Hiring.Camp

GRC Analyst

Castandcrew

·

Yesterday

Salary
$110k – $120k
Location
Remote - United States of America
Workplace
Remote
Type
Full-time
Experience
5+ years
Source
Workday

Description

About Us

At Cast & Crew, we’ve empowered creativity and supported the global entertainment industry for decades. Together with our family of brands - Backstage, CAPS, Checks & Balances, Final Draft, Media Services, Sargent-Disc, and The TEAM Companies – we operate as a combined entertainment technology and services provider offering industry standard screenwriting accounting software, digital payroll products, data & reporting, and a host of creative tools.  The industry continues to move faster than ever, and the need for our expertise, our technology, and our people has never been greater.  We are a production’s best ally every step of the way. #OneCastOneCrew

Position Overview:

The GRC Analyst supports the Information Security Office by managing third-party vendor risk, processing security questionnaires, and assisting with audit and compliance activities across the enterprise. This role is well-suited for someone with a strong compliance background who is looking to grow within information security. The ideal candidate is detail-oriented, organized, and experienced working with compliance frameworks, audit processes, and GRC tools such as Drata or similar platforms. A willingness to learn security concepts and stay current on evolving practices is essential.

Essential Functions

  • Managing the end-to-end third-party vendor risk management program, including onboarding assessments, periodic reviews, and ongoing monitoring of vendor security posture.
  • Supporting an internal ISRM program focused on uncovering cybersecurity risk and adding it to a risk register for prioritization and acceptance and ownership or remediation
  • Completing and responding to inbound security questionnaires (e.g., SIG, CAIQ, custom questionnaires) from clients and partners in a timely and accurate manner.
  • Coordinating information gathering and interviewing of internal stakeholders to support third-party security questionnaire responses.
  • Supporting and maintaining the organization's compliance automation platforms (e.g., Drata and Andromeda), including evidence collection, control mapping, and readiness tracking.
  • Supporting SOC 1 Type 2 and SOC 2 Type 2 audits, including evidence collection, auditor coordination, and remediation of identified gaps.
  • Developing, maintaining, and improving security documentation, policies, standards, procedures, and runbooks.
  • Monitoring and reporting on internal control effectiveness and audit readiness posture.
  • Advising internal lines of business, IT partners, and third parties on how to remediate security gaps identified through assessments or audits.
  • Understanding applicable regulations, guidelines, and industry best practices to manage risk and ensure compliance.
  • Drafting and presenting risk reports and proposals to executive leadership and senior staff.
  • Performing other duties as directed.

Qualifications:

The following certifications are a plus, but are not expected at the time of hire:

  • CISA or CISM (compliance/audit-focused; strongly relevant to this role)
  • CRISC (risk and controls focus)
  • CISSP, GIAC/GSEC, or vendor certifications (AWS/Azure)

Requirements:

5+ years of experience in compliance, audit, GRC, or a related field, with exposure to information security concepts. Equivalent experience in risk management, regulatory compliance, or internal audit will be considered. Candidates should have working knowledge of the following:

  • Compliance frameworks, audit processes, or risk management programs
  • SOC 1 or SOC 2 audit support or audit evidence collection (direct audit experience a plus)
  • Development or maintenance of policies, procedures, and compliance documentation
  • Third-party or vendor risk processes (experience with formal TPRM programs a plus)
  • GRC or compliance automation tools (e.g., Drata, Andromeda, or similar platforms)

Communications:

  • Excellent oral communication skills and comfortable in group or small team settings
  • Excellent written communication skills
  • Ability to take highly technical material and present/communicate it to a non-technical audience

Relationship Building:

  • Builds excellent working relations with all IT colleagues and users, works effectively with department and executive management, and maintains a professional relationship with outside clients and vendors

Planning, Organizing, Prioritizing, Delivering:

  • Exhibits mature organization and time management skills
  • Excellent problem-solving skills
  • Effectively planning and organizing daily work following priorities set by the Risk Manager
  • Demonstrates strong follow-up and follow-through skills in ensuring timely completion of projects
  • Self-starter who actively takes responsibility to resolve issues but also knows when to ask questions to avoid major delays in delivery of work product

Knowledge of:

  • SOC 1 Type 2 and SOC 2 Type 2 audit processes and control frameworks
  • GRC and compliance automation tools, with preference for Drata
  • Security questionnaire frameworks (e.g., SIG, CAIQ, NIST) and third-party risk methodologies
  • Evidence collection, reporting, and security documentation best practices

Skill In:

  • Coordinating SOC audit activities, evidence collection, and auditor communication
  • Working with compliance frameworks such as NIST CSF, NIST 800-53, or ISO/IEC 27001 (familiarity sufficient; deep expertise not required)
  • Completing or supporting security questionnaire responses (SIG, CAIQ, or similar)
  • Writing clear, well-organized compliance documentation and communicating requirements across teams

Physical Demands:

SEDENTARY - Exerts up to 30 lbs. of force occasionally and/or a negligible amount of force frequently or constantly to lift, carry, push, or pull. Involves sitting most of the time but may involve walking or standing for brief periods of time.

