Position Overview:
As a Security GRC Analyst, you will support and operate key security and governance processes within the IT department. Reporting to the Senior Director of IT, this role combines security operations, governance execution, and compliance readiness. The immediate focus is assisting with SOC 2 readiness and remediation while helping operate the company's security program across Microsoft 365, Azure, and internal platforms.
This role is ideal for a security-focused analyst who enjoys investigating alerts, improving security controls, and strengthening governance processes. You will work closely with engineering, IT administrators, and business teams to ensure security controls operate effectively and that the organization continues to mature its security posture over time.
Key Responsibilities:
Security operations and incident investigation
- Monitor and triage alerts from Arctic Wolf MDR and other security monitoring tools.
- Investigate suspicious activity or unusual behavior/patterns.
- Document investigation findings, coordinate remediation actions with IT and engineering teams, and track closure of security issues.
- Support root cause analysis and corrective actions following security incidents.
- Maintain investigation records and evidence to support security monitoring controls.
SOC 2 readiness and remediation
- Assist with remediation of SOC 2 control gaps and readiness activities for the upcoming audit.
- Map remediation tasks to SOC 2 control objectives and track implementation progress in Azure DevOps.
- Coordinate with control owners to implement and test controls.
- Build and maintain audit evidence repositories with traceability from policy to procedure to operational artifacts.
- Participate in internal readiness reviews and assist with auditor requests.
Policy, controls, and governance operations
- Draft, revise, and operationalize policies and SOPs related to information security, access control, change management, incident response, acceptable use, and business continuity.
- Maintain the control library, RACI assignments, and governance review calendar in SharePoint.
- Ensure policies and procedures remain aligned with SOC 2 and internal operational practices.
Insider risk monitoring and security posture improvement
- Support the development of insider risk monitoring processes and investigations.
- Assist with identifying abnormal internal behavior patterns that may indicate security or data protection concerns.
- Contribute to improvements in monitoring, detection, and security response processes.
Qualifications:
- 4 to 6 years experience in IT governance, GRC, security operations, or IT risk management.
- Experience supporting SOC 2, ISO 27001, or similar security frameworks.
- Experience investigating security alerts or supporting incident response activities.
- Working knowledge of identity and access management, vulnerability management, and security monitoring processes.
- Familiarity with Microsoft 365 security features, Entra ID, and Azure environments.
- Strong documentation, investigation, and communication skills.
- Experience collaborating with both technical teams and business stakeholders.
Why Join Us
- Competitive compensation and benefits package.
- Integral role in a highly stable team within a rapidly growing company.
- Opportunities for professional development and career progression.
- Emphasis on work-life balance as a core element of our culture.
- Involvement in cutting-edge projects leveraging the latest cloud technologies.