×
Register Here to Apply for Jobs or Post Jobs. X

Governance, Risk, and Compliance Analyst

Job in Rock Hill, York County, South Carolina, 29732, USA
Listing for: Pike Corporation
Full Time position
Listed on 2026-09-27
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection
Salary/Wage Range or Industry Benchmark: 70000 - 100000 USD Yearly USD 70000.00 100000.00 YEAR
Job Description & How to Apply Below

Position Summary:

The GRC Analyst supports the organization’s governance, risk, and compliance program by maintaining policy and control documentation, coordinating risk assessments, tracking audit and compliance activities, and helping align the information security program with applicable regulatory and industry frameworks. This position partners with Information Security, IT, Human Resources, system owners, and business stakeholders to identify risks, monitor remediation, and maintain a mature, consistent, and auditable security posture.

Essential Functions:
  • Maintain and update information security and identity and access management policies, standards, procedures, control narratives, and supporting documentation in alignment with applicable frameworks, including the NIST Cybersecurity Framework and CIS Controls.

  • Manage the risk register and risk acceptance process, including documenting identified risks, approved exceptions, compensating controls, owners, remediation plans, and periodic reviews.

  • Coordinate customer and vendor risk assessments and security questionnaires; maintain an organized library of approved responses, supporting artifacts, and reusable evidence.

  • Review customer, contractual, regulatory, and audit requirements to identify new or revised controls and documentation needs.

  • Support SOC 2 and other internal or external audits by assisting with planning, control walkthroughs, control mapping, evidence collection, issue tracking, and remediation follow-up.

  • Collect, validate, organize, and submit audit evidence, including access lists, approval records, recertification documentation, tickets, logs, and other control artifacts.

  • Develop and maintain audit procedures, work papers, and runbooks to promote consistent and repeatable audit execution.

  • Prepare clear risk and compliance updates, metrics, and presentation materials for leadership, audit committees, and other stakeholders.

  • Perform periodic access reviews within Active Directory, Microsoft Entra , Oracle, and other in-scope applications to identify inaccurate, stale, orphaned, excessive, or unauthorized access.

  • Review joiner, mover, and leaver activities to validate that access is provisioned, modified, and removed timely and in accordance with least-privilege principles and job responsibilities.

  • Cross-reference HR and contractor data with system records to validate timely deprovisioning, appropriate contract end dates, and recurring access recertification.

  • Audit privileged and administrative account inventories, approvals, business justification, emergency access activity, time-bound access, and privileged access recertifications.

  • Review roles and entitlement combinations for segregation-of-duties conflicts, excessive access, and opportunities to simplify role design and reduce role sprawl.

  • Document audit findings, control gaps, discrepancies, risk decisions, remediation actions, owners, and target dates; maintain regular follow-up with responsible stakeholders.

  • Support role-based access provisioning workflows and periodic reviews of both role definitions and user assignments.

  • Perform other related duties as assigned to support the ongoing needs of the organization.

Minimum Requirements:
  • Bachelor’s degree in Information Security, Cybersecurity, Business, Computer Science, Information Technology, or a related field, or an equivalent combination of education and relevant experience.

  • Three or more years of experience in governance, risk, and compliance; IT audit; identity and access management audit; risk management; or information security compliance.

  • Working knowledge of at least one recognized information security or control framework, such as the NIST Cybersecurity Framework or CIS Controls.

  • Practical experience with Active Directory and Microsoft Entra , including user, group, role, and access reviews.

  • Knowledge of risk assessment methods, control design, control testing, audit evidence, and remediation tracking.

  • Ability to interpret technical and control information and communicate findings clearly to technical and non-technical stakeholders.

  • Experience using GRC, ticketing, workflow, or audit management tools, such as Jira, Service Now GRC, or Archer, and proficiency with standard Microsoft Office applications.

  • Strong organization, documentation, analytical, and follow-up skills with the ability to manage multiple concurrent audits, assessments, policy reviews, and remediation activities.

  • Ability to handle sensitive and confidential information with appropriate…

To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary