All roles

GRC Analyst (AuditBoard REQUIRED) (468968)

Remote · USA Full-time New today

GRC Analyst (AuditBoard) | 468968 DETAILS Location: 100% Remote Position Type: 6M C2H Hourly / Salary: $110K-$140K+ (based on experience level) Travel: Minimal travel to Dallas, TX 75251 (1-2x annually) JOB SUMMARY Vaco is currently seeking a GRC Analyst for a 6M C2H opportunity that is 100% remote. The GRC Analyst will play a critical role in strengthening the security posture of a growing organization by designing, implementing, and managing control and risk workflows within AuditBoard. The GRC Analyst will be pivotal in ensuring compliance with industry standards and regulations, identifying and mitigating risks, and supporting the overall security governance framework.

  • Control / Risk Workflow Management – Design / Configure / Maintain Control Frameworks / Risk Workflows within AuditBoard | Aligning Organizational Objectives / Compliance Requirements | Document / Develop Control Procedures (Mapped to Internal Policy / HIPPA / HITRUST / PCI Frameworks) | Monitor / Update Risk Registers in AuditBoard (Accurate Tracking / Risk Prioritization) | Automate Workflows (Streamlining Control Testing / Evidence Collection / Remediation Processes)
  • Compliance / Audit Support – Facilitate Audits / Assessments Leveraging AuditBoard (Evidence Management / Reporting) | Prepare / Present Reports (Control Effectiveness / Risk Status / Compliance Gaps) to Leadership
  • Risk Assessment / Mitigation – Conduct Risk Assessments to Identify Vulnerabilities / Document Findings in AuditBoard | Develop / Implement Risk Mitigation Strategies / Tracking Progress within GRC Platform | Monitor / Report on KRIs | Proactively Address Emerging Risks
  • Policy / Procedure Development – Create / Update Security Policies / Procedures / Standards to Support Compliance / Risk Management | Ensure Policies are Integrated into AuditBoard for Tracking / Enforcement
  • Training / Awareness – Support Development / Delivery of Security Awareness Training | Promote Culture of Security / Compliance Throughout the Organization
  • Vendor / 3rd Party Risk Management – Evaluate 3rd Party Vendors for Security / Compliance Risks | Track Vendor Assessments working with Business Owners toward Remediation Action Plans / Activities
  • Continuous Improvement – Identify Opportunities to Enhance GRC Processes / Workflows within AuditBoard to Improve Efficiency / Effectiveness | Recommend Improvements to the Security Program
  • Independent / Team Collaboration – Working Independently as a Standalone GRC Resource while Collaborating Cross-Functionally in a Fast-Paced / Small Business Environment
  • Organization / Time Management – Strong Organizational Skills to Manage Multiple Priorities / Audit Deadlines / Control Testing Cycles Simultaneously

About the Project: The GRC Analyst role is a newly created position within the IT Security Team and sits in a small but growing Risk & Compliance Team (currently the manager + this new hire, collaborating closely with Threat Management and Identity Governance teams). The GRC Analyst role is prioritized to drive immediate GRC maturation with the core focus on hands-on AuditBoard (GRC Platform) implementation and optimization, including design / control frameworks, mapping controls to standards, integrating evidence, developing procedures, automating workflows to eliminate manual work, managing the risk register, tracking exceptions / action plans, and handling reporting. Beyond AuditBoard, the GRC Analyst will lead the policies and procedures refresh project, advance third-party risk management (vendor assessments / questionnaires / remediation tracking), conduct application / risk assessments, support internal / external audits / compliance (working with internal audit), monitor key risk indicators, contribute to the 2027 GRC roadmap, and support broader documentation / reporting across security. The GRC Analyst is a high-impact, proactive role emphasizing continuous improvement, spotting / automating inefficiencies, optimizing processes, rather than repetitive tasks. The GRC Analyst will own and grow the AuditBoard-driven compliance / risk workflows, refresh policies, strengthen vendor risk programs, and build a scalable GRC ecosystem. The ideal GRC Analyst will have 5+ years of hands-on experience, including extensive AuditBoard expertise, multi-framework knowledge, and proven risk / compliance project ownership. JOB REQUIREMENTS

  • GRC Tool Administration – Proficiency in Configuring / Customizing / Managing Workflows in AuditBoard/GRC Platforms (Risk Registers / Control Libraries / Issue Tracking / Evidence Collection Workflows / Audit Management Modules)
  • Framework Expertise – Compliance Frameworks (NIST 800-53 / SOC 2 / HIPAA / HITRUST) | Control Mapping / Gap Assessments / Ongoing Monitoring Requirements
  • Risk Management (strong understanding) – Risk Management Principles and Methodologies (Inherent vs. Residual Risk / Risk Scoring Models / Control Effectiveness Evaluations / Risk Treatment Planning)
  • Technical Fou

Apply To This Job

Related roles

[Remote] Intelligence Analyst - Digital Risk Monitoring (Remote)

Remote · USA Full-time

Threat Intelligence Analyst- Remote in USA in Team Cymru Inc

Remote · USA Full-time

Remote AI Security Analyst | Forensics & Threat Modeling

Remote · USA Full-time

SOC Analyst, Information Security Operations (Remote - United States)

Remote · USA Full-time

SOC Analyst - 100% Remote

Remote · USA Full-time

Hiring: Tier 2 SOC Analyst (Full-Time)-(Remote- USA

Remote · USA Full-time

[Remote] SOC Analyst (shift work)

Remote · USA Full-time

SOC Analyst - Remote

Remote · USA Full-time

Cybersecurity SOC Analyst L1 (AI-Assisted Monitoring)

Remote · USA Full-time

Remote Health Writer – New Jersey IEC

Remote · USA Full-time

[Remote] Relationship Manager/Loan Officer (Mortgage)

Remote · USA Full-time

Registered Nurse III MC/CHC Per Diem - CHC Administration

Remote · USA Full-time

Seeking Veterans to Serve Veterans

Remote · USA Full-time

Meeting and Events Coordinator

Remote · USA Full-time

Experienced Customer Service Representative - Live Chat (FULLY REMOTE) at arenaflex

Remote · USA Full-time

Experienced Pharmacy Technician - Data Entry Specialist in Rochester, NY at arenaflex

Remote · USA Full-time

Nuclear Medicine Clinical Application Specialist

Remote · USA Full-time

Experienced Customer Service Representative – Remote Pharmacy Benefit Services Support

Remote · USA Full-time

Health & Benefits - Customer Service Representative / Support Specialist (Remote) at arenaflex

Remote · USA Full-time

Experienced Part-Time Innovation Analyst Trainee – Business Systems & Technology Solutions (Hiring Now at arenaflex)

Remote · USA Full-time