
Junior GRC Analyst
Carol Stream, ILJobSeen 1 day agoSeen in employer's feed 1 day ago
Most applications go out cold — see where you stand first. No sign-up to start.
Watch jobs like this. New roles like this one near Carol Stream, IL, by email.
Don't just apply. Show up ready.
Olive works from this exact posting.
At a glance
Olive lists jobs from US employers, including remote roles you can work from the United States.
Job overview
The Junior GRC Analyst will execute the day‑to‑day cybersecurity Governance, Risk and Compliance program, managing risk assessments, registers and board‑level dashboards. They will lead policy management aligned with frameworks like NIST, HITRUST, HIPAA and PCI DSS, partner across legal, IT and product teams, support audits, handle security questionnaires, and translate technical risks for leadership.
Skills & qualifications
Skills
Qualifications
Full job description
Job Description
Own the day-to-day execution of the cybersecurity Governance, Risk, and Compliance program, including cyber risk assessments, enterprise risk reporting, risk register management, and board-level risk dashboards. Lead policy and standards management, ensuring alignment with frameworks such as NIST, HITRUST, HIPAA, and PCI DSS. Partner with Compliance, Internal Audit, Legal, IT, Engineering, and Product teams to identify, assess, mitigate, and track cybersecurity risks. Support audits and certifications, manage client security questionnaires, review security-related contract language, facilitate risk governance meetings, and provide leadership with clear insights into cybersecurity risk and compliance posture.
Skills and Requirements
3+ years of experience in cybersecurity GRC, IT audit, information security, or compliance. Hands-on experience managing risk registers and the full cyber risk management lifecycle. Experience supporting audits/certifications across at least two frameworks such as NIST CSF, HITRUST, HIPAA, PCI DSS, or SOC 2. Strong knowledge of NIST CSF, HITRUST, HIPAA, and PCI DSS 4.0. Experience reviewing cybersecurity and data protection language in contracts, BAAs, and DPAs. Experience with a GRC platform (ServiceNow GRC, Archer, OneTrust, LogicGate, AuditBoard, etc.). Strong communication skills with the ability to translate technical risks for executive and business audiences. Ability to manage multiple priorities and collaborate across Legal, Compliance, IT, Engineering, Product, Audit, and Leadership teams. Industry certifications such as CISSP, CISA, CISM, CRISC, CIPP, HCISPP, HITRUST CCSFP, or PCI ISA. Experience in healthcare, financial services, or other regulated industries. Hands-on experience supporting HITRUST r2 certifications and/or PCI DSS 4.0 attestations. Knowledge of GDPR, CCPA/CPRA, and other privacy regulations. Familiarity with cloud environments (AWS, Azure, GCP) and SaaS security models. Experience supporting organizations undergoing rapid growth, M&A activity, or technology modernization initiatives. Experience with executive-level risk reporting and board presentations.
We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal employment opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment without regard to race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or the recruiting process, please send a request to [email protected].
Similar jobs, posted recently
Open roles like this one, listed in the last 30 days.
Electrical Engineering AnalystKimley-Horn · Warrenville, IL · $87–91K/yrPosted 5 days agoPosted 5 days agoSenior Contract Analyst - HybridCVS Health · Irving, TX (Hybrid) · $47–112K/yrPosted 4 days agoPosted 4 days ago
Analytic Services - AnalystCVS Health · Remote · US · $44–94K/yrPosted 1 day agoPosted 1 day ago
Analyst, Corporate AuditCVS Health · Northbrook, IL (Hybrid) · $44–94K/yrPosted 1w agoPosted 1w ago
- Junior Trial Attorney (Illinois)Prime Healthcare Management Inc · Aurora, IL · $250–301K/yrPosted 2 days agoPosted 2 days ago
You've read the whole posting — now see how you match it.