Senior GRC Analyst / Senior ISSO Consultant @IBSS
Compliance
Salary $36,000 per yea..
Remote Location
Employment Type contract
Posted 2wks ago

[Hiring] Senior GRC Analyst / Senior ISSO Consultant @IBSS

2wks ago - IBSS is hiring a remote Senior GRC Analyst / Senior ISSO Consultant. πŸ’Έ Salary: $36,000 per year πŸ“Location: Northern America

Role Description

The Senior GRC Analyst / Senior ISSO will support cybersecurity governance, risk management, and compliance (GRC) initiatives across commercial and federal client environments. This role requires hands-on experience supporting cybersecurity compliance activities, including:

  • Supporting NIST SP 800-171 compliance assessments to evaluate organizational security controls and identify gaps requiring remediation.
  • Independently developing and maintaining System Security Plans (SSPs).
  • Identifying documentation and evidence deficiencies.
  • Coordinating directly with stakeholders to request corrected or additional artifacts as needed.
  • Possessing strong written communication skills and the ability to translate technical implementations into defensible compliance documentation.

Key Responsibilities:

  • Governance & Policy Support:
    • Develop, maintain, and update cybersecurity policies, standards, procedures, and supporting documentation.
    • Support policy-to-control mapping and traceability activities across multiple frameworks.
    • Coordinate annual policy reviews and assist with compliance reporting activities.
    • Research cybersecurity laws, regulations, standards, and guidelines relevant to client environments.
  • Risk Management:
    • Conduct system-level and scoped enterprise risk assessments aligned with NIST SP 800-30 methodologies.
    • Identify threats, vulnerabilities, likelihood, impact, and overall risk ratings.
    • Develop risk assessment reports and remediation recommendations.
    • Maintain and track risks within centralized risk registers.
    • Support vendor risk management activities, including third-party security questionnaire and SOC report reviews.
  • Compliance & Audit Readiness:
    • Independently develop and maintain System Security Plans (SSPs) for frameworks such as NIST SP 800-53 and NIST SP 800-171.
    • Document control implementation statements and validate supporting evidence.
    • Identify incomplete, inaccurate, or insufficient artifacts and coordinate directly with technical stakeholders to obtain corrected evidence.
    • Support readiness efforts for frameworks such as CMMC, HIPAA, ISO 27001, SOC 2, and FedRAMP.
    • Participate in internal and external audit engagements, evidence collection activities, stakeholder interviews, and remediation tracking efforts.
    • Maintain POA&Ms and compliance remediation trackers.
  • Methodology & Team Support:
    • Contribute improvements to internal GRC methodologies, templates, checklists, and delivery processes.
    • Provide mentorship and informal guidance to junior team members, apprentices, and interns.
    • Escalate complex issues and risks to senior leadership as appropriate.
    • Participate in monthly volunteer efforts supporting environmental and humanitarian initiatives.

Qualifications

  • Bachelor's degree in Cybersecurity, Information Technology, Information Systems, Computer Science, or related field; OR equivalent cybersecurity coursework and practical experience.
  • 10 to 12 years of hands-on cybersecurity GRC experience.
  • One or more of the following certifications: CCSP, CISA, CISM, CISSP.
  • Experience supporting or documenting compliance activities aligned with:
    • NIST SP 800-53
    • NIST SP 800-171
    • CMMC
  • Experience developing or maintaining System Security Plans (SSPs).
  • Ability to independently identify evidence gaps and request corrected artifacts from stakeholders.
  • Strong written and verbal communication skills.
  • Ability to work independently and within a team environment.

Requirements

  • Familiarity with FedRAMP environments and federal compliance requirements.
  • Security+, CAP, CCP, or similar cybersecurity certification preferred but not required.
  • Experience supporting federal clients or regulated environments preferred.
  • Public Trust eligibility required; Secret clearance eligibility preferred.

Benefits

  • Medical, dental, vision, and prescription drug coverage with a company-paid deductible.
  • Paid time off and federal holidays.
  • Matching 401K plan.
  • Tuition/professional development reimbursement.
  • Flex-Spending (FSA)/Dependent Care Account (DCA) options.
Before You Apply
️
remote Be aware of the location restriction for this remote position: Northern America
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Senior GRC Analyst / Senior ISSO Consultant @IBSS
Compliance
Salary $36,000 per yea..
Remote Location
Employment Type contract
Posted 2wks ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
remote Be aware of the location restriction for this remote position: Northern America
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—

Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 129,760+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later