Cybersecurity GRC Analyst

Follett Content Solutions LLCMchenry, IL
$115,000 - $120,000Hybrid

About The Position

Follett Content Solutions is seeking a Cybersecurity GRC Analyst to strengthen the organization’s governance, risk, and compliance posture. This role involves formalizing IT policies, operationalizing Microsoft Purview, and ensuring audit readiness. The analyst will align security practices with business risk, regulatory requirements, and industry frameworks like SOC 2, NIST CSF, and PCI DSS. This position is crucial for managing governance initiatives, including evidence collection, control mapping, and coordination with external auditors and consultants. The role requires developing and maintaining policies for device management, identity, and data handling, overseeing data classification, DLP, insider risk, and compliance reporting through Microsoft Purview. It also involves partnering with the Cybersecurity Specialist and SOC provider, tracking remediation activities, supporting risk assessments, and ensuring timely closure of audit findings. The analyst will maintain documentation for audit readiness and leadership reporting, lead cybersecurity awareness training, and monitor emerging regulatory trends to ensure ongoing resilience and compliance.

Requirements

  • 7-10 years experience
  • Bachelor’s degree or equivalent in Computer Science, Information Systems, Cybersecurity, or related discipline OR demonstrated ability to meet job requirements through comparable years of applicable work experience.
  • 7+ years related experience in IT, cybersecurity operations, or governance, risk, and compliance.
  • Strong written and oral communication skills with the ability to positively engage with business stakeholders, IT management, and external auditors.
  • Experience with Microsoft Purview, Intune, Defender, SentinelOne, or similar governance/security platforms.
  • Familiarity with compliance frameworks such as SOC 2, PCI DSS, ISO 27001, and NIST CSF.
  • Ability to translate business requirements and risks into actionable governance and compliance controls.
  • Knowledge of risk assessment procedures, policy formation, role-based authorization methodologies, and incident response governance.
  • Solid project management skills, especially in cross-functional environments involving external vendors or auditors.
  • Strong team-oriented interpersonal skills; ability to effectively interface with diverse teams across all levels of the organization.
  • Previous experience coordinating with third-party providers, consultants, or auditors for compliance initiatives.
  • Experience creating leadership ready documentation, dashboards, or reports that communicate compliance posture, risk trends, or remediation progress.
  • Prior involvement in security awareness training programs or organizational compliance initiatives.
  • Experience supporting or implementing role based access controls (RBAC), least privilege models, or identity governance processes.
  • Experience coordinating with external auditors, consultants, or managed service providers for compliance, risk, or governance initiatives.
  • Background working with IT Operations, Infrastructure, or Application Development teams to implement governance controls, close audit gaps, or deploy compliance related tooling.

Responsibilities

  • Develops and maintains policies, standards, and procedures across device management, identity, and data handling.
  • Operationalizes data classification, DLP, insider risk, and compliance reporting through Microsoft Purview.
  • Partners with the Cybersecurity Specialist and SOC provider to integrate governance with operational telemetry.
  • Tracks remediation activities, supports risk assessments, and ensures timely closure of audit findings.
  • Maintains documentation for audit readiness and leadership reporting.
  • Leads annual cybersecurity awareness training efforts and promotes a culture of compliance.
  • Monitors emerging regulatory trends and frameworks, recommending updates to policies, tools, and practices.
  • Drafts, maintains, and enforces IT security policies, standards, and procedures across device management, identity, and data handling.
  • Aligns governance practices with organizational risk appetite and regulatory requirements.
  • Ensures policies are auditable, scalable, and communicated effectively across the organization.
  • Serves as primary point of contact for SOC 2 Type II certification efforts, coordinating evidence collection and control mapping.
  • Supports PCI DSS self-assessment activities and other compliance initiatives.
  • Coordinates with external auditors, consultants, and vendors to ensure successful certification outcomes.
  • Assists in internal risk assessments, identifying gaps and recommending remediation strategies.
  • Partners with IT and business stakeholders to translate technical risks into business impact.
  • Monitors compliance telemetry and integrates findings into governance processes.
  • Ensures remediation activities are documented and aligned with organizational priorities.
  • Identifies and coordinates projects to close security gaps.
  • Works with IT Operations and Cybersecurity teams on tool deployments and implementation/tuning.
  • Works with Application Development teams on defining guardrails for AI initiatives to ensure AI agents are inventoried and managed properly.
  • Works closely with IT Stakeholders on identifying and prioritizing projects based on risk assessment.
  • Develops and deploys annual cybersecurity awareness training programs.
  • Promotes a culture of compliance and risk awareness across all levels of the organization.
  • Provides guidance and education on governance frameworks (SOC 2, NIST CSF, PCI DSS, CIS Controls).
  • Shares knowledge of emerging regulatory trends and best practices with leadership and staff.

Benefits

  • Reasonable accommodations to job applicants with disabilities
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service