Sr. GRC Analyst

TriCom Technical Services LLC

  • Overland Park, KS
  • 5 days ago

    Highlights

    Working proficiency with NIST 800-53 (moderate baseline), NIST CSF, CIS Critical Security Controls, ISO 27001/27002, and AICPA SOC 2. Demonstrated ability to interpret controls and connect them to operational practice - beyond coordinating audit evidence. Success here requires someone who can speak the frameworks fluently but has genuine empathy for IT operations - reading the spirit of a control, not just the letter, and partnering with operations to write policy that reflects reality.

    Numbers & Facts

    LocationOverland Park, KS

    Description

    Sr. Governance, Risk & Compliance (GRC) Analyst

    Summary

    Newly created seat on a small, growing GRC team inside a global engineering and construction organization. The security program is early in its maturity curve - policies and standards are being rewritten this year, and risk assessment today is largely experiential. This role helps build that foundation: writing standards, bringing conventional risk assessment methodology to the practice, reviewing client contract security provisions, and managing third-party risk. Success here requires someone who can speak the frameworks fluently but has genuine empathy for IT operations - reading the spirit of a control, not just the letter, and partnering with operations to write policy that reflects reality.

    Responsibilities

    • Help rewrite and refresh enterprise security policies and standards, aligned to a consolidated set of frameworks
    • Conduct risk assessments using established methodology (NIST 800-30/800-37) and maintain the risk register
    • Interpret control requirements and work directly with IT operations to drive alignment and remediation
    • Review client contract provisions for data security, breach reporting, cyber resilience, and compliance certifications
    • Perform third-party/supply chain risk assessments and communicate vendor risk to business stakeholders
    • Support SOC 2 and other certification and audit efforts by collecting policy and control evidence

    Requirements

    • Bachelor's degree in Information Systems, Information Security, or related field
    • 7+ years in GRC executing or auditing against standards, frameworks, and regulations
    • Working proficiency with NIST 800-53 (moderate baseline), NIST CSF, CIS Critical Security Controls, ISO 27001/27002, and AICPA SOC 2
    • Demonstrated ability to interpret controls and connect them to operational practice - beyond coordinating audit evidence
    • Experience developing security policy and standards documentation
    • Working knowledge of cyber and privacy laws and regulations

    Preferred

    • Hands-on IT operations background (Microsoft 365, Azure administration)
    • Experience in a regulated environment
    • Familiarity with FAR, DFARS, CMMC
    • ServiceNow IRM or comparable GRC platform (shallow learning curve - training available)
    • CRISC, CISSP, or comparable certification

    This is a 6-Month Contract-to-Hire opportunity to sit in Overland Park, KS, Cary, NC, or Houston, TX with our Overland Park, KS client. Low-cost employee benefits, paid time off, paid Holidays, and a 401(k) (with an immediately vested company match) are available with TriCom during the contract period. H-1B visa sponsorship is not available for this position. No third parties, please.

    #LI-BH1

    Similar Jobs