Information Technology Security Analyst

The Phoenix Group

Charlotte (NC)

Hybrid

USD 95,000 - 116,000

Full time

4 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Hybrid work model
Relocation assistance
Certification sponsorship

Job summary

The Phoenix Group Advisors in Charlotte, NC seeks a skilled GRC leader to establish and drive the organization's risk and compliance program, with emphasis on ISO 27001 and executive visibility. You will manage risk assessments across apps, infrastructure, cloud, and vendors, coordinate audits, and develop dashboards for senior leadership while embedding privacy controls.

The role offers a hybrid work model, opportunities for professional growth, and relocation consideration as the organization

Qualifications

  • Bachelor’s degree in cybersecurity, information systems, risk management, or related field.
  • 2–5 years in cybersecurity compliance, GRC, risk management, or audit.
  • Experience supporting ISO 27001, NIST CSF, SOX, SOC 2, and related frameworks.
  • Knowledge of privacy principles and DPIAs/PIAs.
  • Familiarity with GRC platforms and control mapping.

Responsibilities

  • Lead the development, implementation, and management of the GRC program.
  • Perform risk assessments across apps, infra, cloud, vendors, and processes.
  • Maintain risk register and tracking until closure.
  • Coordinate internal and external cybersecurity audits and assessments.
  • Support privacy initiatives including DPIAs and data inventories.
  • Review vendor security questionnaires and third-party risk assessments.
  • Assist in maintaining cybersecurity policies, standards, and procedures.
  • Develop dashboards and metrics for executive reporting.
  • Collaborate with Legal, IT, Security, and Infrastructure teams to embed controls.

Skills

Cybersecurity
GRC
Risk management
Audit support
Data privacy

Education

Bachelor’s degree in Cybersecurity or related field

Tools

RSA Archer
ServiceNow GRC
LogicManager
MetricStream

Job description

This role involves establishing and leading the organization’s GRC program, focusing on ISO 27001, risk assessments, and compliance frameworks, with high visibility to executive leadership. The ideal candidate will have strong experience with cybersecurity controls, data privacy, and GRC program implementation, contributing to the organization’s strategic cybersecurity posture and growth.

Key Responsibilities
  • Lead the development, implementation, and management of the GRC program, ensuring efficient adoption of ISO 27001 standards and cybersecurity frameworks
  • Perform comprehensive cybersecurity risk assessments on applications, infrastructure, cloud environments, vendors, and business processes; facilitate risk identification, analysis, and treatment activities
  • Maintain and update the risk register and track remediation or mitigation activities until closure
  • Coordinate internal and external cybersecurity audits, assessments, and compliance reviews across multiple standards such as ISO 27001, NIST CSF, NIST 800-53, NIST 800-171, SOC 2, FedRAMP, CMMC, and SOX, ensuring evidence collection and control documentation
  • Support privacy initiatives including Data Protection Impact Assessments (DPIAs), privacy documentation, data inventories, classifications, and retention policies
  • Review vendor security questionnaires, third-party risk assessments, and related audit reports; ensure vendor cybersecurity and privacy compliance
  • Assist in maintaining cybersecurity policies, standards, and procedures; facilitate governance reviews, policy exception tracking, and metrics development
  • Develop dashboards, key risk indicators, compliance metrics, and trend analyses for executive reporting
  • Collaborate with cross-functional teams including Legal, IT, Security, and Infrastructure to embed risk and compliance controls into operational workflows
Core Qualifications & Requirements
  • Bachelor’s degree in Cybersecurity, Information Systems, Risk Management, Business, Legal Studies, or related field preferred
  • 2-5 years of experience in cybersecurity compliance, GRC, risk management, audit, or related roles
  • Demonstrated experience supporting cybersecurity frameworks such as ISO 20000, ISO 27001, NIST Cybersecurity Framework (CSF), NIST 800-53, NIST 800-171, SOC 2, FedRAMP, CMMC, and Sarbanes-Oxley (SOX)
  • Proven ability to perform cybersecurity risk assessments, manage compliance programs, and support audit preparation and evidence collection
  • Knowledge of data privacy principles, privacy impact assessments (PIAs), DPIAs, third-party risk reviews, and privacy-related controls
  • Strong understanding of cybersecurity controls, industry standards, and GRC platforms
Nice-to-Have Qualifications
  • Professional certifications such as CISSP, CISA, Security+, CRISC, ISO 27001 Lead Implementer, or CIPP are advantageous
  • Experience leading multi-disciplinary teams or major program initiatives with oversight responsibilities
  • Ability to crosswalk controls between cybersecurity frameworks and compliance requirements
  • Familiarity with control mapping, remediation tracking, and risk register maintenance
Core Technical Skills
  • Security frameworks: ISO 20000, ISO 27001, NIST 800-53, NIST 800-171, NIST CSF, SOC 2, FedRAMP, CMMC, SOX controls
  • Data privacy: DPIAs, PIAs, data inventories, classifications, privacy policies
  • GRC platforms: RSA Archer, ServiceNow GRC, LogicManager, MetricStream (preferred)

This role offers the opportunity to lead high-visibility cybersecurity compliance initiatives, collaborate with executive leadership, and shape the organization’s security governance, enabling accelerated career growth within a forward-thinking company.

Compensation and Benefits
  • Salary range: Up to $105,000 annually, with a 12% bonus potential
  • Hybrid work model: 2 days onsite, 3 days remote in Charlotte, NC
  • Opportunity for relocation and professional development, including certifications

The Phoenix Group Advisors is an equal opportunity employer. We are committed to creating a diverse and inclusive workplace and prohibit discrimination and harassment of any kind based on race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, genetic information, disability, or veteran status. We strive to attract talented individuals from all backgrounds and provide equal employment opportunities to all employees and applicants for

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior GRC / Information Security Compliance Analyst
Senior GRC / Information Security Compliance Analyst

RecruitHook • Teaneck Township (NJ)

On-site
USD 120,000 - 160,000
Principal Security GRC Analyst
Principal Security GRC Analyst

Jobgether • United States

On-site
USD 150,000 - 210,000
High autonomy
Multi-framework exposure
Cloud environment experience
Cybersecurity GRC Specialist
Cybersecurity GRC Specialist

The TemPositions Group of Companies • New York (FL)

On-site
USD 140,000 - 190,000
Cybersecurity GRC Analyst
Cybersecurity GRC Analyst

duvari group • Fenton (MO)

On-site
USD 83,000 - 131,000
Information Security Engineer, GRC
Information Security Engineer, GRC

KYOCERA AVX Components Corporation • Fountain Inn (SC)

On-site
USD 90,000 - 120,000
GRC Analyst
GRC Analyst

The Emery Company, LLC • Houston (TX)

On-site
USD 85,000 - 110,000
Information Security Engineer, GRC
Information Security Engineer, GRC

KYOCERA AVX Greenville LLC • Fountain Inn (SC)

On-site
USD 100,000 - 130,000
Manager - IT Governance, Risk and Compliance
Manager - IT Governance, Risk and Compliance

Plexus Corp. • Neenah (WI)

On-site
USD 112,000 - 169,000
Governance, Risk, & Compliance (GRC) Analyst
Governance, Risk, & Compliance (GRC) Analyst

Districttechgroup • Washington

Hybrid
USD 80,000 - 100,000
Fully remote work environment
Competitive salary and performance bonuses
Health, dental, and vision insurance
+2
Cyber GRC Specialist
Cyber GRC Specialist

Jobtailor • Washington

On-site
USD 90,000 - 130,000