GRC Analyst
Listed on 2026-06-05
-
IT/Tech
Cybersecurity, Information Security
Governance, Risk, and Compliance (GRC) Analyst – Data & Insights (D&I) Solutions
Tyler Technologies is seeking a
* Governance, Risk, and Compliance (GRC) Analyst
* to support our Data & Insights (D&I) solutions within the Security team. This role offers an opportunity to own and evolve the compliance posture of Tyler’s D&I cloud platform, primarily focusing on sustaining and strengthening our FedRAMP Moderate Authorization to Operate (ATO) in an evolving regulatory landscape.
As a central driver of audit readiness, continuous monitoring, and compliance program execution, you will partner closely with Security, Engineering, Infrastructure & Release (TIRE), Legal, Privacy, and external assessors. The fast‑paced, results‑driven environment requires strong coordination, documentation quality, and risk‑informed decision‑making to deliver secure, compliant, and resilient cloud services.
LocationSeattle, Washington | Remote
Responsibilities- Own FedRAMP Moderate authorization sustainment and audit readiness. Manage continuous monitoring (Con Mon), POA&Ms, annual assessments, evidence quality, and overall ATO health.
- Lead readiness for evolving FedRAMP standards, including FedRAMP 2020. Track program changes, identify compliance gaps, and coordinate documentation and process updates.
- Serve as the primary compliance program coordinator for the D&I Security team. Partner across Security, Engineering, Infrastructure & Release (TIRE), Legal, Corporate Security and Privacy, and external assessors to deliver consistent, audit‑ready outcomes.
- Own FedRAMP change management and authorization boundary governance. Manage Security Impact Analyses (SIAs), Significant Change Requests and Notifications (SCRs/SCNs), authorization boundary documentation, and federal / Authorizing Official (AO) communications.
- Support risk‑based decision‑making. Document control exceptions, risk acceptances, and compensating controls in alignment with FedRAMP and organizational governance.
- Coordinate external assurance activities, including SOC 2 Type II assessments. Manage auditor engagement, evidence collection, findings tracking, and alignment with existing FedRAMP/NIST controls.
- Maintain the system‑of‑record for compliance documentation and artifacts. Own the System Security Plan (SSP), Con Mon plan, control narratives, diagrams, and appendices to ensure accuracy, traceability, and defensibility.
- Drive multi‑framework compliance alignment across regulated environments. Support FedRAMP, CJIS, HIPAA, and GDPR through gap identification, baseline documentation, and evidence reuse.
- Plan and execute internal compliance assessments. Manage annual OWASP SAMM re‑assessments, periodic Cloud Security Assessments (AWS Well‑Architected), and internal CJIS audits to measure maturity and prevent compliance drift.
- Support D&I’s cloud security and Tyler’s security maturity initiatives. Manage applicable assessments and re‑assessments, and align outcomes with broader security and compliance goals.
- Continuously improve compliance processes and maturity. Reduce manual effort, improve evidence quality, and prepare the organization for increased automation and reporting expectations.
- Strong organization and prioritization skills. Ability to manage continuous monitoring, POA&Ms, evidence collection, change tracking, and audit deliverables across overlapping timelines without losing accuracy.
- Clear, accurate written and verbal communication. Ability to document controls and evidence clearly and explain compliance requirements, risks, and decisions to engineers, auditors, customers, and non‑technical stakeholders.
- Collaborative, cross‑functional working style. Comfort partnering with Security, Engineering, Infrastructure, Legal, Privacy, and external assessors to drive consistent, audit‑ready outcomes.
- Detail‑oriented with a systems‑level perspective. Ability to track control requirements, dependencies, and boundary impacts while understanding how individual updates affect overall authorization health.
- Reliability and accountability. Consistently follows through on assigned work, maintains accurate records, meets deadlines, and communicates…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).