Information Security Analyst - GRC platform
Core
Manage and automate Governance, Risk & Compliance (GRC) tools and workflows to support security controls, risk assessments, and audit evidence collection.
Role type
Information Security Analyst (GRC)
Builds
Automated compliance workflows, dashboards, and reports for control monitoring and audit readiness.
Domain
Information Security / Compliance / Risk Management
Deliverable
production ML models | product features | dashboards & analysis | client delivery | infrastructure | physical/clinical work
Required skills
GRC tool administration, compliance framework knowledge (ISO 27001, SOC 2, PCI DSS), automation (scripting, integrations), data quality management, cross-functional collaboration
Preferred skills
AuditBoard (CrossComply) experience, SOX ITGC/SOC 1/2 knowledge, Power BI/Excel reporting, Python/PowerShell scripting, CISA/CISSP/CRISC certifications
Technologies
ServiceNow GRC, OneTrust, Jira, SIEM/SOAR, IAM platforms, AuditBoard (CrossComply), Power BI, Python, PowerShell
Responsibilities
Manage and maintain GRC/compliance tools for control monitoring and evidence collection; Automate compliance workflows and integrate with IAM/ticketing systems; Support security controls aligned with ISO 27001, SOC 2, PCI DSS; Translate audit requirements into tooling workflows; Handle daily administration, troubleshooting, and documentation of compliance tools; Define and enforce standards for compliance evidence naming, retention, and versioning
Seniority
Mid-level, hands-on IC