Information Security GRC Lead - Policy & Risk Management

NorthMark Compute & Cloud

Dallas (TX)

On-site

USD 90,000 - 120,000

Full time

2 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Lunch stipend
Medical benefits
Dental & Vision
Parental leave
Life insurance
Disability insurance
401(k) match
Flexible benefits
PTO 25 days
Company holidays

Job summary

NorthMark Compute & Cloud is seeking a GRC Analyst to join the Information Security team in Dallas, TX. You will drive security governance, change management, risk assessments, and policy lifecycle, collaborating with Engineering, Product, Legal, and Operations to keep our controls robust and compliant.

You will own the risk register, produce executive‑level summaries, and maintain the policy library aligned to ISO 27001, SOC 2, and NIST CSF. The role offers strong visibility and impact.

Qualifications

  • Bachelor degree in IS/CS/Business or equivalent experience.
  • 4–8 years in GRC, information security governance, compliance, or risk management.
  • Hands‑on experience owning or contributing to security change management, risk assessment, or policy management.
  • Working knowledge of ISO 27001, SOC 2, NIST CSF, NIST SP 800‑53, or CIS Controls.
  • Experience developing, reviewing, and publishing information security policies, standards, and procedures.
  • Familiarity with risk register management: identifying, rating, tracking, and reporting risks.
  • Experience with GRC automation platforms such as ServiceNow GRC, Vanta, Drata, Hyperproof, or Archer.
  • Proficiency with Jira/Confluence for change tracking, risk registers, and policy workflows.
  • Strong written communication translating security requirements to policy language.
  • Collaborative across Engineering, Legal, HR, and Operations.
  • Certs preferred: CISM, CRISC, CISA, CISSP, ISO 27001 Lead Implementer/Auditor, or CompTIA Security+.

Responsibilities

  • Own and operate the security change management review process — triaging change requests and documenting findings and approvals.
  • Iterate on change management processes to reduce friction for low‑risk changes while ensuring rigor for high‑risk ones.
  • Conduct security reviews for new products, features, third‑party integrations, and vendor onboarding.
  • Facilitate threat identification workshops and risk discussions with engineering, product, and operations.
  • Maintain the enterprise information security risk register with clear ownership and prioritization.
  • Develop risk reporting dashboards and summaries for the CISO and executives.
  • Author and manage the information security policy library — aligned to ISO 27001, SOC 2, and NIST CSF.
  • Manage the security exception process with the GRC Manager and track expiry/renewal.
  • Monitor governance adherence and produce compliance metrics for security leadership.
  • Serve as point of contact for cross‑functional forums like CAB and Risk Committee.

Skills

GRC governance
Risk assessment
Policy management
Security frameworks
Policy drafting
Cross-functional collaboration
Jira/Confluence

Education

Bachelor’s degree in Information Systems, CS, or Business Admin

Tools

ServiceNow GRC
Vanta
Drata
Hyperproof
Archer
Jira
Confluence

Job description

NorthMark Compute & Cloud is seeking a GRC Analyst to join the Information Security team in Dallas, TX. You will drive security governance, change management, risk assessments, and policy lifecycle, collaborating with Engineering, Product, Legal, and Operations to keep our controls robust and compliant.

You will own the risk register, produce executive‑level summaries, and maintain the policy library aligned to ISO 27001, SOC 2, and NIST CSF. The role offers strong visibility and impact.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC & Security Policy Lead
GRC & Security Policy Lead

NMC2 • Dallas (TX), Northern (KY)

Hybrid
USD 81,000 - 99,000
GRC Analyst: Security Governance & Risk
GRC Analyst: Security Governance & Risk

NorthMark Strategies LLC • Dallas (TX)

On-site
USD 95,000 - 125,000
Company-Paid Lunch Stipend
Employer-Paid Medical (HDHP) including
Dental and Vision benefits
+4
GRC Analyst: Shape Security Governance & Risk
GRC Analyst: Shape Security Governance & Risk

NorthMark Strategies • Dallas (TX)

On-site
USD 110,000 - 140,000
Lunch stipend
Medical benefits
Paid time off
GRC Analyst
GRC Analyst

NMC2 • Dallas (TX), Northern (KY)

Hybrid
USD 81,000 - 99,000
GRC Compliance Auditor - SOC 2 / ISO 27001 Expert
GRC Compliance Auditor - SOC 2 / ISO 27001 Expert

NorthMark Compute & Cloud • Dallas (TX)

On-site
USD 110,000 - 150,000
Lunch stipend
Medical benefits (employer-paid)
Parental leave
+4
GRC Compliance Auditor: SOC 2 & ISO 27001 Expert
GRC Compliance Auditor: SOC 2 & ISO 27001 Expert

NMC2 • Dallas (TX), Northern (KY)

Hybrid
USD 120,000 - 160,000
Remote Security GRC Analyst: Risk & Compliance Lead
Remote Security GRC Analyst: Risk & Compliance Lead

NEPSE Trading • United States

On-site
USD 70,000 - 77,000
Health insurance
401(k) plan with company match
Pension plan
+1
Dallas-Based SOC 2/ISO 27001 GRC Auditor
Dallas-Based SOC 2/ISO 27001 GRC Auditor

NorthMark Strategies LLC • Dallas (TX)

On-site
USD 90,000 - 140,000
Company-Paid Lunch Stipend
Employer-Paid Medical Insurance
Dental and Vision Benefits
+5
GRC Compliance Auditor: SOC 2 & ISO 27001 Specialist
GRC Compliance Auditor: SOC 2 & ISO 27001 Specialist

NorthMark Strategies • Dallas (TX)

On-site
USD 90,000 - 130,000
Company-Paid Lunch Stipend
100% Employer-Paid Medical
Dental and Vision benefits
+4
GRC Analyst
GRC Analyst

NorthMark Compute & Cloud • Dallas (TX)

On-site
USD 90,000 - 120,000
Lunch stipend
Medical benefits
Dental & Vision
+7