
GRC Analyst
Point Wild (Formerly Pango Group)
full-time
Posted on:
Location Type: Remote
Location: United States
Visit company websiteExplore more
Salary
💰 $80,000 - $95,000 per year
Job Level
Tech Stack
About the role
- Conduct regular security audits and risk assessments to identify vulnerabilities and areas for improvement.
- Monitor and assess compliance with internal security policies and external regulatory requirements.
- Recommend and track appropriate security controls and mitigation strategies.
- Maintain detailed records of compliance activities, including assessments, corrective actions, and audit results.
- Prepare compliance documentation and reports for internal leadership and external auditors.
- Maintain and support the Simpluris cybersecurity compliance program.
- Regularly update policies, procedures, standards, and documentation to align with evolving regulatory and contractual requirements.
- Develop and maintain templates, tools, and resources to support compliance and audit readiness.
- Utilize compliance and GRC tools to track controls, evidence, risks, and remediation efforts.
- Support third-party risk assessments, vendor questionnaires, and ongoing vendor compliance monitoring.
- Serve as the primary point of contact between Corporate, Technology, and Operational teams.
- Collaborate with IT, legal, and business units to address compliance challenges.
- Communicate complex technical and regulatory requirements in a clear, accessible manner to diverse audiences.
- Conduct or support internal security audits and compliance reviews.
- Stay current with industry standards, federal regulations, and cybersecurity best practices.
- Support incident response activities, investigations, and post-incident documentation as needed.
- Collect, validate, and maintain audit evidence to support regulatory and customer audits.
- Assist with control testing, gap analysis, and remediation tracking.
Requirements
- Bachelor’s degree in information technology, Cybersecurity, Computer Science, Information Security, or a related field.
- 1–3 years of experience in IT security, compliance, risk management, or a related role.
- Experience with compliance and GRC tools (Drata or Vanta).
- Familiarity with cybersecurity and frameworks, including:
- NIST 800-53 R5 (CMMC is a plus)
- Type 2 SOC 2
- HIPAA, PCI-DSS, or GDPR.
- Strong understanding of information security principles and best practices.
Benefits
- Competitive pay
- Generous health and wellness benefits
- Retirement savings plans
- Parental leave
- Much more!
Applicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills & Tools
security auditsrisk assessmentscompliance documentationcontrol testinggap analysisremediation trackinginformation security principlescybersecurity best practices
Soft Skills
communicationcollaborationorganizational skills
Certifications
Bachelor’s degreeCMMCType 2 SOC 2HIPAAPCI-DSSGDPR