IT Governance, Risk and Compliance Analyst
Please use Google Chrome or Mozilla Firefox when accessing Candidate Home.
By joining the American Red Cross you will touch millions of lives every year and experience the greatness of the human spirit at its best. Are you ready to be part of the world's largest humanitarian network?
Join us—Where your Career is a Force for Good!
Job Description
As an IT GRC Analyst, you will help mature and maintain the organization's Governance, Risk, and Compliance (GRC) program. You will focus on control assessment by evaluating, reviewing, tracking, and supporting policies and controls aligned with NIST 800-53 / 171, COBIT, ISO 27001, and SOC 2 frameworks. This role works cross-functionally with IT, Information Security, Internal Audit, Legal, and Finance to assess risks, improve processes, and support audit readiness. This position will be virtually located / work-from-home and need to work east-coast hours, with typical workday starting at 8am.
Key Responsibilities
- Support daily GRC operations, policy development, and audit readiness.
- Collaborate with stakeholders to strengthen internal controls and ensure compliance with federal regulations and industry standards.
- Promote control awareness and accountability through training and consultation.
- Maintain GRC tools (e.g., ServiceNow IRM) and stay current on technology trends.
- Evaluate IT control effectiveness across infrastructure, applications, and cloud environments.
- Review documentation, identify gaps, and recommend improvements.
- Track and report control findings, risks, and remediation plans.
- Support exception and risk acceptance processes.
- Coordinate with internal / external auditors and business units during assessments.
- Provide consulting and first-level support for audit activities and findings.
- Assist in developing and executing remediation strategies.
- Assist in drafting, reviewing, and implementing IT policies, standards, and procedures.
- Analyze regulatory requirements and recommend updates to improve compliance.
Required Minimum Qualifications
Bachelor's degree in Information Technology, Cybersecurity, Information Systems, or a closely related discipline.Minimum 4 years of experience in IT audit, compliance, or Information Security.Strong understanding of control frameworks : NIST, ISO, COBIT, FedRAMP, SOC 2.Experience with control assessments, documentation review, audit coordination, and utilizing ServiceNow IRM (preferred) to manage GRC workflows, automate evidence collection, and streamline issue remediation.Skilled in drafting and reviewing IT policies, standards and procedures.Strong communication, analytical, and project management skills.Experience working cross-functionally with technical and business teams.Familiarity with SAFe Agile or similar iterative delivery frameworks.Certifications such as CISA, CRISC, CISSP, CISM are a plus.Combination of candidate's education and general experience satisfies requirements so long as the total years equate to description's minimum education and general experience years combined (Management experience cannot be substituted).Pay Information
The annual salary range for this position is $90K - $110K. We do not offer an annual bonus for this role. American Red Cross salaries are aligned to the specific geographic location in which the work is primarily performed.
Benefits
Medical, Dental, Vision plansHealth Spending Accounts & Flexible Spending AccountsPTO : Starting at 19 days a year; based on type of job and tenureHolidays : 11 paid holidays comprised of six core holidays and five floating holidays401K with up to 6% matchPaid Family LeaveEmployee AssistanceDisability and Insurance : Short + Long TermService Awards and recognitionEqual Opportunity
The American Red Cross is an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to sex, gender identity, sexual orientation, race, color, religion, national origin, disability, protected veteran status, age, or any other characteristic protected by law. Qualified applicants with arrest or conviction records will be considered for employment in accordance with applicable state and local laws. The American Red Cross is a proud EONS partner.
How to Apply
Make your career a force for good!
Apply now at the American Red Cross career page.
J-18808-Ljbffr