GRC Controls Analyst – Cybersecurity & Audit Readiness

TikTok USDS Joint Venture

New York (NY)

On-site

USD 99,000 - 196,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

TikTok USDS Joint Venture LLC is seeking a GRC Cybersecurity Controls Analyst to support the operation, testing, and improvement of the controls framework across ISO 27001, SOC 2, NIST CSF, PCI and related certifications.

The role collaborates with control owners, product, security, legal, and audits to evaluate control design, evidence, and operating effectiveness, and to drive automation of GRC processes in a fast-moving environment.

Qualifications

  • Bachelor’s degree in Information Security, Cybersecurity, Information Technology, Risk Management, Compliance, Engineering, Data Analytics, or related field, or equivalent practical experience.
  • 3+ years of experience in GRC, IT risk, security controls, audit readiness, control testing, compliance, or related field.
  • Experience gathering, reviewing, and assessing technical control evidence from stakeholders, systems, tools, dashboards, or documentation repositories.
  • Working knowledge of ISO 27001, NIST CSF, SOC 2, PCI-DSS, or similar control frameworks.
  • Familiarity with security domains such as IAM, Vulnerability Management, Incident Management, Data Security, SDLC, Privacy.
  • Strong writing and documentation skills with ability to create clear control narratives and testing summaries.

Responsibilities

  • Maintain and improve the controls framework, including control descriptions, mappings, owners, evidence expectations, testing procedures, and narratives.
  • Perform control testing and validation: design, implementation, and operating effectiveness testing.
  • Review evidence submitted by control owners to determine adequacy for audit or assessment.
  • Coordinate with owners and stakeholders to resolve evidence gaps and improve testing quality.
  • Support audits, certifications, and assessments (ISO 27001, SOC 2, PCI, NIST CSF).
  • Support GRC automation by defining requirements for workflow automation and scalable testing processes.
  • Work with engineering teams to understand data sources and opportunities to automate control validation.
  • Contribute to high-quality documentation and defensible testing across the Controls & Certifications function.

Skills

GRC
Audit readiness
Control testing
Documentation
Stakeholder management
Security controls
ISO 27001 / NIST CSF
Cross-functional collaboration
Automation

Education

Bachelor’s degree in Information Security / Cybersecurity / IT / Risk/ Compliance

Tools

SQL
APIs
Data workflows
Automation tooling

Job description

TikTok USDS Joint Venture LLC is seeking a GRC Cybersecurity Controls Analyst to support the operation, testing, and improvement of the controls framework across ISO 27001, SOC 2, NIST CSF, PCI and related certifications.

The role collaborates with control owners, product, security, legal, and audits to evaluate control design, evidence, and operating effectiveness, and to drive automation of GRC processes in a fast-moving environment.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Cybersecurity Controls Analyst — Audit & Automation
GRC Cybersecurity Controls Analyst — Audit & Automation

TikTok USDS Joint Venture • Washington

On-site
USD 89,000 - 176,000
GRC Risk Management Analyst: Drive Security Risk & Compliance
GRC Risk Management Analyst: Drive Security Risk & Compliance

TikTok USDS Joint Venture • New York (NY)

On-site
USD 99,000 - 196,000
Health insurance
401(k) matching
Paid parental leave
+1
Senior IT Compliance & Security Controls Analyst
Senior IT Compliance & Security Controls Analyst

TikTok • San Jose (CA)

On-site
USD 112,000 - 162,000
IT Audit Manager: Lead Risk & Controls
IT Audit Manager: Lead Risk & Controls

TikTok USDS Joint Venture • San Jose (CA)

On-site
USD 116,000 - 216,000
Senior GRC & InfoSec Systems Analyst
Senior GRC & InfoSec Systems Analyst

Dorsey & Whitney LLP • Wilmington (DE)

On-site
USD 114,000 - 150,000
GRC Analyst: Cyber Risk, Compliance & Audit Leadership
GRC Analyst: Cyber Risk, Compliance & Audit Leadership

Chaos, Inc. • Washington, Northern (KY)

Hybrid
USD 120,000 - 150,000
Health benefits 100% paid by company
401k with company match
Free daily lunch
+2
Cyber GRC Specialist: Policy, Risk & Audit
Cyber GRC Specialist: Policy, Risk & Audit

Brown Advisory • Washington

On-site
USD 105,000 - 127,000
Medical
Dental
Vision
+1
GRC IT Associate - SOC Audits & Growth
GRC IT Associate - SOC Audits & Growth

Weaver • Little Falls (NJ)

On-site
USD 70,000 - 100,000
Senior GRC InfoSec Lead: Audits, Risk & Compliance
Senior GRC InfoSec Lead: Audits, Risk & Compliance

Dorsey & Whitney LLP • Minneapolis (MN)

On-site
USD 115,000 - 155,000
Senior GRC & ISMS Analyst: Security Audits & Compliance
Senior GRC & ISMS Analyst: Security Audits & Compliance

Dorsey & Whitney LLP • Dallas (TX)

On-site
USD 120,000 - 170,000