Quick Overview
Seniority
Mid Senior
Work mode
Hybrid
Location
Sacramento, CA, United States
Posted
Yesterday
Job Description
Position: Cybersecurity GRC Analyst / Consultant
Duration: 6 months with extension Possible
Location: Sacramento, CA (Hybrid)
Can attend the Sacramento office for two consecutive days each month, generally the first Wednesday and Thursday.
Position Overview
The GRC & Incident Response Security Professional will support the client's information-security governance, risk, compliance, third-party risk, and incident-response functions. The role will work closely with the Information Security Office and provide risk advisory, compliance, incident management, and remediation support.
Key Responsibilities
- Governance, Risk & Compliance
- Develop, update, and maintain security policies, procedures, standards, and documentation.
- Administer and support enterprise GRC platforms.
- Perform security risk assessments and compliance reviews.
- Provide risk advisory services aligned with:
- CMS ARC-AMPE
- NIST SP 800-53 Revision 5
- IRS Publication 1075
- Applicable laws, regulations, and internal security requirements.
- Conduct third-party/vendor security due diligence.
- Perform vendor risk assessments and contract/control reviews.
- Support continuous monitoring and risk reporting.
- Develop corrective-action plans and track remediation.
- Incident Response
- Develop and maintain incident-response plans and playbooks.
- Support security investigations and incident-management activities.
- Assist with evidence handling and documentation.
- Coordinate incident communications and reporting.
- Support post-incident reviews.
- Serve as backup security incident manager.
- Provide incident status and escalation reporting to the CISO when required.
- Participate in after-hours/on-call incident-response activities when necessary.
Required Qualifications
- Experience in information security, GRC, risk management, or incident response.
- Strong knowledge of security policies, procedures, standards, and controls.
- Experience with enterprise GRC platforms.
- Experience performing security risk assessments and third-party risk assessments.
- Knowledge of NIST SP 800-53 and security-control frameworks.
- Experience developing incident-response plans and playbooks.
- Experience supporting investigations, evidence handling, and post-incident activities.
- Strong documentation and communication skills.
- Experience in regulated public-sector, healthcare, health-exchange, or similar environments is preferred.
Similar jobs
- RM
Java - Full Stack Developer Sr. - Rmantras with Security Clearance
Rmantras
Ashburn, VA🇺🇸On-site6 weeks agoAgileAngularConfluence+3Technology - LT
Senior Specialist, Integration and Test Engineer
NewL3Harris Technologies
Palm Bay, Florida🇺🇸On-site7 minutes agoConfluenceJiraTechnology - AS
Sr Solutions Architect, Alexa+
NewAmazon.com Services LLC
Seattle, Washington🇺🇸Hybrid7 minutes agoAWSGenerative AILLMTechnology - DE
Senior Manager, Solutions Architecture
NewDisney Experiences
Kissimmee, Florida🇺🇸$179.5k - $240.6k/yrHybrid7 minutes agoSAFeAWSAgile+7Technology - DE
Senior Manager, Solutions Architecture
NewDisney Experiences
Orlando, Florida🇺🇸$179.5k - $240.6k/yrHybrid7 minutes agoSAFeAWSAgile+7Technology - AS
Business Process Analyst
Apex Systems
Denver, CO🇺🇸On-site2 weeks agoAgileConfluenceJira+1Technology