Governance, Risk, and Compliance Analyst

Pike•Baxter Village, SC
•Hybrid

About The Position

The GRC Analyst supports the organization’s governance, risk, and compliance program by maintaining policy and control documentation, coordinating risk assessments, tracking audit and compliance activities, and helping align the information security program with applicable regulatory and industry frameworks. This position partners with Information Security, IT, Human Resources, system owners, and business stakeholders to identify risks, monitor remediation, and maintain a mature, consistent, and auditable security posture.

Requirements

  • Bachelor’s degree in Information Security, Cybersecurity, Business, Computer Science, Information Technology, or a related field, or an equivalent combination of education and relevant experience.
  • Three or more years of experience in governance, risk, and compliance; IT audit; identity and access management audit; risk management; or information security compliance.
  • Working knowledge of at least one recognized information security or control framework, such as the NIST Cybersecurity Framework or CIS Controls.
  • Practical experience with Active Directory and Microsoft Entra ID, including user, group, role, and access reviews.
  • Knowledge of risk assessment methods, control design, control testing, audit evidence, and remediation tracking.
  • Ability to interpret technical and control information and communicate findings clearly to technical and non-technical stakeholders.
  • Experience using GRC, ticketing, workflow, or audit management tools, such as Jira, ServiceNow GRC, or Archer, and proficiency with standard Microsoft Office applications.
  • Strong organization, documentation, analytical, and follow-up skills with the ability to manage multiple concurrent audits, assessments, policy reviews, and remediation activities.
  • Ability to handle sensitive and confidential information with appropriate discretion.

Nice To Haves

  • Experience in a regulated industry, such as energy, utilities, financial services, healthcare, or critical infrastructure.
  • Knowledge of NERC CIP or other critical infrastructure compliance requirements.
  • Experience supporting SOC 2, SOX, or similar internal or third-party audits, including identity and access management control testing and evidence collection.
  • Experience with third-party or vendor risk management programs.
  • Relevant certification or progress toward certification, such as CISA, CRISC, CompTIA Security+, or ISO 27001 Lead Implementer.

Responsibilities

  • Maintain and update information security and identity and access management policies, standards, procedures, control narratives, and supporting documentation in alignment with applicable frameworks, including the NIST Cybersecurity Framework and CIS Controls.
  • Manage the risk register and risk acceptance process, including documenting identified risks, approved exceptions, compensating controls, owners, remediation plans, and periodic reviews.
  • Coordinate customer and vendor risk assessments and security questionnaires; maintain an organized library of approved responses, supporting artifacts, and reusable evidence.
  • Review customer, contractual, regulatory, and audit requirements to identify new or revised controls and documentation needs.
  • Support SOC 2 and other internal or external audits by assisting with planning, control walkthroughs, control mapping, evidence collection, issue tracking, and remediation follow-up.
  • Collect, validate, organize, and submit audit evidence, including access lists, approval records, recertification documentation, tickets, logs, and other control artifacts.
  • Develop and maintain audit procedures, workpapers, and runbooks to promote consistent and repeatable audit execution.
  • Prepare clear risk and compliance updates, metrics, and presentation materials for leadership, audit committees, and other stakeholders.
  • Perform periodic access reviews within Active Directory, Microsoft Entra ID, Oracle, and other in-scope applications to identify inaccurate, stale, orphaned, excessive, or unauthorized access.
  • Review joiner, mover, and leaver activities to validate that access is provisioned, modified, and removed timely and in accordance with least-privilege principles and job responsibilities.
  • Cross-reference HR and contractor data with system records to validate timely deprovisioning, appropriate contract end dates, and recurring access recertification.
  • Audit privileged and administrative account inventories, approvals, business justification, emergency access activity, time-bound access, and privileged access recertifications.
  • Review roles and entitlement combinations for segregation-of-duties conflicts, excessive access, and opportunities to simplify role design and reduce role sprawl.
  • Document audit findings, control gaps, discrepancies, risk decisions, remediation actions, owners, and target dates; maintain regular follow-up with responsible stakeholders.
  • Support role-based access provisioning workflows and periodic reviews of both role definitions and user assignments.
  • Perform other related duties as assigned to support the ongoing needs of the organization.

Benefits

  • Medical, dental and vision insurance
  • HSA, dependent care and medical flexible spending accounts
  • Employee Assistance Program (EAP)
  • 401(k) with company match
  • Life insurance, and short-term and long-term disability
  • Paid time off, paid holidays, and family and medical leave
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service