Job Closed
This listing is no longer active.
Innovation & Technology Enabling Business Growth
Information Security GRC Analyst
Location
United States
Posted
23 days ago
Salary
$65K / year
Seniority
Junior
Job Description
Information Security GRC Analyst
Ascend Technologies
• Assist in the development, implementation, and assessment of information security policies, standards, and procedures aligned to industry frameworks and regulatory compliance (HIPAA, SEC, FTC, NIST CSF, ISO 27001, SOC 2, CMMC, etc.) • Assist with risk assessments, gap analyses, and control evaluations across multiple client engagements simultaneously across various industries • Participate in the development of risk registers, risk treatment plans, and remediation roadmaps • Assist with third-party/vendor risk assessments and due diligence activities • Document findings, prepare client-facing reports, and contribute to presentations and deliverables • Support audit readiness activities and facilitate evidence collection for audits and assessments • Stay current on emerging threats, regulatory changes, and evolving GRC best practices • Collaborate with GRC consultants and vCISOs to deliver engagements on time and within scope • Support the configuration, data entry, and maintenance of GRC tooling and platforms used to manage client compliance programs • Other responsibilities as assigned by management.
Job Requirements
- 1–2 years of experience in GRC, cybersecurity, IT audit, or a related discipline
- Foundational knowledge of security frameworks such as NIST CSF, ISO 27001, or CIS Controls
- Strong written and verbal communication skills, with the ability to convey technical concepts to non-technical audiences
- Ability to manage multiple tasks and deadlines in a fast-paced, client-driven environment
- Proficiency in Microsoft Office Suite (Word, Excel, PowerPoint)
- Strong analytical skills and attention to detail
- Strong problem-solving and critical-thinking abilities.
- Collaborative, customer‑centric mindset.
- High integrity and commitment to confidentiality.
- Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Business, or a related field (preferred)
- Relevant certifications or progress toward: CompTIA Security+, CISA, CRISC, or GRC Professional (preferred)
- Familiarity with GRC platforms such as Apptega, StandardFusion, or ControlMap (preferred)
- Experience with cloud environments (AWS, Azure, GCP) and associated compliance considerations (preferred)
- Experience with security awareness training platforms (KnowBe4, InfoSec IQ) (preferred)
Benefits
- Health insurance
- Flexible work arrangements
- Professional development opportunities
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Identify, evaluate, and appropriately address alerts and incidents • Develop detections based on the MITRE ATT&CK Framework • Proactively identify emerging threats and conduct threat hunting for undetected activity within the environment • Assess alerts to establish their legitimacy and urgency • Adhere to SOC playbooks and standard operating procedures (SOPs) to promote consistency in triage and decision-making • Conduct a thorough review and audit of existing logging systems to identify any gaps in detection capabilities • Review threat intel reports and feeds • Perform in-depth investigations on Windows, Linux, and MacOS hosts • Create stories to enhance the SOAR environment for engineers • Enhance SOC processes with feedback and operational insights • Serve as both a mentor and an escalation point for SOC engineers • Tune security tool configuration to minimize false positives • Work closely with security leaders, engineers, and compliance teams to implement effective security plans • Serve as a subject matter expert for security tools, applications, and processes
• Drive the end-to-end delivery of initiatives that transform how physical security solutions are provided to employees and guests globally. • Support the Security Enablement Engineering team in the deployment and configuration of automated systems. • Work daily with Workplace, IT, Legal, and HR to ensure security workflows align with company-wide priorities. • Conduct research and help build business cases for new security vendors, tools, and operational efficiencies. • Maintain and update global standards for physical security systems, ensuring consistency in user experience across all office locations. • Collect and analyze data from security systems and employee feedback to report on program effectiveness and KPIs. • Assist in running pilot programs and design sprints, incorporating stakeholder feedback to iterate on security processes. • Act as the central point of contact for project-specific coordination between operations, engineering, and site-level teams.
Senior Cybersecurity Engineer
Hyundai TransleadWe start with hiring amazing and talented people, empowered to put customers' needs at the center of everything we do!
• Protect enterprise technology environments by designing, implementing, and operating cybersecurity controls • Deliver threat detection and monitoring capabilities • Conduct vulnerability management and incident response support • Provide security architecture guidance and risk assessment activities • Strengthen operational security through policy enforcement and network segmentation
Data Protection & AI Security, Staff Engineer
The Hershey CompanyThe Hershey Company is an Equal Opportunity Employer. The policy of The Hershey Company is to extend opportunities to qualified applicants and employees on an equal basis regardless of an individual's race, color, gender, age, national origin, religion, citizenship status, marital status, sexual orientation, gender identity, transgender status, physical or mental disability, protected veteran status, genetic information, pregnancy, or any other categories protected by applicable federal, state or local laws. The Hershey Company is an Equal Opportunity Employer - Minority/Female/Disabled/Protected Veterans. You may request a reasonable accommodation if you are unable or limited in your ability to use or access our online application process as a result of a disability. You can request an accommodation via phone or email. To request an accommodation via phone, please call +1 877-804-1794 and leave a voicemail with your contact information. You may also email a request for accommodation to ApplicationHelp@hersheys.com. Please be sure to include “Accommodation Needed” in the subject line. This will ensure that your email is routed to the appropriate contact who will handle your request.
• Serve as the strategic technical leader responsible for advancing the enterprise data protection program • Develop the data protection roadmap, translating governance priorities into technical initiatives • Lead the design and implementation of security controls that protect sensitive data across endpoints, cloud services, collaboration platforms, and AI systems • Identify risks, define long-term capabilities, and develop the technical roadmap required to protect sensitive information across the enterprise • Collaborate with cross-functional stakeholders to ensure sensitive data is properly owned, classified, governed, and protected




