Information Security Analyst

AMISEQ

San Jose (CA)

On-site

USD 95,000 - 120,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

AMISEQ is seeking an Information Security Governance, Risk, and Compliance (GRC) Analyst to enhance their risk management program and compliance with standards such as ISO27001 and GDPR. The role focuses on contributing to the development and execution of risk management strategies while leveraging AI and intelligent automation.

The ideal candidate will have at least 5 years of relevant experience, with a solid understanding of governance frameworks and practical knowledge of AI applications in GRC processes.

Qualifications

  • 5 years in governance, risk and compliance or information security.
  • Knowledge of CISSP security domains and best practices.
  • Understanding of security regulatory requirements (SOX, GDPR).
  • Experience with security governance models (ISO 27001, NIST).
  • Ability to communicate complex risk concepts to stakeholders.
  • Hands-on experience in building AI/automation solutions.

Responsibilities

  • Support the GRC operating model and customer engagement.
  • Perform risk assessments addressing security threats.
  • Design and deploy AI-powered GRC processes.
  • Extract insights from GRC datasets for risk scoring.
  • Ensure compliance with ISO 42001 and EU AI Act.

Skills

Governance, risk, and compliance
Information security risk management
AI-powered solutions development
Risk assessment
Knowledge of ISO standards

Tools

APIs
Python scripting
Low-code platforms

Job description

Information Security Governance, Risk, and Compliance (GRC) Analyst

The GRC analyst will contribute to the development and operational execution of the program, including risk management and compliance with standards and regulations such as ISO27001, ISO 42001, EU GDPR, and EU AI Act, and transforming the program through intelligent automation, AI agents, and data-driven solutions.

Responsibilities
  • Support the GRC operating model and the service-oriented customer engagement model.
  • Support GRC capabilities, such as enterprise security risk management, compliance and audit management, policy management, security awareness training, third party risk management, and metrics and reporting.
  • Perform risk assessments that address security threats, changes to systems and/or applications, process improvement initiatives, supplier assessments (including downstream outsourcers) and other requests from the business.
  • Design, build, and deploy AI-powered solutions (including agents) to scale GRC processes including but not limited to Security questionnaires, Risk assessments, Evidence collection and control testing
  • Develop automated workflows and pipelines using APIs, scripting, or low-code platforms
  • Apply LLMs/NLP to analyze policies, audit findings, and regulatory requirements
  • Extract insights from large GRC datasets to build and maintain AI-driven risk scoring and prioritization models.
  • Partner with security, engineering, and data teams to productionize AI use cases.
  • Ensure secure, compliant, and governed use of AI aligned with ISO 42001 and EU AI Act.
Qualifications
  • Candidate must have 5 years working in governance, risk and compliance and/or information security and risk management.
  • Functional knowledge of some CISSP security domains and information security industry standard and best practices.
  • Functional knowledge of applicable security regulatory requirements (SOX, GDPR, AI Act).
  • Functional knowledge of ISMS governance models (i.e. ISO 27001, NIST, CAIQ), information security roles, security controls.
  • Functional knowledge of common security certifications (i.e. ISO 27001, ISO 42001, SOC1, SOC2) and ability to glean significance from findings identified in these reports.
  • Ability to communicate risk methodologies and concepts to business units and IT teams.
  • Demonstrated experience with controls definition, development, implementation and assessment.
  • Hands‑on experience building or customizing AI/automation solutions, including LLM-based workflows, agents, or copilots, API integrations, scripting (e.g., Python), or low-code platforms.
  • Ability to translate GRC use cases into scalable automation solutions.
  • Understanding of AI risks, controls, and governance frameworks (ISO 42001, AI Act).
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC & AI Security Analyst: Risk, Compliance & Automation
GRC & AI Security Analyst: Risk, Compliance & Automation

AMISEQ • San Jose (CA)

On-site
USD 95,000 - 120,000
IT Security GRC Analyst
IT Security GRC Analyst

The Phoenix Group • Charlotte (NC)

On-site
USD 85,000 - 120,000
Information Security Analyst - GRC & Operations
Information Security Analyst - GRC & Operations

WHSmith North America • Las Vegas (NV)

Hybrid
USD 70,000 - 110,000
GRC Specialist (Governance, Risk & Compliance)
GRC Specialist (Governance, Risk & Compliance)

360CyberX • United States

On-site
USD 70,000 - 90,000
Senior GRC Analyst
Senior GRC Analyst

Jobtailor • New York (NY)

On-site
USD 140,000 - 190,000
IT GRC Lead Analyst
IT GRC Lead Analyst

Ohio Farmers Insurance Company • Westfield Center (OH)

Hybrid
USD 90,000 - 120,000
GRC Analyst
GRC Analyst

The Emery Company, LLC • Houston (TX)

On-site
USD 85,000 - 110,000
AI Governance & Security GRC Analyst
AI Governance & Security GRC Analyst

Metropolis Technologies • Los Angeles (CA)

On-site
USD 100,000 - 135,000
Healthcare benefits
401(k) plan
Disability coverage
+3
GRC Analyst
GRC Analyst

New York Technology Partners • Chicago (IL)

On-site
USD 65,000 - 90,000
Senior Information Security Engineer
Senior Information Security Engineer

SmartRecruiters Inc • Town of Poland (NY)

Hybrid
USD 110,000 - 150,000
Competitive salaries
Remote-friendly culture
Strong internal mobility