×
Register Here to Apply for Jobs or Post Jobs. X

GRC Analyst

Job in Boston, Suffolk County, Massachusetts, 02298, USA
Listing for: Trigent Software Inc
Full Time position
Listed on 2026-07-25
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, IT Business Analyst, IT Consultant
Salary/Wage Range or Industry Benchmark: 95000 - 130000 USD Yearly USD 95000.00 130000.00 YEAR
Job Description & How to Apply Below

Title: GRC Analyst
Location:
Boston, MA (Onsite once in a month)

Duration: 12 Months (Possible Extension)

Summary: We are seeking a highly analytical and experienced GRC Analyst to lead risk assessments, draft robust security policies, and ensure compliance across global frameworks. In this role, you will bridge the gap between technical security measures and regulatory requirements.

The ideal candidate will have strong hands-on experience conducting Third-Party Risk Assessments
, performing comprehensive Gap Analyses
, and evaluating Product Risks
. Furthermore, given our global footprint, deep familiarity with GDPR alongside standard security frameworks (NIST CSF, ISO 27001) is critical.

Key Responsibilities
  • Comprehensive Risk Assessments:
    Conduct end-to-end Risk Assessments (RA) on internal systems, business processes, and emerging products (Product Risk Assessments) to identify and mitigate vulnerabilities.
  • Third-Party & Vendor Risk Management (TPRM):
    Lead security reviews on third-party vendors, partners, and SaaS tools to evaluate their security posture and ensure they meet organizational standards before onboarding.
  • Policy Drafting & Governance:
    Author, update, and implement comprehensive Information Security (IS) policies, standards, and guidelines aligned with industry best practices and global frameworks.
  • Regulatory Compliance & GDPR:
    Ensure continuous compliance with global data privacy regulations, specifically GDPR and US-specific requirements, coordinating closely with legal and privacy teams.
  • Gap Analysis & Audit Prep:
    Execute regular gap analyses against frameworks like NIST CSF and ISO 27001 to identify weaknesses in the current security posture and drive remediation plans.
  • Metrics & Reporting:
    Develop risk registers, track remediation efforts, and prepare performance dashboards for local and global leadership teams.
Required Qualifications & Skills
  • Experience:

    4+ years of dedicated experience in IT Governance, Risk, and Compliance (GRC) or IT Audit.
  • Framework Mastery:
    Strong working knowledge of NIST CSF, ISO/IEC 27001, and GDPR compliance.
  • Hands-on Assessment

    Skills:

    Proven experience conducting Third-Party/Vendor Risk Assessments and Product/Application Risk Assessments.
  • Technical Writing:
    Exceptional ability to draft clear, concise, and enforceable Information Security policies from scratch.
  • Preferred

    Certifications:

    Possession of (or active pursuit of) one or more of the following:
  • CISA (Certified Information Systems Auditor)
  • CRISC (Certified in Risk and Information Systems Control)
  • CISSP (Certified Information Systems Security Professional)
  • CIPP/E or CIPM (Certified Information Privacy Professional/Europe)
Preferred Qualifications
  • Experience working in a global organization with cross-border data transfer requirements.
  • Experience in highly regulated industries (e.g., Pharmaceuticals, Biotech, Healthcare, or Finance).
  • Familiarity with GRC management tools (e.g., Service Now GRC, One Trust, Archer).
#J-18808-Ljbffr
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary