Hiring.Camp

Senior GRC / Third-Party Risk / Data Protection Analyst

Peraton

·

Yesterday

Salary
$104k – $166k
Location
, US
Workplace
Remote
Type
Full-time
Department
Security
Seniority
Senior
Experience
8+ years
Education
Bachelor
Closing date
Today
Source
iCIMS

Description

Responsibilities

**Position Is Contingent Upon Award**

Peraton Labs is hiring a Senior GRC / Third-Party Risk / Data Protection Analyst to own the governance, risk, and compliance engine of the engagement — policy, control testing, and POA&M management — together with third-party security risk management and the data protection and insider threat program for the California health benefit exchange and the CalHEERS eligibility and enrollment system.

You will work with Covered California security leadership and privacy stakeholders, vendors and their security teams, our on-site security engineering and incident response colleagues, and the independent assessment team, for whom you are the operational-side evidence provider. The goal is that the program's compliance posture against NIST SP 800-53 Rev. 5, ARC-AMPE, and IRS Publication 1075 is real, evidenced, and audit-ready on any given day rather than reconstructed once a year.

What You Will Do In This Role:

  • Own policy and control documentation. Author and maintain security policies, procedures, standards, plans, and control documentation for the environment.
  • Test controls and close POA&Ms. Perform control testing and gap analysis against NIST SP 800-53 Rev. 5, document deficiencies, and manage POA&Ms through remediation and verified closure.
  • Keep the program audit-ready. Maintain the control evidence library and GRC platform records, control mappings, and compliance reporting; support the annual independent assessment as the operational-side evidence provider, without acting as an assessor.
  • Run third-party security risk management. Conduct vendor security due diligence and assessments, contract and control reviews, continuous monitoring, and risk reporting.
  • Lead data protection. Discover and catalog confidential data, define and apply the data classification scheme, and implement protective controls including DLP, encryption, and access controls.
  • Support the insider threat program. Contribute to insider threat use cases, monitoring, and escalation procedures in coordination with privacy, HR, and legal stakeholders.
  • Carry the regulated-data obligations. Support IRS Publication 1075 and ARC-AMPE compliance activities and the privacy obligations of the contract's Privacy Addendum; participate in the on-call incident response rotation.

Qualifications

Required:

  • Bachelor's degree in information systems, cybersecurity, or business with a security concentration. In lieu of a degree, an additional 4 years of relevant experience will be considered.
  • 8+ years of experience in security governance, risk, and compliance, third-party risk management, or data protection.
  • Active CISA or CGRC certification.
  • Demonstrated experience performing control assessment and gap analysis against NIST SP 800-53 Rev. 5, and managing the POA&M lifecycle from deficiency identification through closure.
  • Demonstrated third-party and vendor security risk management experience, including questionnaire-based assessment frameworks such as SIG or CAIQ, contract and control review, and continuous monitoring.
  • Hands-on experience with data classification and data-flow mapping, and with an enterprise DLP platform such as Microsoft Purview, Netskope, or Forcepoint.
  • Precise compliance writing ability — policies, control narratives, and deficiency write-ups that withstand external review — and working knowledge of an enterprise GRC platform.
  • US Citizenship and the abillity to pass a California criminal background clearance (Gov. Code §1043 / 10 CCR §6456) before starting work or accessing any confidential information, PII, PHI, federal tax information, or financial information.

Desired:

  • CIPP/US certification. CRISC, CIPT, or CISM are also valued.
  • Experience with ARC-AMPE security and privacy requirements.
  • Experience with IRS Publication 1075 and FTI safeguarding, including participation in a Safeguard Review.
  • Working knowledge of HIPAA/HITECH and the California Consumer Privacy Act.
  • Experience with CMS requirements and Authority to Connect support, including Security Assessment Workbooks (SAWs), security assessment reports, and control evidence packages.
  • Experience in California state government compliance environments.
  • Experience with health benefit exchange or Medicaid eligibility systems.
  • Experience with encryption and key management concepts and with insider threat program design.

Peraton Overview

Peraton is a next-generation national security company that drives missions of consequence spanning the globe and extending to the farthest reaches of the galaxy. As the world’s leading mission capability integrator and transformative enterprise IT provider, we deliver trusted, highly differentiated solutions and technologies to protect our nation and allies. Peraton operates at the critical nexus between traditional and nontraditional threats across all domains: land, sea, space, air, and cyberspace. The company serves as a valued partner to essential government agencies and supports every branch of the U.S. armed forces. Each day, our employees do the can’t be done by solving the most daunting challenges facing our customers. Visit peraton.com to learn how we’re keeping people around the world safe and secure.

