What are the responsibilities and job description for the GRC analyst position at Frontier Cybersecurity Consulting?
Company Description Frontier Cybersecurity Consulting helps organizations build robust security and compliance foundations that meet the expectations of regulators, auditors, and enterprise partners. The company specializes in audit readiness, guiding clients through risk assessments and remediation for frameworks such as HIPAA, SOC 2, and other industry-relevant standards. Its practical, project-based approach focuses on assessing risk, implementing tailored controls and documentation, and leaving clients fully audit-ready with defensible evidence. Frontier also offers retained compliance monitoring to keep programs current as regulations and threats evolve. Based in South Florida, Frontier is a trusted partner for businesses seeking enterprise-grade rigor without enterprise-level overhead.
Role Description The GRC Analyst role is a full-time, on-site position located in Miami, FL. The analyst will support governance, risk, and compliance engagements, including conducting risk assessments, mapping controls to regulatory and framework requirements, and helping prepare clients for audits such as HIPAA and SOC 2. Day-to-day responsibilities include documenting policies and procedures, collecting and organizing evidence, tracking remediation activities, and maintaining compliance artifacts to ensure they are audit-ready. The role also involves monitoring regulatory changes, participating in client meetings to clarify requirements and findings, and collaborating with technical and business stakeholders to align security controls with organizational objectives. The GRC Analyst will contribute to continuous improvement of internal templates, methodologies, and compliance monitoring practices.
Qualifications
- Strong understanding of governance, risk, and compliance principles, including experience with common frameworks (e.g., HIPAA, SOC 2, ISO 27001, NIST).
- Ability to perform risk assessments, control mapping, and gap analyses, and to translate requirements into practical, organization-specific controls.
- Experience drafting and maintaining policies, procedures, standards, and other compliance documentation, with attention to clarity and consistency.
- Proficiency in evidence collection, audit preparation, and working with auditors or external assessors to support successful reviews.
- Solid analytical and critical-thinking skills, including the ability to interpret regulations and security best practices for diverse business environments.
- Effective communication and collaboration skills, with the ability to work closely with technical teams, business stakeholders, and clients.
- Strong organizational skills, including task prioritization, deadline management, and maintaining accurate records across multiple projects.
- Familiarity with cybersecurity concepts, controls, and tooling (e.g., access management, logging and monitoring, data protection) is highly beneficial.
- Bachelor’s degree in information security, information systems, compliance, or a related field, or equivalent practical experience.
- Relevant certifications such as CISA, CRISC, CISSP, or CCSK are a plus.