Senior GRC Information Security Systems Analyst - Direct Hire

VITS Consulting

  • Minneapolis, MN
  • 3 days ago
  • $110,000–$140,000

Highlights

Senior GRC Information Security Systems Analyst Location: Minneapolis, MN (Preferred) or one of the following office locations: Anchorage, AK Boise, ID Chicago, IL Costa Mesa, CA Dallas, TX Denver, CO Des Moines, IA Minneapolis, MN Missoula, MT New York, NY Palo Alto, CA Phoenix, AZ Salt Lake City, UT Seattle, WA Washington, DC Wilmington, DE. The ideal candidate will possess extensive experience in Information Security Management Systems (ISMS), regulatory compliance, security risk assessments, Identity & Access Management (IAM), Data Loss Prevention (DLP), security awareness programs, and enterprise security governance.

Numbers & Facts

LocationMinneapolis, MN
Salary$110,000–$140,000

Description

Senior GRC Information Security Systems Analyst

Location: Minneapolis, MN (Preferred) or one of the following office locations: Anchorage, AK Boise, ID Chicago, IL Costa Mesa, CA Dallas, TX Denver, CO Des Moines, IA Minneapolis, MN Missoula, MT New York, NY Palo Alto, CA Phoenix, AZ Salt Lake City, UT Seattle, WA Washington, DC Wilmington, DE

Position Type: Direct Hire

Work Authorization: U.S. Citizens Only

Job Summary

We are seeking an experienced Senior GRC Information Security Systems Analyst to join our Information Security team. This role is responsible for leading Governance, Risk, and Compliance (GRC) initiatives while strengthening the organization's cybersecurity posture through risk management, compliance, audit readiness, and security governance.

The ideal candidate will possess extensive experience in Information Security Management Systems (ISMS), regulatory compliance, security risk assessments, Identity & Access Management (IAM), Data Loss Prevention (DLP), security awareness programs, and enterprise security governance. You will collaborate with cross-functional teams to ensure compliance with industry standards, improve security controls, and support enterprise-wide cybersecurity initiatives.

Key Responsibilities Governance, Risk & Compliance
  • Maintain and continuously improve the Information Security Management System (ISMS).

  • Develop, maintain, and update information security policies, standards, procedures, and documentation.

  • Support ongoing compliance efforts by adapting security documentation to organizational, technology, and threat landscape changes.

  • Generate Information Security metrics, dashboards, and executive reporting.

  • Coordinate and support internal and external security audits and compliance assessments.

  • Lead audit preparation activities and support ISO recertification efforts.

  • Document audit findings, remediation plans, and corrective actions.

  • Collaborate with business and technology teams to implement and monitor security controls.

  • Support continuous monitoring and automation of compliance-related security controls.

  • Maintain Statements of Applicability (SoA), policies, procedures, and compliance documentation.

Risk Management
  • Conduct enterprise technology and information security risk assessments.

  • Perform project-based cybersecurity risk assessments.

  • Evaluate software, cloud platforms, third-party vendors, and technology services for security risks.

  • Maintain enterprise Technology Risk Registers.

  • Present risk assessment findings and remediation recommendations to leadership.

  • Track risk remediation activities through completion.

Client & Third-Party Security
  • Complete customer security questionnaires and security assessment requests.

  • Support cybersecurity sections of RFPs and contract reviews.

  • Conduct pre-contract and post-contract security assessments.

  • Perform third-party vendor technology risk assessments.

  • Evaluate security and privacy controls for vendors and SaaS platforms.

  • Support ongoing vendor security monitoring activities.

Identity & Access Management (IAM)
  • Support enterprise Identity and Authorization governance.

  • Improve Role-Based Access Control (RBAC) processes.

  • Review privileged accounts, service accounts, and user entitlements.

  • Perform least-privilege assessments and permission cleanup.

  • Support Privileged Identity Management (PIM) initiatives.

  • Conduct periodic user access reviews.

  • Validate repeatable authorization governance processes.

Data Protection & Human Risk
  • Support enterprise Data Loss Prevention (DLP) governance.

  • Review DLP controls for regulatory and compliance requirements.

  • Assist with data classification initiatives.

  • Monitor DLP effectiveness and recommend improvements.

  • Support Human Risk Management initiatives.

  • Coordinate annual security awareness training.

  • Support phishing simulation campaigns.

  • Track training participation and security awareness metrics.

Collaboration & Continuous Improvement
  • Partner with IT, Compliance, Risk, Audit, Security Operations, and business teams.

  • Identify opportunities to automate compliance monitoring.

  • Improve enterprise security governance processes.

  • Support cybersecurity projects and strategic initiatives.

  • Perform additional security-related duties as assigned.

Required Qualifications
  • Bachelor's degree in Computer Science, Information Security, Information Systems, Business, or a related discipline (or equivalent experience).

  • 7+ years of Information Security, Cybersecurity, or GRC experience.

  • Experience implementing or maintaining an Information Security Management System (ISMS).

  • Experience with multiple security compliance frameworks, including:

    • ISO 27001:2022

    • SOC 2

    • GDPR

    • NIST Cybersecurity Framework (CSF)

    • NIST 800-53

  • Experience developing and maintaining:

    • Security policies

    • Standards

    • Procedures

    • Controls

    • Governance documentation

  • Experience conducting:

    • Security audits

    • Compliance assessments

    • Security risk assessments

    • Client security reviews

    • Vendor security assessments

  • Experience maintaining enterprise Technology Risk Registers.

  • Strong understanding of Governance, Risk & Compliance (GRC) practices.

  • Experience supporting enterprise security awareness programs.

  • Excellent written and verbal communication skills.

  • Strong organizational and project management abilities.

  • Ability to manage multiple priorities in a fast-paced environment.

Required Technical Skills

Experience with:

  • Microsoft Azure

  • Microsoft 365

  • Active Directory

  • Microsoft Entra ID

  • Microsoft Purview

  • Microsoft Defender

  • Microsoft Sentinel

  • Exchange Online

  • Exchange On-Premises

  • Microsoft Teams

  • OneDrive

  • Zoom

  • OAuth

  • Single Sign-On (SSO)

  • SaaS Security

  • Identity & Access Management (IAM)

  • Role-Based Access Control (RBAC)

  • Privileged Identity Management (PIM)

  • Data Loss Prevention (DLP)

Preferred Qualifications
  • CISSP, CISM, CISA, or equivalent security certification.

  • Experience supporting ISO certification programs.

  • Knowledge of ISO 42001.

  • Experience with Microsoft Copilot and Anthropic Claude AI.

  • Experience within professional services or other highly regulated industries.

  • Strong understanding of cybersecurity best practices, governance, and emerging threats.

Required Skills
  • Governance, Risk & Compliance (GRC)

  • Information Security Management Systems (ISMS)

  • ISO 27001

  • SOC 2

  • GDPR

  • NIST CSF

  • NIST 800-53

  • Security Risk Assessments

  • Internal & External Audits

  • Third-Party Risk Management

  • Vendor Security Assessments

  • Information Security Policies & Standards

  • IAM

  • RBAC

  • PIM

  • DLP

  • Microsoft Azure

  • Microsoft 365

  • Entra ID

  • Microsoft Purview

  • Microsoft Defender

  • Microsoft Sentinel

  • Active Directory

  • Security Awareness Training

  • Phishing Simulation

  • Compliance Reporting

  • Technology Risk Management

Work Authorization
  • U.S. Citizens Only

Employment Type
  • Direct Hire

Preferred Work Locations
  • Anchorage, AK

  • Boise, ID

  • Chicago, IL

  • Costa Mesa, CA

  • Dallas, TX

  • Denver, CO

  • Des Moines, IA

  • Minneapolis, MN (Preferred)

  • Missoula, MT

  • New York, NY

  • Palo Alto, CA

  • Phoenix, AZ

  • Salt Lake City, UT

  • Seattle, WA

  • Washington, DC

  • Wilmington, DE

Similar Jobs

Genesis10

ITSM Process Analyst - Hybrid

  • Minneapolis, MN
11 days ago
See more jobs