careertakescareertakes

Associate Analyst, IT Governance Risk & Compliance

Confidential ClientBiotechnology & Life Sciences
Entry LevelFull-timeOn-Site$64,417 - $86,049
San Diego, California
A Day Ago

The Associate Analyst supports Confidential Client's Cyber Security Governance, Risk, and Compliance program by assisting with risk assessments, third-party reviews, audit support, and policy administration. This entry-level role involves maintaining GRC records, tracking remediation activities, preparing reports, and developing foundational knowledge of cybersecurity frameworks and regulatory requirements under guidance. The position offers growth opportunities through professional development and engagement with industry standards such as NIST CSF, ISO 27001, and CIS Controls.

Boost your chances. Upload your resume to see your match score.

Unlock Match Rate
Description

About Careertakes

👉 Important disclosure: Careertakes is a third-party recruiting platform supporting this hiring process. If selected, you will be employed directly by our client, IT.

Applicants for this role may also receive access to additional matched opportunities through the Careertakes platform.


About the Role

Confidential Client is seeking an Associate Analyst to support their Cyber Security Governance, Risk, and Compliance (GRC) program. This is an entry-level, full-time position based in San Diego, CA. Under the guidance of the GRC Lead, you will help with risk assessments, third‑party reviews, audit and compliance support, policy administration, evidence collection, issue tracking, and reporting. This role is ideal for someone building practical GRC experience and looking to develop expertise in cybersecurity frameworks and controls.


What You’ll Do

  • Assist with routine IT and cyber security risk assessments: gather evidence, document results, and escalate questions or exceptions for review.
  • Support third‑party risk efforts: track requests/questionnaires, organize vendor evidence, perform initial completeness checks, and maintain assessment records.
  • Coordinate evidence requests and organize artifacts for framework assessments, audits, and compliance reviews.
  • Maintain accurate GRC records (risk registries, controls, issues, action plans, exceptions) in approved systems.
  • Map policies, controls, and evidence to requirements such as NIST CSF 2.0, ISO 27001, and CIS Controls using established procedures.
  • Track remediation activities, follow up with action owners, document updates, and escalate overdue items.
  • Support policy and procedure administration: formatting, version control, review routing, publication, and training/communication records.
  • Prepare routine metrics, dashboards, and status reports using templates; validate data and investigate variances under guidance.
  • Participate in meetings, trainings, research, and process improvement activities; communicate professionally and protect confidential information.

Who You Are / Qualifications

  • Bachelor’s degree in Cybersecurity, IT, Information Systems, Business, Risk Management, or a related field with 0–2 years of related experience (internships, co‑ops, academic projects, labs, or equivalent practical experience qualify) OR
  • Associate’s degree in a related field plus 1+ year of related experience (including internships, co‑ops, military service, or equivalent practical experience).
  • Relevant coursework, training, or a foundational certification is preferred but not required.
  • Foundational understanding of IT cybersecurity, governance, risk, compliance and IT controls gained through education, training, internships, projects, or related experience.
  • Familiarity with NIST CSF, ISO 27001, CIS Controls, or SOC 2 through coursework or practical exposure.
  • Proficiency with Microsoft 365 applications and basic spreadsheet skills (sort, filter, reconcile, summarize).
  • Good communication, analytical, and problem‑solving skills; detail oriented with strong follow‑through.
  • Ability to collect, organize, and review evidence against defined criteria under supervision and to document findings using established templates.
  • Ability and willingness to learn GRC processes, tools, and authoritative guidance; receive coaching and pursue ongoing development. Familiarity with automation tools and AI concepts (responsible use, privacy, security) is a plus.
  • Ability to handle confidential information with discretion.

Compensation & Benefits

  • Hourly pay range: $30.97–$41.37 per hour.
  • Annual bonus target: 15% of earned base salary.
  • Eligibility for long‑term equity incentives where applicable.
  • Benefits may include medical, prescription drug, dental, and vision coverage; retirement savings plan with company match; paid vacation, holidays, and personal days; and paid caregiver/parental and medical leave — subject to plan terms and eligibility.
    Note: Individual pay decisions depend on factors such as work location, role responsibilities, experience, and skills.

Additional Details

  • Employment type: Full‑time.
  • Location: San Diego, CA (on‑site or as specified by Confidential Client).
  • This posting is intended to comply with applicable state pay transparency requirements; the salary range above reflects the employer’s stated range for this role.
  • Applicants are encouraged to self‑identify accommodations needed during the hiring process.

Equal Opportunity & Hiring Transparency

Careertakes and our client are Equal Opportunity Employers committed to building a diverse and inclusive workforce. We prohibit discrimination or harassment of any kind. To support a fair and efficient hiring process, AI tools may be used to assist with application review or resume screening. These tools do not replace human decision-making. Final hiring decisions are made by people.

If you have questions about how your data is used, please contact us directly.

Negotiate a higher salary! Check the salary ranges for this job type in your area.

View My Salary Range