IT GRC Analyst
On-siteCovington, Louisiana, United States
Job Summary
Execute user access reviews, collect control evidence, and maintain the organization's risk register to support Globalstar's information security governance, risk, and compliance programs. Administer audit plans for SOC 2, ISO 27001, and SOX, coordinate with internal and external auditors, and prepare findings presentations to reduce organizational risk. Manage vendor third-party risk activities, including security questionnaire reviews and ongoing monitoring, while overseeing data privacy obligations under GDPR and CCPA. Utilize GRC tooling to automate compliance monitoring, produce accurate reporting, and streamline documentation for leadership review. Provide project coordination support for IT implementations, ensuring control requirements are met prior to go-live.
Required Qualifications
- Bachelor's degree in Business Administration, Information Systems, Risk Management, Security Management, or equivalent work experience
- 2–5 years of progressive experience in IT governance, risk, and compliance, IT audit, or a closely related discipline
- Demonstrated hands-on experience with SOC 2 and/or ISO 27001 audit or assessment cycles
- In-depth understanding of IT compliance frameworks and regulations such as NIST SP 800-53, SOC 2, SOX, CCPA, and GDPR
- Comprehensive knowledge of the concepts and principles of internal controls and regulatory compliance
- Willingness and ability to travel as needed
- Willingness and ability to work after regularly scheduled hours as needed
- Ability to sit at a desk for prolonged periods working on a computer (4 to 8 hours)
- Ability to operate the equipment used for the job
- Ability to lift 15 pounds at times
Desired Qualifications
- IT security and privacy certifications such as CISA, CISSP, CRISC, CISM, CIPM, or CDPSE preferred
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.