job summary:
Our client is looking for a Governance Risk and Compliance Analyst for a 4 month contract to hire opportunity located in Phoenix, AZ.
location: Phoenix, Arizona
job type: Contract
salary: $40 - 44 per hour
work hours: 8am to 5pm
education: Bachelors
responsibilities:
Role Overview: Information Security Analyst (GRC) Our client is seeking an experienced and highly motivated Information Security Analyst (ISA) to join their Governance, Risk, and Compliance (GRC) team. In this role, you will engage with cross-functional business units to understand reporting, data, and security needs.
You will collaborate across departments to define project requirements, establish data dependencies and relationships to develop system activity diagrams and data models, and draft specifications for enterprise information policies. Additionally, you will support user adoption, training, and customer service while working alongside technical project managers to deliver high-quality project artifacts.
Key Responsibilities
- Risk & Audit Assessments: Perform risk assessments and audit reviews; generate comprehensive findings reports, action plans (POA&Ms), and recommendations for security improvements and tracking.
- Documentation & Compliance: Review, update, and manage security audit plans, system security plans, and risk documentation to ensure accuracy and proactive problem-solving.
- Incident & Network Review: Evaluate system data, draft environmental observations/incident reports, and review suspicious network activity.
- Standards & Regulations: Research industry standards, best practices, laws, and regulations to ensure institutional compliance across all IT systems.
- Stakeholder Support: Develop user adoption and training materials, provide technical guidance to internal teams, and assist project managers in maintaining accurate project documentation.
qualifications:
Qualifications & Core Competencies
Knowledge & Experience
Frameworks & Standards: Strong working knowledge of cybersecurity and privacy frameworks (e.g., NIST 800-53, HIPAA/HITRUST, IRS Pub 1075, CJIS, MARS-E, Risk Management Framework / RMF).
GRC Expertise: Deep understanding of internal auditing, internal controls, risk management practices, and information system authorizations.
Technical Domains: Familiarity with technical system audits across multiple IT domains, including Windows/Unix, database administration, networking, and software development.
Key Skills & Abilities
Policy & Strategy: Ability to draft, assess, and continuously improve security policies and procedures aligned with strategic goals.
Communication: Excellent interpersonal, written, and oral communication skills with experience presenting to senior management.
Collaborative Problem-Solving: Ability to exercise sound judgment when policies are ambiguous, synthesize feedback, and build strong cross-departmental relationships.
skills:
activity diagrams,Information Security,IT security,cybersecurity and privacy,information analysis,data flows,data systems,information security management,Information Systems,Windows,Plan of Action and Milestones,Privacy Controls,software development,Unix,written and oral communication skills,leadership,networking,problem solving,highly motivated,proactively,audit reviews,internal auditing,Audit,conducting audits,customer service,logical and physical data models,database administration,Economic,editing,Governance Risk and Compliance (GRC),Information Security Risk Management,security principles,internal control,internal controls,Knowledge of laws,NIST 800-53,operational planning,requirements gathering,risk assessments,risk management practices,Risk Management Framework (RMF),Security,security practices,security policies,socializing,training,user adoption
Equal Opportunity Employer: Race, Color, Religion, Sex, Sexual Orientation, Gender Identity, National Origin, Age, Genetic Information, Disability, Protected Veteran Status, or any other legally protected group status.
At Randstad Digital, we welcome people of all abilities and want to ensure that our hiring and interview process meets the needs of all applicants. If you require a reasonable accommodation to make your application or interview experience a great one, please contact
Pay offered to a successful candidate will be based on several factors including the candidate's education, work experience, work location, specific job duties, certifications, etc. In addition, Randstad Digital offers a comprehensive benefits package, including: medical, prescription, dental, vision, AD&D, and life insurance offerings, short-term disability, and a 401K plan (all benefits are based on eligibility).
This posting is open for thirty (30) days.
![]()