GRC Analyst

You support governance, risk management, and compliance programs by assessing security risks, monitoring compliance with policies and regulations, coordinating audits, maintaining security documentation, managing risk registers and control matrices, tracking remediation, and conducting third-party security risk assessments.

Responsibilities

  • Support governance, risk management, and compliance programs
  • Assess security risks and controls
  • Monitor compliance with internal policies and external regulations
  • Coordinate internal and external audits
  • Ensure appropriate controls protect business information and technology assets
  • Identify risks with cross-functional teams
  • Track remediation activities
  • Improve the organization’s risk and compliance posture
  • Maintain security policies, standards, procedures, and compliance documentation
  • Manage risk registers, control matrices, audit findings, and corrective action plans
  • Conduct third-party and vendor security risk assessments

Requirements

  • Experience in governance, risk, and compliance, information security, IT risk management, or cybersecurity compliance roles
  • Hands-on experience performing security risk assessments, control assessments, compliance reviews, and privacy reviews
  • Experience with ISO 27001, NIST CSF, SOC 2, PCI DSS, GDPR, or similar regulatory requirements
  • Experience supporting internal and external audits through evidence collection, control validation, and remediation tracking
  • Experience developing, reviewing, and maintaining security policies, standards, procedures, and compliance documentation
  • Experience managing risk registers, control matrices, audit findings, and corrective action plans
  • Experience conducting third-party and vendor security risk assessments and reviewing supplier compliance documentation

See also

要針對這個職缺調整履歷嗎?

目前無法檢查您與這個職缺的符合程度;請先將履歷加入個人檔案,下次即可查看。

A new version of freehire is available