Virtru logo
Virtru

Respect the people. Respect the data. Virtru equips you to protect your data anywhere and everywhere it's shared.

Security Governance, Risk & Compliance (GRC) Analyst

Security AnalystSecurity AnalystFull TimeRemoteSeniorTeam 51-200Since 2012H1B No SponsorCompany SiteLinkedIn

Location

District Of Columbia + 1 moreAll locations: District Of Columbia | Washington

Posted

5 days ago

Salary

$130K - $170K / year

Seniority

Senior

Bachelor Degree5 yrs expEnglishAWSAzureCloudGoogle Cloud PlatformSplunk

Job Description

Security Governance, Risk & Compliance (GRC) Analyst

Virtru

• Manage and implement complex controls frameworks for large systems, consisting of Cloud infrastructure and Software as a Service (SaaS) services (GCP, AWS, GitHub, Okta, etc). • Design and develop automation solutions for evidence collection across Cloud infrastructure, endpoints, and SaaS services. • Conduct risk assessments across business units and processes. Identify risk findings and recommend remediation and risk mitigation strategies. • Participate in incident response (IR) activities, providing risk analysis and remediation support as needed. • Assist or implement automated controls to support risk mitigation efforts across various business units with stakeholders. • Incorporate CMMC certification into Virtru’s slate of compliance assessments and ongoing monitoring activities (FedRAMP, SOC 2, PCI). • Facilitate the third-party vendor on-boarding and annual review process by evaluating the security of current and prospective partners. • Enhance the team with your individualism, spirit, and love of learning.

Job Requirements

  • Minimum of 5+ years of information security, IT audit and/or IT Risk Management, or GRC Analyst/Engineer experience
  • Deep understanding of at least few of the following: CMMC, NIST 800-53 & 800-171, FedRAMP, SOC 2, PCI, and/or other global privacy compliance frameworks
  • Technical acumen. Strong understanding of modern cloud technologies (AWS, GCP, Azure, etc.) and familiarity with GRC tools (Hyperproof, Vanta, Drata, etc) and SIEM tools (Datadog, Splunk)
  • You’re a relationship builder and have worked with both business and technical risk and understand how to translate risk to various levels of the organization
  • Have experience training and coaching teams to become better security and privacy practitioners
  • Like working on an autonomous agile team. At Virtru, you will have ownership of security, but you'll collaborate with everyone to make sure we produce and implement the right solutions
  • Ability to resolve conflicts and drive issues to completion.
  • Work independently with little or no supervision while maintaining a high level of efficiency.

Benefits

  • A Flexible PTO policy — we strongly encourage you to take time off (in addition to 14 holidays) to ensure that you are getting the proper time needed to unplug and recharge.
  • A $1,500 annual Learning & Development Stipend focused on providing you the resources to continually learn and professionally grow.
  • Frequent company-sponsored team celebrations that provide ample opportunities to connect with teammates and be social!
  • Access to an Employee Assistance Program
  • Access to Headspace, a mental health app tailored to your specific needs.
  • A flat 3% contribution to your retirement account
  • A high degree of flexibility — Have an appointment, errand, or family emergency to take care of? Hop to it! We give you the time and space to take care of you and your own first.

Related Job Pages

More Security Analyst Jobs

Cherokee Federal logo

Cybersecurity Analyst

Cherokee Federal

Building. Solving. Serving.

Full TimeRemoteTeam 5,001-10,000Since 1969H1B No Sponsor

• Monitor and analyze security events utilizing Splunk Enterprise Security (ES). • Build, maintain, and tune Splunk searches, correlation rules, alerts, and dashboards. • Conduct incident response activities from detection through containment, eradication, recovery, and closure. • Investigate endpoint security incidents utilizing Microsoft Defender for Endpoint. • Perform endpoint policy management and incident investigations. • Assess AWS cloud security telemetry utilizing GuardDuty, Security Hub, and related cloud security services. • Identify threats, vulnerabilities, suspicious activity, and cloud misconfigurations. • Execute alert triage, incident scoping, and escalation activities according to established playbooks. • Recommend updates and improvements to operational procedures and incident response playbooks. • Support threat hunting activities and detection engineering initiatives aligned to MITRE ATT&CK methodologies. • Perform phishing investigations, alert enrichment, and forensic review activities. • Conduct root cause analysis and document corrective actions following security incidents. • Track incidents and operational tasks utilizing case management systems. • Participate in tabletop exercises and operational readiness activities. • Collaborate with Security Operations teams, Incident Response personnel, and federal stakeholders. • Prepare reports and communicate findings to technical and non-technical audiences. • Perform other job-related duties as assigned.

United States
$153K - $160K / year
Deutsche Telekom IT Solutions logo

Security Analyst

Deutsche Telekom IT Solutions

As Hungary’s most attractive employer in 2025 (according to Randstad’s representative survey), Deutsche Telekom IT Solutions is a subsidiary of the Deutsche Telekom Group. The company provides a wide portfolio of IT and telecommunications services with more than 5300 employees. We have hundreds of large customers, corporations in Germany and in other European countries. DT-ITS received the Best in Educational Cooperation award from HIPA in 2019, acknowledged as the Most Ethical Multinational Company in 2019. The company continuously develops its four sites in Budapest, Debrecen, Pécs and Szeged and is looking for skilled IT professionals to join its team.

Full TimeRemoteTeam 5,001-10,000

Role Description You don’t want to cry when you hear about WannaCry? Loki isn’t only a German firegod to you? You know what Meltdown/Spectre are, maybe you even know what cryptojacking is? Then the following position is for you! If you join us, your daily tasks will be as follows: - Detection, analysis and management of security incidents - Making and evaluating reports - Monitoring the customer’s environment - Tracking IT security issues (vulnerabilities, 0day exploits, malware) and making/fitting the rules for detecting them in the client's environment - Change and incident management - Analysis of malicious code in sandbox Qualifications - If you love to learn and you have a need for continuous development - If you know network models (OSI, TCP/IP) - If you know how operating systems work (Windows, Linux) - You speak English on business level - You are fluent in Hungarian - It's not a problem if you have to spend about one-third of your working hours in shifts - You have basic knowledge of script languages: python, bash, JS and so on - You are familiar with the logs of security systems: proxy, AV, WAF, IDS, Webserver, DNS - You've done PCAP analysis Benefits - Please be informed that our remote working possibility is only available within Hungary due to European taxation regulation. Company Description As Hungary’s most attractive employer in 2025 (according to Randstad’s representative survey), Deutsche Telekom IT Solutions is a subsidiary of the Deutsche Telekom Group. The company provides a wide portfolio of IT and telecommunications services with more than 5300 employees. We have hundreds of large customers, corporations in Germany and in other European countries. DT-ITS received the Best in Educational Cooperation award from HIPA in 2019, acknowledged as the Most Ethical Multinational Company in 2019. The company continuously develops its four sites in Budapest, Debrecen, Pécs and Szeged and is looking for skilled IT professionals to join its team.

