- Salary
- $120k – $150k
- Location
- Remote, USA
- Workplace
- Remote
- Type
- Full-time
- Department
- Technology
- Seniority
- Lead
- Education
- Master
- Visa
- Not sponsored
- Source
- Lever
Description
The Role
Great Gray is seeking a Lead Information Security Analyst to join our Information Security team. This role will lead IT governance, risk assessment, and security compliance activities while supporting enterprise risk management and compliance with regulations and frameworks such as SOC 2 and the NIST Cybersecurity Framework. The analyst will also coordinate the review, development, implementation, and documentation of policies, processes, procedures, and practices that support the information security management system (ISMS).
Location
This position work remote from the United States. Please note that remote employment in this role is restricted to candidates residing in states where Great Gray is currently registered as an employer. These states are limited to: CA, CO, CT, DC, DE, FL, GA, IL, IN, MA, MD, MI, MN, NC, NH, NJ, NV, NY, OH, PA, RI, SC, TN, TX and VA.
Visa sponsorship or transfer of an existing visa is not available for this position. Applicants must be authorized to work directly for any employer in the United States without visa sponsorship or transfer.
Responsibilities
- Lead and manage GRC functions including compliance monitoring, audit management, and risk assessment.
- Ensure compliance with relevant regulatory requirements and security frameworks (SOC 2, NIST, industry-specific standards, etc.)
- Prepare for and manage compliance audits, assessments, and regulatory reviews
- Maintain security documentation, evidence, and audit trails for compliance purposes
- Develop, maintain, and enforce information security policies and procedures
- Vendor Risk Management security assessments, onboarding, and reviews.
- Collaborate with cross-functional teams to integrate security and compliance into business processes
- Mentor and support the Information Security Analysts in both analyst and GRC functions
- Monitor security posture, identify threats, and recommend remediation measures
- Conduct vulnerability assessments, penetration testing, and security assessments on systems and applications
- Participate in incident response activities and conduct post-incident analysis
- Stay current with security trends, vulnerabilities, and emerging compliance requirements
Qualifications & Experience
- Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related field.
- 5-10+ years of audit, compliance, or technical experience.
- Excellent knowledge of IT security control trends as well as auditing & compliance best practices.
- Effective communication skills (written and verbal) to properly articulate complicated IT controls and compliance issues to leadership and partners.
- Positive attitude and a strong commitment to delivering quality work.
- Relevant training and/or industry certifications in auditing, compliance, or IT security.
- Ability to thrive in a fast-paced, dynamic environment and manage multiple priorities effectively.
- Comfortable navigating ambiguity.
- Entrepreneurial mindset to bring best practice ideas to the team.
- Your standards reflect our core values: Growth Mindset, Disciplined Curiosity, Grit, Results Ownership, Collaboration.
Base Pay Range*
$120,000-$150,000
*This base pay range is subject to change and may be modified in the future.
The pay range displayed above is the base pay compensation range that Great Gray expects to pay for this position at the time of this posting. Individual compensation within this range, or that may warrant a provision for pay beyond this range, depends on multiple factors, including, but not limited to, candidate’s prior education and relevant work experience and training as well as position location and local market demands. Our pay-for-performance culture also includes participation in an annual incentive bonus plan for this position which is not included in the ‘Base Pay Range’ noted above.