Cybersecurity GRC Analyst II
New American FundingAbout the role
Overview
Position: IT GRC Analyst II
Location: On-Site role in Santa Ana, CA.
Compensation: starting at $100K+ DOE
*Actual compensation may vary from posting based on geographic location, work experience, education, and/or skill level.
Position Summary: The Cybersecurity GRC Analyst II will be a key member of our fast-paced, growing Cybersecurity Services team. This role is intensely focused on Governance, Risk, and Compliance (GRC) and serves as a primary point of contact for responding to external audits. The Analyst will be responsible for day-to-day IT compliance, data governance, and IT risk management functions. This role is critical in defining, creating, and managing IT policies and standards to meet legal and regulatory requirements.
Responsibilities
- External Audit Management: Lead the coordination and response to all external IT audits and regulatory examinations. Act as the primary liaison for external auditors, managing evidence collection, interviews, and formal responses to findings.
- Compliance & Controls Testing: Design, lead, and perform comprehensive IT control reviews and compliance testing aligned with regulatory and industry frameworks (e.g., SOC 2, NIST, NY DFS, CCPA/CPRA). Identify control weaknesses and recommend remediation strategies.
- Audit Strategy & Execution: Collaborate with senior IT leadership and Governance teams to develop audit plans and testing strategies based on enterprise risk assessments. Lead high-impact audits across infrastructure, cloud, applications, and cybersecurity domains.
- Controls & Risk Evaluation: Independently evaluate the design and operating effectiveness of IT controls, including access management, change management, data protection, network security, business continuity, and disaster recovery.
- Technology & Evidence Review: Assess automated evidence gathered by NAF’s Next Gen GRC/IRM platform. Partner with control owners to validate effectiveness and drive continuous improvement in evidence quality and timeliness for both internal and external audits.
- Reporting & Recommendations: Prepare executive-level audit reports that clearly articulate testing performed, risk exposure, control gaps, and actionable recommendations. Present findings to leadership, governance bodies, and external auditors.
- Remediation Oversight: Guide and monitor the implementation of remediation plans for audit findings, ensuring timely and effective resolution of identified issues. Conduct follow-up reviews to validate remediation efforts.
- Risk Management: Support ongoing IT risk assessment efforts to identify areas of heightened risk. Recommend enhancements to control coverage and risk mitigation practices based on audit results and industry trends.
- Stakeholder Engagement: Serve as a trusted advisor between IT, business units, and external auditors. Ensure strong collaboration and alignment of controls testing and audit evidence across the organization.
- Regulatory & Industry Expertise: Stay informed on emerging regulatory requirements, auditing standards, and technology trends. Interpret and apply requirements to improve NAF’s IT risk and compliance posture.
Qualifications
- Deep understanding of IT governance, compliance, and risk management principles.
- Proven experience managing and responding to external IT audits.
- Strong knowledge of frameworks and standards such as SOC 2, NIST CSF/800-53, CIS Controls, NY DFS, and CCPA/CPRA.
- Experience with IT GRC/IRM platforms (e.g., Archer, ServiceNow, OneTrust, or similar).
- Familiarity with cloud environments (Azure, AWS, GCP) and modern IT infrastructures.
- Proven ability to adapt to rapidly changing technology landscapes and compliance requirements.
- Excellent analytical, problem-solving, and critical thinking skills.
- Strong interpersonal, written, and verbal communication abilities, with experience presenting to senior leadership and cross-functional teams.
Education, Experience & Certification:
- Education: Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or a related field.
- Experience: Minimum 5-7 years of progressive experience in IT audit, IT risk management, cybersecurity, or compliance in a complex enterprise environment.
- Certifications: Professional certifications are highly preferred: CISA, CISSP, CRISC, CISM, CGRC (formerly CAP), CDPSE, CGEIT, CIA.
Work Authorization:
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s