×
Register Here to Apply for Jobs or Post Jobs. X

Associate GRC Analyst

Remote / Online - Candidates ideally in
Richmond, Henrico County, Virginia, 23214, USA
Listing for: CoStar
Remote/Work from Home position
Listed on 2026-07-25
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 75000 - 101000 USD Yearly USD 75000.00 101000.00 YEAR
Job Description & How to Apply Below

Associate GRC Analyst Job Description

CoStar Group (NASDAQ: CSGP) is a leading global provider of commercial and residential real estate information, analytics, and online marketplaces. Included in the S&P 500 Index, CoStar Group is on a mission to digitize the world’s real estate, empowering all people to discover properties, insights and connections that improve their businesses and lives. We have been living and breathing the world of real estate information and online marketplaces for over 35 years, giving us the perspective to create truly unique and valuable offerings to our customers.

We’ve continually refined, transformed and perfected our approach to our business, creating a language that has become standard in our industry, for our customers, and even our competitors. We continue that effort today and are always working to improve and drive innovation. This is how we deliver for our customers, our employees, and investors. By equipping the brightest minds with the best resources available, we provide an invaluable edge in real estate.

Responsibilities
  • Perform routine governance operations such as periodic user access reviews, triage of anomalous control alerts, and audit support.
  • Support third-party risk assessments for new and existing vendors — distributing and reviewing security questionnaires and performing initial reviews of SOC reports or equivalent control attestations.
  • Draft clear, well-organized written summaries of assessments, risk findings and recommendations for both technical and non-technical audiences.
  • Help maintain our GRC tooling and records — keeping vendor inventories, assessment trackers, and supporting documentation current, organized, and audit-ready.
  • Contribute to security-awareness efforts across the company, generating bespoke and culture-relevant information security awareness materials and communications that help build and reinforce a healthy security culture.
  • Arrive ready to learn, grow, and develop your career within Cybersecurity, adopting a continuous learning mindset.

This position is located in Richmond, VA and is in office Monday through Thursday and work from home on Friday.

Basic Qualifications
  • Bachelor’s Degree required from an accredited, not for profit, in person, university or college.
  • A track record of commitment to prior employers
  • 1–3 years of experience in an adjacent field such as IT, audit, compliance, information security, or a related analytical or operational role.
  • A genuine and demonstrated curiosity about technology and cybersecurity, paired with the self-motivation to take on unfamiliar challenges and see them through.
  • Excellent written communication with meticulous attention to detail — you take pride in accurate, well-organized, polished work.
  • Familiarity with core security concepts — for example, least privilege, defense in depth, the CIA triad (confidentiality, integrity, and availability), authentication versus authorization, encryption in transit and at rest, and common attack types such as phishing and social engineering.
  • Strong organizational and time-management skills, with the ability to track many moving pieces without dropping detail.
  • A collaborative, approachable style and a willingness to engage with people across the business.
Preferred Qualifications and Skills
  • Excellent verbal communication and presentation skills, with a proven track record of communicating clearly to diverse audiences, including both non-technical and highly technical stakeholders.
  • Entry-level certifications, or demonstrable progress toward them, such as CompTIA Security+ or ISC2 Certified in Cybersecurity (CC).
  • Experience in a service-oriented technology role, such as an IT help desk or technical customer support function.
  • Exposure to ticketing and workflow tools.
  • Experience in developing automation – whether it is through standard scripting languages such as Python, Power Shell, or through applications such as Power Automate.
  • Experience reading or summarizing SOC reports, security questionnaires (SIG, CSA CAIQ), or other vendor documentation.
  • Hands-on experience applying AI to accomplish real work — for example, building or orchestrating agentic workflows,…
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary