Epicareer Might not Working Properly
Learn More

Government, Risk, and Compliance (GRC) Analyst

Salary undisclosed

Checking job availability...

Original
Simplified

As a GRC Analyst, you will be a key player in ensuring the organization's compliance with regulatory and customer requirements, managing risks, and fostering a culture of accountability. The role involves collaborating closely with cross-functional teams to assess current security controls and to continuously improve the company’s risk management framework. You will also play a critical role in ensuring that security and privacy initiatives are effectively managed in accordance with relevant legal, regulatory, and industry-specific requirements.

Responsibilities:

  • Governance Framework & Policy Management: Support the development, maintenance, and enforcement of the company’s information security governance framework and policies, ensuring alignment with industry standards and regulations.
  • Risk Management: Assist in identifying, assessing, and managing security risks across the company. Use risk assessment methodologies and tools to evaluate risk exposure and ensure that risk mitigation strategies are in place.
  • Compliance Monitoring & Reporting: Ensure adherence to relevant legal, regulatory, and industry requirements (e.g., CCPA, GDPR, SOC 2, PCI-DSS). Monitor compliance and generate reports on security posture, audit readiness, and policy enforcement.
  • Security Controls Evaluation: Collaborate with security teams to evaluate the effectiveness of existing security controls and recommend improvements. Ensure that security measures meet industry standards and mitigate identified risks.
  • Internal & External Audits: Coordinate and assist with internal and external audits, preparing necessary documentation, evidence, and reports. Respond to audit findings and assist with remediation efforts.
  • Incident Management Support: Assist in tracking and reporting security incidents, ensuring compliance with incident response procedures, and providing support to ensure timely resolution and documentation.
  • Training & Awareness: Assist in developing and delivering GRC training programs to raise awareness of governance, risk, and compliance topics within the organization.
  • Continuous Improvement: Support the identification of areas for improvement in GRC processes, tools, and systems. Work with stakeholders to drive improvements to the overall GRC framework and processes.

About You:

You are a detail-oriented and analytical professional with a passion for governance, risk management, and compliance in the ever-evolving world of information security. With at least two years of experience in GRC or a related field, you have developed a strong understanding of security frameworks such as ISO 27001, NIST, SOC 2, and ITIL. Your ability to assess security risks, implement effective controls, and support compliance initiatives makes you a key contributor to any organization’s security posture.

Your background in information security, computer science, or business administration has equipped you with both the technical knowledge and strategic mindset needed to navigate regulatory requirements like CCPA, GDPR, and PCI-DSS. Whether it's assisting with audits, evaluating security controls, or developing policies, you thrive in a role that requires attention to detail, collaboration, and problem-solving.

Strong communication skills allow you to effectively translate complex security and risk-related concepts to both technical and non-technical stakeholders. You are proactive, adaptable, and eager to drive continuous improvement in GRC processes, ensuring that organizations remain compliant, secure, and prepared for future challenges.

Key Qualifications:

  • Experience:
  • 2+ years of experience in governance, risk management, or compliance within an information security or IT environment.
  • Hands-on experience in assessing and implementing security controls, conducting risk assessments, and supporting audit and compliance activities.
  • Education: Bachelor’s degree in Information Security, Computer Science, Business Administration, or a related field.
  • Certifications: One or more of the following certifications is preferred:
  • Certified Information Systems Auditor (CISA)
  • Certified in Risk and Information Systems Control (CRISC)
  • Certified Information Security Manager (CISM)
  • Certified Information Privacy Professional (CIPP)
  • Technical Skills:
  • Proven track record of implementing security governance in a predominantly cloud-based or SaaS environment.
  • Knowledge of security frameworks such as ISO 27001, NIST Cybersecurity Framework, SOC 2, and ITIL.
  • Proficiency in understanding and documenting security controls across IT infrastructure, networks, applications, and data management.
  • Strong Communication Skills: Ability to effectively communicate complex security and risk-related information to both technical and non-technical stakeholders.
  • Attention to Detail: Strong organizational skills and a keen eye for detail in policy review, risk management, and compliance reporting.

Desired Skills & Attributes:

  • Problem Solving: Ability to analyze complex situations, identify risks, and propose practical solutions.
  • Team-Oriented: Ability to work collaboratively with cross-functional teams, including IT, legal, audit, and compliance departments.
  • Proactive & Self-Motivated: Ability to work independently, prioritize tasks, and manage multiple projects simultaneously.
  • Adaptability: Flexibility to adapt to changes in regulations, security technologies, and risk management methodologies.

About Us:

Passport is the technology leader in parking compliance and curbside payment solutions. By helping cities integrate paid parking, enforcement operations, and payment infrastructure into one software solution, Passport provides the only platform that connects the complexities of mobility to efficiently manage and monetize the curb. From mobile payments to citation issuance, permitting technology and more, Passport is empowering cities of all sizes with better insights to improve parking turnover, expand revenue opportunities, and create better compliance. Passport is trusted by more than 800 clients across North America.

