What are the responsibilities and job description for the Analyst, IT Security GRC - Compliance Framework position at Insight Global?
3 month contract to hire, 2x week onsite in Charlotte, NC
Must-Haves:
- 2β5 years of experience in IT Compliance, Information Security, Risk Management, Audit, or GRC
- Strong knowledge of NIST Cybersecurity Framework (CSF)
- Experience with ISO 27001, NIST 800-53, NIST 800-171, SOC 2, CMMC, and FedRAMP frameworks
- Experience supporting audits, evidence collection, compliance documentation, and control mapping
- Experience conducting cybersecurity risk assessments and remediation tracking
- Strong documentation, communication, and stakeholder management skills
- Experience with GRC or compliance management platforms
- Ability to work cross-functionally with technical and business teams
Plusses:
- Security , CGRC, CISA, CRISC, CISSP, or ISO 27001 Lead Implementer certification
- SOX and ITGC experience
- Experience implementing or building a GRC platform
- Experience creating governance policies and procedures
- Bachelor's degree in a related field
Day-to-Day:
- Support the buildout of a brand-new enterprise GRC program
- Help implement and mature the organization's GRC platform
- Lead ISO 27001 alignment activities and framework mapping efforts
- Maintain compliance documentation, policies, standards, and procedures
- Coordinate and support internal and external audits
- Collect and organize audit evidence
- Build and maintain risk registers
- Track remediation efforts and corrective action plans
- Develop security governance roadmaps and compliance metrics
- Partner with leadership to promote a security-first culture
Job Description:
Insight Global is seeking an Analyst, IT Security GRC for a top industrial services and equipment rental client. This opportunity is heavily focused on cybersecurity compliance frameworks and governance maturity, with a primary emphasis on ISO 27001 implementation and alignment activities. The ideal candidate will assist with building a new GRC platform, supporting audits, managing compliance documentation, conducting risk assessments, and helping establish policies and procedures from the ground up. This is an excellent opportunity for someone looking to gain hands-on experience building a mature governance program while helping shape the future security culture of a growing cybersecurity organization.
Top Initiatives:
- Build out a brand-new GRC platform
- Drive ISO 27001 and compliance framework maturity
- Establish governance processes, policies, and security standards
Salary : $30 - $42