Cybersecurity GRC Analyst - ONLY W2

Hybrid in Reston, VA, US • Posted 2 hours ago • Updated 2 hours ago
Contract W2
6 Months
Remote
Depends on Experience
Fitment

Dice Job Match Score™

🫥 Flibbertigibetting...

Job Details

Skills

  • Cybersecurity
  • GRC
  • Governance
  • Risk
  • Compliance.
  • NIST
  • IDS
  • PCI DSS
  • CRISC
  • CISSP

Summary

-------------------ONLY W2--------------------ONLY W2-------------------ONLY W2-------------

Title: Cybersecurity GRC Analyst

Location: Reston, VA (Predominantly Remote)

Duration: 6 Months Contract

Job Description:

Terms of Employment

  • Contract, 6 Months
  • Location: Remote (Reston, VA; regular remote flexibility with occasional monthly/quarterly on-site visits and mandatory on-site final interview)
  • Candidate must reside in DMV area.

Overview

  • Our client is seeking a Cyber Security & Risk Management Analyst to ensure the organization's data remains protected from inappropriate access, disclosure and/or damage. The Cyber Security & Risk Management Analyst will advocate for and execute the processes and practices of the Cybersecurity team while supporting business and customer needs.

Responsibilities include:

  • Support the Cybersecurity Risk Management program providing support and guidance to a team of technically diverse cybersecurity specialists personnel while further supporting collaboration across the various risk related teams in the organization.
  • Support continuous monitoring efforts by partnering with TPRM, Procurement, Legal, and key business stakeholders.
  • Support the assessment of cybersecurity controls, identify gaps, assist in development of mitigation strategies, and manage them to closure.
  • Collaborate with internal and external teams to assess, monitor, and manage risks.
  • Work with business teams to conduct thorough assessments to identify potential risks to the organization. This includes evaluating their security practices, data handling procedures, and regulatory compliance (e.g., HIPAA, PCI, GDPR, etc.)
  • Represent Cybersecurity from a Risk Management perspective and execute security risk management leadership through the design and implementation of cybersecurity controls to maintain the confidentiality, integrity and availability of information systems and data.
  • Prepare detailed risk assessment reports, clearly articulating findings and recommendations and maintain a comprehensive repository of all risk assessments and associated documentation.
  • Conduct risk analyses to ensure consistency in the detailed risk assessment lifecycle inclusive of identification, socialization, mitigation, and closure.
  • Design, implement, and integrate security solutions to address enterprise risks and exposures.
  • Develop and maintain Information Security Risk Metrics supported by KPIs and KRIs to support the analytics team.
  • Test and report on new technologies to address security concerns and work closely with the vulnerability management team on the identified risks.
  • Support compliance/risk management efforts in support of NIST, FedRAMP, and HIPAA to include but not limited to: external assessment readiness/support, self-assessments, risk assessments, Plans-Of-Action-and-Milestone (POA&M) management, continuous monitoring.

Required Skills & Experience

  • Bachelor s degree in Cybersecurity, Computer Science, Information Technology, or similar and 3+ years of experience in cybersecurity and risk management to include in the healthcare and/or health insurance industry.
  • Significant understanding of NIST Risk Management Framework (RMF), NIST Cybersecurity Framework (CSF), and NIST 800-53.
  • Knowledgeable of Information Security Risk Management methodologies including FAIR quantitative model.
  • Knowledgeable of PCI DSS compliance.
  • Highly skilled performing risk assessments.
  • Experience using Governance, Risk, and Compliance (eGRC) tools.
  • Highly skilled in technical writing and documentation with proven ability to translate technical requirements to the business.
  • Excellent presentation and verbal communication skills.
  • Ability to understand, develop, and socialize security policies, standards, and procedures.
  • Ability to effectively lead/complete tasks with a minimal level of supervision.

Preferred Skills & Experience

  • Possess CRISC, CISSP, or similar certification(s).
  • Experience using an eGRC tool such as Hyperproof, Archer, or ServiceNow.
  • Knowledgeable of SOC 2 and/or HITRUST compliance.
  • Proficiency with security controls for cloud environments (Azure and AWS) including FedRAMP requirements.
  • Familiarity with security tools such as wireless and network scanning applications, vulnerability assessment applications and concepts, IDS/IPS, Data Loss Prevention, and other appropriate security related tools and capabilities.
  • Experience working in a large, complex, multi-platform environment.
  • Familiarity with HIPAA Security Rule and compliance requirements.

Sincerely,

Preetam Raj

Team Lead, Talent Acquisition

nTech Workforce Inc.

D:

E:

Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 10300723
  • Position Id: 23547MPR
  • Posted 2 hours ago
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Remote or Silver Spring, Maryland

Today

Full-time

USD 3,000.00 per month

Washington, District of Columbia

Today

Full-time

USD 100,000.00 - 145,000.00 per year

McLean, Virginia

Today

Full-time

USD 113,000.00 - 188,000.00 per year

Remote or Haymarket, Virginia

Today

Full-time

USD 149,282.00 - 207,459.00 per year

Search all similar jobs