Apply Edge Start your job search

Senior GRC / Information Security Compliance Analyst

RecruitHook · Rutherford, NJ

Apply & track with Apply Edge
Our client is seeking an experienced Governance, Risk & Compliance (GRC) professional with 5–8 years of experience to support information security, compliance, risk management, and reporting initiatives. This role will help strengthen the organization’s security and compliance programs while working across teams to promote a security-first culture.Key ResponsibilitiesSupport implementation of policies, standards, and procedures aligned with ISO 27001, ISO 42001, NIST, GDPR, GLBA, CCPA, and other applicable regulations.Conduct risk, vulnerability, and gap assessments and help identify and remediate compliance gaps.Perform SOX, SOC 1/SOC 2, ITGC/ITAC, internal audit, and privacy control testing.Assess control effectiveness and support compliance with applicable U.S. federal and privacy regulations.Partner with cross-functional teams to manage compliance requirements and drive security improvements.Develop reports, dashboards, and presentations for senior leadership.Support security awareness programs, including training, phishing simulations, and e-learning.Track training effectiveness and recommend continuous improvements.What We’re Looking For5–8 years of experience in GRC, information security, IT audit, compliance, or a related field.Strong knowledge of at least two U.S. privacy, cybersecurity, or federal regulatory requirements, such as FTC regulations, CCPA/CPRA, COPPA, CIRCIA, or NIST frameworks.Expertise in at least four areas including ISO 27001, ISO 42001, SOC, SOX, COSO/COBIT, privacy regulations, ITGC/ITAC controls, risk assessments, or internal audit.Strong written and verbal communication skills.Ability to work cross-functionally and manage multiple priorities.Working knowledge of IT infrastructure, cloud security, IAM/IGA, MFA, network security, SDLC, DevSecOps, and CI/CD is a plus.Experience with tools such as RSA Archer, Microsoft 365, AWS, Azure, GCP, or OCI is preferred.