job summary:
# Information Security GRC Analyst
**Location:** Mount Laurel, NJ (Hybrid - 2 days onsite, transitioning to 4 days onsite)
**Employment Type:** 12-Month Contract
**Extension Possible:** Yes
**Conversion Possible:** No
**Start Date:** November 1, 2026
**Schedule:** Monday-Friday, core business hours
### Position Overview
We are seeking an experienced **Information Security GRC Analyst** to support a large financial services organization's application and infrastructure currency program.
This role focuses on ensuring applications and their supporting infrastructure are updated from outdated or end-of-support technologies while maintaining compliance with established information security standards.
The analyst will work closely with application security teams, business owners, and technology stakeholders to conduct risk assessments, identify control gaps, track exceptions, and provide visibility into technology risks and remediation progress.
The ideal candidate will have a strong background in information security, IT governance, technology risk management, and experience using Archer and ServiceNow.
### Key Responsibilities
- Support application and infrastructure currency initiatives, including the remediation of outdated and end-of-support technologies.
- Review, validate, and update Technology Asset Risk Assessments (TARAs) and Control Gap Assessments (CGAs).
- Partner with Business Information Security Officers (BISOs), Business Asset Owners, Technology Asset Owners, and Information Security teams to complete required assessments.
- Identify, track, and report security control exceptions, technology vulnerabilities, and compliance gaps.
- Ensure remediation activities remain aligned with established project scope and security standards.
- Monitor progress toward reducing technology vulnerabilities and end-of-life/end-of-support risks.
- Maintain weekly trackers and prepare reports outlining completed activities, outstanding risks, and remediation progress.
- Participate in regular project meetings and collaborate with internal security, technology, and governance teams.
- Provide reporting and visibility to Governance, Risk & Compliance stakeholders.
### Required Qualifications
- **5+ years of experience in Information Security.**
- Hands-on experience with **Archer** risk management tools.
- Experience with **ServiceNow**.
- Experience conducting technology risk assessments and evaluating security controls.
- Strong knowledge of IT governance, information security controls, and technology risk management frameworks.
- Experience challenging or reviewing first-line-of-defense (1B) risk and control activities, including third-party risk activities.
- Experience identifying and tracking vulnerabilities, control gaps, and remediation activities.
- Ability to work independently, manage competing priorities, and communicate effectively with technical and business stakeholders.
- Associate degree in technology or a related field.
### Preferred Qualifications
- CISSP, CISM, or similar information security certification or training.
- Previous experience within banking or financial services.
- Experience supporting application currency, technology lifecycle management, or infrastructure modernization initiatives.
### Additional Information
- Initial training period of approximately two months.
- Approximately 50% of the role involves meetings and stakeholder collaboration.
- Internal stakeholder interaction only.
- No travel required.
- Overtime may be required as needed.
### About the Opportunity
This is an opportunity to contribute to a technology risk reduction and modernization initiative within a leading financial services organization. The successful candidate will play an important role in improving application compliance, reducing security vulnerabilities, and supporting the organization's broader information security and technology governance objectives.
location: Mount Laurel Township, New Jersey
job type: Contract
salary: $80 - 83 per hour
work hours: 8am to 5pm
education: Associates
responsibilities:
**Typical Day-to-Day Responsibilities:**
- Attend meetings and standups to identify the scope of Currency Factory work.
- Work with application-assigned BISOs to review TARAs and CGAs.
- Update and complete assessments in collaboration with BISOs, Business Asset Owners (BAOs), and Technology Asset Owners (TAOs).
- Ensure projects remain within the defined scope of Currency Factory work.
- Report to both BISO teams and Currency Factory teams to keep stakeholders informed.
- Participate in multiple weekly meetings with currency uplift projects, the Currency Factory team, and the U.S. BISO team.
- Maintain weekly trackers and reporting to identify completed work, outstanding concerns, and progress.
- Track the success of currency uplifts in reducing asset vulnerabilities, control gaps, and end-of-life/end-of-support concerns.
TARA = Technology Asset Risk Assessment - identifies inherent risk; completed with the technology owner.
CGA = Control Gap Assessment - identifies residual risk; completed with the business owner.
BAO = Business Asset Owner
TAO = Technology Asset Owner
Time Spent in Meetings: Approximately 50%
Stakeholder Interaction: Internal
qualifications:
Required Qualifications
5+ years of experience in Information Security.
Hands-on experience with Archer risk management tools.
Experience with ServiceNow.
Experience conducting technology risk assessments and evaluating security controls.
Strong knowledge of IT governance, information security controls, and technology risk management frameworks.
Experience challenging or reviewing first-line-of-defense (1B) risk and control activities, including third-party risk activities.
Experience identifying and tracking vulnerabilities, control gaps, and remediation activities.
Ability to work independently, manage competing priorities, and communicate effectively with technical and business stakeholders.
Associate degree in technology or a related field.
Preferred Qualifications
CISSP, CISM, or similar information security certification or training.
Previous experience within banking or financial services.
Experience supporting application currency, technology lifecycle management, or infrastructure modernization initiatives.
Equal Opportunity Employer: Race, Color, Religion, Sex, Sexual Orientation, Gender Identity, National Origin, Age, Genetic Information, Disability, Protected Veteran Status, or any other legally protected group status.
At Randstad Digital, we welcome people of all abilities and want to ensure that our hiring and interview process meets the needs of all applicants. If you require a reasonable accommodation to make your application or interview experience a great one, please contact
Pay offered to a successful candidate will be based on several factors including the candidate's education, work experience, work location, specific job duties, certifications, etc. In addition, Randstad Digital offers a comprehensive benefits package, including: medical, prescription, dental, vision, AD&D, and life insurance offerings, short-term disability, and a 401K plan (all benefits are based on eligibility).
This posting is open for thirty (30) days.
![]()