Governance, Risk & Compliance (GRC) Analyst
Core
Own and mature the cybersecurity GRC program by establishing governance, policies, and risk processes across IT, Cybersecurity, Physical Security, and Manufacturing teams.
Role type
GRC Analyst
Builds
Cybersecurity risk processes, control frameworks, and compliance programs
Domain
Defense / Cybersecurity / GRC
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
NIST CSF, NIST RMF, ISO/IEC 27000 series, CMMC/NIST 800-171, NIST 800-53, OT/ICS security concepts, GRC tooling administration, formal risk assessment methodology, third-party audit support
Preferred skills
Cloud-centric third-party audit support, building risk registers and control frameworks, writing policy for non-security audiences
Technologies
GRC tooling
Responsibilities
Own risk assessments and maintain centralized risk register; Design and maintain unified control framework with MTD/RPO/RTO definitions; Write and maintain security policies; Manage GRC tooling and workflows; Coordinate third-party and certification audits; Act as connective tissue between departments to drive security requirements; Report on risk posture and program maturity; Support customer/vendor cybersecurity risk management
Seniority
Mid-level, hands-on IC
