Technical Security Risk & Governance Analyst - 26-01643

NavitasPartnersHarrisburg, PA
13hHybrid

About The Position

"Navitas Partners, LLC" is seeking a Technical Security Risk & Governance Analyst to support enterprise cybersecurity risk, compliance, and governance initiatives. This role conducts risk assessments, control testing, audit coordination, and GRC activities across on-prem, cloud (IaaS/PaaS/SaaS), and hybrid environments.

Requirements

  • Bachelor’s degree in Information Security, IT, Computer Science, or related field (or equivalent experience).
  • 3+ years of experience in information security, risk management, or audit.
  • Hands-on experience with technical assessments, configuration validation, and vulnerability interpretation.
  • Experience using GRC tools and developing risk treatment plans.
  • Strong knowledge of IAM, network security, encryption, SIEM/logging, and cloud security principles.
  • Strong analytical, documentation, and executive communication skills.

Nice To Haves

  • Preferred Certifications: CISSP, CISM, CRISC, CGRC (CAP), Security+, CCSK/CCSP, CISA.
  • AWS/Azure cloud security certifications.

Responsibilities

  • Perform technical risk assessments; document likelihood, impact, and mitigation plans.
  • Conduct control testing aligned with NIST CSF/800-53, CIS Controls, ISO 27001 , and applicable regulatory requirements (CJIS, IRS Pub 1075, HIPAA, FERPA, PCI DSS).
  • Support ATO processes, security attestations, and continuous monitoring.
  • Manage policies, standards, control libraries, and risk registers within GRC platforms.
  • Coordinate internal/external audits, evidence collection, and remediation tracking.
  • Govern vulnerability management (SLA tracking, exceptions, risk acceptance).
  • Perform third-party/vendor security reviews (SOC 2, ISO certifications, cloud providers).
  • Develop dashboards (Excel/Power BI) and present risk posture to leadership.
  • Provide security guidance for incidents and change management activities.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service