GRC Analyst
Austin, TX - USA
Job Summary
We are seeking a Technical Customer Support Representative (REMOTE) for a full-time and direct hire role for one of our amazing partners. This role is remote but you MUST be living in the United States and be a US Citizen or Green Card Holder. This role does NOT offer sponsorship its NOT a consulting role and we do NOT work with 3rd parties!
Overview
We are seeking a GRC Analyst to help build and expand a formal Governance Risk and Compliance program within a growing technology organization that serves government and other highly regulated customers. You will play a key part in supporting SOC 2 and GovRAMP initiatives maintaining the controls and evidence required for audits managing compliance-related documentation and helping communicate the organizations security posture to customers and government agencies. This is an opportunity to build and improve processes rather than simply maintain an established program. You will work across engineering compliance sales and product teams to turn security and regulatory requirements into practical well-documented processes.
This is an opportunity to join a growing organization at an important stage of its compliance journey. You will have the opportunity to help establish scalable GRC processes strengthen audit readiness support government contracting opportunities and work directly with technical and business leaders to build a mature security and compliance function.
Responsibilities:
- Governance Risk & Compliance
- Support the ongoing development and administration of the organizations GRC program. Help maintain compliance with frameworks and requirements including NIST SP 800-53 CJIS Security Policy SOC 2 and GovRAMP.
- Maintain the enterprise risk register and assist with periodic risk assessments.
- Monitor control performance and identify areas requiring remediation or improvement.
- Develop update organize and maintain security and compliance policies and procedures.
- Manage policy version control approvals annual reviews and employee attestations.
- Audit & Authorization Support
- Provide hands-on support for SOC 2 and GovRAMP audit and authorization activities.
- Assist with gap assessments and track remediation efforts through completion.
- Collect organize validate and maintain audit evidence.
- Work closely with engineering and other technical teams to identify and complete compliance-related requirements.
- Help ensure controls are consistently documented and supported by appropriate evidence.
- Customer Security & Compliance
- Act as a primary point of contact for customer security questionnaires vendor assessments and compliance reviews.
- Develop and maintain a centralized library of approved responses and supporting documentation.
- Improve the efficiency and consistency of questionnaire responses while reducing duplicate work.
- Maintain customer-facing materials that accurately describe the organizations security privacy and compliance posture.
- Coordinate responses to recurring customer and third-party risk assessments.
- Contract Compliance
- Monitor contractual requirements related to security privacy compliance reporting and service obligations.
- Maintain a centralized calendar of recurring contractual deliverables and deadlines.
- Coordinate items such as monthly and quarterly reports SLA documentation insurance certificates certifications and other required compliance materials.
- Ensure commitments made to government and commercial customers are tracked through completion.
- RFPs & Government Proposals
- Partner with the Growth team on government and public-sector RFPs solicitations and proposal opportunities.
- Develop and edit security technical compliance and management sections of proposals.
- Support proposal amendments customer questions formal responses and post-award activities.
- Create reusable proposal content and maintain a library of approved security and compliance language.
- Translate technical security capabilities into clear compelling information that can be evaluated by procurement and government stakeholders.
Requirements:
- 35 years of experience in GRC security compliance information security internal audit or a related discipline.
- Experience working within a federal regulated or cloud-based technology environment.
- Hands-on participation in at least one complete audit or authorization cycle involving SOC 2 FedRAMP StateRAMP/GovRAMP ISO 27001 CMMC or a comparable framework.
- Working knowledge of NIST SP 800-53 SOC 2 and GovRAMP requirements.
- Technical understanding of cloud and/or on-premises environments including areas such as
- Identity and access management Encryption Security logging and monitoring Network architecture Software development lifecycle and change management.
- Practical experience using AI tools for research drafting documentation analysis or evidence-management activities.
- Strong cross-functional communication skills to move comfortably between technical and business environments. You will take complex engineering concepts and turn them into clear documentation for auditors customers and procurement teams and then translate compliance requirements into actionable tasks for technical teams.
- An evidence-first mindset to understand that saying a control is in place isnt enough. You know how to identify collect organize and validate the evidence necessary to demonstrate that a control is operating effectively.
- Builder mentality where you are comfortable creating structure where processes are still evolving. You dont need an established playbook to get started and can develop practical workflows that scale as the organization grows.
- Organization & execution skills to manage multiple priorities stakeholders and deadlines simultaneously particularly when working toward externally driven audit certification or proposal deadlines.
- Strategic thinking with hands-on execution skills. You should be comfortable balancing immediate compliance needs with longer-term improvements to systems documentation and processes.
- Adaptability to thrive in an environment where priorities can change quickly and are comfortable taking ownership solving problems independently and creating new approaches when necessary.
- Strong written and verbal communication skills.
- Demonstrated ability to coordinate several concurrent initiatives while meeting firm external deadlines.
- Ability to work independently and establish processes without extensive direction.
Preferred Experience
- Experience with the CJIS Security Policy FBI NGI or criminal justice information systems.
- Experience supporting government or public-sector RFPs and proposal development.
- Familiarity with compliance automation platforms such as Vanta Drata or similar tools.
- Experience working directly with government agencies or organizations subject to federal security requirements.
All qualified applicants will receive consideration for employment without regard to race color national origin age ancestry religion sex sexual orientation gender identity gender expression marital status disability medical condition genetic information pregnancy or military or veteran status.