Information Security Governance, Risk and Compliance (GRC) Analyst

Cyquent, Inc

Rockville, MD

JOB DETAILS
SKILLS
Administrative Skills, Analysis Skills, Business Solutions, CISM - Certified Information Security Manager, Capability Maturity Model Integration (CMMI), Computer Science, Customer Relations, Customer Support/Service, Detail Oriented, Develop and Maintain Customers, Documentation, Government, ISO (International Organization for Standardization), IT Governance, Information Technology & Information Systems, Information Technology/Systems Audit, Information/Data Security (InfoSec), Leadership, Multitasking, Policy Development, Presentation/Verbal Skills, Project/Program Coordination, Record Keeping, Reporting Dashboards, Reporting Skills, Risk, Risk Analysis, Risk Management, Security Analysis, ServiceNow, Status Reports, Team Player, Technical Support, Technical Writing, Time Management, Writing Skills
LOCATION
Rockville, MD
POSTED
1 day ago
Information Security Risk Analyst

Job Summary

Our client is seeking an Information Security Risk Analyst to support policy exception administration, risk analysis, and enterprise risk management activities. The role involves maintaining risk records, processing policy exceptions, and utilizing ServiceNow IRM to support governance and compliance processes.

Key Responsibilities

Policy Exception Administration

  • Review policy exception requests for completeness.

  • Verify required documentation and business justifications.

  • Request additional information when needed.

  • Maintain exception records in ServiceNow.

  • Track requests through the approval process.

  • Monitor exception expiration dates and coordinate renewals and closures.

  • Prepare status reports.

Risk Analysis

  • Review policy exception requests using client-approved methodologies.

  • Evaluate business impact, likelihood, and risk.

  • Identify compensating controls.

  • Prepare written risk analyses and approval/denial recommendations for CISO review.

  • Document analyses in ServiceNow.

Enterprise Risk Register

  • Maintain the client's Information Security Risk Register.

  • Create and update risk records.

  • Record risks identified through:

    • Third-party penetration tests

    • Third-party security assessments

    • Internal risk assessments

    • Vulnerability scanning

    • Policy exceptions

    • Security incidents

    • Other approved sources

  • Track mitigation activities, due dates, and risk status.

  • Maintain supporting documentation and generate reports.

ServiceNow IRM

  • Process policy exceptions.

  • Maintain Risk Register records.

  • Track approvals.

  • Maintain documentation.

  • Generate reports and dashboards.

Customer Interaction

Communicate professionally with:

  • Department IT Staff

  • Department Management

  • Information System Owners

  • Client Leadership

  • Office of Enterprise Information Security

Qualifications

Education

Bachelor's degree in one of the following:

  • Cybersecurity

  • Information Systems

  • Information Technology

  • Computer Science

  • Business Information Systems

Preferred Certifications

  • CompTIA Security+

  • Certified Information Security Manager Fundamentals (CISM-F)

  • NIST Cybersecurity Framework (NCSF) Practitioner

  • ISACA IT Risk Fundamentals Certificate

  • ISACA Cybersecurity Audit Certificate

  • HIPAA Security Training or Compliance Certificates

Experience

Minimum

  • One (1) year of professional experience in Information Security, IT Governance, Compliance, Risk Management, Information Technology, Audit, or a related field.

  • Recent graduates with relevant internship or equivalent experience are encouraged to apply.

Preferred

  • Experience with ServiceNow.

  • Experience with Microsoft Office 365.

  • Experience with Governance, Risk and Compliance (GRC).

  • Experience preparing technical documentation.

  • Experience in customer service environments.

  • Experience coordinating projects, tasks, or workflows.

Knowledge

Basic understanding of:

  • Cybersecurity principles

  • Information Security

  • Risk Management

  • NIST Cybersecurity Framework

  • Risk Scoring Systems/Quantitative Risk Frameworks

  • HIPAA

Skills

  • Strong analytical and critical thinking

  • Excellent written and verbal communication

  • Customer service skills

  • Organization and attention to detail

  • Time management

  • Ability to learn new technologies quickly

  • Ability to work independently

  • Professionalism

  • Ability to manage multiple priorities

    About Cyquent
    Cyquent is a CMMI & ISO Certified Technology Enabler providing end-to-end IT solutions and services to organizations in both the public and private sectors since 2001. We are known for delivering high-quality, scalable solutions across complex enterprise environments.
    Why Join Cyquent?
    This is an opportunity to work alongside a high-performing technology team supporting a wide range of enterprise and public sector clients. You'll gain hands-on experience working on impactful projects in a collaborative and fast-paced environment.
    We offer:

  • Competitive salary and 401(k)
  • Comprehensive health benefits (medical, dental, and vision) starting on Day 1
  • Paid time off annually, plus state holidays
  • Support for professional growth, including certification assistance and continued learning opportunities .

About the Company

C

Cyquent, Inc