Apply

Ready to go for it?

AI Apply speeds things up—apply directly if you prefer.

FREE ACCESS
5,000–10,000 jobs/day
JobTailor Logo

See all jobs on JobTailor

Search thousands of fresh jobs every day.

Discover
  • Fresh listings
  • Fast filters
  • No subscription required
Create a free account and start exploring right away.
Verterim, Inc.

Junior GRC Analyst, Student Associate

Verterim, Inc.

Junior GRC Analyst supporting Governance, Risk, and Compliance client assignments under senior managers at a managed GRC program. Focused on policy management, risk coordination, and evidence collection.

Posted 7/20/2026internshipNorth Carolina • 🇺🇸 United StatesEntry LevelWebsite

Core Competencies

Role fit
Core Competencies

Use this summary to align your resume positioning with the role.

Demonstrates expertise in Information Security and Cybersecurity principles, with a strong focus on ISO 27001, NIST, and SOC 2 frameworks. Proficient in documentation, vendor communication, and GRC platform management to ensure compliance and effective policy implementation.

Highest-signal resume keywords
ISO 27001 Policy MappingNIST CSF/800-53 FamiliaritySOC 2 Compliance KnowledgeGRC Platform ManagementMeticulous Documentation

ATS Keywords

Tailor your resume
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills
Control MappingPolicy FormattingEvidence AnalysisDocumentation ValidationData Import Management
Soft Skills
Clear WritingClient CommunicationProbing Follow-UpIndependent WorkCollaboration
Tools & Technologies
JiraServiceNowVantaDrataArcher
Industry Keywords
Information SecurityCybersecurityGRCSOPsTicketing

Tech Stack

Tools & technologies
Cyber SecurityServiceNow

About the role

Key responsibilities & impact
  • Support multiple client assignments under the direction of senior managers and client stakeholders.
  • Tailor, format, and maintain client policies using established templates (e.g., ISO/NIST).
  • Drive annual review cycles: reminders, tracking, and sign‑off capture.
  • Perform initial control mapping (e.g., policy → ISO 27001, NIST CSF/800‑53, CMMC) for senior review.
  • Run and manage imports of GRC core data for example Employee / contactor tables, Asset tables, Exception tables.
  • Coordinate vendor outreach, send questionnaires (e.g., SIG Lite, CAIQ), and follow up to closure.
  • Execute monthly evidence hunts aligned to frameworks (ISO 27001, SOC 2).
  • Produce weekly SLA reports (e.g., criticals > 14 days), open/route tickets, and track resolution.
  • Prepare clean user lists for access reviews; highlight anomalies and terminations.
  • Collaborate on agent design/tuning for: email drafting, evidence triage, tone/sentiment analysis, and process orchestration.

Requirements

What you’ll need
  • Current enrollment in a college‑level program (Information Security, Cybersecurity, MIS, or related).
  • Familiarity with core security concepts and controls.
  • Working knowledge of ISO 27001, NIST (CSF/800‑53), SOC 2; ability to map policies/controls.
  • Meticulous documentation, artifact validation, and checklist discipline.
  • Probing follow‑up questions that clarify vendor/client responses and strengthen outcomes.
  • Clear, concise writing; professional client/vendor email etiquette.
  • Comfort with SOPs, ticketing (Jira/ServiceNow), spreadsheets, and GRC platforms (e.g., Vanta, Drata, Archer, ServiceNow).
  • Interest in leveraging AI for automation, evidence analysis, and workflow orchestration.
  • Ability to work under direction from senior managers and clients; deliver reliable outcomes independently.

Benefits

Comp & perks
  • Paid, outcome‑based engagements with flexible scheduling.
  • Resume‑building experience across real‑world GRC operations.
  • Client exposure and professional references; potential direct‑hire opportunities with clients.
  • Hands‑on participation in AI‑enabled GRC processes with human‑in‑the‑loop mentorship.
  • Structured coaching from senior GRC leaders; clear playbooks and quality reviews.