Information Security Administrator, GRC - Boston

Mintz

Boston (MA)

On-site

USD 85,000 - 100,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Bonus eligible
Comprehensive benefits package

Job summary

Mintz in Boston is seeking an Information Security Analyst – GRC to support the firm's information security compliance program, including audit readiness, policy governance, risk tracking, and control reviews. The role also participates in the on‑call rotation and assists with first‑level security event triage.

The ideal candidate has 3–5 years in information security, compliance, audit, or governance, with strong organizational and documentation skills, and proficiency with Microsoft 365.

Qualifications

  • Bachelor's degree or equivalent professional experience.
  • 3-5 years of experience in information security, compliance, audit, project coordination, governance, operational risk, or related discipline.
  • Strong organizational and documentation skills.
  • Experience managing multiple priorities and deadlines.
  • Strong written and verbal communication skills.
  • Ability to function in a fast-paced, service-oriented environment.

Responsibilities

  • Support the firm's information security compliance program.
  • Coordinate audit preparation and maintain supporting evidence.
  • Maintain policies, standards, procedures, and ISMS documentation.
  • Perform recurring control reviews and compliance checks.
  • Track risks, exceptions, findings, and remediation activities.
  • Prepare security metrics, dashboards, and compliance reporting.
  • Administer the firm's security awareness training and phishing simulation program, including campaign scheduling, reporting, and compliance tracking.
  • Support ISO 27001 activities and future compliance initiatives.
  • Participate in the Information Security on-call rotation.
  • Review and triage low-complexity security alerts.
  • Escalate suspicious activity according to documented procedures.
  • Assist with incident documentation and follow-up activities.
  • Coordinate security projects and recurring compliance activities.
  • Track action items, deliverables, and remediation plans.
  • Facilitate communication between technical and business teams.

Skills

Organizational skills
Documentation skills
Project coordination
Communication skills
Analytical abilities
Attention to detail
Team collaboration
Judgment and ethics
Customer service mindset

Education

Bachelor's degree or equivalent

Tools

Microsoft 365

Job description

The Information Security Analyst – GRC supports the firm's information security compliance program, including audit readiness, policy governance, risk tracking, control reviews, security metrics, and compliance documentation. The role also participates in the Information Security on-call rotation and assists with first-level security event triage using established procedures.

We welcome candidates with experience in cybersecurity, compliance, audit, project coordination, governance, or operational risk who demonstrate strong organizational skills and an interest in developing expertise in information security compliance.

Responsibilities:
  • Support the firm's information security compliance program.
  • Coordinate audit preparation and maintain supporting evidence.
  • Maintain policies, standards, procedures, and ISMS documentation.
  • Perform recurring control reviews and compliance checks.
  • Track risks, exceptions, findings, and remediation activities.
  • Prepare security metrics, dashboards, and compliance reporting.
  • Administer the firm's security awareness training and phishing simulation program, including campaign scheduling, reporting, and compliance tracking.
  • Support ISO 27001 activities and future compliance initiatives.
Security Operations Support
  • Participate in the Information Security on-call rotation.
  • Review and triage low-complexity security alerts.
  • Escalate suspicious activity according to documented procedures.
  • Assist with incident documentation and follow-up activities.
  • Training will be provided on firm-specific security tools and processes.
Project & Process Coordination
  • Coordinate security projects and recurring compliance activities.
  • Track action items, deliverables, and remediation plans.
  • Facilitate communication between technical and business teams.
  • Identify opportunities to improve processes and documentation.
Qualifications:
  • Bachelor's degree or equivalent professional experience.
  • 3-5 years of experience in information security, compliance, audit, project coordination, governance, operational risk, or related discipline.
  • Strong organizational and documentation skills.
  • Experience managing multiple priorities and deadlines.
  • Strong written and verbal communication skills.
  • Proficiency with Microsoft 365.
  • Ability to function in a fast-paced, service-oriented environment, prioritize multiple projects on a daily basis, and adjust to shifting priorities.
  • Strong planning, project management and organizational skills.
  • Strong sense of urgency.
  • Facility analyzing, working with and presenting data.
  • Ability to collaborate and gain the respect, trust, and confidence of the Firm’s attorneys and professional staff.
  • Creative and proactive approach to problem solving.
  • Facilitate teamwork and identify opportunities to develop new processes/infrastructure.
  • Demonstrated ability to grasp and implement new concepts quickly.
  • Strong analytical abilities, resourcefulness, and attention to detail.
  • Ability to work independently and as part of a team with a proactive and positive style that fosters collaborative working relationships.
  • Outstanding sense of customer service.
  • Deep personal commitment to integrity, excellent judgment, and the highest standards of ethics.
  • Must display the highest level of diplomacy, tact and discretion, with comfort in handling and maintaining confidential information
Preferred Qualifications:
  • Experience supporting employee training, awareness, compliance, or change management programs.
  • Experience supporting compliance, audit, or risk management programs.
  • Exposure to frameworks such as ISO 27001, NIST, SOC 2, or HIPAA.
  • Experience preparing reports, dashboards, or metrics.
  • Experience working in a regulated or professional services environment.
The Ideal Candidate:

