All roles
Apply for this role →
Cybersecurity GRC Analyst (Junior)
Posted 09/23/2026
As a Junior GRC & Information Security Analyst, you will support the execution of the organization’s risk, compliance, and audit readiness programs. You will assist with risk assessments, control reviews, audit preparation, and evidence collection across frameworks such as NIST CSF, NIST 800-53, ISO 27001, and SOC 2. In this role, you will work with internal teams to identify control gaps, maintain risk registers and compliance documentation, support third-party vendor reviews, and help track risk acceptances and exceptions through closure. You will also assist with customer security questionnaires, maintain the evidence library, and support control mapping across frameworks to reduce duplicate testing. This position is ideal for a detail-oriented junior professional looking to build hands-on experience in GRC, information security compliance, audit support, and third-party risk management.
What you will do
- Support monitoring of organizational policies, procedures, and controls to help ensure compliance.
- Assist with risk assessments, documentation, and audit preparation.
- Work with teams across departments to identify weaknesses and support risk mitigation activities.
- Analyze data for potential security gaps and assist with preparing reports for management.
- Help maintain the enterprise risk register and track risk acceptances and exceptions through to closure.
- Support third-party and vendor security reviews and maintain the vendor risk tier model.
- Assist with inbound customer security questionnaires and maintain the evidence library.
- Support control mapping across frameworks to reduce duplicate testing, including NIST CSF, ISO 27001, and SOC 2.
What we are looking for
- 0-2 years in GRC, information security, or IT audit.
- Bachelor's degree in information security, business, or related field — equivalency accepted.
- Working knowledge of NIST CSF 2.0, NIST 800-53, ISO 27001, and SOC 2; HIPAA or PCI by vertical.
- Hands-on experience with a GRC platform.
- Strong written communication — the deliverable is a report to management.
Nice to have
- CRISC, CISM, CISA, or CISSP. CRISC indexes higher here than in any other title on this board.
- Risk methodology exposure — COBIT or FAIR.
- Vendor risk program ownership.
Skills and expertise
NIST CSF 2.0
NIST 800-53
ISO 27001/27002
SOC 2
COBIT
FAIR
RSA Archer
ServiceNow GRC
LogicManager
Vanta
Drata
Secureframe