GRC Analyst

ACADIAN INC
  • LA
    3 days ago

    Job Description

    Acadian Companies is hiring a Governance, Risk, and Compliance (GRC) Analyst to join the Information Security Department in Lafayette, LA.

    Role Overview

    Reporting directly to the Information Security Officer (ISO), the GRC Analyst is a foundational team member responsible for operationalizing enterprise security governance, risk management, and regulatory compliance. Operating independently from IT operations, this role bridges technical security controls, business operations, and executive leadership by leading the Cyber Supply Chain Risk Management (C-SCRM) lifecycle and managing the Plan of Action and Milestones (POA&M) remediation tracker.

    Key Responsibilities

    Third-Party Risk Management

    • Design and maintain vendor risk tiering methodologies based on data access, criticality, and business impact.
    • Evaluate annual security questionnaires and review third-party attestations (SOC 2, ISO 27001, HITRUST, SBOMs).

    Risk & Remediation Governance

    • Maintain the Risk Register and POA&M log, tracking audit findings and vulnerability assessments to resolution.
    • Coordinate with stakeholders to design actionable remediation plans and validate technical control implementations.

    Governance & Compliance

    • Draft and update policies aligned with NIST CSF 2.0 and HIPAA; develop organizational profiles to drive maturity.
    • Execute periodic User Access Reviews (UAR) and support annual Incident Response Plan (IRP) tabletop exercises.

    Qualifications

    • Bachelor's Degree in Cybersecurity, Risk Management, Computer Science, or a related field (or equivalent experience).
    • 2-5 years of professional experience in GRC, IT audit, or cybersecurity risk management.
    • Practical experience with NIST CSF, NIST SP 800-53, or ISO/IEC 27001; HIPAA experience highly preferred.

    Numbers & Facts

    LocationLA

    Skills

    • Analysis Skillsunmatched
    • Business Operationsunmatched
    • Computer Scienceunmatched
    • Computer Securityunmatched
    • Enterprise Protectionunmatched
    • HIPAA (Health Insurance Portability and Accountability Act)unmatched
    • ISO (International Organization for Standardization)unmatched
    • Incident Responseunmatched
    • Information Technology/Systems Auditunmatched
    • Information/Data Security (InfoSec)unmatched
    • International Electro-Technical Commission (IEC)unmatched
    • Internet Securityunmatched
    • Leadershipunmatched
    • Organizational Development/Managementunmatched
    • Policy Developmentunmatched
    • Regulatory Complianceunmatched
    • Riskunmatched
    • Risk Managementunmatched
    • Supply Chain Managementunmatched
    • U.S. National Institute of Standards and Technology (NIST)unmatched

    Be found by employers

    5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

    Level up your application

    Professional resume templates

    Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

    Free resume templates

    Free resume builder

    Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

    Free resume builder