careertakescareertakes

Associate GRC Analyst

Confidential ClientReal Estate & Construction
Entry LevelFull-timeHybrid$75,000 - $101,000
Richmond, Virginia
4 Days Ago

The Associate GRC Analyst at Confidential Client supports the cybersecurity and IT governance program by performing governance operations, third-party risk assessments, audit support, and security awareness initiatives. This role collaborates cross-functionally to maintain compliance, manage risk, and enhance security culture while developing expertise in governance, risk, and compliance within a hybrid work environment.

Boost your chances. Upload your resume to see your match score.

Unlock Match Rate
Description

About Careertakes

👉 Important disclosure: Careertakes is a third-party recruiting platform supporting this hiring process. If selected, you will be employed directly by our client, IT.

Applicants for this role may also receive access to additional matched opportunities through the Careertakes platform.


Overview

Confidential Client is hiring an Associate GRC (Governance, Risk & Compliance) Analyst to help evolve and grow their cybersecurity and IT governance program. As an early-career member of the IT Governance, Risk, and Compliance team you will support day-to-day governance operations, third‑party risk assessments, security awareness initiatives, audit support, and controls governance while developing deeper GRC expertise.

This role is based in Richmond, VA. The standard schedule is in-office Monday–Thursday with work-from-home on Friday.


Key Responsibilities

  • Perform routine governance operations such as periodic user access reviews, triage of anomalous control alerts, and audit support.
  • Support third‑party risk assessments for new and existing vendors — distribute and review security questionnaires and perform initial reviews of SOC reports or equivalent control attestations.
  • Draft clear, well-organized written summaries of assessments, risk findings, and recommendations for both technical and non‑technical audiences.
  • Help maintain GRC tooling and records — keep vendor inventories, assessment trackers, and supporting documentation current, organized, and audit‑ready.
  • Contribute to security‑awareness efforts across the company by creating culture‑relevant awareness materials and communications.
  • Adopt a continuous learning mindset and actively develop your cybersecurity and GRC career.

Basic Qualifications

  • Bachelor’s degree from an accredited, in-person university or college.
  • 1–3 years of experience in an adjacent field such as IT, audit, compliance, information security, or a related analytical or operational role.
  • Demonstrated curiosity about technology and cybersecurity and self-motivation to learn new concepts.
  • Excellent written communication with strong attention to detail.
  • Familiarity with core security concepts (least privilege, defense in depth, CIA triad, authentication vs. authorization, encryption, common attack types such as phishing/social engineering).
  • Strong organizational and time‑management skills.
  • Collaborative and approachable; able to engage effectively with cross-functional stakeholders.

Preferred Qualifications & Skills

  • Strong verbal communication and presentation skills for diverse audiences.
  • Progress toward or possession of entry‑level certifications (e.g., CompTIA Security+, ISC2 Certified in Cybersecurity).
  • Experience in a service‑oriented technology role (IT help desk, technical support).
  • Exposure to ticketing/workflow tools and GRC platforms.
  • Experience developing basic automation (Python, PowerShell, Power Automate, etc.).
  • Experience reading or summarizing SOC reports, SIG or CSA CAIQ questionnaires, or similar vendor documentation.
  • Hands‑on experience applying AI to automate workflows or augment business processes (practical usage, not just research).

What’s in it for You / Benefits

Confidential Client offers competitive compensation, professional development, and a comprehensive benefits package, which may include:

  • Comprehensive medical, vision, and dental coverage.
  • Life, legal, and supplemental insurance options.
  • Virtual and in‑person mental health counseling services.
  • Commuter and parking benefits (location dependent).
  • 401(k) plan with employer match.
  • Employee stock purchase plan.
  • Paid time off and paid holidays.
  • Tuition reimbursement and internal training programs.
  • On‑site or reimbursed fitness options (location dependent).
  • Access to employee resource groups and workplace wellbeing programs.
  • Complimentary beverages and healthy snacks at office locations.

Compensation & Work Authorization

  • Base compensation range: $75,000 – $101,000 annually. Final pay is based on factors including geographic location, skills, and experience.
  • This role is open to candidates authorized to work full‑time in the United States. Confidential Client is not able to provide visa sponsorship for this position.

Additional Information

  • This position may require background checks and pre‑employment substance abuse screening consistent with applicable law.
  • Confidential Client is committed to maintaining a safe, inclusive, and compliant workplace. You will work collaboratively across Cybersecurity, IT Operations, Product & Development, HR, Finance, and Sales teams.

Equal Opportunity & Hiring Transparency

Careertakes and our client are Equal Opportunity Employers committed to building a diverse and inclusive workforce. We prohibit discrimination or harassment of any kind. To support a fair and efficient hiring process, AI tools may be used to assist with application review or resume screening. These tools do not replace human decision-making. Final hiring decisions are made by people.

If you have questions about how your data is used, please contact us directly.

Negotiate a higher salary! Check the salary ranges for this job type in your area.

View My Salary Range