Senior GRC Analyst
Posted 2hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
GRC Analyst leading cybersecurity assessments and compliance programs at Hotman Group. Collaborating with clients and mentoring junior analysts in a fully remote role.
Responsibilities:
- Lead assessments and audits of security and IT control environments
- Design, implement, and mature cybersecurity and compliance programs
- Develop risk registers, conduct risk assessments, and track remediation efforts
- Create and refine policies, standards, and procedures aligned with top frameworks including SOC 2, ISO 27001, NIST CSF, HIPAA, HITRUST, CMMC, and others
- Prepare clients for internal audits and external assessments
- Translate technical, regulatory, and business requirements into clear, actionable deliverables for client stakeholders
- Communicate findings, manage client feedback, and drive outcomes even when stakeholders push back
- Mentor junior analysts and contribute to the growth of our GRC practice
- Participate in peer review of deliverables before they go to clients.
Requirements:
- Permanent authorization to work in the U.S. -- no sponsorship of any kind now or in the future
- Able to pass a background check
- Hands-on GRC experience with a track record of owning deliverables, producing frameworks-based documentation, and driving remediation -- not just supporting programs from the inside
- Deep working knowledge of compliance standards including SOC 2, ISO 27001, NIST CSF, HIPAA, and HITRUST
- Experience communicating findings and recommendations directly to clients or senior internal stakeholders
- Excellent writing skills -- your deliverables are clear, polished, and do not require heavy editing before they go to a client
- Strong critical thinking and professional judgment
- A high level of accountability and ownership
- Comfort working independently in a fully remote environment with minimal hand-holding
- A default toward communication.
Benefits:
- Active certifications such as CISA, CISM, CISSP, or CRISC are strongly preferred.
- Reliable high-speed internet and a secure, private remote workspace.


















