Information Security Sr Anlyst

OTSICary, NC
Onsite

About The Position

Object Technology Solutions, Inc (OTSI) has an immediate opening for a Sr. Information Security Analyst - GRC. This role involves supporting independent certification and audit by working with D&IT peer groups and lines of business to collect documentation and evidence of security policies and operations. It also includes requesting and reviewing documentation and evidence from control owners to certify and validate compliance to standards and industry-accepted best practice. The analyst will monitor the regulatory and legal landscape globally and across market sectors, maintaining awareness of compliance requirements. Additionally, the role involves acting as an informed voice in policy development, ensuring alignment with regulatory, legal, and contractual requirements, and assisting in the establishment and enforcement of standards of practice documentation. The position also supports the establishment, collection, and improvement of metrics to measure the effectiveness of cyber risk management and provide data-driven insights. Collaboration with peer D&IT groups to collect KPIs and KRIs, and driving efficiency through automation are key aspects. The role contributes subject matter expertise to the third-party risk assessment process, identifying and communicating vendor engagement risks and mitigation actions. Assisting in the review of client security requirements in contracts and aggregating relevant clauses to inform contractual risk is also part of the responsibilities. Miscellaneous duties include assisting in the development of user training aligned with the cyber threat landscape, establishing and implementing metrics, proposing enhancements, supporting internal audit, and assisting with security certifications/attestations/audits. The analyst will also assist in the development of risk treatment plans and monitor action progress, collaborating with the GRC team for timely and quality deliverables, and contributing expertise to GRC-related requests.

Requirements

  • Bachelor’s degree in information systems, Information Security, or a related field
  • 7–10 years of experience in GRC executing or auditing against standards, frameworks, and industry regulations
  • Demonstrated experience supporting GRC functions for global companies
  • Solid proficiency in risk assessment methodologies and frameworks
  • Proven ability to assess alignment of internal policy, process, control design and operations, and cyber risk management with regulatory standards and frameworks
  • Strong collaboration with IT teams
  • Familiarity with industry standards and frameworks (e.g., NIST CSF and supporting SP’s, ISO 27001, AICPA SOC)
  • Working knowledge of cyber and privacy laws and regulations
  • Solid understanding of information security principles and concepts
  • Strong desire to create task and functional efficiencies through use of technology and tools, especially GenAI
  • Attention to detail and critical thinking
  • Ethical judgment and integrity
  • Ability to manage multiple tasks and deadlines
  • Strong interpersonal and stakeholder engagement skills

Nice To Haves

  • Strong analytical, organizational, and communication skills
  • Professional certifications such as CRISC, CISSP or others
  • Experience with ServiceNow Risk Management platform
  • Knowledge of FAR, DFARS, CMMC
  • Experience with GRC platforms and risk management methodologies
  • Ability to work independently and collaboratively as required

Responsibilities

  • Contract Risk Management
  • Regulatory Compliance Risk Management
  • IT Governance
  • Cyber Risk Management
  • Supplier/Third Party Risk Management
  • Assist development of user training aligned with cyber threat landscape
  • Support internal audit
  • Assist with security certification/attestations/audits to demonstrate control effectiveness to independent service auditors/assessors and C3PAO’s
  • Assist in development of risk treatment plans and monitoring progress of actions.
  • Collaborate with members of the GRC team to ensure timely and quality deliverables to internal and external customers
  • Contribute subject matter expertise in review and response to internal and external sourced GRC related requests
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service