GRC Analyst: Shape Security Governance & Risk

NorthMark Strategies

Dallas (TX)

On-site

USD 110,000 - 140,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Lunch stipend
Medical benefits
Paid time off

Job summary

NorthMark Compute & Cloud (NMC²) is seeking a GRC Analyst to join the Information Security team in Dallas. You will own the security change management review, conduct risk and vendor assessments, maintain the enterprise risk register, and manage the policy library.

Day to day you will work with Engineering, Product, Legal, and Operations to turn governance into practical, compliant processes and clear risk summaries for the CISO and leadership.

Qualifications

  • Bachelor’s degree in Information Systems, CS, Business Admin, or related field, or equivalent experience.
  • 4–8 years of experience in GRC, information security governance, compliance, or risk management.
  • Hands‑on experience owning or contributing to security change management, risk assessment, or policy management.
  • Familiarity with at least two major frameworks: ISO 27001, SOC 2, NIST CSF, NIST SP 800-53, or CIS Controls.
  • Experience developing, reviewing, and publishing information security policies and procedures.
  • Familiarity with risk register management: identifying, rating, tracking, and reporting risks.
  • Experience with GRC/compliance automation platforms such as ServiceNow GRC, Vanta, Drata, Hyperproof, or Archer.
  • Proficiency with Jira, Confluence, or similar for change tracking and policy workflows.
  • Strong written communication for translating security requirements to policy language.
  • Collaborative working style with cross‑functional engagement.
  • Certifications: CISM, CRISC, CISA, CISSP, ISO 27001 Lead Implementer/Auditor, or CompTIA Security+ preferred.

Responsibilities

  • Own and operate the security change management review process—triaging incoming IT and infrastructure changes and documenting findings.
  • Iterate on change management processes to balance low‑risk changes with appropriate rigor for high‑risk ones.
  • Conduct security reviews for new products, features, third‑party integrations, and vendor onboarding.
  • Facilitate threat identification workshops and risk discussions with Engineering, Product, and Operations.
  • Maintain the enterprise Information Security risk register with clear ownership and prioritization.
  • Develop risk reporting dashboards and narratives for the CISO and executives; monitor risk landscape.
  • Author, revise, and manage the information security policy library aligned to ISO 27001, SOC 2, and NIST CSF.
  • Manage the security exception process with the GRC Manager and track expiry/renewal.
  • Monitor governance adherence and produce compliance metrics for security leadership.
  • Serve as a day‑to‑day contact for multiple functions on governance questions and CAB/Risk Committee participation.

Skills

GRC experience
Change management
Risk assessment
Policy management
GRC platforms
Jira/Confluence
Security frameworks
Policy writing
Stakeholder collaboration
Certifications

Education

Bachelor’s degree in Information Systems, Computer Science, Business Administration, or related field

Tools

ServiceNow GRC
Vanta
Drata
Hyperproof
Archer

Job description

NorthMark Compute & Cloud (NMC²) is seeking a GRC Analyst to join the Information Security team in Dallas. You will own the security change management review, conduct risk and vendor assessments, maintain the enterprise risk register, and manage the policy library.

Day to day you will work with Engineering, Product, Legal, and Operations to turn governance into practical, compliant processes and clear risk summaries for the CISO and leadership.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC & Security Policy Lead
GRC & Security Policy Lead

NMC2 • Dallas (TX), Northern (KY)

Hybrid
USD 81,000 - 99,000
GRC Analyst: Security Policy & Risk Lead
GRC Analyst: Security Policy & Risk Lead

NorthMark Compute & Cloud • Dallas (TX)

On-site
USD 80,000 - 130,000
GRC Analyst: Security Governance & Risk
GRC Analyst: Security Governance & Risk

NorthMark Strategies LLC • Dallas (TX)

On-site
USD 95,000 - 125,000
Company-Paid Lunch Stipend
Employer-Paid Medical (HDHP) including
Dental and Vision benefits
+4
GRC Analyst
GRC Analyst

NMC2 • Dallas (TX), Northern (KY)

Hybrid
USD 81,000 - 99,000
GRC Analyst
GRC Analyst

NorthMark Compute & Cloud • Dallas (TX)

On-site
USD 80,000 - 130,000
GRC Analyst
GRC Analyst

NorthMark Strategies • Dallas (TX)

On-site
USD 110,000 - 140,000
Lunch stipend
Medical benefits
Paid time off
GRC Compliance Auditor: SOC 2 & ISO 27001 Expert
GRC Compliance Auditor: SOC 2 & ISO 27001 Expert

NMC2 • Dallas (TX), Northern (KY)

Hybrid
USD 120,000 - 160,000
GRC Analyst: Risk, Compliance & Audit Lead
GRC Analyst: Risk, Compliance & Audit Lead

Access Data Consulting Corporation • Phoenix (AZ)

Hybrid
USD 80,000 - 100,000
GRC Compliance Auditor
GRC Compliance Auditor

NMC2 • Dallas (TX), Northern (KY)

Hybrid
USD 120,000 - 160,000
Remote Security GRC Analyst: Risk & Compliance Lead
Remote Security GRC Analyst: Risk & Compliance Lead

NEPSE Trading • United States

On-site
USD 70,000 - 77,000
Health insurance
401(k) plan with company match
Pension plan
+1