Senior GRC Information Security Systems Analyst - Direct Hire

VITS Consulting Corp

Minneapolis (MN)

On-site

USD 120,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

VITS Consulting Corp is seeking a Senior GRC Information Security Systems Analyst to join our Information Security team in a direct hire role. The position supports governance, risk, and compliance initiatives, with emphasis on ISMS, audits, and security governance across multiple office locations.

The ideal candidate will have extensive ISMS experience, familiarity with ISO 27001, SOC 2, GDPR, NIST CSF, and NIST 800-53, plus strong stakeholder communication.

Qualifications

  • Bachelor's degree in a related field or equivalent experience.
  • 7+ years of Information Security, Cybersecurity, or GRC experience.
  • Experience implementing or maintaining an ISMS.
  • Experience with ISO 27001:2022, SOC 2, GDPR, NIST CSF, NIST 800-53.
  • Experience developing and maintaining security policies, standards, procedures, and controls.
  • Experience conducting security audits, compliance assessments, and vendor security reviews.
  • Strong written and verbal communication, organization, and PM skills.

Responsibilities

  • Lead Governance, Risk, and Compliance initiatives and audits.
  • Maintain ISMS, policies, standards, and documentation.
  • Coordinate internal and external security audits and assessments.
  • Manage risk registers and report to leadership.
  • Collaborate with IT, Compliance, Risk, and business teams.
  • Support awareness programs and security governance improvements.

Skills

GRC
ISMS
Security governance
Audit readiness
Regulatory compliance
Risk assessments
Vendor security
IAM
DLP
Security metrics

Education

Bachelor's degree in Computer Science/Information Security

Tools

Azure
Microsoft 365
Active Directory
Microsoft Entra ID
Microsoft Defender
Microsoft Sentinel
OAuth
SSO
PIM

Job description

Senior GRC Information Security Systems Analyst

Location: Minneapolis, MN (Preferred) or one of the following office locations: Anchorage, AK Boise, ID Chicago, IL Costa Mesa, CA Dallas, TX Denver, CO Des Moines, IA Minneapolis, MN Missoula, MT New York, NY Palo Alto, CA Phoenix, AZ Salt Lake City, UT Seattle, WA Washington, DC Wilmington, DE

Position Type: Direct Hire

Work Authorization: U.S. Citizens Only

Job Summary

We are seeking an experienced Senior GRC Information Security Systems Analyst to join our Information Security team. This role is responsible for leading Governance, Risk, and Compliance (GRC) initiatives while strengthening the organization's cybersecurity posture through risk management, compliance, audit readiness, and security governance.

The ideal candidate will possess extensive experience in Information Security Management Systems (ISMS), regulatory compliance, security risk assessments, Identity & Access Management (IAM), Data Loss Prevention (DLP), security awareness programs, and enterprise security governance. You will collaborate with cross-functional teams to ensure compliance with industry standards, improve security controls, and support enterprise-wide cybersecurity initiatives.

