GRC Analyst

NorthMark Compute & Cloud

Dallas (TX)

On-site

USD 90,000 - 120,000

Full time

5 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Lunch stipend
Medical benefits
Dental & Vision
Parental leave
Life insurance
Disability insurance
401(k) match
Flexible benefits
PTO 25 days
Company holidays

Job summary

NorthMark Compute & Cloud is seeking a GRC Analyst to join the Information Security team in Dallas, TX. You will drive security governance, change management, risk assessments, and policy lifecycle, collaborating with Engineering, Product, Legal, and Operations to keep our controls robust and compliant.

You will own the risk register, produce executive‑level summaries, and maintain the policy library aligned to ISO 27001, SOC 2, and NIST CSF. The role offers strong visibility and impact.

Qualifications

  • Bachelor degree in IS/CS/Business or equivalent experience.
  • 4–8 years in GRC, information security governance, compliance, or risk management.
  • Hands‑on experience owning or contributing to security change management, risk assessment, or policy management.
  • Working knowledge of ISO 27001, SOC 2, NIST CSF, NIST SP 800‑53, or CIS Controls.
  • Experience developing, reviewing, and publishing information security policies, standards, and procedures.
  • Familiarity with risk register management: identifying, rating, tracking, and reporting risks.
  • Experience with GRC automation platforms such as ServiceNow GRC, Vanta, Drata, Hyperproof, or Archer.
  • Proficiency with Jira/Confluence for change tracking, risk registers, and policy workflows.
  • Strong written communication translating security requirements to policy language.
  • Collaborative across Engineering, Legal, HR, and Operations.
  • Certs preferred: CISM, CRISC, CISA, CISSP, ISO 27001 Lead Implementer/Auditor, or CompTIA Security+.

Responsibilities

  • Own and operate the security change management review process — triaging change requests and documenting findings and approvals.
  • Iterate on change management processes to reduce friction for low‑risk changes while ensuring rigor for high‑risk ones.
  • Conduct security reviews for new products, features, third‑party integrations, and vendor onboarding.
  • Facilitate threat identification workshops and risk discussions with engineering, product, and operations.
  • Maintain the enterprise information security risk register with clear ownership and prioritization.
  • Develop risk reporting dashboards and summaries for the CISO and executives.
  • Author and manage the information security policy library — aligned to ISO 27001, SOC 2, and NIST CSF.
  • Manage the security exception process with the GRC Manager and track expiry/renewal.
  • Monitor governance adherence and produce compliance metrics for security leadership.
  • Serve as point of contact for cross‑functional forums like CAB and Risk Committee.

Skills

GRC governance
Risk assessment
Policy management
Security frameworks
Policy drafting
Cross-functional collaboration
Jira/Confluence

Education

Bachelor’s degree in Information Systems, CS, or Business Admin

Tools

ServiceNow GRC
Vanta
Drata
Hyperproof
Archer
Jira
Confluence

Job description

The Company

NorthMark Compute & Cloud (NMC²) is backed by dedicated leadership and investment, with a clear mission as it operates at the bleeding edge of technology. Its goal is to scale and enhance the high-performance computing (HPC) and cloud infrastructure that supports its clients’ research, production, and delivery, enabling breakthroughs that shape the industries of tomorrow. Its engineers build critical infrastructure to eliminate friction in scientific research, simulations, analysis, and decision-making, accelerating discovery and driving faster innovation.

The Company

NorthMark Compute & Cloud (NMC²) is backed by dedicated leadership and investment, with a clear mission as it operates at the bleeding edge of technology. Its goal is to scale and enhance the high-performance computing (HPC) and cloud infrastructure that supports its clients’ research, production, and delivery, enabling breakthroughs that shape the industries of tomorrow. Its engineers build critical infrastructure to eliminate friction in scientific research, simulations, analysis, and decision-making, accelerating discovery and driving faster innovation.

THE POSITION

NMC² is hiring a GRC Analyst to join the Information Security team, reporting to the GRC & Privacy Manager and based at our Dallas, TX offices at Victory Commons. This role is the operational engine of NMC²’s security governance program — responsible for the processes, documentation, and cross-functional coordination that keep our compliance posture current and our risk exposure understood. You will run the security change management review process, conduct risk and vendor assessments, maintain the enterprise risk register, and own the lifecycle of NMC²’s security policy library. Day-to-day, you will work closely with Engineering, Product, Legal, and Operations — acting as the connective tissue between technical teams and the governance structures that protect the business. The right person for this role is equally at home authoring a policy document, running a risk workshop with a product team, and producing a clean risk summary for the CISO. You bring strong judgment about where governance adds real value, and you know how to design processes that people actually follow.

