Exposure to OT/SCADA environments, substations, generation assets, EMS, DERMS, or industrial control systems.
  • Certifications such as CIS, ACIS, SP, CISM, CRISC, Security+, ISO 27001 Lead Auditor/Implementer.
  • Experience with GRC platforms such as ServiceNow GRC, Archer, OneTrust, AuditBoard, LogicGate, Drata, Vanta.
  • Experience supporting SOC 2, ISO 27001, SOX ITGC, PCI, or customer security reviews.
  • Experience creating executive dashboards, compliance scorecards, risk registers, and audit reporting.
Why Join?
  • Opportunity to help build and define a new GRC function.
  • High visibility within a growing Information Security organization.
  • Exposure to both traditional enterprise IT and operational technology environments.
  • Opportunity to contribute to the modernization of cybersecurity, risk, and compliance practices within a critical infrastructure environment.
  • Strong potential for long-term conversion and career growth.

Beacon Hill is an equal opportunity employer and individuals with disabilities and/or protected veterans are encouraged to apply.

California residents: Qualified applications with arrest or conviction records will be considered for employment in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act.

Company Profile

Beacon Hill Technologies, a premier National Information Technology Staffing Group, provides world class technology talent across all industries utilizing a complete suite of staffing services. Beacon Hill Technologies' dedicated team of recruiting and staffing experts consistently delivers quality IT professionals to solve our customers' technical and business needs. Beacon Hill Technologies covers a broad spectrum of IT positions, including Project Management and Business Analysis, Programming/Development, Database, Infrastructure, Quality Assurance, Production/Support and ERP roles. Learn more about Beacon Hill and our specialty divisions, Beacon Hill Associates, Beacon Hill Financial, Beacon Hill HR, Beacon Hill Legal, Beacon Hill Life Sciences and Beacon Hill Technologies by visiting www.bhsg.com.

Benefits Information
  • Medical
  • Dental
  • Vision
  • Federal leave programs
  • State leave programs
  • Upon successfully being hired, details will be provided related to our benefit offerings.

We look forward to working with you. Beacon Hill. Employing the Future

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Analyst
GRC Analyst

Beacon Hill Staffing Group, LLC • Montgomery (AL)

Hybrid
USD 70,000 - 110,000
GRC Analyst
GRC Analyst

Beacon Hill Staffing Group, LLC • Bismarck (ND)

Hybrid
USD 96,000 - 138,000
Medical
Dental
Vision
+2
GRC Analyst
GRC Analyst

Beacon Hill Staffing Group, LLC • Columbia (SC)

Hybrid
USD 83,000 - 124,000
Medical
Dental
Vision
+2
GRC Analyst
GRC Analyst

Beacon Hill Staffing Group, LLC • Lincoln (NE)

Hybrid
USD 90,000 - 120,000
GRC Analyst
GRC Analyst

Beacon Hill Staffing Group, LLC • Carson City (NV)

Hybrid
USD 90,000 - 130,000
Medical
Dental
Vision
+1
GRC Analyst
GRC Analyst

Beacon Hill Staffing Group, LLC • Atlanta (GA)

Hybrid
USD 110,000 - 135,000
Medical
Dental
Vision
+2
GRC Analyst
GRC Analyst

Beacon Hill Staffing Group, LLC • Sacramento (CA)

Hybrid
USD 90,000 - 130,000
Medical
Dental
Vision
+1
GRC Analyst
GRC Analyst

Beacon Hill Staffing Group, LLC • Richmond (VA)

Hybrid
USD 90,000 - 120,000
Medical
Dental
Vision
+2
GRC Analyst
GRC Analyst

Beacon Hill Staffing Group, LLC • Boise (ID)

Hybrid
USD 70,000 - 90,000
GRC Analyst
GRC Analyst

Beacon Hill Staffing Group, LLC • Saint Paul (MN)

Hybrid
USD 90,000 - 130,000
Medical
Dental
Vision
+1