GRC Analyst (0-1 years of experience) to join our growing Information Security and Compliance team. In this role, you will assist in ensuring that our organization adheres to internal policies, industry standards, and regulatory requirements.
This is an excellent entry-level opportunity for a recent graduate or someone early in their IT/Security career to gain hands-on experience in cybersecurity governance, risk management, and compliance frameworks. You will work closely with senior analysts and cross-functional teams to identify risks and maintain a robust security posture.
-
Assist in documenting and maintaining information security policies, procedures, and standards.
-
Help prepare for internal and external compliance audits (e.g., SOC 2, ISO 27001, GDPR, HIPAA, or PCI-DSS).
-
Gather, organize, and track evidence required for compliance assessments.
-
Support the team in conducting routine information security risk assessments.
-
Assist in identifying, documenting, and tracking security risks in the company’s Risk Register.
-
Follow up with internal teams on the status of risk remediation plans.
-
Review vendor security questionnaires and documentation to assess third-party risk.
-
Maintain the repository of approved vendors and track renewal/re-assessment dates.
-
Assist in administering the company’s security awareness training programs and phishing simulations.
-
Help compile data and metrics for weekly or monthly GRC dashboards and reports.