GRC Analyst: Security Policy & Risk Lead

NorthMark Compute & Cloud

Dallas (TX)

On-site

USD 80,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

NorthMark Compute & Cloud in Dallas, TX is seeking a GRC Analyst to join the Information Security team. You will manage security change reviews, perform risk and vendor assessments, and maintain the enterprise risk register, aligning policies with frameworks to protect critical services.

Collaborate with Engineering, Product, Legal, and Operations to document controls, report risk to the CISO, and ensure governance processes are followed.

Qualifications

  • Bachelor’s degree or equivalent experience in information systems, cybersecurity, or a related field.
  • 4–8 years of experience in GRC, information security governance, compliance, or risk management.
  • Hands-on experience with security change management, risk assessment, or policy management processes.
  • Working knowledge of major security frameworks or standards — ISO 27001, SOC 2, NIST CSF, NIST SP 800-53, or CIS Controls.
  • Experience developing, reviewing, and publishing information security policies, standards, and procedures.
  • Familiarity with risk register management and reporting.
  • Experience with GRC platforms (e.g., ServiceNow GRC, Vanta, Drata, Hyperproof, or Archer).
  • Proficiency with project/workflow tools (Jira, Confluence) for change tracking and policy workflows.
  • Strong written communication to translate security requirements for non-technical audiences.
  • Collaborative with Engineering, Legal, HR, and Operations.
  • Certifications such as CISM, CRISC, CISA, CISSP, ISO 27001 Lead Implementer/Auditor, or CompTIA Security+ preferred.

Responsibilities

  • Own and operate the security change management review process, coordinating with Engineering and IT stakeholders and documenting findings and approvals.
  • Iterate on change management processes, runbooks, and risk criteria to balance rigor and agility for low- and high-risk changes.
  • Conduct security reviews for new products, features, third‑party integrations, and vendor onboarding, tracking remediation of gaps.
  • Facilitate threat identification workshops and risk discussions with cross-functional teams for major initiatives.
  • Maintain the enterprise information security risk register, clearly articulating risks and tracking mitigations.
  • Develop risk reporting dashboards and summaries for the CISO and executives; monitor emerging risks.
  • Author, revise, and manage the information security policy library aligned to ISO 27001, SOC 2, and NIST CSF.
  • Manage the security exception process with the GRC Manager and track expiry/renewal.
  • Monitor governance adherence and produce compliance metrics for security leadership.
  • Serve as a liaison for Engineering, Product, Legal, HR, and Operations on governance questions.

Skills

Change management
Risk assessment
Policy writing
Stakeholder communication
Cross-functional collaboration

Education

Bachelor’s degree in Information Systems, Computer Science, Business Administration, or related field

Tools

ISO 27001
SOC 2
NIST CSF
NIST SP 800-53
CIS Controls

Job description

NorthMark Compute & Cloud in Dallas, TX is seeking a GRC Analyst to join the Information Security team. You will manage security change reviews, perform risk and vendor assessments, and maintain the enterprise risk register, aligning policies with frameworks to protect critical services.

Collaborate with Engineering, Product, Legal, and Operations to document controls, report risk to the CISO, and ensure governance processes are followed.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC & Security Policy Lead
GRC & Security Policy Lead

NMC2 • Dallas (TX), Northern (KY)

Hybrid
USD 81,000 - 99,000
GRC Analyst: Security Governance & Risk
GRC Analyst: Security Governance & Risk

NorthMark Strategies LLC • Dallas (TX)

On-site
USD 95,000 - 125,000
Company-Paid Lunch Stipend
Employer-Paid Medical (HDHP) including
Dental and Vision benefits
+4
GRC Analyst: Shape Security Governance & Risk
GRC Analyst: Shape Security Governance & Risk

NorthMark Strategies • Dallas (TX)

On-site
USD 110,000 - 140,000
Lunch stipend
Medical benefits
Paid time off
GRC Analyst
GRC Analyst

NMC2 • Dallas (TX), Northern (KY)

Hybrid
USD 81,000 - 99,000
GRC Analyst
GRC Analyst

NorthMark Compute & Cloud • Dallas (TX)

On-site
USD 80,000 - 130,000
Remote Security GRC Analyst: Risk & Compliance Lead
Remote Security GRC Analyst: Risk & Compliance Lead

NEPSE Trading • United States

On-site
USD 70,000 - 77,000
Health insurance
401(k) plan with company match
Pension plan
+1
GRC Cyber Security Analyst - Enterprise Risk & Compliance
GRC Cyber Security Analyst - Enterprise Risk & Compliance

Insight Global • San Antonio (TX)

On-site
USD 95,000 - 125,000
GRC Analyst: Risk, Compliance & Audit Lead
GRC Analyst: Risk, Compliance & Audit Lead

Access Data Consulting Corporation • Phoenix (AZ)

Hybrid
USD 80,000 - 100,000
GRC Analyst: Risk, Compliance & Security Awareness
GRC Analyst: Risk, Compliance & Security Awareness

Protective • United States

Remote
USD 70,000 - 77,000
Health insurance
Dental insurance
Vision insurance
+5
GRC & Security Compliance Analyst
GRC & Security Compliance Analyst

Cast & Crew • United States

On-site
USD 110,000 - 120,000
Medical
Dental
Vision
+3