(GRC) Cybersecurity Analyst ( Full-time ) Atlanta, GA - DK
$95,000–$110,000 year
On-siteAtlanta, Georgia, United States
Job Summary
Monitor information systems for security incidents and vulnerabilities, responding promptly to mitigate threats and collaborating with IT teams to deploy firewalls and intrusion detection systems. Conduct regular risk assessments and security audits to identify weaknesses, analyze breaches to determine root causes, and develop strategies to prevent future occurrences. Develop and implement security policies, procedures, and protocols while providing training and awareness programs for faculty, staff, and students. Prepare reports on cybersecurity status, serve as a liaison with external agencies, and lead the development of enterprise-wide security policies and risk assessments. Validate control implementation against NIST, DFARS, and CMMC frameworks, coordinate audits and regulatory reviews, and mentor junior analysts. Interpret laws and standards for complex infrastructures, drive process improvements, and lead GRC projects and initiatives.
Required Qualifications
- Bachelor's degree in cybersecurity, information security, information assurance, or a related field, or an equivalent combination of education and experience
- 5+ years of progressively responsible experience in governance, risk, compliance, or information security in a complex environment
- Strong practical knowledge of security technologies and controls, as well as operating system platforms including Windows, macOS, Linux, and core networking technologies
- Demonstrated experience with vulnerability management processes and tools, including scanning, reporting, prioritization, and remediation tracking
- Solid understanding of threats, vulnerabilities, exploitation techniques, and how they map to business risk
- Advanced experience with data analysis and reporting in Excel (pivot tables, lookups, intermediate/advanced formulas; scripting or macros a plus)
- Proven ability to assess and communicate the priority and business impact of vulnerabilities and risks to both technical and non-technical stakeholders
- Excellent written and verbal communication skills, including experience drafting policies, standards, and executive-level summaries
- One or more intermediate or advanced cybersecurity/GRC certifications such as CISSP, CISM, CISA, SecurityX, CCNP-Security, or equivalent
Desired Qualifications
- Master's degree in cybersecurity, information security, information assurance, business, or a related field
- Deep understanding of cybersecurity frameworks and best practices such as NIST 800-53/171, CMMC, RMF, MITRE ATT&CK, and OWASP Top 10
- Demonstrated experience leading audit, assessment, or certification efforts (e.g., NIST, CMMC, DFARS, FedRAMP, or similar)
- Experience developing and tracking security and compliance metrics for remediation stakeholders and leadership
- Strong knowledge of common vulnerability categorizations and scoring systems such as CVE, CVSS, and CWE
- Proficiency with Atlassian Confluence for documentation and knowledge management
- Proficiency with Atlassian Jira for workflow, issue tracking, and project management
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.