Haystack
← Back to Jobs
Technology
ST

IT GRC Analyst

StackNexus Inc.United States🇺🇸United StatesPosted 1 Sept 2026

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
United States
Posted
Yesterday
SOC 2GDPRHIPAAPenetration Testing

Job Description

Required:

2+ years of experience in a GRC, IT compliance, or security operations role

Familiarity with SOC 2 (Type I or Type II) and the audit lifecycle

Experience managing vendors or external service providers

Strong written communication you'll be writing policies, auditor responses, and client-facing answers

Comfortable coordinating across departments (services, IT, sales, legal) to get information and drive action

Detail-oriented, organized, and able to manage multiple concurrent deadlines (audit cycles, questionnaires, vendor engagements)

Preferred:

Experience with compliance automation platforms (Vanta, Drata, Secureframe, Tugboat Logic)

Familiarity with additional frameworks (ISO 27001, HIPAA, PCI-DSS, GDPR/CCPA)

Experience responding to enterprise client security questionnaires (e.g., via SIG, CAIQ, or custom formats)

Relevant certifications: Security+, CISA, CRISC, or similar

Basic understanding of penetration testing methodology (enough to read and interpret vendor reports, not perform testing)

Similar jobs