Experienced IT/Security GRC Analyst Job at Hotman Group, LLC, Remote

Vy9WYWZsUitzWWtwSEQ3dU5QenI4QTdYUGc9PQ==
  • Hotman Group, LLC
  • Remote

Job Description

Hotman Group has an opportunity for a full-time, remote,  experienced IT/ Security GRC Analyst . This position  requires previous 3-5 years experience in a similar role or function, and starts as contract-to-hire. Top-tier workers will be converted to permanent within 6 months.

The IT/ Security Governance, Risk, and Compliance (GRC) Analyst will be supporting cybersecurity, compliance, risk, and GRC program initiatives for our clients. This person will work closely with the team and our senior partners to provide client and backend support for security/ IT controls, assessments, analysis, risk, audits, GRC tools, policies, processes, industry frameworks, privacy, just to name a few.

Responsibilities

  • Assess, evaluate, and make recommendations regarding the adequacy of the security/ IT controls for the client's environment and business objectives
  • Develop policies, procedures, and processes based on audit findings and/ or compliance framework requirements
  • Crosswalk controls across multiple security compliance frameworks and regulation to foster adoption and identify gaps
  • Advise and develop security standards, guidelines, and controls based on best practices and compliance frameworks
  • Translate security analyses, audit results, and compliance guidance into plain English that is understandable and actionable
  • Analyze and suggest improvements for security/ IT controls in both design and operation effectiveness
  • Develop risk registers, ideally aligned to controls, and execute basic risk assessment and management practices
  • Perform assessments (risk and/or compliance) to develop a baseline for creating or expanding a security program
  • Develop plans and tracking for non-compliance with applicable controls, and monitoring remediation progress against agreed upon timelines
  • Work with various client GRC tools
  • Perform data analysis and manipulation as needed to analyze a problem and create a solution for our clients
  • Evaluate new and existing technologies for compliance with information governance controls (e.g., access, authentication, encryption, logging, retention)
  • Perform other duties for Hotman Group or as assigned to best serve our clients in their security, risk, compliance, or GRC programs

Knowledge, Skills, and Abilities

  • Ability to manage and execute numerous parallel activities in a fast-paced, dynamic team environment
  • Strong organizational skills with ability to manage multiple tasks and projects, demonstrated prioritization and decision-making skills to not miss deadlines or drop assignments
  • Strong written and verbal skills, including a demonstrated ability to translate complex or technical information into concepts that are easily understood and actionable
  • Familiarity and knowledge of fundamental security/ IT concepts (e.g., retention, data classification, change management, access control, asset management, third party risk)
  • Demonstrated critical thinking skills, but also able to follow instruction to meet the team's overall objective
  • Technical aptitude to be able to learn new technologies quickly with little instruction
  • Strong attention to detail and high commitment to quality
  • Good attitude and courtesy to work with a smaller, fast-paced team
  • Efficient worker looking for ways to gain efficiencies and maximize time spent
  • Able to operate with a high degree of independence executing with excellent follow-through for assigned tasks, but also knowing when to stop, ask questions, and seek input from the team or management
  • Passionate about cybersecurity, risk, compliance, and GRC to make companies more secure and healthy in protecting their data
  • Not afraid to roll your sleeves up, learn what's needed to learn, get done what needs to get done
  • Reliability, discretion and confidentiality

Requirements

  • Bachelor or Graduate degree in a cybersecurity, information systems, or related field
  • 3-5 years experience in a cybersecurity, audit, risk, compliance, or GRC role required
  • Working knowledge of common security and privacy frameworks and regulation (e.g. ISO, NIST, CIS, SOC 2, HIPAA, CCPA, PCI DSS)
  • Knowledge of risk management practices, and risk-based thinking to drive prioritization
  • Experience responding to, analyzing, and communicating security and information technology-related practices and controls
  • Preference given to those with security or risk management certifications, or willingness to pursue
  • Technical skills : Excel, Word, PowerPoint, GRC tools, quick learner of new technologies in general
  • Understand audit processes and requirements
  • Candidate must be located in the USA, and have permanent authorization to work in the USA for any employer
  • Clear background check
  • Strong Internet connection and secure working area

About Us

Hotman Group is a rapidly growing boutique firm with deep commitment to quality and execution for our clients. We help business leaders with integrity gain the trust of their customers by providing comprehensive cybersecurity & GRC services.

We offer cybersecurity strategy and program development; fully managed programs including execution, implementation, maturation, and remediation; and everything in between with one-time projects like policies, audits, questionnaires, risk assessments, incident response plans, testing, third party vendors, and other cybersecurity or compliance challenges. We support all the top security compliance frameworks, e.g. SOC 2, NIST CSF, ISO 27001, HITRUST to name just a few.

Our Corporate Culture

We pride ourselves on leaving the Corporate culture behind and creating a collaborative environment where everyone can thrive and grow, be excited to fully show up to work every day, and have a lot of fun in the process of solving complex problems and creating amazing results for our clients!

Perks

  • Fully remote collaborative team
  • Opportunities to grow as we serve our clients
  • Break the Corporate mold
  • Work hard, play hard
  • Passionate about what we do

Benefits *

  • Paid holidays and time off
  • 401K with employer match
  • Medical insurance
  • Short- and long-term disability insurance
  • Life insurance
  • Paid training and development

* Benefits are only available to full-time permanent employees, not contract or contract-to-hire.

No calls or agencies please.

Job Tags

Remote job, Holiday work, Permanent employment, Full time, Contract work, Temporary work,

Similar Jobs

Braun Intertec

Project Engineer- Solar Job at Braun Intertec

 ...with offices located in ten states. As a part of our exciting growth initiatives, we are...  ...comprehensive medical, vision, and dental plans, paid time off (as well as volunteer time off),...  .... If you need assistance completing your online application, please email hrhelp@... 

Aspen Medical

Emergency Medicine Physician Job at Aspen Medical

 ...Aspen Medical has an exciting opportunity for a motivated Emergency Medicine Physician to partner with us in providing medical services to UN sponsored Kenyan Peacekeepers and US Government staff at a field hospital in Port Au Prince, Haiti. This will be a deployed, rotational... 

SALT Dental Partners

Dental Receptionist Job at SALT Dental Partners

 ...At Dental Kidz Club, we provide Exceptional and Affordable dentistry to every child! We believe that every child is a special creation and deserves to be treated special no matter where they may be from. If you enjoy serving and you are looking for a mission to connect... 

MedQuest Associates LLC

Radiology Extender Job at MedQuest Associates LLC

 ...States. Through direct ownership and joint ventures, the company operates a mixed network of independent and hospital-affiliated radiology centers that perform diagnostic tests used to help identify , diagnose, and monitor a range of health conditions. In addition... 

TJX Companies, Inc.

Full Time Merchandise Associate (Clocktower Square) Job at TJX Companies, Inc.

 ...in short supply at our more than 1,000 TJ Maxx stores. They all have different products...  ...environment. Adheres to operational, merchandise, and loss prevention standards. Cross-trained...  ...and effectively with management and Associates Accepts recognition and...