Sr. Governance, Risk & Compliance (GRC) Analyst
Summary
Newly created seat on a small, growing GRC team inside a global engineering and construction organization. The security program is early in its maturity curve - policies and standards are being rewritten this year, and risk assessment today is largely experiential. This role helps build that foundation: writing standards, bringing conventional risk assessment methodology to the practice, reviewing client contract security provisions, and managing third-party risk. Success here requires someone who can speak the frameworks fluently but has genuine empathy for IT operations - reading the spirit of a control, not just the letter, and partnering with operations to write policy that reflects reality.
Responsibilities
- Help rewrite and refresh enterprise security policies and standards, aligned to a consolidated set of frameworks
- Conduct risk assessments using established methodology (NIST 800-30/800-37) and maintain the risk register
- Interpret control requirements and work directly with IT operations to drive alignment and remediation
- Review client contract provisions for data security, breach reporting, cyber resilience, and compliance certifications
- Perform third-party/supply chain risk assessments and communicate vendor risk to business stakeholders
- Support SOC 2 and other certification and audit efforts by collecting policy and control evidence
Requirements
- Bachelor's degree in Information Systems, Information Security, or related field
- 7+ years in GRC executing or auditing against standards, frameworks, and regulations
- Working proficiency with NIST 800-53 (moderate baseline), NIST CSF, CIS Critical Security Controls, ISO 27001/27002, and AICPA SOC 2
- Demonstrated ability to interpret controls and connect them to operational practice - beyond coordinating audit evidence
- Experience developing security policy and standards documentation
- Working knowledge of cyber and privacy laws and regulations
Preferred
- Hands-on IT operations background (Microsoft 365, Azure administration)
- Experience in a regulated environment
- Familiarity with FAR, DFARS, CMMC
- ServiceNow IRM or comparable GRC platform (shallow learning curve - training available)
- CRISC, CISSP, or comparable certification
This is a 6-Month Contract-to-Hire opportunity to sit in Overland Park, KS, Cary, NC, or Houston, TX with our Overland Park, KS client. Low-cost employee benefits, paid time off, paid Holidays, and a 401(k) (with an immediately vested company match) are available with TriCom during the contract period. H-1B visa sponsorship is not available for this position. No third parties, please.
#LI-BH1