GRC Analyst

The-Acadian-Companies

Louisiana (MO)

On-site

USD 70,000 - 95,000

Full time

11 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health insurance
401(k)

Job summary

Acadian Companies in Lafayette, LA is seeking a Governance, Risk, and Compliance (GRC) Analyst to join the Information Security Department. The role focuses on operationalizing governance, risk management, and regulatory compliance while bridging security controls with business operations and leadership.

Reporting to the ISO, you will lead the C-SCRM lifecycle, manage POA&M remediation, and support policy development and annual compliance activities across HIPAA and other standards.

Qualifications

  • Bachelor’s degree in cybersecurity, risk management, computer science, or related field.
  • 2–5 years of professional GRC, IT audit, or cybersecurity risk management experience.
  • Practical experience with NIST CSF, NIST SP 800-53, or ISO/IEC 27001; HIPAA experience preferred.

Responsibilities

  • Lead third-party risk management, including vendor risk tiering and assessments.
  • Maintain the Risk Register and POA&M log, track findings and remediation.
  • Draft/update policies aligned with NIST CSF 2.0 and HIPAA; support UARs and IRP exercises.

Skills

GRC
Risk management
Regulatory compliance
NIST CSF

Education

Bachelor's Degree in Cybersecurity or related field

Tools

SOC 2
ISO 27001
HIPAA

Job description

Acadian Companies is hiring a Governance, Risk, and Compliance (GRC) Analyst to join the Information Security Department in Lafayette, LA.

Role Overview

Reporting directly to the Information Security Officer (ISO), the GRC Analyst is a foundational team member responsible for operationalizing enterprise security governance, risk management, and regulatory compliance. Operating independently from IT operations, this role bridges technical security controls, business operations, and executive leadership by leading the Cyber Supply Chain Risk Management (C-SCRM) lifecycle and managing the Plan of Action and Milestones (POA&M) remediation tracker.

Key Responsibilities
Third-Party Risk Management
  • Design and maintain vendor risk tiering methodologies based on data access, criticality, and business impact.
  • Evaluate annual security questionnaires and review third-party attestations (SOC 2, ISO 27001, HITRUST, SBOMs).
  • Maintain the Risk Register and POA&M log, tracking audit findings and vulnerability assessments to resolution.
  • Coordinate with stakeholders to design actionable remediation plans and validate technical control implementations.
Governance & Compliance
  • Draft and update policies aligned with NIST CSF 2.0 and HIPAA; develop organizational profiles to drive maturity.
  • Execute periodic User Access Reviews (UAR) and support annual Incident Response Plan (IRP) tabletop exercises.
Qualifications
  • Bachelor’s Degree in Cybersecurity, Risk Management, Computer Science, or a related field (or equivalent experience).
  • 2–5 years of professional experience in GRC, IT audit, or cybersecurity risk management.
  • Practical experience with NIST CSF, NIST SP 800-53, or ISO/IEC 27001; HIPAA experience highly preferred.
Location

All Locations , Louisiana , United States

Position Type

Full-time

  • We offer comprehensive insurance benefits for full-time employees, including but not limited to Medical, Dental, Vision coverages, along with 401(k) and ESOP (Employee Stock Ownership Program), and Vacation and Sick time.

Acadian Companies is an Equal Opportunity Employer / Aff… Employment is based solely upon one's individual merit and qualifications directly related to professional competence. We don't discriminate on the basis of race, color, religion, national origin, veterans, ancestry, pregnancy status, sex, age, marital status, disability, medical condition, sexual orientation, gender identity, or any other characteristics protected by law. We will make reasonable accommodations to meet our obligations under the Americans with Disabilities Act (ADA) and state disability laws.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Analyst: Risk & Compliance with ESOP Benefits
GRC Analyst: Risk & Compliance with ESOP Benefits

The-Acadian-Companies • Louisiana (MO)

On-site
USD 70,000 - 95,000
Health insurance
401(k)
Governance, Risk & Compliance Analyst (Third-Party Risk Analyst)
Governance, Risk & Compliance Analyst (Third-Party Risk Analyst)

recruit22 • Chicago (IL)

On-site
USD 65,000 - 90,000
Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

Delta Dental of Missouri • Missouri

Hybrid
USD 80,000 - 100,000
Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

Delta-Denta • St. Louis (MO)

Hybrid
USD 75,000 - 110,000
GRC Analyst
GRC Analyst

The Emery Company, LLC • Houston (TX)

On-site
USD 85,000 - 110,000
Governance Risk & Compliance Analyst
Governance Risk & Compliance Analyst

System One • Denver (CO)

Hybrid
USD 80,000 - 100,000
Health and welfare benefits
401(k) plan
Medical, dental, and vision coverage
GRC Analyst
GRC Analyst

Recru • Houston (TX)

Hybrid
USD 90,000 - 120,000
IT Governance Risk & Compliance (GRC) Analyst
IT Governance Risk & Compliance (GRC) Analyst

Trustmark • Ridgeland (MS)

Hybrid
USD 65,000 - 85,000
Senior GRC Analyst
Senior GRC Analyst

Louisiana Blue • Baton Rouge (LA)

On-site
USD 90,000 - 120,000
GRC Analyst II
GRC Analyst II

Frontgrade Technologies • Colorado Springs (CO)

On-site
USD 70,000 - 90,000
Immediate Medical, Dental, and Vision
401K Match with 100% immediate vesting
Tuition Reimbursement/Student Loan Repayment
+2