The analyst will be responsible for building and executing internal compliance assessments, with a strong focus on governance, risk, and compliance activities.
Key Requirements:
• Hands-on experience with GRC platforms/tools (client currently uses AuditBoard; experience with Archer or similar tools is acceptable)
• Strong understanding of control framework mapping and governance
• Ability to map IT and cybersecurity controls to industry-recognized frameworks and standards, including:
– NIST CSF
– CIS Critical Security Controls
– PCI DSS
GRC, Reporting & Documentation:
• Maintain assessment artifacts, evidence, and workpapers within approved GRC tools and internal documentation repositories
• Ensure traceability between controls, evidence, risks, and framework requirements to support audits and regulatory inquiries