GRC Analyst – SecOps

Bright Defense, LLC.

United States

On-site

USD 70,000 - 90,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A security consulting company in the United States is looking for a GRC Analyst II to support governance programs for clients. In this role, you will onboard customers, perform gap assessments, and develop security policies. The ideal candidate will have 2-3 years in information security and excellent communication skills. This position demands a collaborative mindset and a solid understanding of security frameworks. Join us to help strengthen our clients' security posture.

Qualifications

  • 2–3 years of relevant experience in information security, compliance, or risk management.
  • Exceptional written and verbal communication skills.
  • Solid understanding of common security frameworks (ISO 27001, SOC 2, NIST CSF).
  • Proven experience developing and implementing security policies and controls.
  • Strong attention to detail and ability to manage multiple tasks.

Responsibilities

  • Support customer onboarding and ensure clients understand their security program.
  • Perform gap assessments against security frameworks.
  • Draft and maintain information security policies and procedures.
  • Explain governance frameworks and policy requirements to stakeholders.
  • Develop and track risk registers and mitigation plans.
  • Prepare high-quality documentation and status reports for customers.

Skills

Information security
Compliance
Risk management
Verbal communication
Written communication
Attention to detail
Collaboration

Job description

About the Role:

As aGRC Analyst II on our Governance Team, you’ll play a critical role in helping our customers establish and implement robust security governance programs. You’ll work directly with clients to support customer onboarding, policy development, gap reviews, and compliance readiness, and you’ll be the trusted point of contact to clearly communicate security policies, processes, and requirements to our customers.

Key Responsibilities:
  • Support customer onboarding and kick‑off, ensuring clients understand their security program roadmap and governance objectives.
  • Perform gap assessments to identify areas for improvement against frameworks such as ISO 27001, SOC 2, NIST, or other relevant standards.
  • Draft, review, and maintain information security policies, procedures, and controls, ensuring they are clearly communicated and explained to customers.
  • Effectively explain governance frameworks and policy requirements to non‑technical stakeholders.
  • Develop and track risk registers, mitigation plans, and corrective action plans.
  • Coordinate hand‑offs between governance activities and technical teams (e.g., Offensive Security, SecOps).
  • Prepare clear, high‑quality documentation and status reports for customers.
  • Support clients through audit readiness and defense, helping collect evidence, track findings, and remediate gaps.
  • Participate in regular customer status meetings and provide input on governance milestones and deliverables.
Requirements:
  • ✅ 2–3 years of relevant experience in information security, compliance, or risk management.
  • ✅ Exceptional written and verbal communication skills are mandatory — you must be able to confidently and clearly explain security policies and governance requirements to diverse audiences.
  • ✅ Support US Eastern and Pacific timezones from 9 AM–6 PM.
  • ✅ Solid understanding of common security frameworks (ISO 27001, SOC 2, NIST CSF, etc.).
  • ✅ Proven experience developing and implementing security policies and controls.
  • ✅ Strong attention to detail and ability to manage multiple tasks and customer deliverables simultaneously.
  • ✅ A collaborative, customer‑focused mindset — you thrive in a cross‑functional team environment.
Nice to Have:
  • ➕ Relevant certifications, such as ISO 27001 Lead Implementer, CISA, CISSP (Associate), Security+, or similar.
  • ➕ Experience working with clients in regulated industries (e.g., finance, healthcare, SaaS).
  • ➕ Exposure to tools for risk and compliance management.
Why You’ll Love This Role:
  • ✅ Directly help customers build trust and strengthen their security governance posture.
  • ✅ Develop hands‑on expertise with real‑world frameworks, audits, and compliance practices.
  • ✅ Be part of a supportive team that values strong communication, clear documentation, and continuous learning.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Specialist (Governance, Risk & Compliance)
GRC Specialist (Governance, Risk & Compliance)

360CyberX • United States

On-site
USD 70,000 - 90,000
GRC Analyst
GRC Analyst

The Emery Company, LLC • Houston (TX)

On-site
USD 85,000 - 110,000
Information Security Analyst - GRC & Operations
Information Security Analyst - GRC & Operations

WHSmith North America • Las Vegas (NV)

Hybrid
USD 70,000 - 110,000
GRC Analyst II - Security Governance & Compliance Lead
GRC Analyst II - Security Governance & Compliance Lead

Bright Defense, LLC. • United States

Remote
USD 70,000 - 90,000
GRC Analyst
GRC Analyst

Glocomms • Dallas (TX)

Hybrid
USD 90,000 - 150,000
Competitive base salary
Annual bonus
Comprehensive medical, dental, and eye
+2
IT Security GRC Analyst
IT Security GRC Analyst

The Phoenix Group • Charlotte (NC)

On-site
USD 85,000 - 120,000
GRC Analyst
GRC Analyst

NMC2 • Dallas (TX), Northern (KY)

Hybrid
USD 81,000 - 99,000
IT GRC Lead Analyst
IT GRC Lead Analyst

Ohio Farmers Insurance Company • Westfield Center (OH)

Hybrid
USD 90,000 - 120,000
Governance, Risk, & Compliance (GRC) Analyst
Governance, Risk, & Compliance (GRC) Analyst

Districttechgroup • Washington

Hybrid
USD 80,000 - 100,000
Fully remote work environment
Competitive salary and performance bonuses
Health, dental, and vision insurance
+2
Senior GRC Analyst
Senior GRC Analyst

Jobtailor • New York (NY)

On-site
USD 140,000 - 190,000