Skip to Content
All roles

Cybersecurity GRC Analyst (Junior)

Richmond, VA Remote Full-time

Posted 09/23/2026

As a Junior GRC & Information Security Analyst, you will support the execution of the organization’s risk, compliance, and audit readiness programs. You will assist with risk assessments, control reviews, audit preparation, and evidence collection across frameworks such as NIST CSF, NIST 800-53, ISO 27001, and SOC 2. In this role, you will work with internal teams to identify control gaps, maintain risk registers and compliance documentation, support third-party vendor reviews, and help track risk acceptances and exceptions through closure. You will also assist with customer security questionnaires, maintain the evidence library, and support control mapping across frameworks to reduce duplicate testing. This position is ideal for a detail-oriented junior professional looking to build hands-on experience in GRC, information security compliance, audit support, and third-party risk management.
Apply for this role →

What you will do

  • Support monitoring of organizational policies, procedures, and controls to help ensure compliance.
  • Assist with risk assessments, documentation, and audit preparation.
  • Work with teams across departments to identify weaknesses and support risk mitigation activities.
  • Analyze data for potential security gaps and assist with preparing reports for management.
  • Help maintain the enterprise risk register and track risk acceptances and exceptions through to closure.
  • Support third-party and vendor security reviews and maintain the vendor risk tier model.
  • Assist with inbound customer security questionnaires and maintain the evidence library.
  • Support control mapping across frameworks to reduce duplicate testing, including NIST CSF, ISO 27001, and SOC 2.

What we are looking for

  • 0-2 years in GRC, information security, or IT audit.
  • Bachelor's degree in information security, business, or related field — equivalency accepted.
  • Working knowledge of NIST CSF 2.0, NIST 800-53, ISO 27001, and SOC 2; HIPAA or PCI by vertical.
  • Hands-on experience with a GRC platform.
  • Strong written communication — the deliverable is a report to management.

Nice to have

  • CRISC, CISM, CISA, or CISSP. CRISC indexes higher here than in any other title on this board.
  • Risk methodology exposure — COBIT or FAIR.
  • Vendor risk program ownership.

Skills and expertise

NIST CSF 2.0 NIST 800-53 ISO 27001/27002 SOC 2 COBIT FAIR RSA Archer ServiceNow GRC LogicManager Vanta Drata Secureframe

Ready to apply?

Apply for this role →