Job Description A leading organization is seeking a Governance, Risk & Compliance (GRC) Analyst for a hybrid role based in Seattle. In this position, you'll take ownership of developing, implementing, and monitoring GRC policies and procedures across the organization, ensuring alignment with industry standards and regulatory frameworks such as SOX, PCI-DSS, NIST, ISO 27001, and TSA. This is a hands-on role that requires conducting thorough risk assessments, identifying and documenting mitigation strategies, and managing governance workflows. You'll be involved in supporting audit teams, overseeing compliance documentation, and tracking remediation of issues identified through audits or risk assessments. Additional responsibilities include developing and delivering risk and compliance awareness training for staff, collaborating with cross-functional teams to facilitate business continuity planning and policy management, assisting with vendor risk management and due diligence, and preparing reports and dashboards on risk status for leadership.
Required Skills & Experience - Strong knowledge of GRC concepts, methodologies, and frameworks (e.g., COBIT, NIST CSF, ISO 27001)
- Experience with risk assessments, control testing, and audit support
- Familiarity with GRC tools or governance/security platforms
- Excellent communication and analytical skills
- Bachelor's degree in Information Security, Business, or related field, or equivalent experience
Desired Skills & Experience - Security or GRC certifications (CISA, CISM, CRISC, CISSP, or comparable)
- Experience responding to government or regulatory oversight (TSA, FAA, etc.)
The Offer Bonus OR Commission eligible
You will receive the following benefits
Medical Insurance
Dental Benefits
Vision Benefits
Paid Time Off (PTO)
401(k) {including match - if applicable}
Applicants must be currently authorized to work in the US on a full-time basis now and in the future.