Senior GRC / Information Security Compliance Analyst

Recruithook

Fort Lee (NJ)

On-site

USD 110,000 - 150,000

Full time

6 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Recruithook is seeking an experienced Governance, Risk & Compliance (GRC) professional in New Jersey to support information security, compliance, risk management, and reporting initiatives. This role helps strengthen the organization’s security and compliance programs while collaborating across teams to promote a security-first culture.

The ideal candidate has 5–8 years in GRC or related fields, deep knowledge of US privacy and cybersecurity requirements, and hands-on experience with controls,

Qualifications

  • 5–8 years of experience in GRC, information security, IT audit, compliance, or a related field.
  • Strong knowledge of at least two U.S. privacy, cybersecurity, or federal regulatory requirements (e.g., CCPA/CPRA, NIST, GDPR, FTC).
  • Expertise in at least four areas such as ISO 27001, ISO 42001, SOC, SOX, COSO/COBIT, privacy regulations, ITGC/ITAC controls, risk assessments, or internal audit.
  • Strong written and verbal communication skills.
  • Ability to work cross-functionally and manage multiple priorities.

Responsibilities

  • Support implementation of policies, standards, and procedures aligned with ISO 27001, ISO 42001, NIST, GDPR, GLBA, CCPA, and other applicable regulations.
  • Conduct risk, vulnerability, and gap assessments and help identify and remediate compliance gaps.
  • Perform SOX, SOC 1/SOC 2, ITGC/ITAC, internal audit, and privacy control testing.
  • Assess control effectiveness and support compliance with applicable U.S. federal and privacy regulations.
  • Partner with cross-functional teams to manage compliance requirements and drive security improvements.
  • Develop reports, dashboards, and presentations for senior leadership.
  • Support security awareness programs, including training, phishing simulations, and e-learning.
  • Track training effectiveness and recommend continuous improvements.

Skills

GRC experience
ISO knowledge
Compliance testing
Risk assessments
Communication skills
Cross-functional collaboration
Cloud security basics
Privacy regulations

Tools

RSA Archer
Microsoft 365
AWS
Azure
GCP

Job description

Our client is seeking an experienced Governance, Risk & Compliance (GRC) professional with 5–8 years of experience to support information security, compliance, risk management, and reporting initiatives. This role will help strengthen the organization’s security and compliance programs while working across teams to promote a security-first culture.

Key Responsibilities

  • Support implementation of policies, standards, and procedures aligned with ISO 27001, ISO 42001, NIST, GDPR, GLBA, CCPA, and other applicable regulations.
  • Conduct risk, vulnerability, and gap assessments and help identify and remediate compliance gaps.
  • Perform SOX, SOC 1/SOC 2, ITGC/ITAC, internal audit, and privacy control testing.
  • Assess control effectiveness and support compliance with applicable U.S. federal and privacy regulations.
  • Partner with cross-functional teams to manage compliance requirements and drive security improvements.
  • Develop reports, dashboards, and presentations for senior leadership.
  • Support security awareness programs, including training, phishing simulations, and e-learning.
  • Track training effectiveness and recommend continuous improvements.

What We’re Looking For

  • 5–8 years of experience in GRC, information security, IT audit, compliance, or a related field.
  • Strong knowledge of at least two U.S. privacy, cybersecurity, or federal regulatory requirements, such as FTC regulations, CCPA/CPRA, COPPA, CIRCIA, or NIST frameworks.
  • Expertise in at least four areas including ISO 27001, ISO 42001, SOC, SOX, COSO/COBIT, privacy regulations, ITGC/ITAC controls, risk assessments, or internal audit.
  • Strong written and verbal communication skills.
  • Ability to work cross-functionally and manage multiple priorities.
  • Working knowledge of IT infrastructure, cloud security, IAM/IGA, MFA, network security, SDLC, DevSecOps, and CI/CD is a plus.
  • Experience with tools such as RSA Archer, Microsoft 365, AWS, Azure, GCP, or OCI is preferred.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior GRC Analyst
Senior GRC Analyst

Averity • New York (NY)

On-site
USD 90,000 - 140,000
Cybersecurity GRC Professional
Cybersecurity GRC Professional

duvari group • United States

On-site
USD 120,000 - 190,000
GRC (Governance, Risk, and Compliance) Consultant
GRC (Governance, Risk, and Compliance) Consultant

Zoho • United States

Remote
USD 120,000 - 180,000
GRC Analyst
GRC Analyst

The Emery Company, LLC • Houston (TX)

On-site
USD 85,000 - 110,000
GRC Analyst
GRC Analyst

AccruePartners • Fort Mill (SC)

On-site
USD 70,000 - 95,000
Direct-hire opportunity
Ownership of GRC initiatives
Exposure to NIST / CIS Controls / SOC
ServiceNow Administrator / Developer
ServiceNow Administrator / Developer

Cynosure IT Innovations LLC • Chicago (IL)

On-site
USD 120,000 - 160,000
Governance, Risk & Compliance Senior Analyst
Governance, Risk & Compliance Senior Analyst

Tier4 Group • Atlanta (GA)

On-site
USD 90,000 - 150,000
GRC Analyst
GRC Analyst

Golden Technology • North Carolina

On-site
USD 120,000 - 160,000
Cybersecurity Governance Analyst
Cybersecurity Governance Analyst

Veriipro • Fort Lauderdale (FL)

On-site
USD 90,000 - 130,000
Sr. IT Security Analyst
Sr. IT Security Analyst

The Marzetti Company • Columbus (OH)

On-site
USD 90,000 - 120,000