Hungary

Role Description Vigilant is hiring a Security Analyst to join our Security Services team. In this position, you will ensure that our first line of response is assessing information security events and incidents across Vigilant's client environments. In this role, you will collaborate and use problem-solving skills as you work among a team of skilled analysts to address complex problems and add value to the organization and our clients. Security Analysts will be responsible for delivering regular scheduled security briefings to our clients. Primary Responsibilities: - The SOC Analyst provides incident detection and response services for our CyberDNA managed Network Security Monitoring service. - This role performs and participates in proactive hunts to identify anomalous activity indicative of active compromise, previous compromise, misconfigurations, or other notable observations to support the protection of our customers' environments. - When not hunting, this role triages and investigates alerts generated from multiple detection technologies & takes necessary action to identify, scope, and guide customers to a rapid and successful remediation. - You will use your knowledge of Information Security to monitor SIEM and logging environments for security events and alerts to potential (or active) threats, intrusions, and/or compromises. - You will work to understand the global threat landscape by working with Vigilant Cyber Threat Intelligence team to maintain awareness. - You will assist with containment of threats and remediation of environment during or after an incident. - You will leverage your knowledge to write comprehensive reports of incident investigations. - Engage with other teams to ensure detections are working as intended. - Provide feedback to the Threat Detection team regarding the logic of existing detections to reduce false-positive rates, and align them more consistently with their intent. - Ensure that security-relevant data is flowing to appropriate systems. - Collaborate across teams for training, development opportunities, and service improvement. - Ensure that documentation, workflows, and processes remain accurate and up-to-date. Qualifications - Expert at analyzing and dissecting PCAP data to validate security events, interpret network traffic, and extract indicators. - Skilled with data collection, log analysis tools, pattern recognition, and managing dashboards. - Baseline knowledge of network protocols, network analysis tools, and general network architecture. - You have a passion for learning. - You possess a demonstrated ability to speak with people with varying knowledge in IT Security concepts and can tailor your message to the audience. - Excellent interpersonal skills and ability to see things through the customer's eyes. - Tremendous attention to detail. - Eligible to work in the United States without company sponsorship. - Bachelor's degree in computer science, information security or related discipline is required or equivalent work experience. Requirements - Prior SOC/CSIRT experience in a 24x7 watch desk environment preferred. - Experience using industry standard EDR tools and platforms including (SentinelOne, Carbon Black, Crowdstrike, Defender ATP). - Strong knowledge of attacker tools, malware families, and known threat actor/group TTPs. - You have a deep understanding of Incident Response framework, root cause analysis. - Capability to look at a process to identify opportunities for cycle-time reduction. - Experience hunting for unknown threats, as well as tracking existing campaigns and adversaries. - Experience providing managed NSM services to multiple customers is a plus. - Hands-on experience with firewalls, routers, and other security appliances. Benefits - This role leverages a flex-schedule that may involve non-traditional working hours and after-hours on-call as needed. - Must be able to work from a Vigilant office (Cincinnati, OH) or remotely from a home office, depending on the candidate's skills and experience. - This position is eligible to US citizens physically residing in the US; any offer of employment is contingent upon background, drug screen, and reference checks.

United States

Role Description Join a dynamic team as a GRC Analyst, where your expertise in IT compliance and risk management directly contributes to organizational success. This remote opportunity is ideal for professionals driven by curiosity, critical thinking, and independence. You'll play a pivotal role in supporting SOX compliance, User Access Reviews, and IT General Controls, while working in a fast-paced, growth-focused environment that rewards initiative and innovation. - Lead and execute SOX compliance activities to ensure regulatory adherence - Conduct thorough User Access Reviews (UARs) across IT systems and applications - Perform comprehensive IT General Controls (ITGC) testing and reviews - Support general IT compliance, governance, risk, and controls initiatives - Identify, investigate, and resolve potential compliance issues proactively - Collaborate with cross-functional teams to implement best-practice controls - Challenge assumptions and drive process improvements through critical analysis Qualifications - Demonstrated experience with SOX compliance activities - Hands-on expertise in User Access Reviews and ITGC testing/reviews - Strong background in IT Compliance, Governance, Risk, and Controls - Superior analytical and problem-solving skills - Ability to work independently with minimal supervision - Proactive, inquisitive mindset-comfortable asking clarifying questions and investigating issues Requirements - Direct IT Compliance experience (strongly preferred over pure audit backgrounds) - Solid understanding of risk, controls, and governance processes - Candidates with audit backgrounds considered if they display strong compliance acumen Benefits - 100% remote work-enjoy flexibility and work-life balance - Exposure to high-impact projects and evolving technologies - Collaborative culture that values curiosity, autonomy, and critical thought - Opportunities for professional growth in IT Governance, Risk, and Compliance

United States