Auf einen Blick
- Aufgaben: Entwickle und implementiere Sicherheitsrichtlinien zur Einhaltung von Standards und Vorschriften.
- Unternehmen: Virtru, ein führendes Unternehmen im Bereich Datenschutz und Sicherheit.
- Vorteile: Attraktives Gehalt, flexible Arbeitszeiten und Möglichkeiten zur beruflichen Weiterentwicklung.
- Weitere Informationen: Dynamisches Team mit Fokus auf kontinuierliche Verbesserung und Innovation.
- Warum dieser Job: Gestalte die Sicherheitskultur aktiv mit und schütze sensible Daten.
- Qualifikationen: Mindestens 5 Jahre Erfahrung in Informationssicherheit oder GRC-Analysen.
Das prognostizierte Gehalt liegt zwischen 170000 - 170000 € pro Jahr.
Security Governance Risk & Compliance (GRC) Analyst at Virtru
About the role Virtru is seeking a dedicated GRC Analyst to join our security team and help develop, implement, and maintain a robust security compliance program.
In this role, you will be responsible for ensuring that our organization meets a variety of industry standards and regulatory requirements, including Fed RAMP, SOC 2, PCI, HIPAA, and GDPR.
Your expertise will support our ongoing efforts to safeguard sensitive data, improve security controls, and demonstrate compliance to clients and regulators.
As part of our team, you will collaborate closely with technical and business stakeholders to translate complex security requirements into practical, automated solutions and processes.
Your work will be instrumental in maintaining Virtru's reputation as a leader in data protection and privacy, enabling us to grow confidently in a highly regulated environment.
- Key facts
- Location: Washington, DC
- Remote Engagement: Full-time
- Virtru's security compliance team is committed to fostering a proactive security culture, and this role offers an exciting opportunity to influence our security posture at a strategic level.
The position involves working on-site at our Washington, DC office, with the possibility of remote work arrangements.
You will be part of a dynamic team focused on integrating compliance into our operational workflows, automating evidence collection, and supporting continuous monitoring efforts.
This role is ideal for someone with a strong background in security frameworks, cloud technologies, and automation tools, who is eager to make a tangible impact on our security practices.
What you'll do
- Lead the management and implementation of control frameworks for cloud infrastructure and Saa S services, ensuring alignment with industry standards and best practices.
- Develop and maintain automated solutions for collecting and verifying compliance evidence across various cloud environments, endpoints, and internal systems.
- Conduct comprehensive risk assessments across different business units, identifying vulnerabilities, assessing their potential impact, and recommending appropriate mitigation strategies.
- Support incident response activities by providing detailed risk analysis, assisting in root cause analysis, and helping coordinate remediation efforts to address security incidents.
- Assist in designing and deploying automated controls to enhance risk mitigation efforts, reduce manual effort, and improve audit readiness.
- Work closely with teams responsible for CMMC certification, integrating certification requirements into ongoing compliance assessments and monitoring activities.
- Evaluate third-party vendors and service providers during onboarding and annual reviews to ensure they meet Virtru's security standards and compliance requirements.
- Collaborate with cross-functional teams to embed security and compliance considerations into product development, deployment, and operational processes.
- Provide guidance and training to internal teams on security controls, compliance requirements, and best practices to foster a security-aware culture.
- Maintain up-to-date knowledge of evolving security standards, regulations, and industry trends to ensure Virtru remains compliant and secure.
- Prepare documentation, reports, and audit evidence for internal reviews and external audits, ensuring completeness and accuracy.
- Contribute to the continuous improvement of security policies, procedures, and automation tools to streamline compliance workflows and reduce manual effort.
- Communicate complex security and compliance issues clearly to technical and non-technical stakeholders, facilitating informed decision-making.
- Participate in security incident investigations and post-incident reviews, providing insights into compliance and risk management.
- Support the development of security awareness programs and initiatives to promote a security-first mindset across the organization.
Requirements
- Minimum of 5 years of experience in information security, IT audit, IT risk management, or as a GRC analyst or engineer.
- Strong knowledge of compliance frameworks such as CMMC, NIST 800-53 & 800-171, Fed RAMP, SOC 2, PCI, HIPAA, GDPR, and other relevant privacy regulations.
