What are the responsibilities and job description for the GRC Analyst position at firstPRO, Inc?
firstPRO is now accepting resumes for a GRC Analyst in Boston, MA. This is a direct hire role and hybrid in Boston.
Purpose:
The Cybersecurity GRC Specialist is responsible for working with the Manager of Cybersecurity to implement and manage the firm’s Governance, Risk, and Compliance framework. The role focuses on aligning policies and controls with industry regulations, performing risk assessments, supporting compliance audits, and promoting a culture of accountability and ethical conduct.
Major Responsibilities:
- Develop and maintain internal policies and procedures that support compliance with industry regulations (e.g., ISO 27001, NIST, SOC 2, GDPR), including maintaining POA&Ms and ATU artifacts
- Perform regular risk assessments and update the firm’s risk register.
- Collaborate with IT and Legal teams to address risks and control deficiencies.
- Monitor regulatory changes and evaluate their impact on firm operations.
- Provide support during internal and external audits, including evidence gathering.
Education:
Bachelor’s degree in Business, Law, Information Systems, or a related field
Experience:
• 3–5 years of experience in GRC, internal audit, compliance, or risk management
• Familiarity with GRC platforms (e.g., ServiceNow GRC, Archer, LogicGate)
• Working knowledge of risk assessment methodologies and control frameworks
Salary : $110,000 - $120,000