Key Responsibilities Governance, Risk & Compliance
  • Maintain and continuously improve the Information Security Management System (ISMS).
  • Develop, maintain, and update information security policies, standards, procedures, and documentation.
  • Support ongoing compliance efforts by adapting security documentation to organizational, technology, and threat landscape changes.
  • Generate Information Security metrics, dashboards, and executive reporting.
  • Coordinate and support internal and external security audits and compliance assessments.
  • Lead audit preparation activities and support ISO recertification efforts.
  • Document audit findings, remediation plans, and corrective actions.
  • Collaborate with business and technology teams to implement and monitor security controls.
  • Support continuous monitoring and automation of compliance-related security controls.
  • Maintain Statements of Applicability (SoA), policies, procedures, and compliance documentation.
Risk Management
  • Conduct enterprise technology and information security risk assessments.
  • Perform project-based cybersecurity risk assessments.
  • Evaluate software, cloud platforms, third-party vendors, and technology services for security risks.
  • Maintain enterprise Technology Risk Registers.
  • Present risk assessment findings and remediation recommendations to leadership.
  • Track risk remediation activities through completion.
Client & Third-Party Security
  • Complete customer security questionnaires and security assessment requests.
  • Support cybersecurity sections of RFPs and contract reviews.
  • Conduct pre-contract and post-contract security assessments.
  • Perform third-party vendor technology risk assessments.
  • Evaluate security and privacy controls for vendors and SaaS platforms.
  • Support ongoing vendor security monitoring activities.
Identity & Access Management (IAM)
  • Support enterprise Identity and Authorization governance.
  • Improve Role-Based Access Control (RBAC) processes.
  • Review privileged accounts, service accounts, and user entitlements.
  • Perform least-privilege assessments and permission cleanup.
  • Support Privileged Identity Management (PIM) initiatives.
  • Conduct periodic user access reviews.
  • Validate repeatable authorization governance processes.
Data Protection & Human Risk
  • Support enterprise Data Loss Prevention (DLP) governance.
  • Review DLP controls for regulatory and compliance requirements.
  • Assist with data classification initiatives.
  • Monitor DLP effectiveness and recommend improvements.
  • Support Human Risk Management initiatives.
  • Coordinate annual security awareness training.
  • Support phishing simulation campaigns.
  • Track training participation and security awareness metrics.
Collaboration & Continuous Improvement
  • Partner with IT, Compliance, Risk, Audit, Security Operations, and business teams.
  • Identify opportunities to automate compliance monitoring.
  • Improve enterprise security governance processes.
  • Support cybersecurity projects and strategic initiatives.
  • Perform additional security-related duties as assigned.
Required Qualifications
  • Bachelor's degree in Computer Science, Information Security, Information Systems, Business, or a related discipline (or equivalent experience).
  • 7+ years of Information Security, Cybersecurity, or GRC experience.
  • Experience implementing or maintaining an Information Security Management System (ISMS).
  • Experience with multiple security compliance frameworks, including:
    • ISO 27001:2022
    • SOC 2
    • GDPR
    • NIST Cybersecurity Framework (CSF)
    • NIST 800-53
  • Experience developing and maintaining:
    • Security policies
    • Standards
    • Procedures
    • Controls
    • Governance documentation
  • Experience conducting:
    • Security audits
    • Compliance assessments
    • Security risk assessments
    • Client security reviews
    • Vendor security assessments
  • Experience maintaining enterprise Technology Risk Registers.
  • Strong understanding of Governance, Risk & Compliance (GRC) practices.
  • Experience supporting enterprise security awareness programs.
  • Excellent written and verbal communication skills.
  • Strong organizational and project management abilities.
  • Ability to manage multiple priorities in a fast-paced environment.
Experience With Required Technical Skills
  • Microsoft Azure
  • Microsoft 365
  • Active Directory
  • Microsoft Entra ID
  • Microsoft Purview
  • Microsoft Defender
  • Microsoft Sentinel
  • Exchange Online
  • Exchange On-Premises
  • Microsoft Teams
  • OneDrive
  • Zoom
  • OAuth
  • Single Sign-On (SSO)
  • SaaS Security
  • Identity & Access Management (IAM)
  • Role-Based Access Control (RBAC)
  • Privileged Identity Management (PIM)
  • Data Loss Prevention (DLP)
Preferred Qualifications
  • CISSP, CISM, CISA, or equivalent security certification.
  • Experience supporting ISO certification programs.
  • Knowledge of ISO 42001.
  • Experience with Microsoft Copilot and Anthropic Claude AI.
  • Experience within professional services or other highly regulated industries.
  • Strong understanding of cybersecurity best practices, governance, and emerging threats.
Required Skills
  • Governance, Risk & Compliance (GRC)
  • Information Security Management Systems (ISMS)
  • ISO 27001
  • SOC 2
  • GDPROops, here.
  • NIST CSF
Work Authorization
  • U.S. Citizens Only
Employment Type
  • Direct Hire
Preferred Work Locations
  • Anchorage, AK
  • Boise, ID
  • Chicago, IL
  • Costa Mesa, CA
  • Dallas, TX
  • Denver, CO
  • Des Moines, IA
  • Minneapolis, MN (Preferred)
  • Missoula, MT
  • New York, NY
  • Palo Alto, CA
  • Phoenix, AZ
  • Salt Lake City, UT
  • Seattle, WA
  • Washington, DC
  • Wilmington, DE
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Analyst
GRC Analyst

The Emery Company, LLC • Houston (TX)

On-site
USD 85,000 - 110,000
Senior GRC / Information Security Compliance Analyst
Senior GRC / Information Security Compliance Analyst

RecruitHook • Teaneck Township (NJ)

On-site
USD 120,000 - 160,000
Information Technology Governance Manager
Information Technology Governance Manager

Signet Jewelers • United States

Hybrid
USD 140,000 - 170,000
401(k) matching
Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

Delta-Denta • St. Louis (MO)

Hybrid
USD 75,000 - 110,000
Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

Delta Dental of Missouri • Missouri

Hybrid
USD 80,000 - 100,000
Senior Cybersecurity Risk & Governance Analyst
Senior Cybersecurity Risk & Governance Analyst

mTrade, LLC. • Oxford (MS)

On-site
USD 110,000 - 160,000
Senior Cybersecurity Risk & Governance Analyst
Senior Cybersecurity Risk & Governance Analyst

Mortgage-Trade-Holding-Company,-LL • Oxford (MS)

On-site
USD 110,000 - 150,000
Principal Security GRC Analyst
Principal Security GRC Analyst

Jobgether • United States

On-site
USD 150,000 - 210,000
High autonomy
Multi-framework exposure
Cloud environment experience
GRC Analyst
GRC Analyst

NMC2 • Dallas (TX), Northern (KY)

Hybrid
USD 81,000 - 99,000
Senior GRC Analyst
Senior GRC Analyst

Insight Global • Town of Florida (NY)

On-site
USD 120,000 - 160,000