×
Register Here to Apply for Jobs or Post Jobs. X

Lead IT GRC Policy & Compliance Analyst #3616539

Job in Richmond, Henrico County, Virginia, 23214, USA
Listing for: Axiom-Path
Full Time position
Listed on 2026-08-18
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, IT Business Analyst
Salary/Wage Range or Industry Benchmark: 95000 - 130000 USD Yearly USD 95000.00 130000.00 YEAR
Job Description & How to Apply Below

Be Part Of A High-Performing Team:

Join a collaborative information security environment supporting enterprise governance, policy, compliance, and audit readiness across a complex organization. This team partners closely with Information Security, Risk, Compliance, Legal, Audit, IT, application owners, and business stakeholders to improve how controls are monitored, evidence is collected, and compliance activities are executed. The role is highly operational, hands‑on, and focused on strengthening security governance through automation, workflow improvement, and effective use of Service Now GRC/IRM and ITSM capabilities.

What's

In Store For You:
Engagement: W2 only (no C2C/1099)

This is a contract-to-hire opportunity with a hybrid onsite preference in Lynchburg or Richmond, Virginia, with openness to remote candidates. The role offers the chance to support enterprise-level information security governance, improve policy and compliance workflows, and help drive more scalable, automated control and evidence processes across multiple stakeholder groups.

How You Will Make An Impact
  • Administer and coordinate Service Now Policy and Compliance modules to support accurate configuration, maintenance, and daily operational use.
  • Manage Service Now ITSM oversight ticket queues, including intake, triage, tracking, and resolution of catalog, policy, and compliance-related requests.
  • Partner with Information Security, Risk, Compliance, Legal, Audit, IT, and business teams to support enterprise policy and compliance initiatives.
  • Operationalize and automate policy and compliance lifecycle activities, including policy reviews, attestations, continuous monitoring, control testing, and evidence collection.
  • Support a “test once, satisfy many” approach to streamline compliance efforts across regulatory, audit, and assurance requirements.
  • Develop dashboards, metrics, and reporting that give leadership and stakeholders visibility into policy, compliance, and control activity.
  • Coordinate evidence and documentation for audits, assessments, regulatory inquiries, and internal reviews.
  • Create and maintain SOPs, job aids, and process documentation to improve consistency, repeatability, and operational efficiency.
  • Identify process improvement opportunities and help implement enhancements that reduce manual work and improve control validation.
  • Execute assigned responsibilities independently while managing deadlines, competing priorities, and escalations as needed.
Are you an experienced IT GRC and Service Now compliance professional ready to make an impact?
  • Bachelor’s degree in Information Technology, Computer Science, or a related field preferred; equivalent IT or cybersecurity experience may be considered.
  • At least 3 years of hands‑on experience with Service Now GRC/IRM, with Service Now ITSM experience strongly preferred.
  • Practical experience applying governance, risk, and compliance principles in an enterprise IT or cybersecurity environment.
  • Working understanding of cybersecurity risks, controls, and frameworks such as NIST SP 800-53, NIST Cybersecurity Framework, and ISO/IEC 27001.
  • Familiarity with governance and control mapping tools such as Unified Control Framework and SIG.
  • Experience supporting policy management, control testing, continuous monitoring, compliance evidence, audits, assessments, and reporting.
  • Strong communication skills with the ability to work across technical and non-technical stakeholders.
  • Understanding of project management principles and SDLC concepts.
  • Strong attention to detail, documentation quality, follow-through, and ability to manage operational tasks independently.
  • Relevant certifications such as Security+, CISA, NIST CSF, PMP, CGRC, CISSP, or CISM are preferred.
  • Experience partnering with Risk, Compliance, Legal, Internal Audit, or regulatory teams is a plus.
  • Familiarity with HIPAA, SOX, NY DFS, SOC 1, and SOC 2 is preferred.
#J-18808-Ljbffr
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary