Loading jobs…
Loading jobs…
ASSYST, Inc. — Rockville, Maryland
ASSYST is seeking an Information Security Governance, Risk & Compliance (GRC) Analyst to support our client in administering and maintaining an established enterprise Information Security Governance, Risk, and Compliance (GRC) program. This role will focus on managing Information Security Policy Exceptions and maintaining the Enterprise Information Security Risk Register using the ServiceNow Integrated Risk Management (IRM) platform. The ideal candidate will work under the guidance of Information Security leadership to execute established governance processes, document and track information security risks, and support enterprise risk management activities.
This position provides an excellent opportunity to gain hands-on experience with enterprise cybersecurity governance, information security risk management, ServiceNow IRM, and policy exception management while collaborating with experienced information security professionals. Note: This position focuses on governance, documentation, and risk management activities. It does not involve performing security assessments, penetration testing, vulnerability assessments, audits, or compliance revie ws.
Responsibilities
: Administer and support the Information Security Policy Exception Program. Maintain and update the Enterprise Information Security Risk Register using the ServiceNow Integrated Risk Management (IRM) platform. Execute established governance processes, standardized risk assessment methodologies, workflows, templates, and reporting procedures.
Review policy exception requests and document findings. Perform information security risk analyses and provide approval or denial recommendations. Document, track, and maintain identified information security risks within the enterprise Risk Register.
Prepare and maintain accurate policy exception tracking records. Produce monthly metrics, quarterly reports, executive dashboards, and ServiceNow documentation. Coordinate assigned tasks, workflows, and activities while ensuring timely completion.
Prepare clear and accurate technical documentation related to governance and risk management processes. Collaborate with internal stakeholders to support enterprise information security governance initiatives. Maintain high standards of documentation accuracy, consistency, and data integrity.
Provide excellent customer service while supporting governance and risk management activities. Work independently while effectively managing multiple priorities and deadlines.
Qualifications
:
Minimum Qualifications
: Professional experience in Information Security, IT Governance, Compliance, Risk Management, Information Technology, Audit, or a related field. Basic understanding of Information Security Governance, Risk Management, and Cybersecurity principles. Strong analytical and critical thinking skills.
Excellent written and verbal communication skills. Strong organizational skills with exceptional attention to detail. Ability to manage multiple priorities in a fast-paced environment.
Ability to quickly learn new technologies and business processes. Demonstrated professionalism and ability to work independently.
Preferred Qualifications
: Experience using ServiceNow, preferably Integrated Risk Management (IRM). Experience with Governance, Risk, and Compliance (GRC) programs or platforms. Experience using Microsoft Office 365 applications.
Experience preparing technical documentation and reports. Experience coordinating projects, tasks, or workflow activities. Experience working in customer service or stakeholder-facing environments.