- Technical proficiency with cloud platforms including Amazon Web Services (AWS), Google Cloud Platform (GCP), and Microsoft Azure.
- Hands-on experience with GRC tools such as Hyperproof, Vanta, and Drata, as well as familiarity with SIEM tools like Datadog and Splunk.
- Proven ability to build and maintain relationships across technical teams, business units, and external vendors, translating risk and compliance requirements into actionable insights.
- Experience in designing and implementing automated compliance evidence collection and monitoring solutions.
- Strong analytical skills, with the ability to assess complex security controls and identify gaps or deficiencies.
- Excellent communication skills, capable of explaining technical security concepts to non-technical stakeholders.
- Ability to work independently and proactively in an agile environment, managing multiple priorities and deadlines.
- Demonstrated problem-solving skills and the capacity to handle conflicts or challenges effectively.
- Experience supporting or leading security audits and assessments, with a focus on continuous improvement.
- Familiarity with security incident response processes and risk mitigation strategies.
- A proactive attitude and enthusiasm for learning new security technologies and standards.
- Nice to have
- Experience working in a federal government contracting environment or supporting compliance with government standards.
- Knowledge of additional security standards such as ISO 27001, CIS Controls, or NIST Cybersecurity Framework.
- Familiarity with scripting or automation languages like Python, Power Shell, or Bash to support automation initiatives.
- Prior experience working with security teams in a Saa S or cloud-native environment.
- Understanding of data privacy laws and their impact on security practices.
- Certification such as CISSP, CISA, CISM, or Security+ is a plus.
Skills & tools
- Cloud platforms: AWS, GCP, Azure
- GRC tools: Hyperproof, Vanta, Drata
- SIEM tools: Datadog, Splunk
- Compliance frameworks: CMMC, NIST 800-53 & 800-171, Fed RAMP, SOC 2, PCI, HIPAA, GDPR
- Practical notes
Compensation for this role ranges from $130,000 to $170,000 annually, commensurate with experience and skills.
Virtru is committed to fostering a diverse and inclusive workplace, welcoming applicants from all backgrounds.
We are an Equal Opportunity Employer and do not discriminate based on race, color, gender, religion, disability, national origin, protected veteran status, age, or any other protected characterics.
This position involves working on-site at our Washington, DC office, with the possibility of remote work arrangements.
The role offers an excellent opportunity to develop expertise in security compliance, automation, and risk management within a fast-growing company dedicated to data privacy and security.
#J-18808-Ljbffr
Security Governance Risk & Compliance (GRC) Analyst Arbeitgeber: Virtru
Virtru ist ein hervorragender Arbeitgeber, der eine dynamische und inklusive Arbeitskultur fördert. Mit einem starken Fokus auf Mitarbeiterentwicklung und kontinuierlichem Lernen bietet das Unternehmen zahlreiche Möglichkeiten zur beruflichen Weiterentwicklung im Bereich Sicherheits-Compliance und Automatisierung. Die Lage in Washington, DC, ermöglicht es den Mitarbeitern, in einem innovativen Umfeld zu arbeiten, das sich der Datensicherheit und dem Datenschutz verschrieben hat.
StudySmarter Expertenrat🤫
Wir sind der Meinung, dass du so Security Governance Risk & Compliance (GRC) Analyst erhalten könntest
✨Werde sichtbar in der IT-Sicherheits-Community
In der IT-Sicherheit gibt’s eine Menge Fachkreise und Konferenzen, die super für Networking sind. Schau dir Events wie die "IT-Security Convention" oder regionale Meetups an, um Gleichgesinnte und potenzielle Arbeitgeber wie Virtru kennenzulernen!
✨Kollaboriere an Open-Source-Projekten
Zeig dein Können und engagiere dich in Open-Source-Projekten, die auf IT-Sicherheit abzielen. Das ist nicht nur eine tolle Möglichkeit, praktische Erfahrungen zu sammeln, sondern auch, um dein Portfolio zu erweitern und Sichtbarkeit in der Branche zu gewinnen.
✨Nutze spezielle Jobportale für IT-Sicherheit
Schau auf spezialisierten Jobportalen wie "heise jobs" oder "StepStone" nach offenen Stellen in der IT-Sicherheit. Hier findest du viele Angebote, die nicht immer auf den großen Plattformen gelistet sind. Vergiss nicht, dich direkt auf der Website von Virtru zu bewerben!
