Overview
On Site
USD 115,000.00 - 155,000.00 per year
Contract - Independent
Skills
Brand
Engineering Design
SAP GRC
FOCUS
Clarity
Information Security
Workflow
Risk Assessment
Organized
Collaboration
Communication
Training
Reporting
Cloud Computing
Leadership
Oracle Linux
CISA
CISM
CISSP
Auditing
Payment Card Industry
Amazon Web Services
System On A Chip
PCI DSS
HIPAA
ISO/IEC 27001:2005
Technical Drafting
Computer Science
Management Information Systems
Writing
Documentation
Attention To Detail
Regulatory Compliance
Relationship Building
NATURAL
Privacy
Marketing
Job Details
Location: Scottsdale, AZ
Salary: $115,000.00 USD Annually - $155,000.00 USD Annually
Description:
We're building something brand new - a secure, scalable business division serving multiple customers under a single AWS tenant. While our engineers design the technical controls, we need someone to ensure that our policies, standards, and procedures (PSPs) align with industry best practices, compliance frameworks, and our unique operating environment.
As our Information Security Analyst (GRC Focus), you'll be the architect of our governance layer. You'll transform security requirements into actionable, auditable PSPs that set the foundation for how we operate. This role isn't just about documentation - it's about creating clarity, driving consistency, and ensuring our security program is always audit-ready.
Candidates MUST be able to commit to a Hybrid or Onsite Schedule in Scottsdale, AZ
This job will have the following responsibilities:
On a typical day, you might:
Qualifications & Requirements:
Skills that Make You Stand Out:
By providing your phone number, you consent to: (1) receive automated text messages and calls from the Judge Group, Inc. and its affiliates (collectively "Judge") to such phone number regarding job opportunities, your job application, and for other related purposes. Message & data rates apply and message frequency may vary. Consistent with Judge's Privacy Policy, information obtained from your consent will not be shared with third parties for marketing/promotional purposes. Reply STOP to opt out of receiving telephone calls and text messages from Judge and HELP for help.
Contact:
This job and many more are available through The Judge Group. Please apply with us today!
Salary: $115,000.00 USD Annually - $155,000.00 USD Annually
Description:
We're building something brand new - a secure, scalable business division serving multiple customers under a single AWS tenant. While our engineers design the technical controls, we need someone to ensure that our policies, standards, and procedures (PSPs) align with industry best practices, compliance frameworks, and our unique operating environment.
As our Information Security Analyst (GRC Focus), you'll be the architect of our governance layer. You'll transform security requirements into actionable, auditable PSPs that set the foundation for how we operate. This role isn't just about documentation - it's about creating clarity, driving consistency, and ensuring our security program is always audit-ready.
Candidates MUST be able to commit to a Hybrid or Onsite Schedule in Scottsdale, AZ
This job will have the following responsibilities:
- Policy Development & Documentation
- Draft, update, and maintain Information Security policies, standards, and procedures tailored to our AWS multi-tenant environment.
- Ensure alignment with compliance frameworks (SOC 2, PCI, HIPAA, ISO 27001).
- Partner with engineers and business stakeholders to ensure policies reflect practical, real-world workflows.
- Risk & Compliance Oversight
- Identify, document, and track security risks across our environment.
- Support risk assessments and provide recommendations for risk treatment plans.
- Assist in readiness for external audits by ensuring documentation and evidence are organized and up-to-date.
- Collaboration & Communication
- Work directly with leadership, engineers, and vendors to ensure policies are clear, actionable, and understood.
- Translate technical requirements into plain-language standards that can be followed by non-technical teams.
- Support training and awareness initiatives to drive adoption of policies.
- Continuous Governance
- Establish document versioning and review cycles to keep policies evergreen.
- Recommend improvements based on lessons learned, new regulations, and evolving business needs.
- Track key governance metrics and report progress to leadership.
On a typical day, you might:
- Write or revise a standard on IAM role reviews to align with least privilege practices.
- Meet with the cloud engineering team to document the procedural steps for AWS GuardDuty alert response.
- Draft a risk statement for leadership related to a newly identified compliance gap.
- Prepare evidence documentation for an upcoming SOC2 audit.
- Deliver a quick briefing to executives on how a policy change affects daily operations.
Qualifications & Requirements:
- We're looking for someone who can think like both a policymaker and a partner. You'll combine your understanding of compliance frameworks with the ability to translate technical practices into clear documentation.
- Certifications such CISA, CISM, CISSP, or AWS Certified Security - Specialty.
- Experience supporting external audits (SOC 2, PCI, HIPAA).
- Familiarity with AWS security services (IAM, GuardDuty, Config, Security Hub).
- Ability to communicate complex security concepts to both technical and business audiences.
- Strong knowledge of compliance frameworks (SOC 2, PCI, DSS, HIPAA, ISO 27001, or similar).
- Demonstrated experience drafting and maintaining security policies, standards, and procedures.
- 5-7 years of experience in IT or IS Governance, Risk, and Compliance.
- Bachelor's degree in Computer Science, Management Information Systems or equivalent experience
Skills that Make You Stand Out:
- Strong writing and documentation skills with attention to detail.
- Ability to "connect the dots" between compliance requirements and technical controls.
- Proven success in building relationships across technical and business teams.
- Natural curiosity and drive to improve processes and reduce risk.
By providing your phone number, you consent to: (1) receive automated text messages and calls from the Judge Group, Inc. and its affiliates (collectively "Judge") to such phone number regarding job opportunities, your job application, and for other related purposes. Message & data rates apply and message frequency may vary. Consistent with Judge's Privacy Policy, information obtained from your consent will not be shared with third parties for marketing/promotional purposes. Reply STOP to opt out of receiving telephone calls and text messages from Judge and HELP for help.
Contact:
This job and many more are available through The Judge Group. Please apply with us today!
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.