Haystack
← Back to Jobs
Remote
Technology
DM

GRC Analyst, Remote

Digital Minds Global Technologies Inc.United States🇺🇸United StatesPosted 1 Sept 2026

Why This Role Stands Out

This remote GRC Analyst role at Digital Minds Global Technologies Inc. offers a fantastic opportunity to deepen your expertise across a range of critical compliance frameworks and contribute to a reputable technology company. You'll thrive here if you are a seasoned professional with a keen eye for detail and a passion for building robust governance, risk, and compliance programs. Apply today to leverage your skills and grow your career in a flexible, impactful environment.

Quick Overview

Seniority
Mid Senior
Work mode
Remote
Location
United States
Posted
1 week ago
SOC 2GDPRHIPAA

Job Description

Job Title: Sr. GRC Analyst
Experience: 9+ Years
Employment Type: Contrac
Location: Remote

We are looking for a detail-oriented Governance, Risk & Compliance (GRC) Analyst to support information security governance, risk management, compliance assessments, audits, and security control activities. The ideal candidate will have hands-on experience with frameworks such as ISO 27001, NIST, SOC 2, PCI-DSS, and GDPR.

Key Responsibilities

  • Conduct IT security, enterprise, and third-party/vendor risk assessments.
  • Maintain risk registers, control libraries, compliance documentation, and remediation plans.
  • Support implementation and maintenance of ISO 27001, NIST, SOC 2, PCI-DSS, GDPR, and other applicable frameworks.
  • Develop, review, and maintain information security policies, standards, procedures, and guidelines.
  • Perform control assessments and identify compliance gaps and security risks.
  • Coordinate internal and external audits and manage audit evidence collection.
  • Track audit findings, corrective actions, exceptions, and remediation activities through closure.
  • Perform third-party/vendor security and compliance assessments.
  • Maintain compliance evidence repositories and ensure documentation is audit-ready.
  • Prepare GRC dashboards, compliance reports, risk metrics, and management presentations.
  • Monitor regulatory and industry changes and assess their impact on organizational compliance.
  • Collaborate with Information Security, IT, Legal, Privacy, Procurement, Internal Audit, and business teams.

Required Skills

  • 6+ years of experience in GRC, Information Security, IT Risk, Audit, or Compliance.
  • Strong knowledge of ISO 27001, NIST CSF, SOC 2, PCI-DSS, GDPR, and security controls.
  • Experience with risk assessments, control testing, audit preparation, and remediation tracking.
  • Experience with Third-Party Risk Management (TPRM).
  • Strong documentation, analytical, communication, and stakeholder-management skills.
  • Familiarity with GRC platforms such as ServiceNow GRC, Archer, OneTrust, AuditBoard, or similar tools is preferred.

Preferred Certifications

  • CISA
  • CRISC
  • CISM
  • CISSP

Nice to Have

  • Experience supporting SOC 1/SOC 2 or ISO 27001 audits.
  • Knowledge of cloud security and cloud compliance.
  • Experience with security questionnaires and customer audits.
  • Knowledge of privacy regulations such as GDPR, HIPAA, or applicable data-protection requirements.

Similar jobs