Demo

IT Security GRC Analyst

The Phoenix Group
Charlotte, NC Full Time
POSTED ON 7/29/2026
AVAILABLE BEFORE 8/27/2026

A leading organization in the information security and compliance industry is seeking a motivated and experienced IT Security Governance, Risk, and Compliance (GRC) Analyst to support their cybersecurity governance, risk management, compliance, and data privacy initiatives within a dynamic enterprise environment.

Role Overview

This role involves establishing and leading the organization’s GRC program, focusing on ISO 20000, risk assessments, and compliance frameworks, with high visibility to executive leadership. The ideal candidate will have strong experience with cybersecurity controls, data privacy, and GRC program implementation, contributing to the organization’s strategic cybersecurity posture and growth.

Key Responsibilities

  • Lead the development, implementation, and management of the GRC program, ensuring efficient adoption of ISO 20000 standards and cybersecurity frameworks
  • Perform comprehensive cybersecurity risk assessments on applications, infrastructure, cloud environments, vendors, and business processes; facilitate risk identification, analysis, and treatment activities
  • Maintain and update the risk register and track remediation or mitigation activities until closure
  • Coordinate internal and external cybersecurity audits, assessments, and compliance reviews across multiple standards such as ISO 27001, NIST CSF, NIST 800-53, NIST 800-171, SOC 2, FedRAMP, CMMC, and SOX, ensuring evidence collection and control documentation
  • Support privacy initiatives including Data Protection Impact Assessments (DPIAs), privacy documentation, data inventories, classifications, and retention policies
  • Review vendor security questionnaires, third-party risk assessments, and related audit reports; ensure vendor cybersecurity and privacy compliance
  • Assist in maintaining cybersecurity policies, standards, and procedures; facilitate governance reviews, policy exception tracking, and metrics development
  • Develop dashboards, key risk indicators, compliance metrics, and trend analyses for executive reporting
  • Collaborate with cross-functional teams including Legal, IT, Security, and Infrastructure to embed risk and compliance controls into operational workflows

Core Qualifications & Requirements

  • Bachelor’s degree in Cybersecurity, Information Systems, Risk Management, Business, Legal Studies, or related field preferred
  • 2-5 years of experience in cybersecurity compliance, GRC, risk management, audit, or related roles
  • Demonstrated experience supporting cybersecurity frameworks such as ISO 20000, ISO 27001, NIST Cybersecurity Framework (CSF), NIST 800-53, NIST 800-171, SOC 2, FedRAMP, CMMC, and Sarbanes-Oxley (SOX)
  • Proven ability to perform cybersecurity risk assessments, manage compliance programs, and support audit preparation and evidence collection
  • Knowledge of data privacy principles, privacy impact assessments (PIAs), DPIAs, third-party risk reviews, and privacy-related controls
  • Strong understanding of cybersecurity controls, industry standards, and GRC platforms

Nice-to-Have Qualifications

  • Professional certifications such as CISSP, CISA, Security , CRISC, ISO 27001 Lead Implementer, or CIPP are advantageous
  • Experience leading multi-disciplinary teams or major program initiatives with oversight responsibilities
  • Ability to crosswalk controls between cybersecurity frameworks and compliance requirements
  • Familiarity with control mapping, remediation tracking, and risk register maintenance

Core Technical Skills

  • Security frameworks: ISO 20000, ISO 27001, NIST 800-53, NIST 800-171, NIST CSF, SOC 2, FedRAMP, CMMC, SOX controls
  • Risk management: Risk assessments, risk treatment, risk registers, remediation tracking
  • Data privacy: DPIAs, PIAs, data inventories, classifications, privacy policies
  • GRC platforms: RSA Archer, ServiceNow GRC, LogicManager, MetricStream (preferred)
  • Auditing & compliance: Evidence collection, control documentation, audit readiness, vendor assessments


Salary : $80,000 - $90,000

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a IT Security GRC Analyst?

Sign up to receive alerts about other jobs on the IT Security GRC Analyst career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at The Phoenix Group

  • The Phoenix Group Arizona, AZ
  • Responsibilities Conduct comprehensive conflict checks for new client and matter intake, ensuring requests are reviewed promptly and accurately while colla... more
  • 1 Day Ago

  • The Phoenix Group Charlotte, NC
  • Role Overview This role involves establishing and leading the organization’s GRC program, focusing on ISO 20000, risk assessments, and compliance framework... more
  • 1 Day Ago

  • The Phoenix Group Philadelphia, PA
  • Role Overview The Senior Systems Engineer will own and evolve the company's cloud infrastructure, focusing on Azure platform management, virtualization, an... more
  • 1 Day Ago

  • The Phoenix Group York, NY
  • Role Overview We're looking for a passionate Guest Experience Associate to create an exceptional workplace experience for employees, clients, and guests. A... more
  • 1 Day Ago


Not the job you're looking for? Here are some other IT Security GRC Analyst jobs in the Charlotte, NC area that may be a better fit.

  • Insight Global Charlotte, NC
  • 3 month contract to hire, 2x week onsite in Charlotte, NC Must-Haves: 2–5 years of experience in IT Compliance, Information Security, Risk Management, Audi... more
  • 3 Days Ago

  • Insight Global Charlotte, NC
  • 3 month contract to hire, 2x week onsite in Charlotte, NC Must-Haves: 2–5 years of experience in IT Compliance, Information Security, Data Privacy, Risk Ma... more
  • 3 Days Ago

AI Assistant is available now!

Feel free to start your new journey!