GRC Analyst II

Frontgrade Technologies

Colorado Springs (CO)

On-site

USD 70,000 - 90,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Immediate Medical, Dental, and Vision
401K Match with 100% immediate vesting
Tuition Reimbursement/Student Loan Repayment
Generous PTO and 11 paid Holidays
8 weeks of Paid Family Leave

Job summary

Frontgrade Technologies is seeking a GRC Analyst II in Colorado Springs, CO. This position involves configuring, implementing, and managing security devices while performing threat analysis and incident management. The ideal candidate will possess a Bachelor's Degree and at least two years of experience in cybersecurity, risk, or compliance, with a strong understanding of NIST 800-171. The role offers benefits like medical, dental, and 401K match, along with a flexible work schedule and generous paid time off.

Qualifications

  • Minimum two years of experience in cybersecurity, technology risk, compliance, or audit roles.
  • Experience supporting IT audits, risk assessments, or compliance assessments.
  • Ability to travel up to 10%.

Responsibilities

  • Provide security mitigation planning and maintenance of GRC activities aligned with NIST 800-171.
  • Document and maintain GRC artifacts including risk registers.
  • Assist with audits and regulatory reviews.

Skills

Cybersecurity
Compliance assessments
Risk assessments
NIST 800-171
Communication skills

Education

Bachelor's Degree
Master's Degree

Job description

The Governance, Risk, and Compliance (GRC) Analyst II configures, implements, and manages security devices through strategic and technical security mitigation planning. This involves daily threat analysis and incident management.

Responsibilities
  • Provide strategic and technical security mitigation planning and participate in the design, development, and maintenance of GRC activities aligned with NIST 800-171
  • Document and maintain GRC artifacts including process documentation, risk registers, and control mappings
  • Develop, maintain, and track Plans of Actions and Milestones (POA&Ms), including remediation status and supporting evidence
  • Participate in stakeholders interviews, working sessions, and documentation reviews to support GRC assessments
  • Provide technical expertise in the development, maintenance, and enhancement of corporate security operating procedures, standards and best practices
  • Assist with preparation for internal and external audits, assessments, and regulatory reviews, including evidence collection and response coordination
Qualifications
  • Bachelor's Degree
  • Minimum two (2) years of experience in cybersecurity, technology risk, compliance, audit related roles. OR (6) years of experience may be considered in lieu of a Bachelor's Degree. OR No experience required in lieu of Masters Degree.
  • Experience supporting IT audits, risk assessments, or compliance assessments
  • Working knowledge of CMMC controls, NIST 800-171 requirements, and compliance processes
  • Hands‑on experience developing and maintaining POA&Ms
  • Ability to follow defined processes while managing multiple compliance‑related tasks
  • Ability to travel up to 10%
  • Active Secret clearance or the ability to obtain and maintain
Preferred Qualifications
  • Experience performing NIST-based security or technology risk assessments
  • Industry certifications such as CISA, CRISC, Security+, or similar credentials
  • Strong written and verbal communication skills, particularly for documentation and audit response
  • Detail‑oriented with strong analytical and organizational skills
Other Benefits Include
  • Immediate Medical (FSA and HSA), Dental, and Vision
  • 401K Match with 100% immediate vesting
  • 9X80 compressed work schedule for qualifying roles
  • Career Opportunity and Growth
  • Tuition Reimbursement/Student Loan Repayment
  • Generous PTO and 11 paid Holidays per year (9 designated holidays and 2 floating holidays)
  • 8 weeks of 100% Paid Family Leave

This position may require access to technology, materials, software or hardware that is controlled by either ITAR or EAR U.S. export laws. As a condition of any job offer, in order to be employed in this position, you may need to obtain a U.S. Government export license(s), as required by law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Analyst
GRC Analyst

The Emery Company, LLC • Houston (TX)

On-site
USD 85,000 - 110,000
Compliance Analyst (GRC/RMF Focused)
Compliance Analyst (GRC/RMF Focused)

CL 1e6d8f31 073f 48cd b324 b581c00084bf • Washington

Hybrid
USD 80,000 - 110,000
Information Security Engineer, GRC
Information Security Engineer, GRC

KYOCERA AVX Greenville LLC • Fountain Inn (SC)

On-site
USD 100,000 - 130,000
Information Security Engineer, GRC
Information Security Engineer, GRC

KYOCERA AVX Components Corporation • Fountain Inn (SC)

On-site
USD 90,000 - 120,000
GRC Analyst I
GRC Analyst I

C2 Labs, Inc. • Knoxville (TN)

On-site
USD 60,000 - 85,000
Governance, Risk and Compliance Analyst Senior
Governance, Risk and Compliance Analyst Senior

Cone Health • Greensboro (NC)

On-site
USD 90,000 - 130,000
Information Security Engineer, GRC
Information Security Engineer, GRC

KYOCERA AVX Greenville • Fountain Inn (SC)

On-site
USD 140,000 - 190,000
Security Assessor (RMF / GRC)
Security Assessor (RMF / GRC)

Digital Global Connectors • McLean (VA)

Hybrid
USD 110,000 - 160,000
(GRC) Cybersecurity Analyst ( Full-time ) Atlanta, GA - DK
(GRC) Cybersecurity Analyst ( Full-time ) Atlanta, GA - DK

Central Business Solutions, Inc • Atlanta (GA)

On-site
USD 95,000 - 110,000
Cybersecurity Audit Analyst
Cybersecurity Audit Analyst

Applied Aerospace • Huntsville (AL)

On-site
USD 70,000 - 90,000