- Company Name
- Rootshell Inc
- Job Title
- GRC Analyst
- Job Description
-
**Job Title:** GRC Analyst
**Role Summary:**
Analyze and enhance an organization’s governance, risk, and compliance posture by assessing, designing, and monitoring controls aligned with industry frameworks and regulatory requirements.
**Expectations:**
Deliver actionable insights on risk exposure, enforce control effectiveness, and support audit readiness across IT and business domains.
**Key Responsibilities:**
- Apply security frameworks (NIST SP 800‑53, ISO 27001/2, PCI DSS, SOC 2, CIS & SANS Controls) to assess and improve controls.
- Conduct risk assessments for vendors and internal systems, translating findings into business impact.
- Support risk treatment, exception management, and remediation planning.
- Review and audit IT controls (COBIT, IT General Controls) and security architecture (authentication, encryption, data protection).
- Collaborate with system engineers, auditors, and stakeholders to explain technical findings and recommendations.
- Maintain up‑to‑date documentation of control design, evidence, and audit trail.
**Required Skills:**
- Deep knowledge of information security and risk management concepts.
- Expertise in security control domains: asset management, configuration management, SDLC, logging/monitoring, data and network security, identity & access management, vulnerability management.
- Proficiency with logical access, encryption, DLP, secure coding, vulnerability tools, and network security technologies.
- Strong analytical, problem‑solving, and documentation abilities.
- Excellent written and verbal communication for stakeholder engagement.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience).
- Minimum one of: CISSP, CISA, CISM, CEH, ISO 27001 Lead Auditor, or ISO 27001 Lead Implementer.
Santa clara, United states
Hybrid
05-12-2025