Senior GRC Analyst
EverfoxAbout the role
Intelligent. Dynamic. Resilient.
Everfox, formerly Forcepoint Federal, has been defending the world’s most critical data and networks against the most complex cyber threats imaginable for more than 25 years. As trailblazers in defense-grade, high assurance cyber security, we have been leading the way in developing and delivering innovative cyber security technology. We protect data wherever it resides. Our unwavering dedication and commitment to our customers and the critical missions they serve are what set us apart. We are dynamic, vigilant, and proactive in everything we do. Our suite of cross domain, threat protection and insider risk solutions empower governments and enterprise organizations to use data safely - where and however their people need it. At Everfox, we innovate, we invest, we achieve. We protect what matters most to our customers. And we offer protection like no other. We do all of this so our customers can focus on what matters most… their mission.
Job Title: Senior Governance, Risk, and Compliance Analyst
Job Location: Remote
Description:
The Senior Governance, Risk, and Compliance Analyst is responsible for understanding security requirements to meet industry best practices with a focus on certification and regulatory requirements. As part of this role, this role is responsible for mapping these requirements to security controls and actionable practices across various functions within the company. In some instance this individual will be responsible for designing security controls that best fit our environment while maintaining security compliance. Finally applying automation to as many controls as practicable to ensure on-going compliance (e.g., evidence collection) and managing compliance programs from a centralized governance management system.
This role is technical and analytical in nature and demands a fast learner with a history of technical knowledge and cloud security experience combined with business experience working in both on-premises and cloud product vendor environment (ideally Azure).
The ideal candidate will be highly skilled in translating security governance and compliance requirements to a wide range of company functional units, helping these functional units understand the need for, and approach to comply with information security policies, required security controls and how to appropriately capture evidence of compliance on an on-going basis. This role requires extensive experience in successfully completing security audits for certification programs. The role should have experience working in a cloud product environment for several years.
Duties and Responsibilities:
Governance and Compliance:
Working with external security auditors for various certification programs including NIST 800-171, NIST 800-53A, GDPR, PCI-DSS, and various others to facilitate successful internal and external security audits that lead to industry certifications.
Ensure all security controls required for several security certification programs including NIST 800-171/CMMC, NIST 800-53A/FedRAMP, among others, are designed, operational, and properly mapped. This includes annual review and updating of existing IS Policies, Standards, and Procedures, as well as development of new documents as necessary to support GRC requirements.
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s