Remote Senior IT GRC Analyst – SOC 2 Readiness

cmgfi

United States

On-site

USD 120,000 - 160,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

CMG is seeking a Senior IT GRC Analyst to lead policy development and audit execution within its IT Governance, Risk, and Compliance program, with emphasis on SOC 2 readiness. You will work with the GRC team and IT to plan audits, maintain the policy framework, and manage auditor relationships.

The role requires strong writing, independent judgment, and deep knowledge of control frameworks (NIST CSF, ISO 27001, SOX) plus experience in financial services or regulated industries.

Qualifications

  • Bachelor's degree in IT, cybersecurity, or related field.
  • 5+ years in IT audit, compliance, or GRC.
  • Direct SOC 2 audit cycle experience.
  • Experience in financial services or regulated industries.
  • Knowledge of NIST CSF, ISO 27001, or SOX.
  • Policy writing and documentation skills.

Responsibilities

  • Lead SOC 2 readiness scope, gap analysis, and control design.
  • Serve as audit engagements contact and coordinate with regulators.
  • Develop and maintain IT policies, standards, procedures.
  • Plan and execute audit activities, evidence gathering, and findings documentation.
  • Identify control gaps and track remediation with owners.
  • Advise IT leadership on audit and policy matters.
  • Translate regulatory changes into policy updates.
  • Contribute to ongoing development and improvement of GRC processes and tooling.

Skills

SOC 2
NIST CSF
ISO 27001
SOX
CISA
CRISC
GRCP
Policy writing
Communication

Education

Bachelor's degree in IT

Job description

CMG is seeking a Senior IT GRC Analyst to lead policy development and audit execution within its IT Governance, Risk, and Compliance program, with emphasis on SOC 2 readiness. You will work with the GRC team and IT to plan audits, maintain the policy framework, and manage auditor relationships.

The role requires strong writing, independent judgment, and deep knowledge of control frameworks (NIST CSF, ISO 27001, SOX) plus experience in financial services or regulated industries.

Get your free, confidential resume review.

or drag and drop your file here.