What are the responsibilities and job description for the Analyst, IT Security GRC - Data Privacy & Third Party position at Insight Global?
3 month contract to hire, 2x week onsite in Charlotte, NC
Must-Haves:
- 2–5 years of experience in IT Compliance, Information Security, Data Privacy, Risk Management, Audit, or GRC
- Experience supporting cybersecurity and privacy risk assessments
- Knowledge of data privacy regulations and security best practices
- Experience with third-party/vendor risk management processes
- Experience supporting audits, evidence collection, and compliance documentation
- Experience maintaining risk registers and remediation activities
- Strong communication, documentation, and stakeholder management skills
- Experience using GRC, privacy, or risk management platforms
Plusses:
- Experience conducting PIAs and DPIAs
- Strong vendor risk management background
- Knowledge of NIST, ISO 27001, SOC 2, or related frameworks
- Security , CISA, CGRC, CRISC, or CISSP certifications
- SOX or ITGC experience
- Bachelor's degree in a related field
Day-to-Day:
- Conduct third-party cybersecurity and privacy risk reviews
- Support enterprise data privacy initiatives and governance efforts
- Maintain data inventories, classifications, retention, and protection programs
- Assist with privacy assessments including PIAs and DPIAs
- Perform cybersecurity risk assessments across vendors and business processes
- Maintain risk registers and track remediation efforts
- Coordinate audit activities and documentation requests
- Support policy exception management and corrective action plans
- Develop dashboards, compliance metrics, and risk reporting
- Partner with Legal, HR, IT, Security, and business teams to strengthen privacy and vendor governance practices
Job Description:
Insight Global is seeking an Analyst, IT Security GRC for a top industrial services and equipment rental client. This position will focus primarily on enterprise data privacy initiatives and third-party risk management activities within a newly established GRC team. The ideal candidate will support vendor risk assessments, privacy compliance efforts, data governance initiatives, remediation tracking, and cybersecurity risk management processes. This role offers an opportunity to play a key part in shaping the organization's privacy and third-party risk program while partnering with stakeholders across Security, Legal, HR, Infrastructure, Cloud, and business operations.
Top Initiatives:
- Build out a brand-new GRC platform
- Drive ISO 27001 and compliance framework maturity
- Establish governance processes, policies, and security standards
Salary : $30 - $42