Role Overview
The Security
Risk, GRC & Compliance Analyst supports the day-to-day execution of the
organization's cybersecurity risk, governance and compliance program.
This role is
responsible for maintaining accurate risk and compliance information,
coordinating audit readiness, managing evidence, supporting security
assessments and tracking remediation.
The ideal
candidate is highly organized, detail-oriented and able to independently manage
recurring GRC activities while appropriately escalating material risks and
issues.
Key
Responsibilities
- Maintain the cybersecurity risk
register and track remediation activities.
- Support cybersecurity risk
assessments and document findings.
- Support SOC 2 and PCI readiness
activities, where applicable.
- Maintain the security control
framework and documentation.
- Coordinate control testing and
evidence collection.
- Support external audits and
security assessments.
- Track audit findings, remediation
plans and due dates.
- Manage customer security
questionnaires and security due diligence requests.
- Support third-party cybersecurity
risk assessments.
- Maintain security policies,
standards and related documentation.
- Prepare cybersecurity metrics,
dashboards and management reporting.
- Maintain audit and compliance
evidence in a centralized manner.
- Identify opportunities to automate
evidence collection, questionnaires, reporting and recurring GRC
activities.
- Escalate material security,
compliance or control issues to Security leadership.
- Partner with Technology, Security
and business teams to obtain required information and close identified
gaps.
Requirements
- 4–7 years of experience in
cybersecurity GRC, information security, risk, compliance or a related
discipline.
- Experience with SOC 2,
cybersecurity controls and audit readiness.
- Familiarity with PCI requirements
preferred.
- Experience managing risk
registers, evidence, control testing and remediation tracking.
- Strong documentation and
organizational skills.
- Ability to manage multiple
workstreams and deadlines independently.
- Strong written and verbal
communication skills.
- Financial services, fintech or
regulated-industry experience preferred.
- Familiarity with GRC platforms and
automation tools preferred.
- Remote- US Shift
Skills Required
- 5-8 years experience in Risk, Compliance, Operations, or Governance within FinTech, Banking, Payments, or BaaS
- Strong understanding of regulatory compliance, risk management, vendor risk, audit readiness, and access control frameworks
- Experience building and scaling risk or compliance programs across multiple business functions
- Knowledge of BSA/AML
- Knowledge of FinCEN
- Knowledge of Nacha
- Knowledge of PCI DSS
- Knowledge of SOC 2
- Knowledge of OCC
- Knowledge of FFIEC
- Knowledge of GLBA
- Experience with Power BI
- Experience with JIRA
- Experience with ServiceNow
- Experience with Salesforce
- Strong analytical, organizational, and stakeholder management skills
- Systems-thinking and process improvement mindset
- Ability to manage multiple priorities in a fast-paced environment
- Excellent communication and cross-functional collaboration skills
- Proactive, resourceful, and results-oriented approach
- Strong problem-solving and decision-making abilities
- High level of integrity, accountability, and professionalism
- Ability to build scalable governance frameworks and operational infrastructure
What We Do
IncubXperts TechnoConsulting is an IT company specializing in enterprise web and mobile application development, offering AI-native software engineering partnerships and product strategy advisory services.