Target Salary Range

$104,000 - $166,000. This represents the typical salary range for this position. Salary is determined by various factors, including but not limited to, the scope and responsibilities of the position, the individual’s experience, education, knowledge, skills, and competencies, as well as geographic location and business and contract considerations. Depending on the position, employees may be eligible for overtime, shift differential, and a discretionary bonus in addition to base pay.

EEO

EEO: Equal opportunity employer, including disability and protected veterans, or other characteristics protected by law.

Skills

CybersecurityRisk ManagementComplianceHIPAA

Similar Jobs

30

Senior GRC Analyst

Preply · Barcelona · Hybrid

Yesterday

Senior GRC Analyst

Preply · London · Hybrid

Yesterday

Governance, Risk & Compliance (GRC) Senior Analyst

Mesh · United States - Remote, San Francisco, CA +2 · Remote

Yesterday

Senior GRC Engineer - GOV (FedRAMP 20x)

Workstreet · Remote (United States) · Remote

Yesterday

Senior GRC Analyst

Bcbsla · Remote-LA, United States of America · Remote

2 days ago

Sr Cybersecurity Analyst - GRC

Dexcom · Manila, Philippines +1

2 days ago

Senior Governance, Risk, and Compliance (GRC) Analyst (Remote)

RainFocus · Orem, UT · Remote

2 days ago

Sr. Security Engineer - GRC EU/UK Regulation & Data Protection

xAI · London, England, United Kingdom

2 days ago

GRC/IRM ServiceNow Technology Implementation Solutions – Senior Manager

Pwc · Chicago - One North Wacker Drive, United States of America +11

3 days ago

Senior Solution Sales Executive, GRC - DACH

Workiva · Remote - GER BB, Germany · Remote

3 days ago

Senior Manager, GRC Regulatory Assurance

TMX group of companies includes · Toronto - 100 Adelaide St W, Canada

3 days ago

SAP GRC Senior Consultant

Professional Kyndryl · Sao Paulo (KBR51645) WeWork Office, Brazil · Remote

3 days ago

Senior Cybersecurity Consultant (GRC)

Ensigninfosecurity · SG_Ensign_Kallang Place, L7 (Left Wing), Singapore

3 days ago

Senior GRC Specialist

OCS Ontario Cannabis Store · Toronto, ON, Canada

3 days ago

Senior Engineer, Information Security GRC

Ice · Atlanta, GA, US

4 days ago

GRC Senior Validation Advisor (SAP Controls & Assurance)

Maersk · INDJZ03 - Pune - Weikfield IT - CITI Infopark, India

4 days ago

Senior GRC Manager

Converge Technology Solutions · United States · Remote

4 days ago

Senior Cybersecurity Engineer, GRC Automation and Continuous Control Monitoring

Marathon Petroleum Corporation (MPC) · San Antonio TX, United States of America +2

5 days ago

Senior Security Analyst, GRC

Greatamerica · Cedar Rapids, IA, United States of America · Remote

5 days ago

Senior GRC Programmer/Analyst

Huntington · Easton Ops Cols C Oh, United States of America +8 · Onsite

1 week ago

Senior Information Security GRC Specialist

Reconomy · Bucharest

1 week ago

Senior Analyst, GRC

Veterinaryemergencygroupst · VEG Headquarters, White Plains, NY

1 week ago

Senior Consultant GRC

Devoteam · Madrid, MD, Spain · Remote

1 week ago

Senior Consultant SAP Security: Berechtigungsmanagement & GRC (all genders)

Wavestone · -, -

1 week ago

Assurance - Auditor Senior Riesgos Tecnológicos (GRC IT)

Pwc · Madrid - Paseo de la Castellana 259 B, Spain

1 week ago

Senior Consultant SAP Security: Berechtigungsmanagement & GRC (all genders)

Europe Wavestone · -, -, Deutschland

1 week ago

Senior Information Security Manager (GRC)

Deepl · Munich +2

1 week ago

Senior GRC Consultant (Cyber & Information Security)

Implement Consulting Group · Hellerup, Denmark

1 week ago

Senior GRC Specialist, APAC

Airwallex · CN - Shanghai · Onsite

1 week ago

Analyst-Cyber GRC, Sr.

Tallgrass Energy · Lakewood, CO, United States, US

1 week ago