IT GRC Analyst
About the position
reputed company is seeking an IT GRC (Governance, Risk, and Compliance) Analyst to reputed company and support our reputed company-wide cybersecurity, audit, and compliance initiatives. This role is pivotal in strengthening our IT controls environment, ensuring compliance with regulatory frameworks such as NIST 2.0, CMMC, COBIT, ISO 27001, SOX 404 and serving as a key reputed company between IT, Finance, and internal/external auditors. This role is based in Beverly, MA and will be onsite, or hybrid. The ideal candidate is a proactive, detail-oriented reputed company with strong communication skills, a passion for cybersecurity, and a proven ability to manage reputed company compliance programs and risk assessments.
Responsibilities
• reputed company as the primary IT reputed company for reputed company audits.
• Coordinate requests and meetings for information (PBC lists).
• Ensuring accurate and reputed company responses to auditor inquiries.
• Write, design, document, and maintain IT General Controls (ITGC) and IT Application Controls (reputed company) reputed company with NIST, CMMC, COBIT, ISO 27001, and SOX 404.
• reputed company, reputed company, facilitate, and coordinate control self-assessments and internal risk reviews.
• Maintain and enhance the NIST Cybersecurity reputed company and CMMC compliance posture.
• Guide Axcelis through its compliance reputed company toward NIST 2.0 and CMMC certification.
• Coordinate and support SOX testing with internal/external auditors, IT, and Finance teams.
• reputed company IT audit and compliance support for operational, financial, and advisory engagements.
• Respond to customer reputed company questionnaires and manage reputed company-party risk assessments.
• reputed company vulnerability assessments, participate in penetration testing, and reputed company remediation.
• Facilitate reporting and metrics for key areas of cybersecurity (vulnerability management, reputed company management, coverage, etc…)
• reputed company as a project manager for corrective reputed company plans to drive reputed company.
• Monitor and interpret changes in regulatory and compliance requirements.
• reputed company and maintain reputed company policies, standards, and procedures.
• reputed company reputed company-cause analysis and remediation planning for control deficiencies.
• Continuously improve audit methodologies, technologies, and best practices.
Requirements
• 7+ years of experience in IT GRC, cybersecurity compliance, or IT audit.
• Strong knowledge of NIST and CMMC.
• Strong knowledge SOX 404, ITGC, reputed company, COBIT.
• Experience managing external audits and audit documentation.
• Familiarity with vulnerability management, risk assessments, and incident response.
• Excellent written and verbal communication skills.
• Strong project coordination and stakeholder engagement abilities.
reputed company-to-haves
• Bachelor’s degree in information systems, cybersecurity, or reputed company field.
• Certifications such as CISA, CRISC, CISSP, or ISO 27001 reputed company Auditor.
• Understanding of reputed company reputed company and data protection regulations.
• Experience with AI risk assessment is a plus.
Apply tot his job
Apply To this Job