Logo for Hitachi

GRC Consultant-68498

Role overview

Qualifications

  • 5–7 years of experience in GRC, Information Security, IT Risk, IT Audit, Cybersecurity Compliance, or related areas
  • Hands-on experience conducting security and technology risk assessments
  • Strong experience supporting internal and/or external audits end to end
  • Working knowledge of at least two major security frameworks, such as ISO 27001, SOC 2, NIST CSF/800-53, or PCI-DSS

Responsibilities

  • Maintain and update information security policies, standards, procedures, and security-control documentation
  • Conduct security risk assessments across applications, systems, infrastructure, business processes, and vendors
  • Map and assess controls against security and compliance frameworks
  • Partner with Security Engineering, Cloud, Infrastructure, IAM, IT, Legal, and business teams to validate control implementation

About the company

Hitachi logo

Hitachi

Engineering Services

Since its founding in 1910, Hitachi has responded to the expectations of society and its customers through technology and innovation. Our mission is to “Contribute to society through the development of superior, original technology and products.” Over the past 100+ years this commitment has led us to work towards creating a more sustainable society through our “Social Innovation Business”. We work to apply our expertise in information technology (IT), operational technology (OT), and a wide variety of products to advance social infrastructure systems and improve quality of life across the world. Hitachi’s Social Innovation Business is centered around 5 growth sectors: Mobility, Smart Life, Industry, Energy, and IT. Globally, we have nearly 300,000 employees who are working to improve people’s quality of life and our customers’ social, environmental, and economic values to create a sustainable future. The challenges we face as a society are unprecedented, but so are the opportunities. Together, let’s start powering good.

Company details

Company typeXLarge
IndustryEngineering Services
Company size10001

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Function

Cloud & Data Engineering

Our Company

We’re Hitachi Digital Services, a global digital solutions and transformation business with a bold vision of our world’s potential. We’re people-centric and here to power good. Every day, we future-proof urban spaces, conserve natural resources, protect rainforests, and save lives. This is a world where innovation, technology, and deep expertise come together to take our company and customers from what’s now to what’s next. We make it happen through the power of acceleration.

Imagine the sheer breadth of talent it takes to bring a better tomorrow closer to today. We don’t expect you to ‘fit’ every requirement – your life experience, character, perspective, and passion for achieving great things in the world are equally as important to us.

Job description

Title: Senior GRC Analyst

Location: Dallas, TX (Onsite)

Experience: 5–7 years

Meet Our Team

Join our Information Security Governance, Risk, and Compliance (GRC) team, where we partner with Security Engineering, IT, Legal, Privacy, Internal Audit, and business teams to strengthen the organization's security and compliance posture.

Our team is responsible for establishing effective security governance, identifying and managing technology risks, maintaining alignment with industry and regulatory frameworks, and supporting internal and external audits.

In this role, you will help embed security and risk management into day-to-day business operations while improving control monitoring, evidence collection, GRC processes, and compliance automation.

What You'll Be Doing

  • Governance: Maintain and update information security policies, standards, procedures, and security-control documentation.
  • Track policy exceptions and support remediation and governance processes.
  • Translate regulatory, security, and compliance requirements into operational controls.
  • Define, track, and report security metrics and KPIs to support leadership visibility and decision-making.
  • Risk Management
  • Conduct security risk assessments across applications, systems, infrastructure, business processes, and vendors.
  • Maintain the enterprise risk register and track identified risks, remediation plans, owners, due dates, and residual risk.
  • Perform third-party/vendor security risk assessments and due diligence.
  • Support business impact analysis and risk-treatment decisions.
  • Partner with stakeholders to identify control gaps and drive remediation activities.
  • Compliance & Audit
  • Map and assess controls against security and compliance frameworks including:
  • ISO 27001
  • SOC 2
  • NIST CSF / NIST 800-53
  • PCI-DSS
  • GDPR, HIPAA, and other applicable privacy/regulatory requirements
  • Coordinate internal and external audits from evidence gathering through findings closure.
  • Manage audit evidence requests, control testing, findings, and remediation tracking.
  • Support continuous control monitoring and evidence-collection initiatives.
  • Support security certification and attestation programs.
  • Collaboration & GRC Operations
  • Partner with Security Engineering, Cloud, Infrastructure, IAM, IT, Legal, and business teams to validate control implementation.
  • Support security awareness, policy adoption, and governance initiatives.
  • Help mature GRC processes and platforms.
  • Identify opportunities to automate manual compliance, control monitoring, and evidence-collection activities.
  • Support emerging governance areas including cloud security and AI governance.

What You'll Bring to the Team:

  • 5–7 years of experience in GRC, Information Security, IT Risk, IT Audit, Cybersecurity Compliance, or related areas.
  • Hands-on experience conducting security and technology risk assessments.
  • Strong experience supporting internal and/or external audits end to end.
  • Working knowledge of at least two major security frameworks, such as ISO 27001, SOC 2, NIST CSF/800-53, or PCI-DSS.
  • Experience with control mapping, control testing, evidence collection, and remediation tracking.
  • Experience maintaining risk registers and managing risk-remediation activities.
  • Familiarity with third-party/vendor risk management.
  • Understanding of security controls across cloud environments such as AWS, Azure, or GCP, as well as identity and infrastructure.
  • Strong documentation, communication, analytical, and stakeholder-management skills.
  • Bachelor's degree in a related field or equivalent professional experience.
  • Preferred Qualifications
  • CISA, CRISC, CISSP, ISO 27001 Lead Implementer/Auditor, or CompTIA Security+ certification.
  • Hands-on experience with GRC platforms such as ServiceNow GRC/IRM, Archer, OneTrust, Vanta, or Drata.
  • Experience with cloud compliance and continuous-control-monitoring tools.
  • Exposure to compliance automation.
  • Awareness of AI governance, AI risk management, or emerging technology governance.

Key Skills:

Risk Assessment · GRC · Information Security · IT Risk · Control Mapping · Control Testing · Audit Management · ISO 27001 · SOC 2 · NIST · PCI-DSS · Risk Register · Policy Development · Vendor Risk Management · Cloud Security · Compliance Monitoring · Remediation Tracking · GRC Tools

#LI-RS2

About us

We’re a global, team of innovators. Together, we harness engineering excellence and passion to co-create meaningful solutions to complex challenges. We turn organizations into data-driven leaders that can make a positive impact on their industries and society. If you believe that innovation can bring a better tomorrow closer to today, this is the place for you.

Fostering innovation through diverse perspectives

Hitachi is a global company operating across a wide range of industries and regions. One of the things that sets Hitachi apart is the diversity of our business and people, which drives our innovation and growth.

We are committed to building an inclusive culture based on mutual respect and merit-based systems. We believe that when people feel valued, heard, and safe to express themselves, they do their best work.

How we look after you

We help take care of your today and tomorrow with industry-leading benefits, support, and services that look after your holistic health and wellbeing. We’re also champions of life balance and offer flexible arrangements that work for you (role and location dependent). We’re always looking for new ways of working that bring out our best, which leads to unexpected ideas. So here, you’ll experience a sense of belonging, and discover autonomy, freedom, and ownership as you work alongside talented people you enjoy sharing knowledge with.

We’re proud to say we’re an equal opportunity employer and welcome all applicants for employment without attention to race, colour, religion, sex, sexual orientation, gender identity, national origin, veteran, age, disability status or any other protected characteristic. Should you need reasonable accommodations during the recruitment process, please let us know so that we can do our best to set you up for success.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Related jobs

Other jobs at Hitachi

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.