GRC Analyst

Posted 12 Days Ago
Hiring Remotely in United States
Remote
3-5 Years Experience
Information Technology • Consulting
The Role
Network Coverage is seeking a Compliance Analyst with 2-4 years of experience in Information Security. The role involves working remotely with occasional client-facing meetings, focusing on Security Auditing, Readiness Assessment, Policy Writing, and Risk Assessment. Must communicate effectively with clients and team members and meet deadlines in a fast-paced environment.
Summary Generated by Built In

Job Description

Network Coverage is seeking talented and experienced Analysts to join our growing GRC Team. Candidates will primarily work from home, however occasional dispatch may be required for client-facing meetings, presentations, and consultations and/or training.

Applicants must have 2-4 years of experience in an Information Security role for this position. It is essential to demonstrate a strong working knowledge of Information Security and regulatory standards, especially focusing on CMMC (800-171 rev2) and the CMMC ecosystem. Effective communication with clients and team members, as well as the efficient resolution of time-sensitive issues, are mandatory skills.

A GRC Analyst working within the Network Coverage Governance, Risk and Compliance Team will be expected to work within deadlines and will adjust to ever-changing client needs and scenarios within a fast-paced environment.

GRC Analyst (Tier 1/2)

Level: Mid-Level

Reports To: GRC Team Lead

Basic Scope and Function:

As a GRC Analyst at Network Coverage, you will be part of the GRC Team, and your expertise will be an integral part of our all-encompassing V-CISO deliverable with a strong focus on CMMC implementation (NIST 800-171 rev2). You be working closely with team members and clients in various locations across the US and overseas and will fulfill the role of subject matter expert, advising upon the on the most effective approach to security, regulatory compliance and continuously developing and helping to implement Network Coverage’s targeted approach. As a GRC Analyst, you will be responsible for Security Auditing, Readiness Assessment, Policy Writing, Risk Assessment, client onboarding and coordination of implementation treatment resulting from GAP assessment. As a technical solution provider, you will function as the subject matter expert and deliver a highly comprehensive Plan of Action and Milestones and may be expected to report on a scheduled cadence in a client facing capacity, under the guidance of the GRC Team Leadership.

Due to the nature of the work, flexible work hours may also be required if requested for client onsite or after-hours support of accounts in differing regions.

Primary/Essential Duties and Key Responsibilities:

  • Interface with client points of contact as required for onboarding/post sales activity and/or recurring check ins and inquiries.
  • Continuously monitor and triage requests flowing through an inbound ticket queue.
  • Participate in the design and execution of risk assessments and security audits.
  • Participate in the management of employee awareness campaigns for both staff and clients, including phishing simulations and awareness training.
  • Perform CMMC Readiness assessment against 110 controls, delivering a comprehensive SSP and POAM with assisted attestation and SPRS reporting.
  • Assist clients with their assessments with C3PAOs and 3PAOs.
  • Create and Maintain network and data flow diagrams
  • Maintain up-to-date detailed knowledge of the IT security industry including awareness of new or revised security solutions, regulatory requirements, improved security processes, and the development of new attacks and threat vectors.
  • Document best practices and user guides using available collaboration tools and workspaces.
  • Develop and maintain both internal and client-facing documentation, policy libraries and delivery metrics for end-to-end client security and compliance.
  • Provide timely, detailed, and complete reports on vulnerabilities, security events and incidents in a client facing setting.
  • Triage internal security and permissions requests from staff, including but not limited to systems access and employee terminations.
  • Oversee upkeep of internal SOP, ensuring adjustments to protocol are made as tools and methods evolve.
  • Perform QA workflow as necessary to improve upon consistency of product and client experience.
  • Coordinate resources and/or route audit requests appropriately for high volume or regulated client points of contact.
  • Ability to manage a changing and evolving workload and function as decision-maker where needed.
  • Provide after-business hours support if requested and as applicable to geographically distributed client base.
  • Perform other duties and tasks as assigned.

Knowledge, Skills and Abilities (KSAs) Required:

  • Strong problem-solving, analytical skills and the ability to work autonomous.
  • Excellent customer service skills, including understanding how to de-escalate, how to soothe and how to deliver the most efficient solution.
  • Strong communication skills, both verbal and written.
  • Familiarity with regulatory frameworks such as NIST/CMMC, ISO 27001, HIPAA/Hitech, GDPR are a big plus.
  • Strong organizational, operational, and inter-personal skills
  • Strong familiarity with Windows desktop and server operating systems.
  • Strong familiarity with Microsoft Office 365 and Azure Active Directory support and implementation.
  • Strong understanding of networking concepts, familiarity with routers, firewalls, access points, IDS/IPS and VPN.
  • Familiarity with Email threat protection tools and concepts.
  • Familiarity with RMM and asset management tools are a big plus.
  • Understanding of tools and processes used in security monitoring and incident response
  • Experience with Endpoint Detection & Response (EDR) tools
  • Ability to understand vulnerabilities at a technical level and capable of recommending and effectively communicating mitigation strategy
  • Ability to communicate and write in English professionally
  • Reliable personal transportation for use in traveling to clients' offices is essential.

Minimum Experience and Education Required:

  • 2-4 years of experience working in an Information Security capacity.
  • No College Education Required.
  • CompTIA Security+ or similar.
  • High School Diploma or Accredited GED.
  • CMMC RP/RPA/CCP will be considered preferentially.

Supervisory/Managerial Experience and Responsibility:

  • No supervisory or managerial experience required.
  • No supervisory or managerial duties in this role.

Work Environment:

Work is primarily performed in a remote capacity and will require the use of video conferencing software along with a company issued webcam. Work involves operation of computer equipment for 8 hours or more daily.

Network Coverage remote team members must ensure the availability of a stable, reliable, and secure internet connection with adequate bandwidth to support video calls as needed throughout the course of their shift and while performing on-call duties.

Physical Requirements:

  • Sitting
  • Standing
  • Moving of self
  • Moving of equipment
  • Communicating
  • Visual acuity for driving and computer work
  • Kneeling
  • Crawling
  • Reaching
  • Stooping
  • Lifting
  • Pulling

Job Type: Full-time

The Company
HQ: Danvers, Massachusetts
114 Employees
On-site Workplace

What We Do

Network Coverage is a rapidly growing national provider of premium White Glove service offers for Mid-Sized and Enterprise Technology needs. We focus on delivering value to our partners every step of the way, through industry leading response times, world class solutions and the very best talent that our industry has to offer.

Jobs at Similar Companies

Silverfort Logo Silverfort

Head of Global Channel & Field Marketing

Information Technology • Sales • Security • Cybersecurity • Automation
Remote
United States
357 Employees

MassMutual India Logo MassMutual India

Intern - IT Support

Big Data • Fintech • Information Technology • Insurance • Financial Services
Hyderabad, Telangana, IND

Energy CX Logo Energy CX

Talent Acquisition Specialist

Greentech • Professional Services • Business Intelligence • Consulting • Energy • Financial Services • Utilities
Easy Apply
Chicago, IL, USA
55 Employees
65K Annually

Similar Companies Hiring

Energy CX Thumbnail
Utilities • Professional Services • Greentech • Financial Services • Energy • Consulting • Business Intelligence
Chicago, IL
55 Employees
MassMutual India Thumbnail
Insurance • Information Technology • Fintech • Financial Services • Big Data
Hyderabad, Telangana
Silverfort Thumbnail
Security • Sales • Information Technology • Cybersecurity • Automation
GB
357 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account