| Location | Minneapolis, MN |
| Salary | $110,000–$140,000 |
Location: Minneapolis, MN (Preferred) or one of the following office locations: Anchorage, AK Boise, ID Chicago, IL Costa Mesa, CA Dallas, TX Denver, CO Des Moines, IA Minneapolis, MN Missoula, MT New York, NY Palo Alto, CA Phoenix, AZ Salt Lake City, UT Seattle, WA Washington, DC Wilmington, DE
Position Type: Direct Hire
Work Authorization: U.S. Citizens Only
Job SummaryWe are seeking an experienced Senior GRC Information Security Systems Analyst to join our Information Security team. This role is responsible for leading Governance, Risk, and Compliance (GRC) initiatives while strengthening the organization's cybersecurity posture through risk management, compliance, audit readiness, and security governance.
The ideal candidate will possess extensive experience in Information Security Management Systems (ISMS), regulatory compliance, security risk assessments, Identity & Access Management (IAM), Data Loss Prevention (DLP), security awareness programs, and enterprise security governance. You will collaborate with cross-functional teams to ensure compliance with industry standards, improve security controls, and support enterprise-wide cybersecurity initiatives.
Key Responsibilities Governance, Risk & ComplianceMaintain and continuously improve the Information Security Management System (ISMS).
Develop, maintain, and update information security policies, standards, procedures, and documentation.
Support ongoing compliance efforts by adapting security documentation to organizational, technology, and threat landscape changes.
Generate Information Security metrics, dashboards, and executive reporting.
Coordinate and support internal and external security audits and compliance assessments.
Lead audit preparation activities and support ISO recertification efforts.
Document audit findings, remediation plans, and corrective actions.
Collaborate with business and technology teams to implement and monitor security controls.
Support continuous monitoring and automation of compliance-related security controls.
Maintain Statements of Applicability (SoA), policies, procedures, and compliance documentation.
Conduct enterprise technology and information security risk assessments.
Perform project-based cybersecurity risk assessments.
Evaluate software, cloud platforms, third-party vendors, and technology services for security risks.
Maintain enterprise Technology Risk Registers.
Present risk assessment findings and remediation recommendations to leadership.
Track risk remediation activities through completion.
Complete customer security questionnaires and security assessment requests.
Support cybersecurity sections of RFPs and contract reviews.
Conduct pre-contract and post-contract security assessments.
Perform third-party vendor technology risk assessments.
Evaluate security and privacy controls for vendors and SaaS platforms.
Support ongoing vendor security monitoring activities.
Support enterprise Identity and Authorization governance.
Improve Role-Based Access Control (RBAC) processes.
Review privileged accounts, service accounts, and user entitlements.
Perform least-privilege assessments and permission cleanup.
Support Privileged Identity Management (PIM) initiatives.
Conduct periodic user access reviews.
Validate repeatable authorization governance processes.
Support enterprise Data Loss Prevention (DLP) governance.
Review DLP controls for regulatory and compliance requirements.
Assist with data classification initiatives.
Monitor DLP effectiveness and recommend improvements.
Support Human Risk Management initiatives.
Coordinate annual security awareness training.
Support phishing simulation campaigns.
Track training participation and security awareness metrics.
Partner with IT, Compliance, Risk, Audit, Security Operations, and business teams.
Identify opportunities to automate compliance monitoring.
Improve enterprise security governance processes.
Support cybersecurity projects and strategic initiatives.
Perform additional security-related duties as assigned.
Bachelor's degree in Computer Science, Information Security, Information Systems, Business, or a related discipline (or equivalent experience).
7+ years of Information Security, Cybersecurity, or GRC experience.
Experience implementing or maintaining an Information Security Management System (ISMS).
Experience with multiple security compliance frameworks, including:
ISO 27001:2022
SOC 2
GDPR
NIST Cybersecurity Framework (CSF)
NIST 800-53
Experience developing and maintaining:
Security policies
Standards
Procedures
Controls
Governance documentation
Experience conducting:
Security audits
Compliance assessments
Security risk assessments
Client security reviews
Vendor security assessments
Experience maintaining enterprise Technology Risk Registers.
Strong understanding of Governance, Risk & Compliance (GRC) practices.
Experience supporting enterprise security awareness programs.
Excellent written and verbal communication skills.
Strong organizational and project management abilities.
Ability to manage multiple priorities in a fast-paced environment.
Experience with:
Microsoft Azure
Microsoft 365
Active Directory
Microsoft Entra ID
Microsoft Purview
Microsoft Defender
Microsoft Sentinel
Exchange Online
Exchange On-Premises
Microsoft Teams
OneDrive
Zoom
OAuth
Single Sign-On (SSO)
SaaS Security
Identity & Access Management (IAM)
Role-Based Access Control (RBAC)
Privileged Identity Management (PIM)
Data Loss Prevention (DLP)
CISSP, CISM, CISA, or equivalent security certification.
Experience supporting ISO certification programs.
Knowledge of ISO 42001.
Experience with Microsoft Copilot and Anthropic Claude AI.
Experience within professional services or other highly regulated industries.
Strong understanding of cybersecurity best practices, governance, and emerging threats.
Governance, Risk & Compliance (GRC)
Information Security Management Systems (ISMS)
ISO 27001
SOC 2
GDPR
NIST CSF
NIST 800-53
Security Risk Assessments
Internal & External Audits
Third-Party Risk Management
Vendor Security Assessments
Information Security Policies & Standards
IAM
RBAC
PIM
DLP
Microsoft Azure
Microsoft 365
Entra ID
Microsoft Purview
Microsoft Defender
Microsoft Sentinel
Active Directory
Security Awareness Training
Phishing Simulation
Compliance Reporting
Technology Risk Management
U.S. Citizens Only
Direct Hire
Anchorage, AK
Boise, ID
Chicago, IL
Costa Mesa, CA
Dallas, TX
Denver, CO
Des Moines, IA
Minneapolis, MN (Preferred)
Missoula, MT
New York, NY
Palo Alto, CA
Phoenix, AZ
Salt Lake City, UT
Seattle, WA
Washington, DC
Wilmington, DE