What are the responsibilities and job description for the GRC Analyst position at PKH Enterprises?
Job Description
Job Description
GRC Analyst
This opportunity is remote, but may require occasional meetings onsite. Only candidates in the National Capitol Region.
Job Summary : We are seeking a proactive and detail-oriented Cybersecurity Information Assurance Engineer (Junior) / GRC Analyst (Junior) to support the development of information systems assurance programs and enhance the organization’s governance, risk, and compliance (GRC) processes. Under general supervision, the GRC Analyst will assist in implementing security control guidelines, resolving technical issues, and supporting the development of new dashboards, metrics, and automated functionality. The successful candidate will also contribute to federal compliance initiatives, conduct market research, and help streamline cybersecurity operations through automation and policy adherence.
Key Responsibilities :
- Assist in developing and implementing information systems assurance programs and security control guidelines to ensure compliance with cybersecurity best practices.
- Support the resolution of technical issues, prioritization of tasks, and development of methods to enhance cybersecurity operations.
- Prepare activity and progress reports related to information systems audits, ensuring accurate documentation of cybersecurity efforts.
- Develop new dashboard views to support the Cybersecurity Framework (CSF) and establish performance metrics for improved reporting and decision-making.
- Define processes for leveraging data from the Continuous Diagnostics and Mitigation (CDM) dashboard and provide support for stakeholder training on its usage.
- Assist in the automation of existing processes using Power Apps or similar tools to improve operational efficiency.
- Analyze and review emerging federal information security and privacy policies, directives, and mandates, ensuring timely compliance with specified requirements.
- Track the ownership of policies and procedures, ensuring the associated implementation timelines are adhered to and compliance requirements are met.
- Conduct market research and assist in establishing a roadmap for modernizing the organization’s Governance, Risk, and Compliance (GRC) tool, identifying key requirements for improvement.
- Support agency-led High Value Asset (HVA) assessments in compliance with the Cybersecurity and Infrastructure Security Agency (CISA) Assessment Evaluation and Standardization (AES) Program.
- Update and enhance the organization’s Entity-Wise Business Impact Analysis (EWBIA) to align with evolving business and cybersecurity needs.
Qualifications :
Preferred Skills :
Company Description
PKH Enterprises (PKH) is a small, woman-owned professional services firm dedicated to helping clients address challenging policy and technology issues. The PKH team is comprised of professionals with varied backgrounds combining legal, policy and technical expertise and offers the services and experience of business process engineers, senior subject matter experts and certified project managers. Our diverse capabilities help our clients improve performance and achieve innovative solutions to their most complex business problems. Our clients turn to us as partners and trusted advisors, and depend on our ability to anticipate, recognize and address their specific needs. PKHE has a reputation for excellence and remains dedicated to generating successful results for tasks at all levels of project execution.
To all recruitment agencies : PKH Enterprises does not accept unsolicited agency resumes / CVs. PKH Enterprises is not responsible for any fees related to unsolicited resumes / CVs.
PKH Enterprises is an Equal O
Company Description
PKH Enterprises (PKH) is a small, woman-owned professional services firm dedicated to helping clients address challenging policy and technology issues. The PKH team is comprised of professionals with varied backgrounds combining legal, policy and technical expertise and offers the services and experience of business process engineers, senior subject matter experts and certified project managers. Our diverse capabilities help our clients improve performance and achieve innovative solutions to their most complex business problems. Our clients turn to us as partners and trusted advisors, and depend on our ability to anticipate, recognize and address their specific needs. PKHE has a reputation for excellence and remains dedicated to generating successful results for tasks at all levels of project execution. To all recruitment agencies : PKH Enterprises does not accept unsolicited agency resumes / CVs. PKH Enterprises is not responsible for any fees related to unsolicited resumes / CVs. PKH Enterprises is an Equal O