Job Title: Security Analyst I, GRC Job Category: Department/Group: Information Technology Job Code/ Req#: Work Location: Remote Reports To: Level/Salary Range: Position Type: Full Time FLSA STATUS: Travel: 10%, as needed Date Posted: Job Req. Category: Job Description About the role This role will help identify and assess security risks, maintain compliance with applicable regulatory and industry requirements, support audits and assessments, and strengthen security governance across the organization. The ideal candidate has a strong understanding of cybersecurity risk, security controls, compliance frameworks, and third-party risk management. This individual will work closely with Information Security, IT, Legal, Privacy, Internal Audit, and business stakeholders to ensure security risks are appropriately identified, documented, communicated, and remediated. What you will do · Perform cybersecurity and technology risk assessments to identify, document, and evaluate risks across systems, applications, vendors, and business processes. · Maintain and support the organization's information security policies, standards, procedures, and control framework. · Support compliance efforts related to frameworks and regulations such SOC 2, HIPAA, HITRUST, PCI DSS, as applicable. · Assist with internal and external audits, regulatory examinations, security assessments, and customer compliance reviews. · Gather, review, and maintain evidence demonstrating the effectiveness of security and compliance controls. · Track security risks, audit findings, control deficiencies, exceptions, and remediation plans through closure. · Partner with control owners to evaluate control effectiveness and recommend improvements. · Conduct third-party and vendor security risk assessments, including reviewing security questionnaires, certifications, audit reports, and supporting documentation. · Maintain the organization's risk register and help ensure risks are appropriately scored, assigned, monitored, and reported. · Support security awareness, policy acknowledgment, and governance initiatives. · Respond to customer and partner security questionnaires and due diligence requests. · Assist with monitoring changes to regulatory requirements, security standards, and industry best practices. · Develop and maintain GRC metrics, dashboards, reports, and documentation for management and other stakeholders. · Support security exception and risk acceptance processes. · Collaborate with technical security teams to translate technical vulnerabilities and security issues into understandable business risk. · Identify opportunities to automate and improve GRC processes. You will be a good fit if: · You are enthusiastic about Security. · Some experience with Incident Response. · Curiosity and willingness to learn new things. · Excellent organization and planning skills, both technical and strategic. · Stay updated with the latest in technology and cybersecurity trends to recommend improvements to our IT and security infrastructure. · Ability to meet timeframes and solve issues. Requirements · Bachelor's degree in Cybersecurity, Information Technology, Information Systems, Risk Management, or a related field, or equivalent professional experience. · 3+ years of experience in cybersecurity, governance, risk management, compliance, IT audit, or a related discipline. · Relevant professional certification such as Security+, CISA, CRISC, or CGRC. · Working knowledge of cybersecurity frameworks and standards such as HITRUST, SOC 2, PCI-DSS or similar frameworks. · Experience performing security risk assessments or evaluating security controls. · Familiarity with regulatory and compliance requirements relevant to the organization's industry. · Strong analytical, organizational, and documentation skills. · Ability to communicate security and risk concepts effectively to both technical and non-technical stakeholders. · Strong attention to detail and ability to manage multiple assessments, findings, and deadlines simultaneously. · Proficiency with Microsoft Office or similar productivity and reporting tools. Additional Notes This role profile is not intended to be an exhaustive list of qualifications, skills, efforts, duties, responsibilities or working conditions associated with the position. GetixHealth is an equal employment opportunity employer. Approved By: Name Date: Last Updated By: Name Date/Time:
SAP Security & GRC Analyst
Spe
Analyst, HPA Monitoring Analyst, Information Security (L9)
Synchronyfinancial
Analyst / Senior Analyst - SAP Security
Healthcare
Information Security and Compliance Analyst
Genpactexperience
Security Operations Analyst
Securonix
Senior Cyber Security Operations Analyst
Version 1