GRC Analyst
Golden Technology · Raleigh-Durham-Chapel Hill Area
Apply & track with Apply EdgeJob Description
Senior Information Security GRC Analyst Department: Information Security
This role is responsible for performing complex risk assessments, supporting regulatory and customer assurance activities, maintaining risk and compliance documentation, tracking remediation, and partnering with business, technology, privacy, legal, quality, procurement, and audit stakeholders to ensure information security risks are identified, documented, communicated, and managed in alignment with business objectives and risk appetite.Main Duties and ResponsibilitiesLead and perform information security risk assessments for applications, infrastructure, business processes, suppliers, and new technology initiatives, including identification of threats, vulnerabilities, likelihood, impact, control effectiveness, residual risk, and recommended treatment options.Maintain and update risk registers, issue logs, control gap trackers, audit findings, evidence repositories, policy exception records, and remediation plans to support accurate reporting and timely closure.Support the development, review, maintenance, and communication of information security policies, standards, procedures, control documentation, and supporting governance materials.Coordinate internal audits, external audits, regulatory reviews, customer security assessments, RFIs, due diligence questionnaires, and evidence requests by gathering documentation, validating responses, and tracking corrective actions.Support compliance with applicable frameworks, standards, legal, regulatory, contractual, and customer requirements, including ISO/IEC 27001, NIST, COBIT, ITIL, ISO 31000, GDPR, and other applicable cybersecurity and privacy obligations.Partner with application, infrastructure, security operations, privacy, legal, quality, procurement, internal audit, and business stakeholders to ensure security requirements are understood, implemented, and monitored.Support third-party and supplier risk management activities, including security due diligence, questionnaire reviews, contract security input, risk documentation, remediation follow-up, and exception management.Track remediation activities for security risks, audit findings, vulnerability findings, penetration testing results, control gaps, and compliance issues; follow up with owners and escalate overdue or high-risk items as appropriate.Develop dashboards, metrics, management reports, and status updates that communicate risk posture, control effectiveness, audit readiness, compliance obligations, remediation progress, and emerging issues.Support disaster recovery, business continuity, crisis management, and operational resilience activities through documentation, testing support, tabletop exercises, lessons learned, and improvement tracking.Provide senior-level guidance to stakeholders on security risk management, control expectations, policy compliance, evidence requirements, and risk treatment decisions.Monitor changes in information security laws, regulations, frameworks, threats, and industry best practices; recommend updates to policies, controls, procedures, and reporting practices as needed.Support continuous improvement of GRC processes, including automation, workflow optimization, evidence management, reporting enhancements, and adoption of GRC or Integrated Risk Management tooling.Promote a strong security and compliance culture through stakeholder engagement, awareness support, clear communication, and practical guidance.Maintain confidentiality of company, customer, employee, and supplier information and comply with all Information Security standards, procedures, and ethical requirements.Qualifications and ExperienceBachelor’s degree in Information Security, Cybersecurity, Computer Science, Information Technology, Business, Risk Management, or a related field, or equivalent professional experience.5+ years of experience in information security, cybersecurity risk management, IT audit, compliance, governance, or a related GRC role.Experience performing information security risk assessments, control reviews, audit support, compliance assessments, and remediation tracking.Strong working knowledge of information security and risk management frameworks such as ISO/IEC 27001, NIST Cybersecurity Framework, NIST 800-53, ISO 31000, COBIT, ITIL, and related control frameworks.Familiarity with privacy, regulatory, contractual, and customer assurance requirements such as GDPR, SOC 2, and other applicable obligations.Experience supporting customer security questionnaires, RFIs, supplier risk assessments, policy governance, audit evidence collection, and risk reporting.Experience with GRC, Integrated Risk Management, ticketing, workflow, dashboarding, or evidence management tools is preferred.Professional certifications such as CISA, CISM, CISSP, CRISC, ISO 27001 Lead Implementer, ISO 27001 Lead Auditor, or equivalent are preferred.Knowledge, Skills, and CompetenciesStrong understanding of cybersecurity principles, risk management practices, compliance programs, control design, control testing, and audit readiness.Ability to assess risk severity and business impact using multiple sources of information, including assessment results, audit findings, vulnerability data, business context, and control effectiveness.Excellent written and verbal communication skills, with the ability to explain technical, risk, and compliance topics to both technical and non-technical stakeholders.Strong analytical, problem-solving, prioritization, and decision-making capabilities.Ability to manage multiple assignments, deadlines, stakeholders, and competing priorities with limited supervision.Demonstrated ability to influence stakeholders, drive accountability, and support timely remediation of risks and control gaps.Strong attention to detail and ability to produce clear, accurate, and audit-ready documentation.Commitment to delivering practical, business-aligned security guidance and high-quality stakeholder service.Success MeasuresRisk assessments, control reviews, and audit support activities are completed accurately and within agreed timelines.Risk registers, remediation trackers, evidence repositories, policy records, and compliance documentation remain current, complete, and audit-ready.Security risks, control gaps, and audit findings are clearly communicated, appropriately assigned, tracked, and escalated when required.Stakeholders receive timely, practical, and business-aligned guidance on security, risk, and compliance requirements.GRC reporting, metrics, and dashboards provide leadership with accurate visibility into risk posture, compliance status, remediation progress, and emerging issues.