Information Security Risk Analyst (GRC)

Iconma LLC

  • Phoenix, AZ
  • 11 days ago
    Want to know if you’re a fit?
    Upload your resume and let our AI show you.

    Skills

    • Analysis Skillsunmatched
    • Artificial Intelligence (AI)unmatched
    • Auditingunmatched
    • CISA - Certified Information Systems Auditorunmatched
    • CISM - Certified Information Security Managerunmatched
    • CISSP - Certified Information Systems Security Professionalunmatched
    • Computer Securityunmatched
    • Control Objectives for Information and related Technology (COBIT)unmatched
    • Design Evaluationunmatched
    • Document Managementunmatched
    • Documentationunmatched
    • External Auditunmatched
    • Financial Servicesunmatched
    • Health Planunmatched
    • ISO (International Organization for Standardization)unmatched
    • Information Technology Consultingunmatched
    • Information Technology/Systems Auditunmatched
    • Information/Data Security (InfoSec)unmatched
    • Internal Auditunmatched
    • Performance Metricsunmatched
    • Regulationsunmatched
    • Regulatory Complianceunmatched
    • Riskunmatched
    • Risk Analysisunmatched
    • Risk Managementunmatched
    • Sarbanes-Oxley Act (SOX)unmatched
    • Security Analysisunmatched
    • Software Development Lifecycle (SDLC)unmatched
    • Technical Leadershipunmatched
    • Test Automationunmatched
    • U.S. National Institute of Standards and Technology (NIST)unmatched

    Description

    Our client, a IT Services and Consulting company, is looking for a Information Security Risk Analyst (GRC) for their Phoenix, AZ / Hybrid location.

    Responsibilities:

    • Conduct ITGC, ITAC, and Information Security control testing and document results.
    • Perform Risk & Control Self-Assessments (RCSA) and identify technology risks and control gaps.
    • Evaluate control design and operating effectiveness across SDLC, Architecture, and Technology processes.
    • Manage audit findings, control deficiencies, and remediation activities through closure.
    • Support internal/external audits, regulatory reviews, and compliance requests.
    • Partner with SDLC and Architecture teams to provide risk guidance and governance oversight.
    • Monitor risk metrics, control performance, and compliance status.

    Requirements:

    • 5+ years of experience in Technology Risk, Information Security, IT Controls, Audit, or GRC within financial services.
    • Hands-on experience with ITGC, ITAC, and Information Security control testing.
    • Strong knowledge of risk management, controls, RCSA, audit, and regulatory compliance.
    • Experience supporting SDLC and Architecture governance processes.
    • Excellent analytical, documentation, and stakeholder management skills.
    • Preferred Qualifications:
    • Experience with AI-driven control testing automation or control monitoring solutions.
    • Certifications such as CISA, CRISC, CISSP, CISM, or equivalent.
    • Familiarity with regulatory and industry frameworks such as NIST, COBIT, ISO 27001, SOX, or FFIEC.
    • ITGC & ITAC Control Testing
    • Technology Risk Management
    • Information Security Controls
    • RCSA
    • SDLC & Architecture Risk Governance
    • Audit & Regulatory Compliance
    • Years of Experience: 10.00 Years of Experience

    Why Should You Apply?

    • Health Benefits
    • Referral Program
    • Excellent growth and advancement opportunities

    Numbers & Facts

    LocationPhoenix, AZ

    Similar Jobs

    See more jobs