Senior GRC / Third-Party Risk / Data Protection Analyst
$104,000–$166,000 year
RemoteUnited States
Job Summary
Own policy and control documentation, including authoring and maintaining security policies, procedures, standards, plans, and control documentation for the environment. Test controls and close POA&Ms by performing gap analysis against NIST SP 800-53 Rev. 5, documenting deficiencies, and managing remediation. Keep the program audit-ready by maintaining the control evidence library, GRC platform records, and compliance reporting to support the annual independent assessment. Run third-party security risk management through vendor due diligence, assessments, contract reviews, and continuous monitoring. Lead data protection by discovering confidential data, defining classification schemes, and implementing protective controls including DLP, encryption, and access controls. Support the insider threat program and carry regulated-data obligations for IRS Publication 1075 and ARC-AMPE compliance. Carry the regulated-data obligations. Support IRS Publication 1075 and ARC-AMPE compliance activities and the privacy obligations of the contract's Privacy Addendum; participate in the on-call incident response rotation.
Required Qualifications
- Bachelor's degree in information systems, cybersecurity, or business with a security concentration
- In lieu of a degree, an additional 4 years of relevant experience
- 8+ years of experience in security governance, risk, and compliance, third-party risk management, or data protection
- Active CISA or CGRC certification
- Demonstrated experience performing control assessment and gap analysis against NIST SP 800-53 Rev. 5, and managing the POA&M lifecycle from deficiency identification through closure
- Demonstrated third-party and vendor security risk management experience, including questionnaire-based assessment frameworks such as SIG or CAIQ, contract and control review, and continuous monitoring
- Hands-on experience with data classification and data-flow mapping, and with an enterprise DLP platform such as Microsoft Purview, Netskope, or Forcepoint
- Precise compliance writing ability — policies, control narratives, and deficiency write-ups that withstand external review — and working knowledge of an enterprise GRC platform
- US Citizenship
- The ability to pass a California criminal background clearance (Gov. Code §1043 / 10 CCR §6456) before starting work or accessing any confidential information, PII, PHI, federal tax information, or financial information
Desired Qualifications
- CIPP/US certification
- CRISC, CIPT, or CISM
- Experience with ARC-AMPE security and privacy requirements
- Experience with IRS Publication 1075 and FTI safeguarding, including participation in a Safeguard Review
- Working knowledge of HIPAA/HITECH and the California Consumer Privacy Act
- Experience with CMS requirements and Authority to Connect support, including Security Assessment Workbooks (SAWs), security assessment reports, and control evidence packages
- Experience in California state government compliance environments
- Experience with health benefit exchange or Medicaid eligibility systems
- Experience with encryption and key management concepts and with insider threat program design
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.