Information Security GRC Analyst

Frankfort, KY, US • Posted 2 hours ago • Updated 2 hours ago
Full Time
On-site
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • NIST 800-53
  • Risk Analysis
  • Software Troubleshooting
  • Issue Resolution
  • Access Control
  • Leadership
  • Customer Service
  • Communication
  • Organized
  • Dependability
  • Accountability
  • Process Improvement
  • NIST SP 800 Series
  • System Security
  • Continuous Monitoring
  • Management
  • Cloud Computing
  • Data Security
  • Security Policy
  • Policies and Procedures
  • Reporting
  • Security Awareness
  • Training
  • Documentation
  • Information Security Governance
  • CISA
  • ISACA
  • CISSP
  • Information Systems
  • SAP GRC
  • Auditing
  • SAP BASIS
  • Information Technology
  • Cyber Security
  • Regulatory Compliance
  • IT Audit
  • Risk Management
  • Application Support
  • Information Security
  • PASS
  • Licensing
  • Staff Management
  • Security Controls
  • Forensics
  • Microsoft
  • Physical Security
  • Intrusion Detection
  • Computer Networking
  • HTML
  • Problem Solving
  • Risk Assessment
  • Change Management
  • Incident Management
  • Information Assurance
  • Research
  • Testing
  • Data Loss Prevention

Summary

Overview:

Quantam Solutions provides IT solutions and consulting for various clients. We offer competitive hourly wages, health benefits, paid time off, and a 401(k) plan. We are currently seeking an Information Security GRC Analyst. This position is fully onsite in Frankfort, Kentucky. Candidates must currently reside in Kentucky and be able to commute to Frankfort.

Job Description:

Our client is seeking an Information Security Analyst to support technology, information security, Governance, Risk, and Compliance (GRC), and driver licensing operations.

The successful candidate will support driver licensing systems, issuance technology, REAL ID requirements, and related applications and infrastructure. This position will also provide information security and GRC support, including security control assessments, risk assessments, compliance monitoring, security documentation, audit and evidence management, and continuous monitoring activities.

The Information Security Analyst will work closely with System Administrators, IT staff, management, vendors, developers, and other stakeholders to identify security and operational risks, support compliance requirements, improve system processes, and maintain appropriate security controls.

This position may require reviewing and analyzing sensitive and confidential information. The successful candidate must demonstrate a high level of professionalism, accountability, confidentiality, and security awareness and must be able to pass required fingerprint and background checks.

Information Security and GRC Responsibilities

  • Support our client's information security and Governance, Risk, and Compliance (GRC) activities.
  • Assist with the development, review, and maintenance of security policies, procedures, standards, and compliance documentation.
  • Support compliance activities related to federal information security requirements, applicable regulatory requirements, and the protection of Personally Identifiable Information (PII).
  • Assist with NIST Special Publication 800-53 security controls and related control implementation requirements.
  • Assist with security control assessments and documentation of control effectiveness.
  • Participate in risk assessments, risk identification, risk analysis, and risk mitigation activities.
  • Assist with the development and maintenance of System Security Plans (SSPs) and supporting security documentation.
  • Assist with Plans of Action and Milestones (POA&Ms), including documenting identified weaknesses, corrective actions, responsible parties, milestones, and remediation status.
  • Support continuous monitoring activities to identify changes in security posture, system risks, vulnerabilities, and compliance status.
  • Assist with security audits, assessments, reviews, and security audit/evidence management.
  • Collect, organize, validate, and maintain evidence required to demonstrate compliance with security controls and regulatory requirements.
  • Support the assessment and documentation of hybrid controls, including controls involving cloud services, provided services, enterprise controls, external systems, and shared responsibilities.
  • Coordinate with system owners, System Administrators, IT staff, vendors, and other stakeholders to obtain required security documentation and evidence.
  • Monitor identified security findings and assist with tracking remediation activities through completion.
  • Assist with documenting security risks and providing recommendations to management regarding risk treatment and remediation.
  • Support reviews of system changes to determine potential security and compliance impacts.
  • Maintain accurate security records, assessment documentation, and compliance artifacts.
Compliance, Policy, and Training

  • Assist with ongoing compliance monitoring to ensure applicable policies, procedures, security controls, and regulatory requirements remain current and effective.
  • Support the review and updating of policies and procedures when security, technology, regulatory, or operational requirements change.
  • Assist with updating policy and training materials to reflect current compliance and security requirements.
  • Monitor security and compliance training completion and maintain appropriate documentation and records.
  • Assist management with identifying training requirements based on security findings, policy changes, audit results, or regulatory requirements.
  • Communicate security and compliance requirements to employees and stakeholders.
  • Support security awareness activities related to the proper handling of sensitive information, PII, system credentials, and security-related information.
IT and Application Support

