To enhance the security framework of a growing organization, the full-time remote GRC Analyst will design, implement, and manage control and risk workflows, perform third-party risk assessments, and ensure compliance with industry standards and regulations. Key responsibilities Leads the design and governance of control frameworks and risk workflows within the GRC platform, aligning with organizational objectives and compliance requirements Monitors and updates risk registers, ensuring accurate tracking, scoring, and prioritization of risks while driving automation workflows for control testing and evidence collection Conducts risk assessments and collaborates with internal teams and external auditors to facilitate audits and assessments, maintaining compliance with regulatory requirements Required qualifications Bachelor's degree in information security, cybersecurity, computer science, information technology, business administration, or a closely related field, or equivalent experience Minimum of 5 years of relevant experience in governance, risk, and compliance functions within IT or information security Certifications such as Certified Information Systems Auditor (CISA), Certified Risk and Information Systems Control (CRISC), or Certified Information Security Manager (CISM) preferred Prior experience implementing, managing, or auditing security policies and procedures, along with familiarity with compliance frameworks like HIPAA and NIST Experience conducting risk assessments and supporting risk management activities