Sr. Cybersecurity GRC Analyst (Remote)

TPx

United States

On-site

USD 105,000 - 145,000

Full time

11 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

TPx in the United States is seeking a Governance, Risk and Compliance professional to lead audits, drive risk management, and advance disaster recovery and business continuity planning across multiple business units.

The role requires interpreting industry standards, developing and updating policies, and mentoring analysts while collaborating with technology leaders to enhance the organization’s security posture.

Qualifications

  • Experience leading audit engagements end-to-end, from planning to remediation.
  • Knowledge of cybersecurity frameworks and regulatory requirements (NIST CSF, ISO 27001, SOC1, SOC2).
  • Ability to develop, update and communicate policies and procedures.
  • Strong stakeholder management with ability to engage execs.
  • Experience with DR/BCP and third-party risk management.

Responsibilities

  • Own and lead internal and external audit engagements, including determining scope, evidence, testing, remediation and continuous improvement.
  • Drive risk management activities: identification, assessment, tracking, reporting; provide mitigation recommendations.
  • Develop and enhance governance, risk management, disaster recovery, and third-party risk programs.
  • Interpret frameworks and regulations; translate into governance, risk and compliance controls.
  • Lead BIAs and align processes with recovery objectives.
  • Manage DR and BCP activities including exercises and validation.
  • Collaborate with leaders to mature GRC processes and reduce recurring issues.
  • Mentor junior analysts across GRC domains.

Skills

NIST CSF
ISO 27001
SOC 1/2
PCI-DSS
HIPAA

Education

Degree in cybersecurity or information technology
1+ year IT governance, risk and compliance

Tools

GRC Tools
Audit Software

Job description

General Purpose: The ideal candidate will have a strong understanding of cybersecurity best practices, excellent problem-solving skills, and a proactive approach to identifying and mitigating risks. Knowledge of frameworks, attestations and audits, including customer and internal audits such as ISO27001, SOC1, SOC2. Familiar with DR strategies and plans. The ability to write, update and version policies and procedures.

General Purpose: The ideal candidate will have a strong understanding of cybersecurity best practices, excellent problem-solving skills, and a proactive approach to identifying and mitigating risks. Knowledge of frameworks, attestations and audits, including customer and internal audits such as ISO27001, SOC1, SOC2. Familiar with DR strategies and plans. The ability to write, update and version policies and procedures.

Direct Reports: No

Essential Duties and Responsibilities
  • Own and lead internal and external audit engagements, including determining audit scope, evidence requirements and collection, control testing methodology, evaluating control effectiveness, and remediation follow-up, ensuring continual compliance and continuous improvement across multiple business units.
  • Drive risk management activities, including risk identification, assessment, prioritization, tracking, and reporting, to provide recommendations to leadership regarding appropriate mitigation strategies and strengthen the enterprise risk posture.
  • Develop, maintain, and enhance governance, risk management, disaster recovery, business continuity, and third-party risk management programs.
  • Interpret applicable cybersecurity frameworks, regulatory requirements, customer obligations, and industry standards, and exercise independent judgment in developing, implementing, and improving governance, risk, and compliance policies, procedures, and controls.
  • Lead Business Impact Assessments (BIA) and collaborate with stakeholders to align critical processes with recovery objectives.
  • Manage Disaster Recovery (DR) and Business Continuity Planning (BCP) activities, including tabletop exercises, plan maintenance, and validation of recovery strategies.
  • Collaborate with business and technology leaders to mature governance, risk, and compliance processes, streamline reporting, and reduce recurring issues.
  • Lead and mentor junior analysts across GRC domains, fostering a culture of compliance and risk awareness.
  • Build and maintain the TPRM program.
Other Responsibilities
  • Willingness to learn other aspects of Security Operations.
Required Qualifications
  • Team Player with strong communication, organizational, and relationship management skills.
  • Self-motivated, with keen attention to detail and excellent judgment skills.
  • Strong knowledge of security frameworks and regulations (e.g., NIST CSF, ISO 27001, SOC, PCI-DSS, HIPAA).
  • Demonstrated ability to own audit engagements end-to-end, from planning and prioritizing through evidence submission and remediation follow-up.
  • Can develop, track, enhance and communicate risk and security process.
  • Strong stakeholder management skills with the ability to communicate clearly at both technical and executive levels.
  • Experience leading cross-functional initiatives to improve compliance posture or remediate findings.
  • Excellent organizational and project management skills, with attention to detail and deadlines.
  • Ability to write and present articulated documentation and processes.
  • Knowledge of hybrid IT systems, networking, co-locations, and cloud environments.
  • Degree in cybersecurity, computer science, information technology or 1+ years IT work experience in the area of Governance, Risk and Compliance.
  • Use or knowledge of GRC Tools
  • Proven experience working with auditors in IT audit, compliance, or security control assessment within a regulated industry.
  • Professional certification preferred (e.g., CISA, CISSP, CISM, or equivalent).
  • Record of demonstrating sound judgment and ability to exercise discretion on matters of significance with minimal oversight.
Other Qualifications
  • Collaborative team player who works effectively with cross-functional colleagues
  • Strong written and verbal communication skills
  • Demonstrated ability to build productive working relationships across teams

TPx is an Equal Opportunity / Aff…? Qualified applicants will receive consideration for employment without regard to race, color, religious creed, sex (including pregnancy, childbirth, breast-feeding and related medical conditions), sexual orientation, gender identity, gender expression, national origin or ancestry, age, mental or physical disability (including medical condition), military or veteran status, political preference, marital status, citizenship, genetic information or other status protected by law or regulation.

We are committed to providing reasonable accommodations for qualified individuals with disabilities. If you need assistance or an accommodation, please let us know during the application process.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT GRC Lead Analyst
IT GRC Lead Analyst

Westfield Insurance • Westfield Center (OH)

Hybrid
USD 130,000 - 170,000
Senior Cybersecurity Risk & Governance Analyst
Senior Cybersecurity Risk & Governance Analyst

mTrade, LLC. • Oxford (MS)

On-site
USD 110,000 - 160,000
IT Security GRC Analyst
IT Security GRC Analyst

The Phoenix Group • Charlotte (NC)

On-site
USD 85,000 - 120,000
Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

Delta-Denta • St. Louis (MO)

Hybrid
USD 75,000 - 110,000
Information Technology Security Analyst
Information Technology Security Analyst

The Phoenix Group • Charlotte (NC)

Hybrid
USD 54,000 - 90,000
Hybrid work model
Relocation assistance
Certifications support
Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

Delta Dental of Missouri • Missouri

Hybrid
USD 80,000 - 100,000
GRC Security Analyst II
GRC Security Analyst II

Aqua America, Inc. • Bryn Mawr (PA)

On-site
USD 80,000 - 100,000
Equal Opportunity Employer
Accommodation for individuals with disabilities
Governance, Risk & Compliance Analyst I
Governance, Risk & Compliance Analyst I

Geographic Solutions, Inc. • Dunedin (FL)

On-site
USD 60,000 - 100,000
GRC Analyst
GRC Analyst

The Emery Company, LLC • Houston (TX)

On-site
USD 85,000 - 110,000
Cybersecurity Audit Analyst
Cybersecurity Audit Analyst

Elevate Ventures • Huntsville (AL)

On-site
USD 74,000 - 110,000