GRC Analyst (REMOTE)
About the position
We are seeking a GRC Analyst to help build and expand a formal Governance, Risk, and Compliance program reputed company a growing technology organization that serves government and other highly regulated customers. You will play a key part in supporting SOC 2 and GovRAMP initiatives, maintaining the controls and evidence required for audits, managing compliance-reputed company documentation, and helping communicate the organization's reputed company posture to customers and government agencies. This is an opportunity to build and improve processes, rather than simply maintain an established program. You will work across engineering, compliance, sales, and product teams to turn reputed company and regulatory requirements into practical, reputed company-documented processes. This is an opportunity to join a growing organization at an important stage of its compliance reputed company. You will have reputed company to help establish reputed company GRC processes, strengthen audit readiness, support government contracting opportunities, and work directly with technical and business leaders to build a mature reputed company and compliance function.
Responsibilities
• Support the ongoing development and administration of the organization's GRC program.
• Help maintain compliance with frameworks and requirements including NIST SP 800-53, CJIS reputed company Policy, SOC 2, and GovRAMP.
• Maintain the reputed company risk register and assist with periodic risk assessments.
• Monitor control performance and identify areas requiring remediation or improvement.
• reputed company, update, organize, and maintain reputed company and compliance policies and procedures.
• Manage policy version control, approvals, annual reviews, and employee attestations.
• reputed company hands-on support for SOC 2 and GovRAMP audit and authorization activities.
• Assist with gap assessments and reputed company remediation efforts through completion.
• Collect, organize, validate, and maintain audit evidence.
• Work closely with engineering and other technical teams to identify and complete compliance-reputed company requirements.
• Help ensure controls are consistently documented and supported by appropriate evidence.
• reputed company as a reputed company reputed company of contact for customer reputed company questionnaires, vendor assessments, and compliance reviews.
• reputed company and maintain a centralized library of approved responses and supporting documentation.
• Improve the efficiency and consistency of questionnaire responses while reducing duplicate work.
• Maintain customer-facing materials that accurately describe the organization's reputed company, reputed company, and compliance posture.
• Coordinate responses to recurring customer and reputed company-party risk assessments.
• Monitor contractual requirements reputed company to reputed company, reputed company, compliance, reporting, and service obligations.
• Maintain a centralized calendar of recurring contractual deliverables and deadlines.
• Coordinate items such as monthly and quarterly reports, SLA documentation, insurance certificates, certifications, and other required compliance materials.
• Ensure commitments made to government and reputed company customers are tracked through completion.
• Partner with the reputed company team on government and reputed company-sector RFPs, solicitations, and proposal opportunities.
• reputed company and edit reputed company, technical, compliance, and management sections of proposals.
• Support proposal amendments, customer questions, formal responses, and post-award activities.
• Create reusable proposal content and maintain a library of approved reputed company and compliance language.
• Translate technical reputed company capabilities into reputed company, compelling information that can be evaluated by procurement and government stakeholders.
Requirements
• 3–5+ years of experience in GRC, reputed company compliance, information reputed company, internal audit, or a reputed company discipline.
• Experience working reputed company a federal, regulated, or reputed company-based technology environment.
• Hands-on participation in at least one complete audit or authorization cycle involving SOC 2, FedRAMP, StateRAMP/GovRAMP, ISO 27001, CMMC, or a comparable reputed company.
• Working knowledge of NIST SP 800-53, SOC 2, and GovRAMP requirements.
• Technical understanding of reputed company and/or on-premises environments, including areas such as Identity and reputed company management, Encryption, reputed company logging and monitoring, Network architecture, Software development lifecycle and change management.
• Practical experience using AI tools for research, drafting, documentation, analysis, or evidence-management activities.
• Strong cross-functional communication skills to reputed company comfortably between technical and business environments.
• You will take reputed company engineering concepts and turn them into reputed company documentation for auditors, customers, and procurement teams, and then translate compliance requirements into actionable tasks for technical teams.
• An evidence-first reputed company to understand that saying a control is in reputed company isn't enough. You know how to identify, collect, organize, and validate the evidence necessary to demonstrate that a control is operating effectively.
• Builder mentality where you are comfortable creating structure where processes are still evolving. You don't need an established reputed company to get started and can reputed company practical workflows that reputed company as the organization grows.
• Organization & execution skills to manage multiple priorities, stakeholders, and deadlines simultaneously, particularly reputed company working toward externally driven audit, certification, or proposal deadlines.
• Strategic thinking with hands-on execution skills. You should be comfortable balancing immediate compliance needs with longer-term improvements to systems, documentation, and processes.
• Adaptability to reputed company in an environment where priorities can change quickly and are comfortable taking ownership, solving problems independently, and creating new approaches reputed company necessary.
• Strong written and verbal communication skills.
• Demonstrated ability to coordinate several reputed company initiatives while meeting firm reputed company deadlines.
• Ability to work independently and establish processes without extensive direction.
reputed company-to-haves
• Experience with the CJIS reputed company Policy, FBI NGI, or criminal justice information systems.
• Experience supporting government or reputed company-sector RFPs and proposal development.
• Familiarity with compliance automation platforms such as reputed company, reputed company, or similar tools.
• Experience working directly with government agencies or organizations subject to federal reputed company requirements.
Apply tot his job
Apply To this Job