GRC Analyst

NorthMark StrategiesDallas, TX
Onsite

About The Position

NorthMark Compute & Cloud (NMC²) is seeking a GRC Analyst to join its Information Security team. This role is crucial for the operational success of NMC²’s security governance program, focusing on processes, documentation, and cross-functional coordination to maintain compliance and understand risk exposure. The analyst will manage the security change management review process, conduct risk and vendor assessments, maintain the enterprise risk register, and oversee the lifecycle of the security policy library. This position requires close collaboration with Engineering, Product, Legal, and Operations teams, acting as a liaison between technical groups and governance structures. The ideal candidate is adept at authoring policy documents, facilitating risk workshops, and presenting risk summaries to senior leadership, demonstrating strong judgment in applying governance effectively and designing practical processes.

Requirements

  • Bachelor’s degree in Information Systems, Computer Science, Business Administration, or a related field — or equivalent experience.
  • 4–8 years of experience in GRC, information security governance, compliance, or risk management.
  • Hands-on experience owning or significantly contributing to security change management, risk assessment, or policy management processes.
  • Working knowledge of at least two major security frameworks or standards — ISO 27001, SOC 2 TSC, NIST CSF, NIST SP 800-53, or CIS Controls.
  • Experience developing, reviewing, and publishing information security policies, standards, and procedures.
  • Familiarity with risk register management: identifying, rating, tracking, and reporting on information security risks.
  • Experience with GRC or compliance automation platforms such as ServiceNow GRC, Vanta, Drata, Hyperproof, or Archer.
  • Proficiency with project and workflow tools (Jira, Confluence, or similar) for change tracking, risk registers, and policy workflows.
  • Strong written communication skills with the ability to translate technical security requirements into clear, accessible policy language for a non-technical audience.
  • Collaborative working style with demonstrated experience engaging stakeholders across Engineering, Legal, HR, and Operations.
  • Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.

Nice To Haves

  • One or more relevant certifications preferred: CISM, CRISC, CISA, CISSP, ISO 27001 Lead Implementer or Lead Auditor, or CompTIA Security+.

Responsibilities

  • Own and operate the security change management review process — triaging incoming IT and infrastructure change requests, engaging Engineering and IT stakeholders, and documenting findings, approvals, and escalations.
  • Iterate on change management processes, runbooks, and risk criteria to reduce friction for low-risk changes while preserving appropriate rigor for high-risk ones.
  • Conduct security reviews for new products, features, third-party integrations, and vendor onboarding, applying a consistent risk-based assessment methodology and tracking remediation of identified gaps.
  • Facilitate threat identification workshops and risk discussions with Engineering, Product, and Operations for major initiatives or architectural changes.
  • Maintain and continuously improve the enterprise Information Security risk register, ensuring risks are clearly articulated, owned, prioritized, and tracked through to mitigation or acceptance.
  • Develop risk reporting dashboards and narrative summaries for the CISO and executive leadership; monitor the regulatory and threat landscape for emerging risks that warrant program attention.
  • Author, revise, and manage the organization’s information security policy library — policies, standards, procedures, and guidelines — aligned to applicable frameworks including ISO 27001, SOC 2, and NIST CSF.
  • Manage the security exception process: collect requests, facilitate risk-based approvals with the GRC Manager, and track expiry and renewal.
  • Monitor adherence to governance processes across the business (change management, access reviews, training, exception management) and produce compliance metrics for security leadership.
  • Serve as a day-to-day point of contact for Engineering, Product, Legal, HR, and Operations on security governance questions, and represent the Information Security team in cross-functional forums such as the Change Advisory Board and Risk Committee.

Benefits

  • Company-Paid Lunch Stipend via GrubHub
  • 100% Employer-Paid Medical in High Deductible Health Plan
  • Dental and Vision benefits for employees and their families
  • 16 weeks of Paid Parental Leave
  • Employee Assistance Program
  • Life insurance
  • Short-Term Disability and Long-Term Disability
  • 401(k) with Company match (100% of contributions up to 6%)
  • Optional Employee-Paid Benefits: Medical insurance in PPO plan, Health Savings Accounts (with Company Contribution!), Flexible Spending Accounts, Supplemental Life Insurance, Wellhub
  • 25 days of Paid Time Off
  • 12 company holidays
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service