GRC Analyst / GRC Consultant
Location
Santa Clara, CA (Onsite)
Job Summary
We are seeking a skilled GRC (Governance, Risk, and Compliance) Consultant to support enterprise security, compliance, and risk management initiatives for a large-scale IT environment. The ideal candidate will have experience in security
governance, compliance frameworks, risk assessments, audit coordination, and policy management.
This role requires strong collaboration with security, infrastructure, engineering, and business teams to ensure compliance with organizational and regulatory standards.
Key Responsibilities
- Support Governance, Risk, and Compliance (GRC) initiatives across enterprise IT and security environments.
- Conduct risk assessments, gap analyses, and compliance reviews.
- Assist in developing, maintaining, and enforcing security policies, standards, and procedures.
- Coordinate internal and external audits and track remediation activities.
- Monitor compliance with regulatory and industry standards such as ISO 27001, SOC 2, NIST, HIPAA, PCI-DSS, or SOX.
- Work with cross-functional teams to identify and mitigate security and compliance risks.
- Maintain risk registers, audit documentation, and compliance evidence.
- Assist with third-party/vendor risk assessments and security reviews.
- Support incident response and compliance reporting activities when needed.
- Prepare reports, dashboards, and presentations for leadership and stakeholders.
Required Skills
- 5+ years of experience in Governance, Risk, and Compliance (GRC) or Information Security.
- Strong understanding of security and compliance frameworks:
- ISO 27001
- NIST
- SOC 2
- HIPAA
- PCI-DSS
- SOX
- Experience with risk assessments, audit support, and policy management.
- Familiarity with GRC tools and compliance tracking platforms.
- Strong analytical, documentation, and communication skills.
- Ability to work closely with technical and business stakeholders.