GRC Analyst - Seattle
Motion Recruitment · Seattle, WA · Yesterday
HybridFull-time
About the role
A leading organization seeks a Governance, Risk & Compliance (GRC) Analyst for a hybrid role based in Seattle.
Responsibilities
- Developing, implementing, and monitoring GRC policies and procedures aligned with industry standards and regulatory frameworks like SOX, PCI-DSS, NIST, ISO 27001, and TSA.
- Conducting thorough risk assessments, identifying, and documenting mitigation strategies.
- Managing governance workflows, supporting audit teams, overseeing compliance documentation, and tracking remediation of issues.
- Developing and delivering risk and compliance awareness training for staff.
- Collaborating with cross-functional teams for business continuity planning and policy management.
- Assisting with vendor risk management and due diligence.
- Preparing reports and dashboards on risk status for leadership.
Requirements
- Strong knowledge of GRC concepts, methodologies, and frameworks (e.g., COBIT, NIST CSF, ISO 27001).
- Experience with risk assessments, control testing, and audit support.
- Familiarity with GRC tools or governance/security platforms.
- Excellent communication and analytical skills.
- Bachelor’s degree in Information Security, Business, or related field, or equivalent experience.
Qualifications
- Desired: Security or GRC certifications (CISA, CISM, CRISC, CISSP, or comparable).
- Desired: Experience responding to government or regulatory oversight (TSA, FAA, etc.).
Skills
- Strong knowledge of GRC concepts, methodologies, and frameworks (e.g., COBIT, NIST CSF, ISO 27001).
- Experience with risk assessments, control testing, and audit support.
- Familiarity with GRC tools or governance/security platforms.
- Excellent communication and analytical skills.
Benefits
- Medical Insurance
- Dental Benefits
- Vision Benefits
- Paid Time Off (PTO)
- 401(k) {including match – if applicable}