As a GRC Analyst, you will be a key player in ensuring the organization's compliance with regulatory and customer requirements, managing risks, and fostering a culture of accountability. The role involves collaborating closely with cross-functional teams to assess current security controls and to continuously improve the company’s risk management framework. You will also play a critical role in ensuring that security and privacy initiatives are effectively managed in accordance with relevant legal, regulatory, and industry-specific requirements.

Responsibilities:

  • Governance Framework & Policy Management: Support the development, maintenance, and enforcement of the company’s information security governance framework and policies, ensuring alignment with industry standards and regulations.
  • Risk Management: Assist in identifying, assessing, and managing security risks across the company. Use risk assessment methodologies and tools to evaluate risk exposure and ensure that risk mitigation strategies are in place.
  • Compliance Monitoring & Reporting: Ensure adherence to relevant legal, regulatory, and industry requirements (e.g., CCPA, GDPR, SOC 2, PCI-DSS). Monitor compliance and generate reports on security posture, audit readiness, and policy enforcement.
  • Security Controls Evaluation: Collaborate with security teams to evaluate the effectiveness of existing security controls and recommend improvements. Ensure that security measures meet industry standards and mitigate identified risks.
  • Internal & External Audits: Coordinate and assist with internal and external audits, preparing necessary documentation, evidence, and reports. Respond to audit findings and assist with remediation efforts.
  • Incident Management Support: Assist in tracking and reporting security incidents, ensuring compliance with incident response procedures, and providing support to ensure timely resolution and documentation.
  • Training & Awareness: Assist in developing and delivering GRC training programs to raise awareness of governance, risk, and compliance topics within the organization.
  • Continuous Improvement: Support the identification of areas for improvement in GRC processes, tools, and systems. Work with stakeholders to drive improvements to the overall GRC framework and processes.

About You:

You are a detail-oriented and analytical professional with a passion for governance, risk management, and compliance in the ever-evolving world of information security. With at least two years of experience in GRC or a related field, you have developed a strong understanding of security frameworks such as ISO 27001, NIST, SOC 2, and ITIL. Your ability to assess security risks, implement effective controls, and support compliance initiatives makes you a key contributor to any organization’s security posture.

Your background in information security, computer science, or business administration has equipped you with both the technical knowledge and strategic mindset needed to navigate regulatory requirements like CCPA, GDPR, and PCI-DSS. Whether it's assisting with audits, evaluating security controls, or developing policies, you thrive in a role that requires attention to detail, collaboration, and problem-solving.

Strong communication skills allow you to effectively translate complex security and risk-related concepts to both technical and non-technical stakeholders. You are proactive, adaptable, and eager to drive continuous improvement in GRC processes, ensuring that organizations remain compliant, secure, and prepared for future challenges.

Key Qualifications:

  • Experience:
  • 2+ years of experience in governance, risk management, or compliance within an information security or IT environment.
  • Hands-on experience in assessing and implementing security controls, conducting risk assessments, and supporting audit and compliance activities.
  • Education: Bachelor’s degree in Information Security, Computer Science, Business Administration, or a related field.
  • Certifications: One or more of the following certifications is preferred:
  • Certified Information Systems Auditor (CISA)
  • Certified in Risk and Information Systems Control (CRISC)
  • Certified Information Security Manager (CISM)
  • Certified Information Privacy Professional (CIPP)
  • Technical Skills:
  • Proven track record of implementing security governance in a predominantly cloud-based or SaaS environment.
  • Knowledge of security frameworks such as ISO 27001, NIST Cybersecurity Framework, SOC 2, and ITIL.
  • Proficiency in understanding and documenting security controls across IT infrastructure, networks, applications, and data management.
  • Strong Communication Skills: Ability to effectively communicate complex security and risk-related information to both technical and non-technical stakeholders.
  • Attention to Detail: Strong organizational skills and a keen eye for detail in policy review, risk management, and compliance reporting.

Desired Skills & Attributes:

  • Problem Solving: Ability to analyze complex situations, identify risks, and propose practical solutions.
  • Team-Oriented: Ability to work collaboratively with cross-functional teams, including IT, legal, audit, and compliance departments.
  • Proactive & Self-Motivated: Ability to work independently, prioritize tasks, and manage multiple projects simultaneously.
  • Adaptability: Flexibility to adapt to changes in regulations, security technologies, and risk management methodologies.

About Us:

Passport is the technology leader in parking compliance and curbside payment solutions. By helping cities integrate paid parking, enforcement operations, and payment infrastructure into one software solution, Passport provides the only platform that connects the complexities of mobility to efficiently manage and monetize the curb. From mobile payments to citation issuance, permitting technology and more, Passport is empowering cities of all sizes with better insights to improve parking turnover, expand revenue opportunities, and create better compliance. Passport is trusted by more than 800 clients across North America.