Cybersecurity GRC Analyst / Consultant

Sacramento, CA, US • Posted 4 hours ago • Updated 4 hours ago
Contract Independent
Contract W2
Contract Corp To Corp
6 Months
50% Travel Required
On-site
Depends on Experience
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • Incident Response
  • GRC
  • NIST SP 800-53

Summary

Position: Cybersecurity GRC Analyst / Consultant

Duration: 6 months with extension Possible

Location: Sacramento, CA (Hybrid)

Can attend the Sacramento office for two consecutive days each month, generally the first Wednesday and Thursday.

 

Position Overview

The GRC & Incident Response Security Professional will support the client's information-security governance, risk, compliance, third-party risk, and incident-response functions. The role will work closely with the Information Security Office and provide risk advisory, compliance, incident management, and remediation support.

 

Key Responsibilities

  • Governance, Risk & Compliance
  • Develop, update, and maintain security policies, procedures, standards, and documentation.
  • Administer and support enterprise GRC platforms.
  • Perform security risk assessments and compliance reviews.
  • Provide risk advisory services aligned with:
  • CMS ARC-AMPE
  • NIST SP 800-53 Revision 5
  • IRS Publication 1075
  • Applicable laws, regulations, and internal security requirements.
  • Conduct third-party/vendor security due diligence.
  • Perform vendor risk assessments and contract/control reviews.
  • Support continuous monitoring and risk reporting.
  • Develop corrective-action plans and track remediation.
  • Incident Response
  • Develop and maintain incident-response plans and playbooks.
  • Support security investigations and incident-management activities.
  • Assist with evidence handling and documentation.
  • Coordinate incident communications and reporting.
  • Support post-incident reviews.
  • Serve as backup security incident manager.
  • Provide incident status and escalation reporting to the CISO when required.
  • Participate in after-hours/on-call incident-response activities when necessary.

 

Required Qualifications

  • Experience in information security, GRC, risk management, or incident response.
  • Strong knowledge of security policies, procedures, standards, and controls.
  • Experience with enterprise GRC platforms.
  • Experience performing security risk assessments and third-party risk assessments.
  • Knowledge of NIST SP 800-53 and security-control frameworks.
  • Experience developing incident-response plans and playbooks.
  • Experience supporting investigations, evidence handling, and post-incident activities.
  • Strong documentation and communication skills.
  • Experience in regulated public-sector, healthcare, health-exchange, or similar environments is preferred.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 10365731
  • Position Id: 3224-14481-1787861031
  • Posted 4 hours ago
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Remote

Today

Contract

$55.00 - $80.00

Remote

Today

Easy Apply

Contract

$51.35

San Francisco, California

14d ago

Full-time

USD 95,000.00 - 150,000.00 per year

San Ramon, California

Today

Full-time

USD 160,489.00 - 240,734.00 per year

Search all similar jobs