Benefits 

Cast & Crew provides a comprehensive package of employee benefits including: Medical, Dental, Vision, PTO, health and wellness programs, employee discounts, and more! Note: Cast & Crew benefits are subject to eligibility requirements.

Cast & Crew is an equal opportunity employer committed to hiring a diverse workforce and sustaining an inclusive culture. It is our policy to provide equal employment opportunities to all individuals based on job-related qualifications and ability to perform a job, without regard to age, gender, gender identity, sexual orientation, race, color, religion, creed, national origin, disability, genetic information, veteran status, citizenship or marital status, and to maintain a non-discriminatory environment free from intimidation, harassment or bias based upon these grounds.

CA residents
Your personal information may be collected in connection with certain services provided by Cast & Crew or its affiliated companies.  A summary of your California privacy rights can be found at: https://www.castandcrew.com/privacy-policy/

Compensation is commensurate with various factors including, but not limited to, relevant experience, qualifications, skills, training, licensure, certifications, geographic cost of labor, and other business and organizational needs. Compensation range for candidates in other locations may differ based on the cost of labor in that location. The compensation range for this position is: $110,000.00 - $120,000.00 per year.

Skills

AWSAzureCybersecuritySOCRisk ManagementComplianceSOC 2CISSP

Similar Jobs

30

GRC Analyst

American Tower Global · Boston, MA, United States, US · Hybrid

3 days ago

GRC Analyst

Indianapolis & Marion County

4 days ago

GRC Analyst

Paxos · Remote - India · Remote

1 week ago

GRC Analyst

Veralto · IND - Bangalore, Karnataka - Multiple OpCo, India · Hybrid

2 weeks ago

GRC Analyst

Mypassglobal · Cebu · Hybrid

3 weeks ago

GRC Analyst

Zip · San Francisco · Hybrid

3 weeks ago

GRC Analyst

Northmark · Dallas - Victory Commons, United States of America

3 weeks ago

GRC Analyst

Fluidstack · New York, NY · Onsite

1 month ago

GRC Analyst

ASW · MY

1 month ago

GRC Analyst

Vercel · Remote - United States +1 · Remote

1 month ago

GRC Analyst

Network Coverage · Remote · Remote

1 month ago

GRC Analyst

Hempel is · India - Pune · Remote

3 months ago

GRC Analyst

Rogo · New York City · Onsite

3 months ago

Senior GRC / Third-Party Risk / Data Protection Analyst

Peraton · , US · Remote

Yesterday

Senior GRC Analyst

Preply · Barcelona · Hybrid

Yesterday

Senior GRC Analyst

Preply · London · Hybrid

Yesterday

Governance, Risk & Compliance (GRC) Senior Analyst

Mesh · United States - Remote, San Francisco, CA +2 · Remote

Yesterday

GRC Security Analyst

Purestorage · Bangalore, India

Yesterday

Senior GRC Analyst

Bcbsla · Remote-LA, United States of America · Remote

2 days ago

GRC, Vulnerability Management Analyst

Acrisure · 1170 Peachtree St Ste 1200 - ATLANTA, GA, United States of America +1

2 days ago

Sr Cybersecurity Analyst - GRC

Dexcom · Manila, Philippines +1

2 days ago

Senior Governance, Risk, and Compliance (GRC) Analyst (Remote)

RainFocus · Orem, UT · Remote

2 days ago

Mid SAP GRC Security Analyst

Encora · Peru

2 days ago

IT GRC Analyst

Globalstar Inc. Updated · Covington, LA

2 days ago

Cyber Security Analyst (GRC)

Glint Tech Solutions Llc · New York

3 days ago

IT GRC Analyst II

SECU Careers · Operations - Raleigh - Creedmoor Rd, United States of America

4 days ago

Senior Security Analyst, GRC

Greatamerica · Cedar Rapids, IA, United States of America · Remote

5 days ago

GRC Analyst I

Sub-Zero · Madison, WI

1 week ago

Senior GRC Programmer/Analyst

Huntington · Easton Ops Cols C Oh, United States of America +8 · Onsite

1 week ago

Senior Analyst, GRC

Veterinaryemergencygroupst · VEG Headquarters, White Plains, NY

1 week ago