GRC Consultant-68498

HitachiFort Worth, TX
Onsite

About The Position

Join our Information Security Governance, Risk, and Compliance (GRC) team, where we partner with Security Engineering, IT, Legal, Privacy, Internal Audit, and business teams to strengthen the organization's security and compliance posture. Our team is responsible for establishing effective security governance, identifying and managing technology risks, maintaining alignment with industry and regulatory frameworks, and supporting internal and external audits. In this role, you will help embed security and risk management into day-to-day business operations while improving control monitoring, evidence collection, GRC processes, and compliance automation.

Requirements

  • 5–7 years of experience in GRC, Information Security, IT Risk, IT Audit, Cybersecurity Compliance, or related areas.
  • Hands-on experience conducting security and technology risk assessments.
  • Strong experience supporting internal and/or external audits end to end.
  • Working knowledge of at least two major security frameworks, such as ISO 27001, SOC 2, NIST CSF/800-53, or PCI-DSS.
  • Experience with control mapping, control testing, evidence collection, and remediation tracking.
  • Experience maintaining risk registers and managing risk-remediation activities.
  • Familiarity with third-party/vendor risk management.
  • Understanding of security controls across cloud environments such as AWS, Azure, or GCP, as well as identity and infrastructure.
  • Strong documentation, communication, analytical, and stakeholder-management skills.
  • Bachelor's degree in a related field or equivalent professional experience.

Nice To Haves

  • CISA, CRISC, CISSP, ISO 27001 Lead Implementer/Auditor, or CompTIA Security+ certification.
  • Hands-on experience with GRC platforms such as ServiceNow GRC/IRM, Archer, OneTrust, Vanta, or Drata.
  • Experience with cloud compliance and continuous-control-monitoring tools.
  • Exposure to compliance automation.
  • Awareness of AI governance, AI risk management, or emerging technology governance.

Responsibilities

  • Maintain and update information security policies, standards, procedures, and security-control documentation.
  • Track policy exceptions and support remediation and governance processes.
  • Translate regulatory, security, and compliance requirements into operational controls.
  • Define, track, and report security metrics and KPIs to support leadership visibility and decision-making.
  • Conduct security risk assessments across applications, systems, infrastructure, business processes, and vendors.
  • Maintain the enterprise risk register and track identified risks, remediation plans, owners, due dates, and residual risk.
  • Perform third-party/vendor security risk assessments and due diligence.
  • Support business impact analysis and risk-treatment decisions.
  • Partner with stakeholders to identify control gaps and drive remediation activities.
  • Map and assess controls against security and compliance frameworks including: ISO 27001, SOC 2, NIST CSF / NIST 800-53, PCI-DSS, GDPR, HIPAA, and other applicable privacy/regulatory requirements.
  • Coordinate internal and external audits from evidence gathering through findings closure.
  • Manage audit evidence requests, control testing, findings, and remediation tracking.
  • Support continuous control monitoring and evidence-collection initiatives.
  • Support security certification and attestation programs.
  • Partner with Security Engineering, Cloud, Infrastructure, IAM, IT, Legal, and business teams to validate control implementation.
  • Support security awareness, policy adoption, and governance initiatives.
  • Help mature GRC processes and platforms.
  • Identify opportunities to automate manual compliance, control monitoring, and evidence-collection activities.
  • Support emerging governance areas including cloud security and AI governance.

Benefits

  • industry-leading benefits
  • support
  • services that look after your holistic health and wellbeing
  • flexible arrangements that work for you (role and location dependent)
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service