Associate GRC Analyst
Richmond, Henrico County, Virginia, 23220, USA
Listed on 2026-07-25
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Associate GRC Analyst
CoStar Group (NASDAQ: CSGP) is a leading global provider of commercial and residential real estate information, analytics, and online marketplaces. Included in the S&P 500 Index, CoStar Group is on a mission to digitize the world's real estate, empowering all people to discover properties, insights and connections that improve their businesses and lives.
We have been living and breathing the world of real estate information and online marketplaces for over 35 years, giving us the perspective to create truly unique and valuable offerings to our customers. We've continually refined, transformed and perfected our approach to our business, creating a language that has become standard in our industry, for our customers, and even our competitors.
We continue that effort today and are always working to improve and drive innovation. This is how we deliver for our customers, our employees, and investors. By equipping the brightest minds with the best resources available, we provide an invaluable edge in real estate.
We are seeking an Associate GRC Analyst to help evolve and grow CoStar's cybersecurity and information technology governance program. As an Associate on the CoStar Group IT Governance, Risk, and Compliance Team, you will learn and assist in day-to-day governance operations, and progress toward developing ownership and establishing expertise in areas of GRC engagement. You will work alongside and under the guidance of experienced team members, supporting functions such as our third-party risk and compliance programs, security awareness and marketing initiatives, audit and assurance support, and controls governance.
In the course of your work, you will collaborate with stakeholders across Cybersecurity, Information Technology Operations, Product & Development, Human Resources, Finance, and Sales.
This position is located in Richmond, VA and is in office Monday through Thursday and work from home on Friday.
Responsibilities- Perform routine governance operations such as periodic user access reviews, triage of anomalous control alerts, and audit support.
- Support third-party risk assessments for new and existing vendors — distributing and reviewing security questionnaires and performing initial reviews of SOC reports or equivalent control attestations.
- Draft clear, well-organized written summaries of assessments, risk findings and recommendations for both technical and non-technical audiences.
- Help maintain our GRC tooling and records — keeping vendor inventories, assessment trackers, and supporting documentation current, organized, and audit-ready.
- Contribute to security-awareness efforts across the company, generating bespoke and culture-relevant information security awareness materials and communications that help build and reinforce a healthy security culture.
- Arrive ready to learn, grow, and develop your career within Cybersecurity, adopting a continuous learning mindset.
- Bachelor's Degree required from an accredited, not for profit, in person, university or college.
- A track record of commitment to prior employers
- 1–3 years of experience in an adjacent field such as IT, audit, compliance, information security, or a related analytical or operational role.
- A genuine and demonstrated curiosity about technology and cybersecurity, paired with the self-motivation to take on unfamiliar challenges and see them through.
- Excellent written communication with meticulous attention to detail — you take pride in accurate, well-organized, polished work.
- Familiarity with core security concepts — for example, least privilege, defense in depth, the CIA triad (confidentiality, integrity, and availability), authentication versus authorization, encryption in transit and at rest, and common attack types such as phishing and social engineering.
- Strong organizational and time-management skills, with the ability to track many moving pieces without dropping detail.
- A collaborative, approachable style and a willingness to engage with people across the business.
- Excellent verbal communication and presentation skills, with a proven track record of…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).