InfoSec GRC & Vendor Risk Analyst – Hybrid

Rice Park Capital Managment LP

Minneapolis (MN)

Hybrid

USD 90,000 - 130,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Medical, Dental, Vision Insurance
PTO & Paid Holidays
Company Paid Life Insurance
Long-Term Disability
401(k) with employer match

Job summary

Rice Park Capital Managment LP is seeking an Information Security Analyst to own the GRC program, coordinating with an MSSP for ongoing security operations. You will drive policy governance, risk assessments, and regulatory compliance (SOC 2, GLBA) across the organization.

Responsibilities include managing the MSSP, performing internal risk assessments, and supporting due diligence with investors and lenders.

Qualifications

  • Bachelor’s degree in Information Technology, Risk Management, Business, Cybersecurity, or related field
  • 2+ years of information security governance, risk, or compliance (GRC) experience
  • Working knowledge of SOC 2, ISO 27001, NIST CSF, and GLBA
  • Experience with risk assessments, audits, access reviews, and vendor due diligence
  • Strong policy writing, documentation, and project management skills
  • Familiarity with SIEM outputs (MSSP handles operations)
  • Strong organizational and communication skills; vendor management
  • Nice-to-have: SQL/Python for reporting
  • Nice-to-have: CISA/CRISC or similar certification

Responsibilities

  • Own and mature the information security GRC program, including policy governance and risk assessments
  • Manage the MSSP relationship; ensure SLAs and coverage gaps are addressed
  • Lead SOC 2, GLBA compliance efforts; collect evidence and remediate gaps
  • Conduct internal/external risk assessments, audits, and maintain risk register
  • Develop and execute BIA, business continuity planning, and risk management activities
  • Manage investor/lender/security due diligence requests and questionnaires
  • Oversee user access reviews outside MSSP scope; design cadence and controls
  • Lead security awareness initiatives and vendor coordination

Skills

GRC experience
Vendor management
Policy writing
SOC 2 knowledge
Risk assessments
Communication
SQL/Python scripting
CISA/CRISC cert

Education

Bachelor’s degree in IT/Risk/Cybersecurity

Tools

SIEM

Job description

Rice Park Capital Managment LP is seeking an Information Security Analyst to own the GRC program, coordinating with an MSSP for ongoing security operations. You will drive policy governance, risk assessments, and regulatory compliance (SOC 2, GLBA) across the organization.

Responsibilities include managing the MSSP, performing internal risk assessments, and supporting due diligence with investors and lenders.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Security Analyst
Information Security Analyst

Rice Park Capital Managment LP • Minneapolis (MN)

Hybrid
USD 90,000 - 130,000
Medical, Dental, Vision Insurance
PTO & Paid Holidays
Company Paid Life Insurance
+2
Remote Security GRC Analyst: Risk & Compliance Lead
Remote Security GRC Analyst: Risk & Compliance Lead

NEPSE Trading • United States

On-site
USD 70,000 - 77,000
Health insurance
401(k) plan with company match
Pension plan
+1
Senior InfoSec GRC Analyst – Risk & Compliance
Senior InfoSec GRC Analyst – Risk & Compliance

CareSource • Dayton (OH)

On-site
USD 94,000 - 165,000
GRC Analyst: Cyber Risk & Vendor Compliance
GRC Analyst: Cyber Risk & Vendor Compliance

Coretelligent, LLC. • Northern (KY)

Hybrid
USD 70,000 - 88,000
Health insurance
401k
Paid parental leave
+1
Hybrid GRC Analyst I: Risk, Audit & Compliance
Hybrid GRC Analyst I: Risk, Audit & Compliance

Geographic Solutions, Inc. • Palm Harbor (FL)

Hybrid
USD 65,000 - 85,000
Senior Information Security GRC Analyst
Senior Information Security GRC Analyst

CareSource • United States

On-site
USD 94,000 - 165,000
Bonus potential
Total rewards package
GRC Analyst - Hybrid: Risk, Compliance & Security
GRC Analyst - Hybrid: Risk, Compliance & Security

Benesch Law • Cleveland (OH)

Hybrid
USD 99,000 - 120,000
Discretionary bonus
Comprehensive benefits package
Hybrid GRC Analyst: Drive Security Risk & Compliance
Hybrid GRC Analyst: Drive Security Risk & Compliance

System One • Denver (CO)

Hybrid
USD 80,000 - 100,000
Health and welfare benefits
401(k) plan
Medical, dental, and vision coverage
Senior Security GRC Analyst - Hybrid Policy & Risk
Senior Security GRC Analyst - Hybrid Policy & Risk

Yahoo Holdings Inc. in • Nashville (TN)

Hybrid
USD 128,000 - 267,000
Flexible hybrid work
Healthcare
401k plan
+1
GRC Analyst: InfoSec, Vendor Risk & Compliance
GRC Analyst: InfoSec, Vendor Risk & Compliance

Nelson Mullins Riley & Scarborough LLP • Charleston (SC)

On-site
USD 70,000 - 100,000