×
Register Here to Apply for Jobs or Post Jobs. X

GRC Analyst

Job in Canton, Norfolk County, Massachusetts, 02021, USA
Listing for: Aqueduct Technologies, Inc.
Full Time position
Listed on 2026-05-19
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security, IT Business Analyst, Data Security
Salary/Wage Range or Industry Benchmark: 80000 - 100000 USD Yearly USD 80000.00 100000.00 YEAR
Job Description & How to Apply Below

Aqueduct Technologies is seeking a GRC Analyst to join our Governance, Risk, and Compliance (GRC) team. Reporting directly to the Director of GRC, this role plays a pivotal part in designing, executing, and maturing our clients’ security and compliance programs.

As Part Of Our Growing GRC Practice, You Will
  • Support and progressively lead client compliance engagements
  • Contribute to the development of Aqueduct’s GRC service offerings
  • Assist with internal compliance initiatives and audit readiness activities
Core Responsibilities
  • Compliance Readiness and Assessments:
  • Support and conduct readiness assessments aligned to frameworks such as NIST CSF, ISO 27001, SOC 2, HIPAA, PCI DSS, and CMMC
  • Identify control gaps and provide practical, risk based remediation recommendations
  • Assist clients in preparing for external audits and certification efforts
Risk Assessments
  • Perform organizational risk assessments and document risk findings
  • Evaluate control effectiveness and recommend mitigation strategies aligned with business objectives
  • Maintain risk registers and support risk reporting processes
Third Party Risk Management
  • Conduct vendor risk assessments and due diligence reviews
  • Support the development and maintenance of third party risk programs
  • Assist with ongoing monitoring activities and documentation
Client Reporting And Communication
  • Prepare clear, structured reports summarizing findings, risks, and recommended actions
  • Present results to client stakeholders with guidance from senior team members
  • Translate technical findings into business relevant insights
Collaboration And Internal Support
  • Work closely with security operations, engineering, and account teams to align GRC initiatives
  • Support internal compliance initiatives including SOC 2 readiness and audit activities
  • Contribute to documentation development, templates, and process improvement efforts
Professional Development
  • Stay current on evolving cybersecurity risks, regulatory requirements, and industry standards
  • Expand expertise across multiple frameworks and advisory domains
Required

Skills & Qualifications
  • Core Competencies:
  • Strong written and verbal communication skills
  • Analytical thinking and attention to detail
  • Ability to manage multiple client work streams in a consulting environment
  • Professional presence in client facing situations
Technical And Compliance Experience
  • Experience supporting or conducting assessments across one or more major frameworks such as NIST CSF, ISO 27001, SOC 2, HIPAA, PCI DSS, or CMMC
  • Working knowledge of risk assessment methodologies
  • Familiarity with third party risk management concepts and processes
  • Foundational understanding of Zero Trust principles and modern security architecture concepts
Professional Background
  • 3 or more years of experience in information security with exposure to GRC functions
  • Experience in consulting, advisory, or managed services environments preferred
  • Experience with GRC platforms such as Service Now GRC, Archer, Drata, Vanta, or similar tools is a plus
Certifications
  • One or more of the following certifications is preferred but not required:
  • CISA
  • CISM
  • CRISC
  • CISSP
  • CCSP
Work Model
  • Ability to work in a hybrid model in the Canton, MA area
  • Willingness to travel locally for client engagements as needed
Growth Opportunity
  • This role offers a clear path toward Senior GRC Consultant responsibilities. Analysts who demonstrate strong client delivery, technical depth, and engagement ownership will have opportunities to lead larger assessments, mentor junior team members, and expand into broader advisory engagements.

Aqueduct Technologies is committed to developing a diverse and talented team. We celebrate and support diversity and are committed to making an inclusive environment for all employees and applicants including women, minorities, individuals with disabilities, members of the LGBTQIA community, veterans, and any other legally protected group. We are an Equal Opportunity Employer and do not discriminate against any employee or applicant on the basis of any status protected by federal, state, or local laws.

#J-18808-Ljbffr
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary