Demo

GRC Analyst

Thorlabs
Jessup, MD Full Time
POSTED ON 2/1/2025
AVAILABLE BEFORE 3/31/2025

Thorlabs is pleased to play a role in advancing science through the components, instruments, and systems we design and manufacture. We believe that science and innovation have great potential to improve the world around us and are committed to advancing photonics (i.e., light-based) technologies that positively impact our customers, employees, and communities. Via educational outreach and more sustainable business practices, we continuously invest in a brighter future. We recognize that each of our employees is a unique individual with the ability to contribute to our success and seek to find great people who will thrive in our fun, fast-paced culture

The GRC Analyst supports the organization’s Governance, Risk, and Compliance (GRC) initiatives by assisting in policy development, risk assessments, compliance audits, and reporting. This role provides a path to grow into more senior positions in information security and compliance, such as Senior GRC Analyst or Information Security Manager, by gaining hands-on experience with frameworks, tools, and processes critical to the organization’s security posture.

 

Although the location of the position is in Jessup, MD, from time to time it may be required to undertake duties at other Thorlabs locations.

Essential Job Functions include the following, but are not limited to:

Governance and Policy Support

  • Assist in the development, review, and maintenance of information security policies, standards, and procedures.
  • Support alignment with regulatory frameworks such as PCI-DSS, CMMC 2.0, and ISO27001.
  • Collaborate with teams to promote awareness of governance and compliance requirements.

Risk Assessment and Management

  • Conduct risk assessments to identify, document, and report on information security risks.
  • Monitor and track risk mitigation efforts and recommend improvements.
  • Assist in generating Key Risk Indicator (KRI) reports and metrics.

Compliance Monitoring and Auditing

  • Support compliance efforts with frameworks like PCI-DSS, CMMC, and ISO27001.
  • Assist in preparing evidence and documentation for internal and external audits.
  • Help coordinate responses to auditor inquiries and follow-up actions.

Reporting and Documentation

  • Prepare and maintain dashboards and reports on GRC activities, including audit results and compliance metrics.
  • Document findings and recommendations from audits, risk assessments, and compliance reviews.

The Company retains the right to change or assign other duties to this position.

 

Physical Activities:

This is largely a sedentary role; however, it may require the ability to lift, bend or stand as necessary. The employee may occasionally lift or move objects up to 25 pounds.

Experience:

  • 4 years of professional experience, including 2 years in information security with a focus on GRC.
  • Exposure to regulatory frameworks (e.g., PCI-DSS, CMMC, ISO27001, NIST) is preferred.
  • Experience with GRC tools (e.g., RSA Archer, ServiceNow GRC) or a strong willingness to learn.

Education:

  • Bachelor’s degree in Information Security, Computer Science, IT, Business Administration, or a related field (or equivalent experience).

Specialized Knowledge and Skills:

  • Foundational understanding of risk management concepts and security frameworks.
  • Strong organizational skills with the ability to manage multiple priorities.
  • Excellent written and verbal communication skills, including report writing.
  • Strong analytical and problem-solving skills to assess risks, understand controls, and suggest mitigations.
  • Security engineering or software development experience is highly advantageous; experience with data visualization tools is a plus.
  • Hands-on experience with vulnerability management tools (e.g., Qualys, Nessus, Rapid7) and attack surface management solutions is a big plus.

Other:

  • Compliance with International Traffic in Arms Regulations (ITAR).

Job Type - Full Time

$85,000 - 113,000 d.o.e.

Thorlabs values its diverse environment and is proud to be an Equal Employment Opportunity/Affirmative Action Employer.  All qualified individuals will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age or veteran status. Job descriptions are not intended as and do not create employment contracts.  The organization maintains its status as an at-will employer.  Employees can be terminated for any reason not prohibited by law.

Thorlabs offers a complete benefits package that includes medical, dental and vision insurance, company paid life insurance, a generous PTO package, a 401(k) plan, and tuition reimbursement just to name a few..

Salary : $85,000 - $113,000

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a GRC Analyst?

Sign up to receive alerts about other jobs on the GRC Analyst career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$74,367 - $98,680
Income Estimation: 
$131,676 - $196,560
Income Estimation: 
$99,138 - $133,641
Income Estimation: 
$94,973 - $125,755
Income Estimation: 
$96,228 - $129,772
Income Estimation: 
$152,549 - $188,894
Income Estimation: 
$194,072 - $240,547
Income Estimation: 
$135,994 - $168,063
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$139,945 - $168,577
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$70,462 - $84,818
Income Estimation: 
$77,991 - $108,747
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Thorlabs

Thorlabs
Hired Organization Address Jessup, MD Full Time
Thorlabs is pleased to play a role in advancing science through the components, instruments, and systems we design and m...
Thorlabs
Hired Organization Address Jessup, MD Full Time
Thorlabs is pleased to play a role in advancing science through the components, instruments, and systems we design and m...
Thorlabs
Hired Organization Address Lafayette, CO Full Time
This position will contribute to the receiving and managing of inventory to meet demand forecasts. This responsibility r...
Thorlabs
Hired Organization Address Newton, NJ Full Time
This position works among a team of individuals assembling products for our customers under the guidance of experienced ...

Not the job you're looking for? Here are some other GRC Analyst jobs in the Jessup, MD area that may be a better fit.

Supply Chain - Information Systems Analyst

Information Systems Analyst in Baltimore, MD - LifeBridge Health, Baltimore, MD

Archer GRC Developer

Vision, Owings Mills, MD

AI Assistant is available now!

Feel free to start your new journey!