BambooHR-posted 3 months ago
Full-time • Entry Level
UT
1,001-5,000 employees

The GRC Analyst is a key member of BambooHR’s GRC team responsible for evaluating and supporting compliance initiatives covering information security, policy, risk management, data classification, vendor management, privacy, audit, and awareness. This position assists other members of the GRC team with implementing information security policies and documentation, assessing compliance with existing policies, and ensuring overall compliance with security-related requirements from customers. In addition, this position assists with performing security assessments and monitoring and tracking compliance status; developing and improving processes, procedures, standards, and guidance; providing guidance on security control implementation; and implementing process improvement and maturity initiatives. The position will also assist in evaluating risks and controls to support the company’s NIST CSF, ISO 27001, ISO 27018, ISO 42001, SOC 1, SOC 2, HITRUST, FedRAMP, and other regulatory and compliance initiatives. Success in this role requires a good understanding of information security best practices, strong security knowledge, the ability to understand and communicate risk and controls, organization, planning, good communication, and writing skills.

  • Work with internal stakeholder teams to document the implementation of security compliance control implementations for technical, management, and operational requirements
  • Conduct gap analysis of current policies, procedures, and practices as they relate to established guidelines outlined by NIST, FISMA, HIPAA, and other regulatory standards
  • Conduct risk assessments of technology infrastructure and operational processes and controls for assigned areas
  • Embrace AI as an essential tool for improving GRC accuracy, efficiency, and proactive risk management
  • Use AI-powered platforms for continuous controls monitoring, predictive risk assessments, and identifying compliance gaps while incorporating responsible AI use into practices
  • Improve efficiency in evidence collection and analysis, allowing the team to begin shifting time toward higher-value GRC activities with AI support
  • Build and maintain the controls matrix, in alignment with multiple compliance frameworks, including SOC 1 & SOC 2, PCI DSS, NIST CSF, ISO 27001, ISO 27018, ISO42001, HITRUST, and HIPAA
  • Develop and maintain security documentation such as the System Security Plan, Privacy Impact Assessment, Configuration Management Plan, Contingency Plan, Contingency Plan Test Report, POA&M, annual FISMA assessment, and incident reports
  • Assist in delivering and maintaining information security training and awareness programs
  • Perform vendor management/security risk assessments and interface with vendors on occasion
  • Track efforts related to threat and vulnerability assessment processes to monitor and remediate vulnerabilities in a timely manner
  • Bachelor's degree in Computer Science, Information Technology, or related field
  • Minimum of 1 year of experience in compliance, audit, and/or information security
  • CISSP, CISA, CCSA, or equivalent certification preferred
  • Familiarity with enterprise-level compliance tools such as Drata, Vanta, ServiceNow, Archer, IBM GRC or other industry equivalent software
  • Foundational understanding and eagerness to learn FedRAMP, NIST CSF, FISMA, NIST RMF, NIST FIPS 199, ISO 27001, ISO 27018, ISO 42001, SOC 1, SOC 2, HIPAA and HITRUST
  • Basic understanding of cloud based environments for production applications, including Amazon Web Services, Google Cloud, or other large-scale cloud deployments
  • Experience in the vulnerability assessment lifecycle from the point of identification to remediation
  • Interpersonal skills to work as a team member and as a liaison
  • Excellent verbal communication, presentation, organizational and planning skills, and great attitude and ability to learn new things quickly
  • Comprehensive health, life, and disability insurance
  • Generous leave policies that include 4 weeks of vacation, 12 company holidays, parental leave, and volunteer time off
  • 401k plans with up to 6% company match
  • $2000 Paid-Paid Vacation bonus
  • EAP through Headspace
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service