GRC Analyst in Santa Fe, Mexico
Listed on 2026-09-08
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Governance, Risk & Compliance (GRC) Specialist
Beacon Hill was founded to set a new standard in search, career placement, and flexible staffing.
Governance, Risk & Compliance (GRC) Specialist
Location:
Houston, TX (Hybrid: 3 days onsite, 2 remote) OR Chicago, IL (Remote) Duration: 6-Month Contract (Strong Extension/Conversion Potential)
Start Date:
Approximately 3 Weeks from Offer
Overview We are seeking a Governance, Risk & Compliance (GRC) Specialist to join a growing Information Security team supporting a large-scale critical infrastructure environment. This individual will play a key role in strengthening governance, risk management, compliance, and cybersecurity processes across corporate IT, cloud platforms, and operational technology (OT) environments. This is a unique opportunity to help build and mature a cybersecurity governance program from the ground up while partnering closely with security, engineering, infrastructure, legal, procurement, and business stakeholders.
Key Responsibilities- Support and maintain the organization's governance, risk, and compliance program across IT, cloud, and OT environments.
- Develop, review, and maintain security policies, standards, procedures, and control documentation.
- Coordinate audit evidence collection for internal audits, external audits, compliance reviews, and customer assessments.
- Track audit findings, remediation plans, control deficiencies, policy exceptions, and risk acceptance activities.
- Perform control testing and compliance validation to ensure security controls are operating effectively.
- Assist with risk assessments, gap assessments, compliance readiness activities, and control maturity reviews.
- Support vendor and third-party risk management activities, including security questionnaires and risk reviews.
- Collaborate with IT, Security Operations, Infrastructure, Engineering, Legal, Procurement, Compliance, and Operations teams.
- Map security controls to frameworks including NIST, ISO 27001, SOC 2, and CIS Controls.
- Maintain risk registers, compliance calendars, control inventories, and audit repositories.
- Prepare compliance reports, dashboards, scorecards, and presentations for leadership.
- Monitor remediation efforts and work with control owners to ensure timely issue resolution.
- Support continuous improvement initiatives across the information security governance program.
- Stay informed on cybersecurity regulations, compliance trends, and industry best practices.
- 3+ years of experience in Governance, Risk & Compliance (GRC), cybersecurity compliance, IT audit, information security, or related disciplines.
- Strong knowledge of: NIST Cybersecurity Framework (CSF), NIST 800-53, NIST 800-171, ISO 27001, SOC 2, CIS Controls.
- Experience supporting audits, evidence collection, control testing, remediation tracking, and compliance reporting.
- Ability to develop and maintain security policies, standards, procedures, and control documentation.
- Experience conducting risk assessments, gap assessments, and control reviews.
- Familiarity with third-party and vendor risk management processes.
- Strong documentation and communication skills with the ability to translate technical concepts into business-friendly language.
- Experience working with cross-functional teams across technology and business organizations.
- Knowledge of enterprise security controls including identity and access management, vulnerability management, incident response, and change management.
- Strong organizational skills and ability to manage multiple initiatives simultaneously.
- Experience with in energy, utilities, renewable energy, power generation, critical infrastructure, or industrial environments.
- Knowledge of NERC CIP, FERC, or similar industry regulations.
- Exposure to OT/SCADA environments, substations, generation assets, EMS, DERMS, or industrial control systems.
- Certifications such as: CISA, CISSP, CISM, CRISC, Security+, ISO 27001 Lead Auditor/Implementer.
- Experience with GRC platforms such as Service Now GRC, Archer, One Trust, Audit Board, Logic Gate, Drata, Vanta.
- Experience supporting SOC 2, ISO 27001, SOX ITGC, PCI, or customer security reviews.
- Experience creating executive dashboards, compliance scorecards, risk registers, and audit reporting.
Why Join?
- Opportunity to help build and define a new GRC function.
- High visibility within a growing Information Security organization.
- Exposure to both traditional enterprise IT and operational technology environments.
- Opportunity to contribute to the modernization of cybersecurity, risk, and compliance practices within a critical infrastructure environment.
- Strong potential for long-term conversion and career growth.
Beacon Hill is an equal opportunity employer and individuals with disabilities and/or protected veterans are encouraged to apply.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).