Job Closed
This listing is no longer active.
Aprio, LLP is an accounting firm that is on a mission to advise its customers on “how to achieve what’s next.” As an employer, the company is recognized f
Cybersecurity Analyst, IT GRC
Location
United States
Posted
54 days ago
Salary
$80K - $120K / year
Seniority
Mid Level
Job Description
Cybersecurity Analyst, IT GRC
Aprio
• Execute end-to-end third-party and vendor risk assessments, including inherent risk scoring, due diligence reviews, and residual risk evaluation • Review and analyze third-party artifacts such as SOC reports, ISO certifications, policies, procedures, and security questionnaires • Identify control gaps, document risk issues, and track remediation activities with vendors and internal stakeholders • Support onboarding of new vendors and periodic reassessments of existing third parties • Maintain accurate third-party risk documentation in GRC or vendor risk management tools • Develop, maintain, and enhance risk metrics, dashboards, and reporting for third-party risk • Track key performance indicators (KPIs) and key risk indicators (KRIs) related to vendor risk, assessment cycle times, remediation status, and risk trends • Prepare materials for leadership and executive-level reporting, translating risk data into clear, actionable insights • Support audits, regulatory exams, and internal reviews related to third-party risk management • Assist with additional GRC activities as needed, including policy management, risk assessments, control testing, and compliance initiatives • Support alignment with recognized frameworks and standards (e.g., NIST CSF, ISO 27001, SOC, FFIEC, or similar) • Participate in continuous improvement of GRC processes, templates, and methodologies • Collaborate with cross-functional teams including Security, IT, Legal, Procurement, Privacy, and Business Owners
Job Requirements
- 2+ years of experience in Third-Party Risk Management, Vendor Risk Assessments, or GRC-related roles
- Demonstrated experience conducting or supporting third-party risk assessments
- Strong understanding of information security and risk management concepts
- Proven ability to produce clear reporting, metrics, and dashboards
- Strong analytical, organizational, and documentation skills
- Ability to learn quickly, adapt to changing priorities, and manage multiple assessments simultaneously
- Effective written and verbal communication skills
Benefits
- Medical, Dental, and Vision Insurance on the first day of employment
- Flexible Spending Account and Dependent Care Account
- 401k with Profit Sharing
- 9+ holidays and discretionary time off structure
- Parental Leave – coverage for both primary and secondary caregivers
- Tuition Assistance Program and CPA support program with cash incentive upon completion
- Discretionary incentive compensation based on firm, group and individual performance
- Incentive compensation related to origination of new client sales
- Top rated wellness program
- Flexible working environment including remote and hybrid options
Related Guides
Related Categories
Related Job Pages
More Security Analyst Jobs
SME Information Security Analyst
DMI (Digital Management, LLC)At the Intersection of Public and Private Sectors
• Serve as the premier cybersecurity authority within the TALON program • Provide strategic advisory services to TSA’s IT leadership on cybersecurity risk management, security architecture, and compliance program maturity • Assess and shape the security posture of TSA’s engineering portfolio • Engage directly with TSA’s CISO organization, ISSOs, and the O&M contractor to drive integrated security outcomes • Advise on SSI handling requirements, POA&M resolution strategies, and ICAM implementation approaches • Provide technical oversight of security testing and assessment activities across the TALON portfolio • Provide real-time technical guidance to TSA stakeholders and the O&M contractor in critical incident scenarios
SOC Electronics Technician
LeidosLeidos is an innovation company rapidly addressing the world’s most vexing challenges in national security and health.
Job Description Leidos is seeking an Electronic Technician to travel and work aboard ships at sea for extended periods , work rotating shifts, work in excess of 40-hours per week. There will down periods between rotations . **Selected applicant can reside anywhere within the United States as long as he/she is flexible for deployments and travel.** As a member of the IUSS/SURTASS team, you will be responsible for the following: - Operation and maintenance of electronic equipment utilizing common and specialized tools in repair and maintenance of electro/mechanical equipment, test equipment, manufacturers' manuals, schematic diagrams and government procedures to operate and repair electro/mechanical equipment. - Preparation of all required reports; assist higher level personnel in compiling data for reports, procedures and manuals and ensure proper maintenance of records and logs. - Perform collateral duties in security, safety and logistics areas. You will participate in Leidos and Government safety programs, as well as the deployment and retrieval of the array and all other special tasks related to SURTASS operations. This position will require close cooperation and working relationships with active duty military and other Government personnel. Berthing arrangements on board T-AGOS vessels will require sharing staterooms and other facilities. Position requires the ability to perform in an arduous duty environment and the successful candidate must be capable of passing a Mariner's Physical per COMSCINST 6000.l.c and maintain their medical fitness for this position. Basic Qualifications: - Requires high school diploma or equivalent and 2 – 4 years of prior relevant experience. - Demonstrated ability to perform assigned technical/para-engineering tasks and 1 year of experience. - Previous electronics repair and maintenance experience. - Individuals must possess the ability and demeanor to share common spaces over lengthy deployment periods and work closely with others in a small working area and in a shipboard environment. - Selected applicant must be proficient with personal computers and have a familiarity with operational and maintenance publications. - Must be able to communicate effectively both orally and in writing. - Obtain valid U.S. passport in an expeditious manner, have the ability to travel, successfully complete and pass a pre-employment drug screening, and have the ability to obtain and maintain company provided travel charge cards. - Must have successfully completed a class C military electronics repair school and/or have a degree in electronics/information technology. - Must be capable of passing a Mariner's Physical per COMSCINST 6000.l.c and maintain their medical fitness for this position. - Selected applicant will be subject to a government security investigation and must meet eligibility requirements for access to classified information. - Final Secret required to start and ability to obtain a Top Secret. Desired Qualifications: - Security+ or Network+ or A+ certifications - SURTASS program training is highly desired - Familiarity and knowledge of UNIX is desired Background in EKMS/COMSEC KMI Manager If you're looking for comfort, keep scrolling. At Leidos, we outthink, outbuild, and outpace the status quo — because the mission demands it. We're not hiring followers. We're recruiting the ones who disrupt, provoke, and refuse to fail. Step 10 is ancient history. We're already at step 30 — and moving faster than anyone else dares. Original Posting: April 6, 2026 For U.S. Positions: While subject to change based on business needs, Leidos reasonably anticipates that this job requisition will remain open for at least 3 days with an anticipated close date of no earlier than 3 days after the original posting date as listed above. Pay Range: Pay Range $48,100.00 - $86,950.00 The Leidos pay range for this job level is a general guideline only and not a guarantee of compensation or salary. Additional factors considered in extending an offer include (but are not limited to) responsibilities of the job, education, experience, knowledge, skills, and abilities, as well as internal equity, alignment with market data, applicable bargaining agreement (if any), or other law.
Healthcare’s helping hand. CHG shook things up in 1979 by inventing the locum tenens staffing model. We connect doctors with patients who need their care. As the largest physician staffing firm in America, our providers treat millions of patients each year. Our industry is growing and demand is high. This means you’ll have plenty of opportunities to grow and develop in your career. Keeping healthcare healthy can be as fun as it is rewarding Information Security & Privacy is looking for a Product Security Analyst to join our team. The Product Security Analyst will establish Product risk management framework and governance processes across CHG Healthcare's multi-brand portfolio. As a Product Security Analyst on the ISP team you will lead data classification initiatives, manage risk acceptance processes, and deliver executive security reporting. This role will report to the Sr. Manager Application Security. Responsibilities - Lead data classification initiatives across CHG's systems, ensuring proper handling of sensitive healthcare data - Establish and manage formal risk acceptance processes with business teams, facilitating informed security decisions - Develop and deliver monthly executive security risk reports with metrics and trending analysis - Leverage AI tools to analyze security data, identify patterns, and generate actionable insights at scale - Support roadmap deliverables focused on building risk management and governance capabilities Qualifications • Strong understanding of information security principles, risk assessment methodologies, and data classification • Experience developing and presenting security metrics and reports to executive audiences • Excellent analytical skills to synthesize complex information into clear recommendations • Ability to creatively use AI tools to enhance analysis, reporting, and communication workflows • Strong stakeholder management and communication skills across technical and business teams Education & Experience • 3+ years of experience in security analysis, risk management, or GRC (Governance, Risk, and Compliance) roles • Bachelor's degree in Information Security, Risk Management, Business Administration, or related field, or equivalent work experience Preferred • Experience in healthcare or highly regulated industries • Security or risk management certifications such as CISSP, CISM, CRISC, or CGRC • Knowledge of HIPAA, SOC 2, ISO 27001, and other compliance frameworks • Experience with GRC platforms (ServiceNow GRC, Archer, LogicManager, etc.) We believe in fair compensation for all of our people, which is why our pay structure takes into account the cost of labor across U.S. geographic markets. For this position, we offer a pay range of $74,100 -- $143,300 annually, with pay varying depending on work location and job-related factors such as knowledge, position level and experience. During the hiring process, your recruiter can provide more information about the specific salary range for the job location. CHG Healthcare offers starting salaries for sales positions in the form of total target compensation (TTC = base + commission + bonus), which includes base pay, commission, and bonuses. Sales positions receive short-term incentives through commission plans and bonuses. On the other hand, non-sales positions have starting salaries that consist of a base salary and short-term incentives through various bonus plans, which are paid out monthly, quarterly, or annually. #LI-MJ1 In return we offer: • 401(k) retirement plan with company match • Traditional healthcare benefits such as medical and dental coverage, and some unique benefits like onsite health centers, corporate wellness programs, and free behavioral health appointments. • Flexible work schedules - including work-from-home options available • Recognition programs with rewards including trips, cash, and paid time off • Family-friendly benefits including paid parental leave, fertility coverage, adoption assistance, and marriage counseling • Tailored training resources including free LinkedIn learning courses • Volunteer time off and employee-driven matching grants • Tuition reimbursement programs Click here to learn more about our company and culture. CHG Healthcare values a diverse and inclusive workforce. Interested in this role but not a perfect fit? Apply anyway. We welcome applicants of any race, color, religion, sex, sexual orientation, gender identity, national origin, veteran status and individuals with disabilities as an Affirmative Action/Equal Opportunity Employer. We are an at-will employer. What makes CHG Different?
GRC Analyst
Direct TravelDirect Travel is a leading provider of corporate travel management services. By leveraging both the expertise of its people and innovative solutions, Direct Travel enables clients to derive the greatest value from their travel program in terms of superior service, progressive technologies, and significant cost savings. The company is led by CEO Christal Bemont and Executive Chairman Steve Singh, noted business investor and founder of Concur. Direct Travel has offices in over 80 locations and is currently ranked among the top providers of travel on Travel Weekly’s Power List. For more information, visit www.dt.com . Direct Travel is an EOE/AA/Veteran/People with Disabilities employer. If you're ready to chart a new course and advance your career with the valuable moments and travel experiences that await, we welcome you to submit your resume for consideration at Direct Travel. #LI-Remote
Role Description We are seeking a detail-oriented Governance Risk and Compliance (GRC) Analyst to join our Security and Compliance team. The GRC Analyst will work in a collaborative fashion with our internal teams and external partners to manage Security & Compliance risk. Our preference for this role is those who have solid experience in technology, information security or compliance, and have significantly contributed to SSAE18, SOC 2, Payment Card Industry (PCI) ROC and/or ISO 27001 audits. We're looking for team players who want to challenge themselves within a growing company, and are as comfortable talking with senior management about information risk, as they are with IT staff. Therefore, if you thrive in a dynamic environment, then maybe you are the one we’re looking for! This position is a remote position reporting to the Senior Director of Governance, Risk & Compliance. Responsibilities - Conducts audits of internal information security, compliance and privacy processes. - Ensures timely resolution to all audit and risk assessment findings or issues. - Manages OneTrust GRC reporting portal. - Appropriately communicates audit reports, gaps or recommendations to company management, and tracks any open concerns or questions to resolution. - Identifies potential technologies, processes or solutions that could improve the security posture of the company. - Contributes to the development of security standards, access controls, and compliance requirements of applications, network infrastructure, servers and workstations. - Serves as subject matter expert regarding information security and compliance policy. - Maintains awareness of current and emerging threat landscapes. - Assists in reporting security & compliance metrics to management. - Supports additional audit and governance functions as assigned. - Earns the trust and respect of the Direct Travel team. - Grows into a role with increasing responsibility. Qualifications - Direct experience with achieving successful annual PCI Compliance, SSAE18 SOC 2 attestations and/or ISO 27001 certifications. - 1-3 years of experience leading information security audits with a preference for ISO 27001 and SOC 2 audits or assessments. - 1-3 years of experience as an IT, security or compliance analyst, with experience developing security strategy and policy. - Experience authoring policies and procedures. - Solid knowledge of ISO 27001, NIST 800-53, NIST 800-171, NIST CSF. - Experience with full Governance, Risk Management and Compliance Lifecycle. - Personal integrity. - Self-motivated, self-disciplined, and self-governed. You hold yourself to a higher standard than others. - Highly consultative and collaborative nature. - Excellent communications and presentation skills, with the ability to convey complex technology concepts to non-technology stakeholders. - The discipline to work effectively from remote location. - Degree in computer science, information systems, information security, or a related discipline. Equivalent work experience will also be considered. - Experience with Payment Card Industry (PCI) Compliance. - Excellent analytical and stakeholder engagement skills. - Strong organization and planning skills. - Successfully pass background check. - Must be able to lawfully work within the US and have unrestricted work authorization for US. - Ability to travel up to 15% if required. Benefits - In addition to Medical, Dental, and Vision benefits, Direct Travel offers an employee rewards and recognitions program. - Total Rewards Package which includes Wellness, Sustainability, DE&I initiatives, and Mental Health Support. Company Description Direct Travel is a leading provider of corporate travel management services. The company has been providing travel management for over 40 years, working with clients to develop highly customized travel programs. By leveraging both the expertise of its people and innovative solutions, Direct Travel enables clients to derive the greatest value from their travel program in terms of superior service, progressive technologies and significant cost savings. Direct Travel has offices in over 70 locations across North America and the UK and is currently ranked 12th on Travel Weekly’s Power List. For more information, visit www.dt.com . Direct Travel is an EOE/AA/Veteran/People with Disabilities employer. If you're ready to chart a new course and advance your career with the valuable moments and travel experiences that await, we welcome you to submit your resume for consideration at Direct Travel.



