Cybersecurity Compliance Analyst
Cyber Focus AI's mission is to help cybersecurity professionals discover cutting-edge opportunities in their field.
About the role
The Enterprise GRC (Governance, Risk, and Compliance) team functions as a second line of defense, supporting the development and maintenance of Enterprise Technology (ET) risk management and compliance activities. This Analyst role supports the Cyber GRC Compliance & Certification Service Manager in executing day-to-day compliance, certification, and risk management activities across global and regional (EU/Germany) frameworks, including ISO 27001, SOC 2, NIST CSF, GDPR, and other automotive-industry-specific standards. This is a hands-on execution role, ideal for someone building foundational GRC expertise while contributing to certification lifecycle management, evidence collection, control monitoring, and regulatory reporting support.
Responsibilities
- Support the Service Manager in maintaining relationships with OGC, the application teams, and other shared services teams by preparing documentation, tracking action items, and coordinating meeting logistics.
- Assist in the collection, organization, and validation of evidence artifacts, metrics, and control documentation required for the Global IT risk management framework.
- Help monitor information security controls on an ongoing basis and flag deviations, gaps, or emerging risks to the Service Manager for escalation to the global GRC team.
- Coordinate the annual risk assessment process for selected applications by gathering data, coordinating stakeholder input, and drafting supporting documentation.
- Contribute to the preparation of annual reports and governance materials, including drafting content and compiling data for C-level presentations.
- Assist in disseminating GRC training materials and coordinating regional awareness sessions, including scheduling, content adaptation, and tracking participation.
- Maintain and update trackers/logs of newly identified IT risks and compliance gaps, ensuring accurate documentation before escalation to the global GRC team.
- Support certification lifecycle activities (e.g., audit scheduling, evidence readiness checks, tracking remediation actions) for relevant frameworks.
- Conduct research on regional regulatory requirements and summarize findings to support the Service Manager's representation of regional needs within the global team.
- Assist with ad hoc reporting, data analysis, and documentation requests from internal stakeholders, auditors, or the global GRC team.
Requirements
- Bachelor's degree in IT, Cybersecurity, or a relevant business discipline.
- 2-4 years of relevant IT, security, or compliance experience.
- Exposure to security frameworks such as NIST or ISO preferred.
- Experience supporting audits, assessments, or compliance projects is a plus.
- Familiarity with GDPR or other EU regulatory requirements is advantageous but not required.
- Strong Excel/PowerPoint skills for reporting and documentation support.
Skills
- Foundational knowledge of information security risk management, governance, and compliance principles and practices.
- Basic understanding of information systems auditing, control monitoring, and risk assessment concepts.
- Strong research and data-gathering skills, with the ability to synthesize information from internal and external sources.
- Ability to define problems, collect and analyze data, and draw clear, well-supported conclusions.
- Clear written and verbal communication skills, with the ability to translate technical information for varied audiences.
- Strong organizational skills and attention to detail, particularly with sensitive or confidential information.
- Ability to learn quickly, adapt to new tools/frameworks, and work effectively in a fast-paced, evolving environment.
- Good collaboration and stakeholder support skills; customer-service mindset.
- Eagerness to build functional GRC expertise and grow into more senior compliance/certification roles.
Benefits
- Immediate medical, dental, vision, and prescription drug coverage.
- Flexible family care.