Hotman Group, LLC

Entry Level GRC Analyst

Hotman Group, LLC

full-time

Posted on:

Location Type: Remote

Location: TexasUnited States

Visit company website

Explore more

AI Apply
Apply

Job Level

Tech Stack

About the role

  • Assess and improve client security and IT controls
  • Develop policies, processes, and risk assessments aligned to top frameworks like NIST, ISO 27001, and SOC 2
  • Crosswalk and harmonize controls across multiple compliance frameworks
  • Analyze, recommend, and implement security best practices
  • Build risk registers, lead assessments, and monitor remediation progress
  • Work hands-on with GRC tools and contribute to innovative solutions for complex challenges
  • Translate technical and regulatory requirements into clear, actionable steps for clients

Requirements

  • Bachelor’s or Graduate degree in Cybersecurity, Information Systems, or a related field
  • 0-2 years of relevant experience (cybersecurity, audit, risk, compliance, GRC)
  • Solid understanding of fundamental security and IT concepts (access controls, data retention, change management, etc.)
  • Familiarity with major security and privacy frameworks (ISO, NIST, SOC 2, HIPAA, etc.)
  • Ability to pass a background check
  • Reliable internet and a secure remote workspace
  • Bonus points if you’re already pursuing a security or risk certification!
Benefits
  • Cybersecurity strategy and program development
  • Fully managed programs, from implementation to maturation and remediation
  • One-time projects like policies, audits, risk assessments, incident response planning, and more
  • Support across top compliance frameworks like SOC 2, NIST CSF, ISO 27001, HITRUST, and others
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills & Tools
risk assessmentssecurity best practicesaccess controlsdata retentionchange management
Soft Skills
analytical skillscommunication skillsproblem-solvingattention to detail
Certifications
security certificationrisk certification