The successful candidate is:

  • Organized and detail-oriented.
  • Naturally curious and eager to learn.
  • Comfortable coordinating across multiple teams.
  • Strong at managing processes and following through on commitments.
  • Interested in building a career in cybersecurity governance, risk, and compliance.
Professional Development:

The firm supports professional development and encourages pursuit of certifications such as:

  • CISA
  • CRISC
  • CISM
  • Security+
  • CGRC
  • ISO 27001 Internal Auditor

This job description is a general description of the types of responsibilities that are required of an individual in this job. It is not intended to be a complete list of the responsibilities, duties and skills that may be required for this job.

Physical Demands:

This position requires sitting or standing for long periods of time and the continuous operation of standard office equipment, such as computers, keyboards and phones. It also requires mobility sufficient to perform certain job functions, such as getting to photocopiers/scanners/fax machines, and regular bending, reaching, lifting, stooping and occasionally pulling, pushing and/or lifting items that weigh up to 25 pounds.

  • The salary range for this position in Boston is $85,000-$100,000
  • This position is bonus eligible. Mintz offers a comprehensive benefits package.
Privacy Notice for California Applicants
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

Delta-Denta • St. Louis (MO)

Hybrid
USD 75,000 - 110,000
Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

Delta Dental of Missouri • Missouri

Hybrid
USD 80,000 - 100,000
Governance, Risk & Compliance Analyst I
Governance, Risk & Compliance Analyst I

Geographic Solutions, Inc. • Dunedin (FL)

On-site
USD 60,000 - 100,000
GRC analyst at RPL International Miami, FL
GRC analyst at RPL International Miami, FL

RPL International • Miami (FL)

On-site
USD 70,000 - 90,000
Information Security Analyst
Information Security Analyst

Sylvan, Inc. • Detroit (MI)

On-site
USD 90,000 - 130,000
Information Security GRC Analyst
Information Security GRC Analyst

Paymentus • Charlotte (NC)

On-site
USD 85,000 - 120,000
Security Governance & Compliance Analyst
Security Governance & Compliance Analyst

Mintz • Boston (MA)

On-site
USD 85,000 - 100,000
Bonus eligible
Comprehensive benefits package
Sr. Cybersecurity GRC Analyst (Remote)
Sr. Cybersecurity GRC Analyst (Remote)

TPx • United States

On-site
USD 105,000 - 145,000
Information Technology Security Analyst
Information Technology Security Analyst

The Phoenix Group • Charlotte (NC)

Hybrid
USD 54,000 - 90,000
Hybrid work model
Relocation assistance
Certifications support
Manager of Information Security and Compliance
Manager of Information Security and Compliance

iboss • United States

On-site
USD 100,000 - 130,000
Health, Vision, Dental
401(k) with company match
Unlimited Paid Time Off
+1