GRC Analyst
Department: Information Technology
Location: Redondo Beach
Compensation: $90,000 - $120,000 / year
Description We are seeking a Governance, Risk, and Compliance (GRC) Analyst to help build, manage, and scale our information security compliance programs. You will play a hands-on role in maintaining and operationalizing controls for frameworks like CMMC, NIST 800-171, NIST 800-53, and ITAR, while supporting internal risk assessments, customer security reviews, and policy lifecycle management. This role is ideal for someone who thrives on structured thinking, translating security requirements into business-aligned controls, and keeping fast-moving teams inspection-ready. You'll work closely with the InfoSec, IT, legal, and engineering teams while supporting both internal leadership and external customer compliance engagements. Responsibilities- Maintain and track compliance with NIST 800-171, 800-53, CMMC, and ITAR obligations across systems, personnel, and vendors
- Own and manage security documentation, including System Security Plans (SSPs), POA&Ms, RA/RM, and associated audit artifacts
- Leverage Onspring to manage control mappings, evidence collection, policy lifecycle tracking, and compliance reporting
- Assist in the development, revision, and review of security policies, standards, and procedures to ensure alignment with current frameworks
- Collaborate with IT, Security, and Engineering teams to monitor and verify the implementation of technical and administrative controls
- Coordinate and support internal risk assessments, gap analyses, and customer security reviews
- Track and report on compliance status, risk findings, and remediation activities to InfoSec leadership and executive stakeholders
- Support risk-based decision making by conducting internal control reviews and supplier/vendor compliance assessments
- Facilitate end-user security training, compliance briefings, and evidence collection workflows
- Participate in continuous improvement of compliance processes, playbooks, and tooling as the company scales
- 3+ years in a GRC, information security, compliance, or audit support role
- Experience working with, NIST 800-171 and 800-53, CMMC Level 2 or 3, and ITAR and/or export control regimes
- Experience with POA&M management, SSP development, risk assessments, and control mapping
- Experience interfacing with customer security teams or supporting customer-driven compliance reviews
- Demonstrated experience with Onspring or similar GRC platforms (ServiceNow GRC, Archer, etc.)
- Experience supporting defense contractors, aerospace manufacturers, or similar regulated industries
- Demonstrated knowledge of insider threat program requirements, third-party risk programs, or DFARS compliance
- Familiarity with vulnerability management workflows and secure system baselining
- Security certifications such as CAP, CISA, Security+, or Certified CMMC Professional (CCP)
- Strong writing, documentation, and communication skills
Recommended Jobs
Tech 2, Mechanical Engineering
Roles & Responsibilities Collect, maintain, format, and manipulate technical data (e.g., lab or material test results, engineering design changes). Produce engineering documentation, including …
Food Service Worker - Azusa Pacific University
Job Description The Food Service Worker will assist the manager with food/meal preparation; maintain cash receipts and meal records. Assist manager in completing daily reports. Maintain high stand…
Advanced Medical Support Assistant
Applicants pending the completion of educational or certification/licensure requirements may be referred and tentatively selected but may not be hired until all requirements are met. Basic Requirement…
Software Engineer, Infrastructure - Analytics
About the Team The Scaling team designs, builds, and operates critical infrastructure that enables research at OpenAI. Our mission is simple: accelerate the progress of research towards AGI. We…
Cook 3
Press space or enter keys to toggle section visibility OVERVIEW/BASIC FUNCTION: Plan, prep, set up and provide quality service in all areas of hot food production to include, but not …
QE ETL test engineer
Technical Primary Skills: - We need someone with experience leading GW Data migration projects (From Legacy to GW cloud). This includes both ETL testing and functional testing within GW (PC, BC, …
Deal Data Technology & Analytics, Manager Save for Later Remove job
A career in Technology and Data Solutions practice, within Deals M&A Transaction Services, provides the opportunity to help organizations realize the potential of mergers, acquisitions, divestiture…
Repair & Maintenance
Job Description Job Description Restaurant Overview: The Odyssey is an iconic steak-forward concept atop the scenic hills of Granada Hills, with captivating views of the surrounding San Fernan…
Engineering Manager, Evals (API)
About the Team: OpenAI's mission is to ensure that artificial general intelligence (AGI) benefits all of humanity. Through our API, we realize our mission by enabling everyone to harness the power…
Wine and Spirits Merchandiser- (*SF Bay Area Applicants Only)
About Us: Proudly serving our San Francisco Bay Area communities since 1986, Mollie Stone’s Markets is a local, family-owned grocery store chain. With over 38 years of exemplary performance, Molli…