Why This Role Stands Out
This remote GRC Analyst role at Digital Minds Global Technologies Inc. offers a fantastic opportunity to deepen your expertise across a range of critical compliance frameworks and contribute to a reputable technology company. You'll thrive here if you are a seasoned professional with a keen eye for detail and a passion for building robust governance, risk, and compliance programs. Apply today to leverage your skills and grow your career in a flexible, impactful environment.
Quick Overview
Job Description
Job Title: Sr. GRC Analyst
Experience: 9+ Years
Employment Type: Contrac
Location: Remote
We are looking for a detail-oriented Governance, Risk & Compliance (GRC) Analyst to support information security governance, risk management, compliance assessments, audits, and security control activities. The ideal candidate will have hands-on experience with frameworks such as ISO 27001, NIST, SOC 2, PCI-DSS, and GDPR.
Key Responsibilities
- Conduct IT security, enterprise, and third-party/vendor risk assessments.
- Maintain risk registers, control libraries, compliance documentation, and remediation plans.
- Support implementation and maintenance of ISO 27001, NIST, SOC 2, PCI-DSS, GDPR, and other applicable frameworks.
- Develop, review, and maintain information security policies, standards, procedures, and guidelines.
- Perform control assessments and identify compliance gaps and security risks.
- Coordinate internal and external audits and manage audit evidence collection.
- Track audit findings, corrective actions, exceptions, and remediation activities through closure.
- Perform third-party/vendor security and compliance assessments.
- Maintain compliance evidence repositories and ensure documentation is audit-ready.
- Prepare GRC dashboards, compliance reports, risk metrics, and management presentations.
- Monitor regulatory and industry changes and assess their impact on organizational compliance.
- Collaborate with Information Security, IT, Legal, Privacy, Procurement, Internal Audit, and business teams.
Required Skills
- 6+ years of experience in GRC, Information Security, IT Risk, Audit, or Compliance.
- Strong knowledge of ISO 27001, NIST CSF, SOC 2, PCI-DSS, GDPR, and security controls.
- Experience with risk assessments, control testing, audit preparation, and remediation tracking.
- Experience with Third-Party Risk Management (TPRM).
- Strong documentation, analytical, communication, and stakeholder-management skills.
- Familiarity with GRC platforms such as ServiceNow GRC, Archer, OneTrust, AuditBoard, or similar tools is preferred.
Preferred Certifications
- CISA
- CRISC
- CISM
- CISSP
Nice to Have
- Experience supporting SOC 1/SOC 2 or ISO 27001 audits.
- Knowledge of cloud security and cloud compliance.
- Experience with security questionnaires and customer audits.
- Knowledge of privacy regulations such as GDPR, HIPAA, or applicable data-protection requirements.
Similar jobs
- YI
Senior .NET Software Engineer Azure & APIs at Denver/Loveland, CO (Onsite 5 days) || W2 Only
NewYochana IT Solutions
Denver, CO🇺🇸On-siteYesterdaySQLAzureC#+1Technology - MC
AI Architect
NewMaven Companies
Duluth, GA🇺🇸HybridYesterdaySQLMLOpsMLflow+7Technology - CI
SAP CRM Functional Consultant
NewCardinal Integrated Technologies Inc
Santa Clara, CA🇺🇸On-siteYesterdayAgileStakeholder ManagementTechnology - RT
Software Engineer III
NewRussell, Tobin & Associates
Mountain View, CA🇺🇸$80 - $87/hrHybridYesterdaySpringSpring BootTDD+9Technology - VI
Java Full Stack Developer (Exp-6 Years) with (React & Ai Exp)-Hybrid- Full time
NewVisionary Innovative Technology Solutions
Dallas, TX🇺🇸HybridYesterdayMicroservicesSQLSpring+16Technology - SS
Claims Data Analyst
NewSligo Software Solutions Inc.
Albany, NY🇺🇸On-siteYesterdaySQLETLMicrosoft OfficeTechnology