  • Provide IT and application troubleshooting support to users and offices.
  • Work closely with IT staff on system performance, application issues, technical goals, and issue resolution.
  • Assist System Administrators with system credentials, access requests, role assignments, and other technology-related duties.
  • Identify recurring application and system issues and recommend process or technical improvements.
  • Assist with testing system changes, security configurations, application functionality, and access controls.
  • Work with vendors and developers when necessary to investigate and resolve system issues.
  • Document technical issues, resolutions, security concerns, and recommended improvements.
Communication, Leadership, and Customer Service

  • Strong written and verbal communication skills are required.
  • Must be task-oriented, organized, dependable, and capable of working independently.
  • Must work effectively in a team environment and assist others as needed.
  • May be called upon to serve in a lead role.
  • Must demonstrate strong interpersonal skills and the ability to work professionally with employees, management, vendors, and external stakeholders.
  • Must be professional, supportive, diplomatic, flexible, and responsible.
  • Must maintain a high level of accountability and confidentiality.
  • Must be able to communicate technical, security, and compliance information to both technical and non-technical audiences.
  • Must be able to provide recommendations to management regarding security, compliance, system, and process improvements.
Preferred Information Security / GRC Experience

Strong candidates will have hands-on experience with several of the following:

  • NIST SP 800-53
  • Security Control Assessments
  • Risk Assessments
  • System Security Plans (SSPs)
  • Plans of Action and Milestones (POA&Ms)
  • Continuous Monitoring
  • Security Audit and Evidence Management
  • Hybrid Controls
  • Cloud services and shared security responsibilities
  • Enterprise and external system controls
  • Federal information security requirements
  • Regulatory compliance
  • Personally Identifiable Information (PII) protection
  • Data security
  • Security policy and procedure development
  • Compliance monitoring and reporting
  • Security awareness and compliance training
  • Security findings and remediation tracking
  • Risk documentation and mitigation
  • Audit preparation and response
  • Security control documentation and evidence collection
Preferred Certifications

Relevant certifications demonstrating knowledge of information security, governance, risk, compliance, auditing, and security controls are preferred, including:

  • ISC2 CGRC - Certified in Governance, Risk and Compliance
  • ISACA CISA - Certified Information Systems Auditor
  • ISACA CRISC - Certified in Risk and Information Systems Control
  • ISC2 CISSP - Certified Information Systems Security Professional, particularly when combined with strong hands-on GRC experience

Certification alone is not considered a substitute for practical GRC experience. Candidates with demonstrated experience performing security, risk, compliance, assessment, audit, or control-related responsibilities should also be considered.

Education and Experience

A Bachelor's Degree from an accredited college or university is preferred.

An Associate's Degree or relevant administrative, business, research, technical, information technology, cybersecurity, or clerical experience may substitute for the required education on a year-for-year basis, as permitted by applicable requirements.

Candidates should have relevant professional experience in one or more of the following areas:

  • Information Technology
  • Cybersecurity
  • Information Security
  • Governance, Risk, and Compliance
  • Compliance
  • IT Auditing
  • Risk Management
  • Application Support
  • Driver licensing technology

Experience working with government organizations, federal information security requirements, regulated environments, sensitive information, or enterprise technology systems is preferred.

Additional Requirements

  • Must be able to pass required fingerprint and background checks.
  • Must maintain confidentiality when handling PII and other sensitive information.
  • Must be willing to travel when required, including occasional overnight stays.
  • Evening or Saturday hours may occasionally be required.
  • Overtime may be necessary, up to 10 hours per week.
  • Must be able to learn and apply applicable driver licensing laws, policies, procedures, and technology requirements.
  • Must be able to learn and utilize our client's driver licensing systems and related applications.
  • Must work effectively with System Administrators, IT staff, management, vendors, developers, and other business and technical personnel.
  • Must be able to perform other duties as assigned.

Skills:

security controls,forensics,microsoft,physical security,intrusion detection,networking,html,regulated industry,programming,problem resolution,troubleshooting,c,risk assessment,change management,incident response,reports,information assurance,research,vulnerability testing,data loss prevention
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 10280509
  • Position Id: 15cbec4f7d99f7212d9b1d0640241a82
  • Posted 2 hours ago
Create job alert
Never miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Remote

•

Today

Contract

$55.00 - $80.00

Remote

•

2d ago

Easy Apply

Third Party, Contract

Depends on Experience

Remote or North Dakota

•

Today

Full-time

USD 6,000.00 - 6,500.00 per month

Remote

•

Today

Full-time

USD 74,000.00 - 124,000.00 per year

Search all similar jobs