Logo for TRAC Consulting

GRC Analyst (REMOTE)

Role overview

Qualifications

  • 3–5+ years of experience in GRC, security compliance, information security, internal audit, or a related discipline.
  • Experience working within a federal, regulated, or cloud-based technology environment.
  • Hands-on participation in at least one complete audit or authorization cycle involving SOC 2, FedRAMP, StateRAMP/GovRAMP, ISO 27001, CMMC, or a comparable framework.
  • Working knowledge of NIST SP 800-53, SOC 2, and GovRAMP requirements.

Responsibilities

  • Support the ongoing development and administration of the organization's GRC program.
  • Provide hands-on support for SOC 2 and GovRAMP audit and authorization activities.
  • Act as a primary point of contact for customer security questionnaires, vendor assessments, and compliance reviews.
  • Monitor contractual requirements related to security, privacy, compliance, reporting, and service obligations.

About the company

TRAC Consulting logo

TRAC Consulting

Staffing & Recruiting

Process Improvement Consultant/Professional Recruiter Working owner of this company specializing in recruitment in sales and management professionals for the consumer services industry. Consult and implemented several key initiatives for a large multi-million dollar companies. • RPO for an international company, overseeing all recruiting efforts; streamline process and actively recruit • Process consultant with high level authority in three company mergers to gain synergies • Worked with the Information Technology department; customized software for large scale efficiencies • Effectively negotiated with vendors and implemented a background screening process in over 100 branches for a major staffing company • Created a Policies and Procedures manual for On-Site staffing • Created training documents and conducted training for PeopleSoft system conversions

Company details

Company typeTPE
IndustryStaffing & Recruiting
Company size1 - 1

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

We are seeking a Technical Customer Support Representative (REMOTE) for a full-time and direct hire role for one of our amazing partners. This role is remote, but you MUST be living in the United States and be a US Citizen or Green Card Holder. This role does NOT offer sponsorship, it's NOT a consulting role, and we do NOT work with 3rd parties!


Overview

We are seeking a GRC Analyst to help build and expand a formal Governance, Risk, and Compliance program within a growing technology organization that serves government and other highly regulated customers. You will play a key part in supporting SOC 2 and GovRAMP initiatives, maintaining the controls and evidence required for audits, managing compliance-related documentation, and helping communicate the organization's security posture to customers and government agencies. This is an opportunity to build and improve processes, rather than simply maintain an established program. You will work across engineering, compliance, sales, and product teams to turn security and regulatory requirements into practical, well-documented processes.

This is an opportunity to join a growing organization at an important stage of its compliance journey. You will have the opportunity to help establish scalable GRC processes, strengthen audit readiness, support government contracting opportunities, and work directly with technical and business leaders to build a mature security and compliance function.


Responsibilities:

  • Governance, Risk & Compliance
    • Support the ongoing development and administration of the organization's GRC program. Help maintain compliance with frameworks and requirements including NIST SP 800-53, CJIS Security Policy, SOC 2, and GovRAMP.
    • Maintain the enterprise risk register and assist with periodic risk assessments.
    • Monitor control performance and identify areas requiring remediation or improvement.
    • Develop, update, organize, and maintain security and compliance policies and procedures.
    • Manage policy version control, approvals, annual reviews, and employee attestations.
  • Audit & Authorization Support
    • Provide hands-on support for SOC 2 and GovRAMP audit and authorization activities.
    • Assist with gap assessments and track remediation efforts through completion.
    • Collect, organize, validate, and maintain audit evidence.
    • Work closely with engineering and other technical teams to identify and complete compliance-related requirements.
    • Help ensure controls are consistently documented and supported by appropriate evidence.
  • Customer Security & Compliance
    • Act as a primary point of contact for customer security questionnaires, vendor assessments, and compliance reviews.
    • Develop and maintain a centralized library of approved responses and supporting documentation.
    • Improve the efficiency and consistency of questionnaire responses while reducing duplicate work.
    • Maintain customer-facing materials that accurately describe the organization's security, privacy, and compliance posture.
    • Coordinate responses to recurring customer and third-party risk assessments.
  • Contract Compliance
    • Monitor contractual requirements related to security, privacy, compliance, reporting, and service obligations.
    • Maintain a centralized calendar of recurring contractual deliverables and deadlines.
    • Coordinate items such as monthly and quarterly reports, SLA documentation, insurance certificates, certifications, and other required compliance materials.
    • Ensure commitments made to government and commercial customers are tracked through completion.
  • RFPs & Government Proposals
    • Partner with the Growth team on government and public-sector RFPs, solicitations, and proposal opportunities.
    • Develop and edit security, technical, compliance, and management sections of proposals.
    • Support proposal amendments, customer questions, formal responses, and post-award activities.
    • Create reusable proposal content and maintain a library of approved security and compliance language.
    • Translate technical security capabilities into clear, compelling information that can be evaluated by procurement and government stakeholders.

Requirements:

  • 3–5+ years of experience in GRC, security compliance, information security, internal audit, or a related discipline.
  • Experience working within a federal, regulated, or cloud-based technology environment.
  • Hands-on participation in at least one complete audit or authorization cycle involving SOC 2, FedRAMP, StateRAMP/GovRAMP, ISO 27001, CMMC, or a comparable framework.
  • Working knowledge of NIST SP 800-53, SOC 2, and GovRAMP requirements.
  • Technical understanding of cloud and/or on-premises environments, including areas such as
  • Identity and access management, Encryption, Security logging and monitoring, Network architecture, Software development lifecycle and change management.
  • Practical experience using AI tools for research, drafting, documentation, analysis, or evidence-management activities.
  • Strong cross-functional communication skills to move comfortably between technical and business environments. You will take complex engineering concepts and turn them into clear documentation for auditors, customers, and procurement teams, and then translate compliance requirements into actionable tasks for technical teams.
  • An evidence-first mindset to understand that saying a control is in place isn't enough. You know how to identify, collect, organize, and validate the evidence necessary to demonstrate that a control is operating effectively.
  • Builder mentality where you are comfortable creating structure where processes are still evolving. You don't need an established playbook to get started and can develop practical workflows that scale as the organization grows.
  • Organization & execution skills to manage multiple priorities, stakeholders, and deadlines simultaneously, particularly when working toward externally driven audit, certification, or proposal deadlines.
  • Strategic thinking with hands-on execution skills. You should be comfortable balancing immediate compliance needs with longer-term improvements to systems, documentation, and processes.
  • Adaptability to thrive in an environment where priorities can change quickly and are comfortable taking ownership, solving problems independently, and creating new approaches when necessary.
  • Strong written and verbal communication skills.
  • Demonstrated ability to coordinate several concurrent initiatives while meeting firm external deadlines.
  • Ability to work independently and establish processes without extensive direction.


Preferred Experience

  • Experience with the CJIS Security Policy, FBI NGI, or criminal justice information systems.
  • Experience supporting government or public-sector RFPs and proposal development.
  • Familiarity with compliance automation platforms such as Vanta, Drata, or similar tools.
  • Experience working directly with government agencies or organizations subject to federal security requirements.


All qualified applicants will receive consideration for employment without regard to race, color, national origin, age, ancestry, religion, sex, sexual orientation, gender identity, gender expression, marital status, disability, medical condition, genetic information, pregnancy, or military or veteran status.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Related jobs

Other jobs at TRAC Consulting

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.