GRC Analyst

AccruePartners

Fort Mill (SC)

On-site

USD 70,000 - 95,000

Full time

23 hours ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Direct-hire opportunity
Ownership of GRC initiatives
Exposure to NIST / CIS Controls / SOC

Job summary

AccruePartners in Fort Mill, SC is seeking a Governance, Risk & Compliance professional to advance the organization’s security program. You will influence policy, controls, and audit readiness across IT, HR, and business units.

The role emphasizes collaboration, documentation, and practical risk management, with opportunities to liaise on SOC 2, SOX, and regulatory requirements.

Qualifications

  • 3+ years in GRC, IT audit, risk management, or related fields.
  • Experience supporting internal or external audits and collecting evidence.
  • Ability to interpret technical security information for both technical and business stakeholders.
  • Familiarity with GRC, ticketing, workflow or audit-management tools.

Responsibilities

  • Maintain and improve information security policies, standards, procedures, and control documentation.
  • Align security program with NIST CSF and CIS Controls.
  • Manage the risk register and risk acceptance processes.
  • Document risks, compensating controls, owners, remediation plans, and exceptions.
  • Coordinate third-party and vendor security assessments and evidence.
  • Review regulatory, contractual, and audit requirements to identify needed controls.
  • Support SOC 2, SOX, and other audits and related evidence collection.
  • Develop repeatable audit procedures, workpapers, and documentation.
  • Prepare risk and compliance metrics for leadership and stakeholders.
  • Cross-functionally identify control gaps and drive remediation.

Skills

Documentation
Risk assessment
Cross-functional collaboration
Policy interpretation
Security controls

Education

CISA certification
CRISC certification
Security+ certification
ISO 27001 certification

Tools

ServiceNow GRC
Archer
Jira

Job description

  • Established enterprise organization continuing to expand and mature its Information Security function
  • Growing security team creating greater specialization across Security Engineering, Security Operations, and Governance, Risk & Compliance
  • Opportunity to join at an important stage in the evolution of the organization's GRC program
  • Collaborative role partnering across Information Security, IT, Human Resources, system owners, and business leadership
  • Environment where strong documentation, practical risk management, and cross-functional partnership are highly valued
THE TEAM YOU WILL BE JOINING
  • Established enterprise organization continuing to expand and mature its Information Security function
  • Growing security team creating greater specialization across Security Engineering, Security Operations, and Governance, Risk & Compliance
  • Opportunity to join at an important stage in the evolution of the organization's GRC program
  • Collaborative role partnering across Information Security, IT, Human Resources, system owners, and business leadership
  • Environment where strong documentation, practical risk management, and cross-functional partnership are highly valued
What They Offer You
  • Direct-hire opportunity within a growing Information Security organization
  • Ability to take meaningful ownership across governance, risk, compliance, policy, and third-party risk initiatives
  • Opportunity to help mature and standardize security policies, controls, procedures, and audit processes
  • Exposure to recognized security and control frameworks including NIST, CIS Controls, SOC 2, and SOX
  • Highly collaborative role with visibility across technology and business functions
  • Opportunity to become a key individual contributor within the organization's evolving GRC function
What You Will Do
  • Maintain and improve information security policies, standards, procedures, control documentation, and supporting governance materials
  • Help align the organization's security program with frameworks including the NIST Cybersecurity Framework and CIS Controls
  • Manage and maintain the organization's risk register and risk acceptance processes
  • Document identified risks, compensating controls, owners, remediation plans, exceptions, and ongoing review activity
  • Coordinate third-party and vendor security assessments, questionnaires, supporting documentation, and evidence
  • Review contractual, regulatory, customer, and audit requirements to identify required controls and documentation
  • Support SOC 2, SOX, and other internal or external audit activities
  • Coordinate evidence collection, control walkthroughs, issue tracking, and remediation follow-up
  • Develop repeatable audit procedures, workpapers, processes, and supporting documentation
  • Prepare risk and compliance metrics and updates for leadership and other stakeholders
  • Work cross-functionally to identify control gaps, document findings, assign remediation ownership, and drive items through completion
  • Support identity and access control reviews when necessary, while maintaining a broader focus on governance, compliance, policies, procedures, and risk management
BACKGROUND PROFILE
  • 3+ years of experience within Governance, Risk & Compliance, IT Audit, Risk Management, Information Security Compliance, or a related discipline
  • Working knowledge of a recognized security or control framework such as NIST Cybersecurity Framework or CIS Controls
  • Experience supporting internal or external audits and collecting and organizing supporting evidence
  • Strong understanding of risk assessments, control design, control testing, remediation tracking, and policy documentation
  • Experience with third-party or vendor risk management is highly valuable
  • Exposure to SOC 2, SOX, or similar compliance environments preferred
  • Ability to interpret technical security information and communicate findings to both technical and business stakeholders
  • Experience with GRC, ticketing, workflow, or audit-management technologies such as ServiceNow GRC, Archer, Jira, or similar platforms
  • Familiarity with Active Directory and Microsoft Entra ID is beneficial, particularly around access reviews and audit evidence
  • Strong documentation, organization, analytical, and follow-through skills
  • Experience in a regulated or critical-infrastructure environment is beneficial but not required
  • Certifications such as CISA, CRISC, Security+, or ISO 27001 are valuable but not required
LOCATION
  • Fort Mill, SC
  • Onsite
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

GRC Analyst
GRC Analyst

Golden Technology • North Carolina

On-site
USD 120,000 - 160,000
Senior GRC Analyst
Senior GRC Analyst

Averity • New York (NY)

On-site
USD 90,000 - 140,000
GRC (Governance, Risk, and Compliance) Consultant
GRC (Governance, Risk, and Compliance) Consultant

Zoho • United States

Remote
USD 120,000 - 180,000
Staff Risk & Compliance Analyst
Staff Risk & Compliance Analyst

GE Vernova • United States

On-site
USD 85,000 - 120,000
Relocation assistance
Governance, Risk & Compliance Analyst I
Governance, Risk & Compliance Analyst I

Geographic Solutions, Inc. • Dunedin (FL)

On-site
USD 60,000 - 100,000
Governance, Risk & Compliance Senior Analyst
Governance, Risk & Compliance Senior Analyst

Tier4 Group • Atlanta (GA)

On-site
USD 90,000 - 150,000
GRC Specialist II
GRC Specialist II

SCIGON • Salt Lake City (UT)

On-site
USD 116,000 - 144,000
Manager Security Compliance and Risk Management
Manager Security Compliance and Risk Management

RELX • Raleigh (NC)

On-site
USD 118,300 - 219,800
Annual incentive bonus
Senior Governance, Risk & Compliance (GRC) Analyst
Senior Governance, Risk & Compliance (GRC) Analyst

Cianbro • Pittsfield (ME)

On-site
USD 86,450 - 113,750
Employee-owned
Equal opportunity employer
IT GRC Lead Analyst
IT GRC Lead Analyst

Core Specialty Insurance Holdings, Inc. • Cincinnati (OH)

On-site
USD 110,000 - 150,000
Medical Insurance
401(k) match
Wellness program