Search Jobs

Search by job, company or skills

Information Security & GRC Junior Analyst

Information Security & GRC Junior Analyst

GetLocal DataMatics
1-3 Years
  • Posted an hour ago
  • Be among the first 10 applicants

Job Description

Role Summary The Information Security Analyst (GRC) is responsible for supporting governance, risk, and compliance activities across all company sites and client programs. The role ensures adherence to ISO 27001, SOC 2 Type II, and PCI DSS requirements by maintaining security controls, supporting audits, managing risks, and enforcing information security policies across both onsite and work-from-home environments.

Key Responsibilities

1. Governance and Policy Enforcement

• Support the implementation and maintenance of the Information Security Management System (ISMS) aligned with ISO 27001

• Enforce information security policies, standards, and procedures across all sites and programs

• Monitor compliance with internal security policies and escalate non-compliance issues

2. Risk Management

• Perform and maintain risk assessments for systems, processes, and client programs

• Maintain and update the risk register, including risk treatment plans and acceptance records

• Track remediation activities and ensure timely closure of identified risks

3. Compliance and Audit Support

• Support ISO 27001, SOC 2 Type II, and PCI DSS compliance activities across all sites

• Perform control testing and validation to ensure effectiveness of implemented controls

• Collect, review, and maintain audit evidence and documentation

• Coordinate with internal teams and external auditors during audits and assessments

• Track audit findings and ensure proper remediation and closure

4. Access Control Management

• Manage user access provisioning, modification, and deprovisioning across systems based on approved requests

• Perform periodic access reviews to ensure least privilege and segregation of duties

• Ensure compliance with access control policies and audit requirements

5. Security Monitoring and Incident Support

• Monitor security reports and alerts for policy violations and potential risks

• Investigate and document security exceptions and escalate where necessary

• Support incident response activities by providing documentation and compliance validation

6. Vendor and Client Compliance Support

• Assist in security due diligence for vendors and third-party services

• Support client security requirements, audits, and compliance requests

• Ensure alignment of internal controls with client contractual obligations

7. Continuous Improvement

• Identify gaps in controls, processes, and documentation and recommend improvements

• Support security awareness initiatives across the organization

• Assist in improving compliance maturity across multiple sites and programs

• Promote security awareness culture and reinforce secure practices across all employees and programs 8. Security Awareness and Training

• Support the development and delivery of the organization's security awareness program across all sites and WFH environments

• Conduct onboarding and periodic security awareness training aligned with ISO 27001, SOC 2, and PCI DSS requirements

• Track training completion, maintain records, and generate reports for audit and management review

• Assist in phishing simulations and awareness campaigns to improve user security behavior

• Update training materials to address emerging threats, policy changes, and audit findings

Minimum qualifications

  • Bachelor's degree in Information Technology, Computer Science, Computer Engineering, Cybersecurity, Information Systems or related field.
  • 1–2 years experience in IT, cybersecurity, IT audit, compliance, systems administration, network administration or related technology role.
  • Basic understanding of information security principles.
  • Basic understanding of IT general controls.
  • Good understanding of Windows, Microsoft 365, networking, endpoint security and access management is preferred.
  • Strong analytical and problem solving skills.
  • Strong documentation and report writing skills.
  • Good English written and verbal communication.
  • Strong attention to detail.
  • Ability to work with technical and nontechnical stakeholders.
  • Ability to manage evidence, documentation, trackers and deadlines.
  • Willingness to learn ISO 27001, SOC 2 and PCI DSS requirements.
  • Willingness to obtain relevant Information Security/GRC certification.
  • ISO 27001, Security+ or other cybersecurity certification is an advantage but not required.
  • BPO or IT services experience is preferred.

More Info

Job Type:
Industry:
Employment Type:

Key Skills

About Company