IT Security GRC Analyst

The Phoenix Group

Charlotte (NC)

On-site

USD 85,000 - 120,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

The Phoenix Group is seeking an IT Security Governance, Risk, and Compliance (GRC) Analyst to lead and mature the organization’s cybersecurity governance, risk, and data privacy initiatives in a dynamic enterprise environment.

You will establish and drive the GRC program with a focus on ISO 20000 and NIST frameworks, manage risk assessments, audits, and privacy activities, and report to executive leadership on risk posture and mitigations.

Qualifications

  • Bachelor’s degree in cybersecurity, information systems, risk management, or related field.
  • 2–5 years in cybersecurity compliance, GRC, risk management, audit, or related roles.
  • Experience with ISO 20000, ISO 27001, NIST CSF, NIST 800-53/800-171, SOC 2, FedRAMP, CMMC, SOX.
  • Ability to perform risk assessments, manage compliance programs, and support audits.
  • Knowledge of data privacy concepts, PIAs/DPIAs, and third‑party risk controls.
  • Familiarity with GRC platforms and control mapping.

Responsibilities

  • Lead development and management of the GRC program with ISO 20000 and cybersecurity frameworks.
  • Perform risk assessments on applications, infrastructure, cloud, vendors, and processes.
  • Maintain the risk register and track remediation to closure.
  • Coordinate audits and compliance reviews across standards (ISO, NIST, SOC 2, SOX, FedRAMP, CMMC).
  • Support privacy initiatives: DPIAs, PIAs, data inventories, classifications, retention policies.
  • Review vendor security questionnaires and third‑party risk reports for compliance.
  • Assist in policies updates, governance reviews, and metrics development.
  • Develop dashboards and KRIs for executive reporting; collaborate with Legal, IT, Security, Infrastructure.

Skills

GRC
Risk assessment
Audit support
Data privacy
Policy governance
Executive reporting
Cross-functional collaboration

Education

Bachelor’s degree in Cybersecurity or related field

Tools

RSA Archer
ServiceNow GRC
LogicManager
MetricStream

Job description

A leading organization in the information security and compliance industry is seeking a motivated and experienced IT Security Governance, Risk, and Compliance (GRC) Analyst to support their cybersecurity governance, risk management, compliance, and data privacy initiatives within a dynamic enterprise environment.

Role Overview

This role involves establishing and leading the organization’s GRC program, focusing on ISO 20000, risk assessments, and compliance frameworks, with high visibility to executive leadership. The ideal candidate will have strong experience with cybersecurity controls, data privacy, and GRC program implementation, contributing to the organization’s strategic cybersecurity posture and growth.

Key Responsibilities
  • Lead the development, implementation, and management of the GRC program, ensuring efficient adoption of ISO 20000 standards and cybersecurity frameworks
  • Perform comprehensive cybersecurity risk assessments on applications, infrastructure, cloud environments, vendors, and business processes; facilitate risk identification, analysis, and treatment activities
  • Maintain and update the risk register and track remediation or mitigation activities until closure
  • Coordinate internal and external cybersecurity audits, assessments, and compliance reviews across multiple standards such as ISO 27001, NIST CSF, NIST 800-53, NIST 800-171, SOC 2, FedRAMP, CMMC, and SOX, ensuring evidence collection and control documentation
  • Support privacy initiatives including Data Protection Impact Assessments (DPIAs), privacy documentation, data inventories, classifications, and retention policies
  • Review vendor security questionnaires, third-party risk assessments, and related audit reports; ensure vendor cybersecurity and privacy compliance
  • Assist in maintaining cybersecurity policies, standards, and procedures; facilitate governance reviews, policy exception tracking, and metrics development
  • Develop dashboards, key risk indicators, compliance metrics, and trend analyses for executive reporting
  • Collaborate with cross-functional teams including Legal, IT, Security, and Infrastructure to embed risk and compliance controls into operational workflows
Core Qualifications & Requirements
  • Bachelor’s degree in Cybersecurity, Information Systems, Risk Management, Business, Legal Studies, or related field preferred
  • 2-5 years of experience in cybersecurity compliance, GRC, risk management, audit, or related roles
  • Demonstrated experience supporting cybersecurity frameworks such as ISO 20000, ISO 27001, NIST Cybersecurity Framework (CSF), NIST 800-53, NIST 800-171, SOC 2, FedRAMP, CMMC, and Sarbanes-Oxley (SOX)
  • Proven ability to perform cybersecurity risk assessments, manage compliance programs, and support audit preparation and evidence collection
  • Knowledge of data privacy principles, privacy impact assessments (PIAs), DPIAs, third-party risk reviews, and privacy-related controls
  • Strong understanding of cybersecurity controls, industry standards, and GRC platforms
Nice-to-Have Qualifications
  • Professional certifications such as CISSP, CISA, Security+, CRISC, ISO 27001 Lead Implementer, or CIPP are advantageous
  • Experience leading multi-disciplinary teams or major program initiatives with oversight responsibilities
  • Ability to crosswalk controls between cybersecurity frameworks and compliance requirements
  • Familiarity with control mapping, remediation tracking, and risk register maintenance
Core Technical Skills
  • Security frameworks: ISO 20000, ISO 27001, NIST 800-53, NIST 800-171, NIST CSF, SOC 2, FedRAMP, CMMC, SOX controls
  • Data privacy: DPIAs, PIAs, data inventories, classifications, privacy policies
  • GRC platforms: RSA Archer, ServiceNow GRC, LogicManager, MetricStream (preferred)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Information Technology Security Analyst
Information Technology Security Analyst

The Phoenix Group • Charlotte (NC)

Hybrid
USD 54,000 - 90,000
Hybrid work model
Relocation assistance
Certifications support
GRC Analyst
GRC Analyst

Glocomms • Dallas (TX)

Hybrid
USD 90,000 - 150,000
Competitive base salary
Annual bonus
Comprehensive medical, dental, and eye
+2
Information Security Engineer, GRC
Information Security Engineer, GRC

KYOCERA AVX Greenville • Fountain Inn (SC)

On-site
USD 140,000 - 190,000
GRC Analyst
GRC Analyst

The Emery Company, LLC • Houston (TX)

On-site
USD 85,000 - 110,000
Cyber GRC Specialist
Cyber GRC Specialist

Jobtailor • Washington

On-site
USD 90,000 - 130,000
Information Security Engineer, GRC
Information Security Engineer, GRC

KYOCERA AVX Components Corporation • Fountain Inn (SC)

On-site
USD 90,000 - 120,000
Senior IT Risk and Compliance Engineer
Senior IT Risk and Compliance Engineer

Jobtailor • Hartford (CT)

On-site
USD 120,000 - 180,000
Information Security Engineer, GRC
Information Security Engineer, GRC

KYOCERA AVX Greenville LLC • Fountain Inn (SC)

On-site
USD 100,000 - 130,000
GRC Specialist (Governance, Risk & Compliance)
GRC Specialist (Governance, Risk & Compliance)

360CyberX • United States

On-site
USD 70,000 - 90,000
Cybersecurity GRC Professional
Cybersecurity GRC Professional

duvari group • United States

On-site
USD 120,000 - 190,000