  • Own and operate the security change management review process — triaging incoming IT and infrastructure change requests, engaging Engineering and IT stakeholders, and documenting findings, approvals, and escalations.
  • Iterate on change management processes, runbooks, and risk criteria to reduce friction for low-risk changes while preserving appropriate rigor for high-risk ones.
  • Conduct security reviews for new products, features, third‑party integrations, and vendor onboarding, applying a consistent risk‑based assessment methodology and tracking remediation of identified gaps.
  • Facilitate threat identification workshops and risk discussions with Engineering, Product, and Operations for major initiatives or architectural changes.
  • Maintain and continuously improve the enterprise Information Security risk register, ensuring risks are clearly articulated, owned, prioritized, and tracked through to mitigation or acceptance.
  • Develop risk reporting dashboards and narrative summaries for the CISO and executive leadership; monitor the regulatory and threat landscape for emerging risks that warrant program attention.
  • Author, revise, and manage the organization’s information security policy library — policies, standards, procedures, and guidelines — aligned to applicable frameworks including ISO 27001, SOC 2, and NIST CSF.
  • Manage the security exception process: collect requests, facilitate risk‑based approvals with the GRC Manager, and track expiry and renewal.
  • Monitor adherence to governance processes across the business (change management, access reviews, training, exception management) and produce compliance metrics for security leadership.
  • Serve as a day‑to‑day point of contact for Engineering, Product, Legal, HR, and Operations on security governance questions, and represent the Information Security team in cross‑functional forums such as the Change Advisory Board and Risk Committee.
Requirements
  • Bachelor’s degree in Information Systems, Computer Science, Business Administration, or a related field — or equivalent experience.
  • 4–8 years of experience in GRC, information security governance, compliance, or risk management.
  • Hands‑on experience owning or significantly contributing to security change management, risk assessment, or policy management processes.
  • Working knowledge of at least two major security frameworks or standards — ISO 27001, SOC 2 TSC, NIST CSF, NIST SP 800‑53, or CIS Controls.
  • Experience developing, reviewing, and publishing information security policies, standards, and procedures.
  • Familiarity with risk register management: identifying, rating, tracking, and reporting on information security risks.
  • Experience with GRC or compliance automation platforms such as ServiceNow GRC, Vanta, Drata, Hyperproof, or Archer.
  • Proficiency with project and workflow tools (Jira, Confluence, or similar) for change tracking, risk registers, and policy workflows.
  • Strong written communication skills with the ability to translate technical security requirements into clear, accessible policy language for a non‑technical audience.
  • Collaborative working style with demonstrated experience engaging stakeholders across Engineering, Legal, HR, and Operations.
  • One or more relevant certifications preferred: CISM, CRISC, CISA, CISSP, ISO 27001 Lead Implementer or Lead Auditor, or CompTIA Security+.

Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.

Benefits & Perks
  • Company‑Paid Lunch Stipend: Lunch is provided via GrubHub
  • Company‑Paid Benefits: 100% Employer‑Paid Medical in our High Deductible Health Plan, Dental and Vision benefits for employees and their families, 16 weeks of Paid Parental Leave, Employee Assistance Program, Life insurance, Short‑Term Disability and Long‑Term Disability
  • 401(k): Company will match 100% of your contributions up to 6%
  • Optional Employee‑Paid Benefits: Medical insurance in our PPO plan and a variety of other benefits such as Health Savings Accounts (with Company Contribution!), Flexible Spending Accounts, Supplemental Life Insurance, Wellhub and more.
  • Time Off: 25 days of Paid Time Off plus 12 company holidays
EQUAL OPPORTUNITY EMPLOYER

NORTHMARK STRATEGIES LLC IS AN EQUAL EMPLOYMENT OPPORTUNITY EMPLOYER. THE COMPANY'S POLICY IS NOT TO DISCRIMINATE AGAINST ANY APPLICANT OR EMPLOYEE BASED ON RACE, COLOR, RELIGION, NATIONAL ORIGIN, GENDER, AGE, SEXUAL ORIENTATION, GENDER IDENTITY OR EXPRESSION, MARITAL STATUS, MENTAL OR PHYSICAL DISABILITY, AND GENETIC INFORMATION, OR ANY OTHER BASIS PROTECTED BY APPLICABLE LAW. THE FIRM ALSO PROHIBITS HARASSMENT OF APPLICANTS OR EMPLOYEES BASED ON ANY OF THESE PROTECTED CATEGORIES.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Analyst
GRC Analyst

NorthMark Strategies • Dallas (TX)

On-site
USD 110,000 - 140,000
Lunch stipend
Medical benefits
Paid time off
GRC Analyst
GRC Analyst

NorthMark Strategies LLC • Dallas (TX)

On-site
USD 95,000 - 125,000
Company-Paid Lunch Stipend
Employer-Paid Medical (HDHP) including
Dental and Vision benefits
+4
GRC Compliance Auditor
GRC Compliance Auditor

NorthMark Strategies • Dallas (TX)

On-site
USD 90,000 - 130,000
Company-Paid Lunch Stipend
100% Employer-Paid Medical
Dental and Vision benefits
+4
GRC Analyst
GRC Analyst

NMC2 • Dallas (TX), Northern (KY)

Hybrid
USD 81,000 - 99,000
VP of Security Operations
VP of Security Operations

NorthMark Strategies • Town of Texas (WI)

On-site
USD 180,000 - 260,000
Lunch stipend
Employer-paid medical (HDHP)
Dental coverage
+8
VP of Security Operations
VP of Security Operations

NorthMark Strategies • Dallas (TX)

On-site
USD 180,000 - 280,000
Company‑Paid Lunch Stipend
Company‑Paid Benefits
401(k) match
+2
VP of Security Operations
VP of Security Operations

NorthMark Strategies LLC • Dallas (TX), Northern (KY)

Hybrid
USD 180,000 - 280,000
Health insurance
401(k) match
Paid parental leave
+3
VP of Security Operations
VP of Security Operations

NorthMark Compute and Cloud LLC • Town of Texas (WI), Fort Worth (TX)

On-site
USD 180,000 - 240,000
Company-Paid Benefits: Medical, Dental
Life insurance
401(k) company match
+2
GRC Compliance Auditor
GRC Compliance Auditor

NorthMark Strategies LLC • Dallas (TX)

On-site
USD 90,000 - 140,000
Company-Paid Lunch Stipend
Employer-Paid Medical Insurance
Dental and Vision Benefits
+5
Senior Network Security Engineer
Senior Network Security Engineer

NorthMark Compute & Cloud • Dallas (TX)

On-site
USD 125,000 - 180,000
Lunch stipend
Medical benefits
Dental & Vision
+6