FREE ACCESS
5,000–10,000 jobs/day
See all jobs on JobTailor
Search thousands of fresh jobs every day.
Discover
- Fresh listings
- Fast filters
- No subscription required
Create a free account and start exploring right away.

Junior GRC Analyst, Student Associate
Verterim, Inc.Junior GRC Analyst supporting Governance, Risk, and Compliance client assignments under senior managers at a managed GRC program. Focused on policy management, risk coordination, and evidence collection.
Core Competencies
Role fitCore Competencies
Use this summary to align your resume positioning with the role.
Demonstrates expertise in Information Security and Cybersecurity principles, with a strong focus on ISO 27001, NIST, and SOC 2 frameworks. Proficient in documentation, vendor communication, and GRC platform management to ensure compliance and effective policy implementation.
Highest-signal resume keywords
ISO 27001 Policy MappingNIST CSF/800-53 FamiliaritySOC 2 Compliance KnowledgeGRC Platform ManagementMeticulous Documentation
ATS Keywords
Tailor your resumeApplicant Tracking System Keywords
Tip: use these terms in your resume and cover letter to boost ATS matches.
Hard Skills
Control MappingPolicy FormattingEvidence AnalysisDocumentation ValidationData Import Management
Soft Skills
Clear WritingClient CommunicationProbing Follow-UpIndependent WorkCollaboration
Tools & Technologies
JiraServiceNowVantaDrataArcher
Industry Keywords
Information SecurityCybersecurityGRCSOPsTicketing
Tech Stack
Tools & technologiesCyber SecurityServiceNow
About the role
Key responsibilities & impact- Support multiple client assignments under the direction of senior managers and client stakeholders.
- Tailor, format, and maintain client policies using established templates (e.g., ISO/NIST).
- Drive annual review cycles: reminders, tracking, and sign‑off capture.
- Perform initial control mapping (e.g., policy → ISO 27001, NIST CSF/800‑53, CMMC) for senior review.
- Run and manage imports of GRC core data for example Employee / contactor tables, Asset tables, Exception tables.
- Coordinate vendor outreach, send questionnaires (e.g., SIG Lite, CAIQ), and follow up to closure.
- Execute monthly evidence hunts aligned to frameworks (ISO 27001, SOC 2).
- Produce weekly SLA reports (e.g., criticals > 14 days), open/route tickets, and track resolution.
- Prepare clean user lists for access reviews; highlight anomalies and terminations.
- Collaborate on agent design/tuning for: email drafting, evidence triage, tone/sentiment analysis, and process orchestration.
Requirements
What you’ll need- Current enrollment in a college‑level program (Information Security, Cybersecurity, MIS, or related).
- Familiarity with core security concepts and controls.
- Working knowledge of ISO 27001, NIST (CSF/800‑53), SOC 2; ability to map policies/controls.
- Meticulous documentation, artifact validation, and checklist discipline.
- Probing follow‑up questions that clarify vendor/client responses and strengthen outcomes.
- Clear, concise writing; professional client/vendor email etiquette.
- Comfort with SOPs, ticketing (Jira/ServiceNow), spreadsheets, and GRC platforms (e.g., Vanta, Drata, Archer, ServiceNow).
- Interest in leveraging AI for automation, evidence analysis, and workflow orchestration.
- Ability to work under direction from senior managers and clients; deliver reliable outcomes independently.
Benefits
Comp & perks- Paid, outcome‑based engagements with flexible scheduling.
- Resume‑building experience across real‑world GRC operations.
- Client exposure and professional references; potential direct‑hire opportunities with clients.
- Hands‑on participation in AI‑enabled GRC processes with human‑in‑the‑loop mentorship.
- Structured coaching from senior GRC leaders; clear playbooks and quality reviews.