Haystack
← Back to Jobs
Remote
Technology

Cybersecurity GRC Analyst - ONLY W2

nTech SolutionsReston, VA🇺🇸United StatesPosted 13 Aug 2026

Quick Overview

Work Type
Remote
Level
Mid Senior

Job Description

-------------------ONLY W2--------------------ONLY W2-------------------ONLY W2-------------

Title: Cybersecurity GRC Analyst

Location: Reston, VA (Predominantly Remote)

Duration: 6 Months Contract

Job Description:

Terms of Employment

  • Contract, 6 Months
  • Location: Remote (Reston, VA; regular remote flexibility with occasional monthly/quarterly on-site visits and mandatory on-site final interview)
  • Candidate must reside in DMV area.

Overview

  • Our client is seeking a Cyber Security & Risk Management Analyst to ensure the organization's data remains protected from inappropriate access, disclosure and/or damage. The Cyber Security & Risk Management Analyst will advocate for and execute the processes and practices of the Cybersecurity team while supporting business and customer needs.

Responsibilities include:

  • Support the Cybersecurity Risk Management program providing support and guidance to a team of technically diverse cybersecurity specialists personnel while further supporting collaboration across the various risk related teams in the organization.
  • Support continuous monitoring efforts by partnering with TPRM, Procurement, Legal, and key business stakeholders.
  • Support the assessment of cybersecurity controls, identify gaps, assist in development of mitigation strategies, and manage them to closure.
  • Collaborate with internal and external teams to assess, monitor, and manage risks.
  • Work with business teams to conduct thorough assessments to identify potential risks to the organization. This includes evaluating their security practices, data handling procedures, and regulatory compliance (e.g., HIPAA, PCI, GDPR, etc.)
  • Represent Cybersecurity from a Risk Management perspective and execute security risk management leadership through the design and implementation of cybersecurity controls to maintain the confidentiality, integrity and availability of information systems and data.
  • Prepare detailed risk assessment reports, clearly articulating findings and recommendations and maintain a comprehensive repository of all risk assessments and associated documentation.
  • Conduct risk analyses to ensure consistency in the detailed risk assessment lifecycle inclusive of identification, socialization, mitigation, and closure.
  • Design, implement, and integrate security solutions to address enterprise risks and exposures.
  • Develop and maintain Information Security Risk Metrics supported by KPIs and KRIs to support the analytics team.
  • Test and report on new technologies to address security concerns and work closely with the vulnerability management team on the identified risks.
  • Support compliance/risk management efforts in support of NIST, FedRAMP, and HIPAA to include but not limited to: external assessment readiness/support, self-assessments, risk assessments, Plans-Of-Action-and-Milestone (POA&M) management, continuous monitoring.

Required Skills & Experience

  • Bachelor s degree in Cybersecurity, Computer Science, Information Technology, or similar and 3+ years of experience in cybersecurity and risk management to include in the healthcare and/or health insurance industry.
  • Significant understanding of NIST Risk Management Framework (RMF), NIST Cybersecurity Framework (CSF), and NIST 800-53.
  • Knowledgeable of Information Security Risk Management methodologies including FAIR quantitative model.
  • Knowledgeable of PCI DSS compliance.
  • Highly skilled performing risk assessments.
  • Experience using Governance, Risk, and Compliance (eGRC) tools.
  • Highly skilled in technical writing and documentation with proven ability to translate technical requirements to the business.
  • Excellent presentation and verbal communication skills.
  • Ability to understand, develop, and socialize security policies, standards, and procedures.
  • Ability to effectively lead/complete tasks with a minimal level of supervision.

Preferred Skills & Experience

  • Possess CRISC, CISSP, or similar certification(s).
  • Experience using an eGRC tool such as Hyperproof, Archer, or ServiceNow.
  • Knowledgeable of SOC 2 and/or HITRUST compliance.
  • Proficiency with security controls for cloud environments (Azure and AWS) including FedRAMP requirements.
  • Familiarity with security tools such as wireless and network scanning applications, vulnerability assessment applications and concepts, IDS/IPS, Data Loss Prevention, and other appropriate security related tools and capabilities.
  • Experience working in a large, complex, multi-platform environment.
  • Familiarity with HIPAA Security Rule and compliance requirements.

Sincerely,

Preetam Raj

Team Lead, Talent Acquisition

nTech Workforce Inc.

D:

E:

Skills

AWS
PCI DSS
SOC 2
Azure
GDPR
HIPAA

Similar jobs