System One logo

Jr. GRC Analyst

System One

  • Rockville, MD
  • Today
  • $35–$40 Per Hour
System One
Want to know if you’re a fit?
Upload your resume and let our AI show you.

Skills

  • Analysis Skillsunmatched
  • Auditingunmatched
  • Business Solutionsunmatched
  • Business impact analysis (BIA)unmatched
  • CISM - Certified Information Security Managerunmatched
  • Communication Skillsunmatched
  • CompTIA Security+unmatched
  • Computer Scienceunmatched
  • Computer Securityunmatched
  • Customer Support/Serviceunmatched
  • Detail Orientedunmatched
  • Document Managementunmatched
  • Documentationunmatched
  • ISACA (Information Systems Audit and Control Association)unmatched
  • IT Governanceunmatched
  • Information Technology & Information Systemsunmatched
  • Information Technology/Systems Auditunmatched
  • Information/Data Security (InfoSec)unmatched
  • Internet Securityunmatched
  • Leadershipunmatched
  • Maintain Complianceunmatched
  • Metricsunmatched
  • Microsoft Product Familyunmatched
  • Multitaskingunmatched
  • Organizational Skillsunmatched
  • Penetration Testingunmatched
  • Presentation/Verbal Skillsunmatched
  • Project/Program Coordinationunmatched
  • Record Keepingunmatched
  • Reporting Dashboardsunmatched
  • Reporting Skillsunmatched
  • Riskunmatched
  • Risk Analysisunmatched
  • Risk Managementunmatched
  • Security Analysisunmatched
  • ServiceNowunmatched
  • Status Reportsunmatched
  • Systems Administration/Managementunmatched
  • Technical Writingunmatched
  • U.S. National Institute of Standards and Technology (NIST)unmatched
  • Vulnerability Scannersunmatched
  • Workflow Analysisunmatched
  • Writing Skillsunmatched

Description

JUNIOR GRC ANALYST
ROCKVILLE, MD - HYBRID
LONG TERM CONTRACT
SEEKING SOMEONE WHO HAS WORKED WITH THE SERVICENOW GRC APPLICATION

Overview:
  • The GRC Analyst supports the administration of Information Security Governance, Risk, and Compliance programs, including policy exception management and enterprise risk register activities using ServiceNow Integrated Risk Management (IRM).
Working under the guidance of Information Security leadership, the analyst will apply established risk assessment methodologies, workflows, and reporting processes to support enterprise cybersecurity governance and risk management initiatives. This role provides hands-on experience in information security governance, risk analysis, policy exception management, enterprise risk management, and ServiceNow IRM.

Key Responsibilities:

Policy Exception Management
  • Review policy exception requests for completeness and required documentation.
  • Validate business justifications and request additional information as needed.
  • Maintain exception records and track approvals in ServiceNow.
  • Monitor expiration dates, coordinate renewals, and produce status reports.
Risk Analysis
  • Conduct risk evaluations using established methodologies and templates.
  • Assess business impact, likelihood, and overall risk.
  • Identify compensating controls and document risk analyses.
  • Prepare risk-based recommendations for management review.
  • Maintain analysis records in ServiceNow.
Enterprise Risk Register Administration
  • Create, update, and maintain risk records.
  • Track risks identified through assessments, penetration tests, vulnerability scans, security incidents, and other approved sources.
  • Monitor mitigation activities, due dates, and risk status.
  • Maintain supporting documentation and generate reports.
ServiceNow IRM Administration
  • Process policy exceptions.
  • Maintain risk register records.
  • Track approvals and workflows.
  • Generate reports and dashboards.
Stakeholder Support
  • Communicate with IT staff, business stakeholders, system owners, managers, and security teams.
  • Provide professional customer service and clear written and verbal communication.
Education
  • Bachelor's degree in Cybersecurity, Information Technology, Information Systems, Computer Science, Business Information Systems, or a related field.
Preferred Certifications - at least one
  • CompTIA Security+
  • ISACA IT Risk Fundamentals
  • NIST Cybersecurity Framework (NCSF) Practitioner
  • CISM Fundamentals
  • Cybersecurity, audit, or compliance-related certifications

Experience:
Required
  • One (1) year of experience in Information Security, IT Governance, Risk Management, Compliance, Audit, Information Technology, or a related field; or
  • Recent graduate with relevant internship or equivalent experience.
Preferred
  • ServiceNow experience
  • Microsoft 365 proficiency
  • GRC program experience
  • Technical documentation experience
  • Customer service and project coordination experience

Knowledge & Skills:
  • Basic understanding of cybersecurity, risk management, information security, NIST Cybersecurity Framework, and compliance concepts.
  • Strong analytical, organizational, and critical-thinking skills.
  • Excellent written and verbal communication skills.
  • Attention to detail and ability to manage multiple priorities.
  • Ability to work independently and learn new technologies quickly.

Deliverables:
  • Policy exception reviews and tracking records
  • Risk analyses and recommendations
  • Risk register entries and updates
  • Monthly metrics and quarterly reports
  • Executive dashboards
  • ServiceNow documentation and reporting artifacts

#M1
#LI-CB3

Ref: #851-Rockville-S1


Numbers & Facts

LocationRockville, MD
IndustryStaffing/Employment Agencies
Salary$35–$40 Per Hour
Company Size2,500 to 4,999 employees
Websitehttps://systemone.com

About Company

Every day, System One focuses on services and solutions that require a high degree of specialization, in-demand technical skills, and large-scale operational expertise. We are essential partners to those on the front lines of our nation’s most critical infrastructure, technology, and life sciences initiatives. 

Founded more than 40 years ago as a staffing partner to the engineering industry, today System One is a diversified organization operating in over 50 locations and putting more than 9,000 people to work in the United States, Canada, and the United Kingdom.

Similar Jobs

See more jobs