✨Halte deine Skills up-to-date
In der IT-Sicherheit bleibt nichts stehen, also bleib am Ball! Investiere Zeit in Weiterbildung und besuche Online-Kurse oder Webinare zu aktuellen Sicherheitsthemen. Das zeigt nicht nur dein Engagement, sondern stärkt auch dein Profil bei Virtru.
Wir glauben, dass du diese Fähigkeiten brauchst, um Security Governance Risk & Compliance (GRC) Analyst mit Bravour zu bestehen
Einige Tipps für deine Bewerbung 🫡
Zeig deine technischen Skills!:Im Bereich IT-Sicherheit ist es wichtig, dass du deine technischen Fähigkeiten klar kommunizierst. Stelle sicher, dass dein Lebenslauf relevante Zertifikate (wie CEH oder CISSP) sowie praktische Erfahrungen bei Sicherheitsprojekten oder Penetrationstests zeigt. Dies wird uns helfen, einen besseren Eindruck von deinem Fachwissen zu bekommen.
Präsentiere dein Wissen über aktuelle Trends:Wir möchten sehen, dass du über die neuesten Entwicklungen im Bereich IT-Sicherheit informiert bist. In deinem Anschreiben kannst du beispielsweise auf ein aktuelles Sicherheitsproblem oder einen neuen Standard eingehen, den du für relevant hältst. Dadurch zeigst du uns, dass du dich aktiv mit dem Thema auseinandersetzt und für die Position brennst.
Mach deine Leidenschaft deutlich:Da es sich um eine Vollzeitposition handelt, ist es wichtig, dass du uns in deinem Anschreiben zeigst, warum du in der IT-Sicherheit arbeiten möchtest. Erzähl uns von deinen Erfahrungen, wie du zur Cyber-Security gekommen bist und was dich motiviert, in dieser Branche zu arbeiten. Deine Motivation spielt eine große Rolle bei der Auswahl!
Referenzen oder Projekte anfügen:Wenn du bereits an interessanten Projekten gearbeitet hast oder relevante Referenzen hast, die deine Fähigkeiten unterstreichen, füge diese in deine Bewerbung hinzu. Das gibt uns einen Einblick in deine praktische Erfahrung und zeigt, was du wirklich drauf hast. Ein Link zu einem GitHub-Profil oder Sicherheitsanalysen, die du durchgeführt hast, wäre hier super hilfreich!
Wie man sich auf ein Vorstellungsgespräch bei Virtru vorbereitet
✨Sicherheitsprotokolle dominiert!
Mach dich mit den neuesten Sicherheitsprotokollen und -standards vertraut. Bei Virtru könnte es sein, dass du in technisch anspruchsvollen Fragen zu Netzwerksicherheit und Schwachstellenmanagement gefordert wirst – zeig, dass du die Grundlagen und die aktuellen Trends im Bereich IT-Sicherheit beherrschst!
✨Praktische Erfahrung zählt!
Bereite dich darauf vor, über frühere Projekte oder Erfahrungen im Bereich IT-Sicherheit zu sprechen. Es ist wichtig, Beispiele zu haben, wie du Sicherheitslücken identifiziert und behoben hast oder welche Tools du verwendet hast, um Systeme abzusichern. Virtru sucht nach jemandem, der die Theorie auch anwenden kann!
✨Teamarbeit nicht vergessen!
IT-Sicherheit ist oft Teamarbeit. Sei bereit, Fragen zu beantworten, wie du in einem Team umgehst, um Sicherheitsprobleme zu lösen. Denk auch an Beispiel-Situationen, in denen du optimal mit anderen zusammengearbeitet hast – das könnte einen großen Unterschied machen!
✨Motivation und Lernbereitschaft zeigen!
Da es sich um eine Vollzeitstelle handelt, wird Virtru auch wissen wollen, wie motiviert du bist und welche Schritte du unternimmst, um dein Wissen in der sich ständig weiterentwickelnden Welt der IT-Sicherheit auf dem neuesten Stand zu halten. Das könnte in einem Gespräch über deine Weiterbildung oder zertifikatsbezogenen Pläne relevant sein!