Governance, Risk & Compliance (GRC) Analyst
DataStaff Inc is seeking an experienced Governance, Risk & Compliance (GRC) Analyst to support and independently lead cybersecurity governance, risk, and compliance initiatives across a complex technology environment for our client in Morrisville, NC.
Job Description
This position will play an important role in strengthening the organization's risk management practices, control environment, audit readiness, and overall security governance program.
The ideal candidate combines hands-on GRC experience with enough technical understanding to evaluate controls across modern cloud, SaaS, API, distributed-system, and DevSecOps environments. This person must be comfortable working independently while partnering with stakeholders across Information Security, IT, Product, Legal, Privacy, Procurement, Finance, HR, Audit, and other business functions.
Successful candidates should demonstrate strong risk-based judgment, consultative communication, stakeholder influence, ownership, and continuous improvement. The position requires someone capable of independently managing complex workstreams while creating repeatable processes, templates, mappings, and guidance that improve the maturity and consistency of the GRC program.
Key Responsibilities
- Lead cybersecurity risk assessments, maturity assessments, framework gap analyses, and control-mapping exercises, developing well-supported findings and practical recommendations.
- Coordinate internal and external audits, certification activities, customer security and assurance requests, evidence collection, and related compliance activities.
- Manage remediation efforts from identification through resolution, including issue tracking, exceptions, evidence reviews, corrective actions, and cross-functional follow-up.
- Develop and maintain security policies, standards, procedures, control mappings, governance templates, assessment methodologies, and other reusable GRC documentation.
- Support the organization's third-party risk management program, including vendor due diligence, risk assessments, documentation reviews, remediation follow-up, and ongoing monitoring.
- Partner with technical and business stakeholders to evaluate control requirements, risk treatment strategies, compensating controls, exceptions, and corrective actions.
- Evaluate the design, applicability, and operating effectiveness of security controls across technology environments.
- Develop dashboards, metrics, management reports, and status updates that provide visibility into risks, remediation efforts, compliance activities, and program performance.
- Help improve GRC processes, methodologies, documentation, and overall audit readiness.
- Provide guidance and mentoring to less-experienced team members when appropriate.
Required Experience & Qualifications
- 5–8 years of relevant professional experience in cybersecurity GRC, information security risk management, internal audit, compliance, third-party risk, privacy, control assurance, or a closely related discipline.
- At least 2 years of hands-on experience performing risk or control assessments, framework mapping, control reviews, audit coordination, remediation management, or similar GRC activities.
- Demonstrated ability to independently lead work across multiple programs, systems, products, security/control domains, frameworks, or stakeholder groups.
- Strong understanding of cybersecurity governance, risk management, compliance practices, security policies, control frameworks, control taxonomies, issue management, evidence management, and exception processes.
- Working knowledge of technical security controls and modern SaaS, cloud, API, distributed-system, and DevSecOps environments sufficient to assess control design and effectiveness.
- Experience coordinating audits and reviewing evidence for completeness and sufficiency.
- Experience creating policies, standards, procedures, control mappings, assessment documentation, dashboards, and management reporting.
- Strong analytical and risk-based decision-making skills, including the ability to develop practical recommendations when requirements or circumstances are ambiguous.
- Ability to communicate GRC and security concepts effectively to both technical and non-technical audiences.
- Demonstrated ability to influence stakeholders and drive issues toward resolution without relying on direct authority.
- Bachelor's degree in Cybersecurity, Information Systems, Business, Accounting, Risk Management, Public Policy, or a related discipline, or an equivalent combination of directly relevant education and professional experience.
Preferred Qualifications
- Experience within B2B SaaS, healthcare, regulated industries, cloud-based organizations, or multi-product technology environments is preferred.
- Candidates with experience developing formal GRC documentation—including policies, standards, control mappings, assessment procedures, governance templates, audit packages, and executive/management reporting—will be particularly relevant.
- Professional certifications are also desirable, including CISA, CRISC, CISM, CISSP, ISO 27001 Lead Implementer, ISO 27001 Lead Auditor, or relevant certifications in third-party risk, privacy, or auditing.
- Experience mentoring other analysts or leading a significant audit, certification, product compliance, third-party risk, or remediation initiative is also preferred.
This opportunity is available on a corp to corp basis or as a W2 position with a competitive benefits package. DataStaff, Inc. offers medical, dental, and vision coverage options as well as paid vacation, sick, and holiday leave. As many of our opportunities are long-term, we also have a 401k program available for employees after 6 months.