Cyber Security Analyst
AARATECHUSA3d ago
SecurityAnalystremotecurated-jd
Job description
Cyber Security Analyst at AARATECH.
About the role
Aaratech Inc. is hiring a GRC Analyst to manage governance, risk, and compliance operations. You will maintain security frameworks and prepare the organization for audits while ensuring adherence to regulatory standards.
Key facts
What you'll do
- Gather evidence and perform control testing for SOC 2, ISO 27001, and NIST standards.
- Identify compliance gaps and monitor the progress of remediation tasks.
- Create and update internal security policies and compliance records.
- Evaluate risks associated with third-party vendors.
- Work alongside business and IT departments throughout the audit lifecycle.
- Draft reports and organize documentation for upcoming audits.
Requirements
- Bachelor degree in Information Systems, Information Technology, Cyber Security, or a related discipline.
- Minimum of 4 years of professional experience in risk management, IT audit, GRC, or compliance.
- Practical understanding of security control frameworks including NIST, SOC 2, and ISO 27001.
- Proven history of managing security policies and supporting audit processes.
Nice to have
- CISA certification.
- CRISC, CGRC, or ISO 27001 Lead Auditor/Implementer credentials.
- Formal training in NIST or ISO 27001.
- Background in vendor risk management.
Skills & tools
- NIST
- ISO 27001
- SOC 2
- Risk assessment
- Audit preparation
- Policy development
Practical notes
Applicants must be authorized to work in the United States without sponsorship.