ABOUT THE ROLE
We're seeking a detail-oriented Governance, Risk & Compliance (GRC) Analyst to join our growing cybersecurity team, based in Tampa, FL or fully remote. In this role, you'll help strengthen our organization's security posture by supporting governance initiatives, conducting risk assessments, ensuring regulatory compliance, and collaborating with business and technical teams to manage enterprise risk.
This is an excellent opportunity for someone passionate about cybersecurity, risk management, and helping organizations build secure, compliant technology environments.
KEY RESPONSIBILITIES
- Support enterprise governance, risk, and compliance (GRC) initiatives across the organization
- Conduct security and risk assessments to identify vulnerabilities and recommend mitigation strategies
- Assist with compliance efforts related to frameworks such as NIST CSF, NIST 800-53, ISO 27001, CIS Controls, SOC 2, HIPAA, PCI DSS, and CMMC
- Develop, review, and maintain information security policies, standards, and procedures
- Perform third-party vendor risk assessments and ongoing monitoring
- Track remediation efforts and ensure timely resolution of audit findings and security gaps
- Partner with IT, security, legal, and business stakeholders to promote compliance and risk awareness
- Support internal and external audits by gathering evidence and coordinating responses
- Maintain risk registers, compliance documentation, and executive reporting dashboards
- Monitor evolving cybersecurity regulations and recommend process improvements
QUALIFICATIONS
- Bachelor's degree in Cybersecurity, Information Technology, Information Systems, Business, or a related field
- 2+ years of experience in Governance, Risk & Compliance, Information Security, IT Audit, or Cybersecurity
- Working knowledge of cybersecurity frameworks and regulatory standards
- Understanding of enterprise risk management principles
- Strong analytical, organizational, and documentation skills
- Excellent written and verbal communication abilities
- Ability to work collaboratively with technical and non-technical stakeholders
PREFERRED EXPERIENCE
- Experience with GRC platforms such as Archer, ServiceNow GRC, OneTrust, LogicGate, or MetricStream
- Professional certifications such as Security+, GSEC, CISA, CRISC, CGRC, CISSP, or ISO 27001 Lead Implementer/Auditor
- Experience supporting SOC 2, ISO 27001, HIPAA, PCI DSS, FedRAMP, or CMMC compliance programs
- Familiarity with cloud security governance across AWS, Azure, or Google Cloud
- Experience performing vendor risk management and third-party assessments
- Knowledge of vulnerability management, identity and access management (IAM), and security awareness programs