{"21514638":{"jobPath":"/jobs/21514638/security-officer","source":"naylor","job":"21514638","jobTitle":"Security Officer"},"21513823":{"jobPath":"/jobs/21513823/senior-director-federal-laboratory-government-affairs","source":"naylor","job":"21513823","jobTitle":"Senior Director, Federal Laboratory Government Affairs"},"21512833":{"jobPath":"/jobs/21512833/vp-of-it-cybersecurity","source":"naylor","job":"21512833","jobTitle":"VP of IT & Cybersecurity"},"21510313":{"jobPath":"/jobs/21510313/it-project-manager-ii-527053","source":"naylor","job":"21510313","jobTitle":"IT Project Manager II - 527053"},"21516280":{"jobPath":"/jobs/21516280/user-experiences-and-it-operations-manager","source":"naylor","job":"21516280","jobTitle":"User Experiences and IT Operations Manager"},"21511821":{"jobPath":"/jobs/21511821/security-and-privacy-officer","source":"naylor","job":"21511821","jobTitle":"Security and Privacy Officer"},"21512917":{"jobPath":"/jobs/21512917/info-security-ops-engineer-ii","source":"naylor","job":"21512917","jobTitle":"Info Security Ops Engineer II"},"21516025":{"jobPath":"/jobs/21516025/director-of-database-and-office-information-technology","source":"naylor","job":"21516025","jobTitle":"Director of Database and Office Information Technology"},"21517799":{"jobPath":"/jobs/21517799/governance-risk-and-compliance-analyst","source":"naylor","job":"21517799","jobTitle":"Governance, Risk and Compliance Analyst"},"21463896":{"jobPath":"/jobs/21463896/internal-audit-manager","source":"naylor","job":"21463896","jobTitle":"Internal Audit Manager"},"21510286":{"jobPath":"/jobs/21510286/business-systems-analyst-bruin-financial-aid-it-products","source":"naylor","job":"21510286","jobTitle":"Business Systems Analyst, Bruin Financial Aid IT Products"},"21443441":{"jobPath":"/jobs/21443441/associate-director-chief-information-security-officer","source":"naylor","job":"21443441","jobTitle":"Associate Director, Chief Information Security Officer\t"},"21516114":{"jobPath":"/jobs/21516114/internal-audit-director","source":"naylor","job":"21516114","jobTitle":"Internal Audit Director"},"21517568":{"jobPath":"/jobs/21517568/information-security-lead-architect-information-security","source":"naylor","job":"21517568","jobTitle":"INFORMATION SECURITY LEAD ARCHITECT, Information Security"},"21515642":{"jobPath":"/jobs/21515642/data-governance-manager","source":"naylor","job":"21515642","jobTitle":"Data Governance Manager"},"21513085":{"jobPath":"/jobs/21513085/executive-director-of-risk-advisory-insurance-services","source":"naylor","job":"21513085","jobTitle":"Executive Director of Risk Advisory & Insurance Services"},"21516218":{"jobPath":"/jobs/21516218/it-grc-analyst","source":"naylor","job":"21516218","jobTitle":"IT GRC Analyst"},"21517726":{"jobPath":"/jobs/21517726/deputy-chief-information-officer","source":"naylor","job":"21517726","jobTitle":"DEPUTY CHIEF INFORMATION OFFICER"},"21460670":{"jobPath":"/jobs/21460670/information-systems-auditor-auditor-iv","source":"naylor","job":"21460670","jobTitle":"Information Systems Auditor (Auditor IV)"},"21512853":{"jobPath":"/jobs/21512853/access-control-and-security-camera-systems-specialist","source":"naylor","job":"21512853","jobTitle":"Access Control and Security Camera Systems Specialist"},"21510971":{"jobPath":"/jobs/21510971/protective-security-police-officer","source":"naylor","job":"21510971","jobTitle":"Protective Security Police Officer"},"21365794":{"jobPath":"/jobs/21365794/senior-manager-it-audit","source":"naylor","job":"21365794","jobTitle":"Senior Manager IT Audit"},"21516174":{"jobPath":"/jobs/21516174/director-of-information-technology","source":"naylor","job":"21516174","jobTitle":"Director of Information Technology"},"21518334":{"jobPath":"/jobs/21518334/manager-cybersecurity-operations","source":"naylor","job":"21518334","jobTitle":"Manager, Cybersecurity Operations"},"21516133":{"jobPath":"/jobs/21516133/senior-director-government-affairs","source":"naylor","job":"21516133","jobTitle":"Senior Director, Government Affairs"}}
This job description is intended to describe the general nature and level of work being performed by people assigned to this classification. It is not intended to be construed as an exhaustive list of all responsibilities, duties and skills required of personnel so classified.
JOB SUMMARY
The Governance, Risk, and Compliance (GRC) Analyst supports compliance and governance initiatives for both government and higher education environments. The GRC Analyst implements and maintain National Institute of Standards and Technology (NIST) -compliant frameworks, supporting the government's Cybersecurity Maturity Model Certification (CMMC) requirements, and ensuring adherence to security controls across diverse environments. The GRC Analyst will collaborate with teams to assess risk, manage compliance documentation, and ensure that security frameworks and controls are implemented effectively and efficiently.
This position requires occasional availability outside of traditional working hours to address urgent business needs as they arise, including responding to security incidents, supporting software deployments, resolving software issues or system breaks, and addressing other critical operational requirements. The GRC Analyst mitigates disruption to business operations by promptly addressing any issues, regardless of time or day.
MINIMUM QUALIFICATIONS
Proficiency with Cybersecurity Maturity Model Certification and NIST frameworks and controls.
Knowledge of compliance standards in government and higher education environments.
Effective written and verbal communication skills to convey information and explain complex compliance requirements to various stakeholders at different organizational levels
Adaptable, high initiative and strong sense of urgency
Ability to analyze complex data, identify patterns, and translate findings into actionable insights as well as to evaluate risks and develop appropriate responses.
Knowledge and skills required for this position are generally acquired through a bachelor's degree and at least 2-4 years of experience.
KEY RESPONSIBILITIES & ACCOUNTABILITIES
1) Support CMMC compliance efforts within a government environment. 25%
2) Assist in implementing NIST-based security frameworks and controls in a higher education setting. 25%
3) Conduct risk assessments and audits to ensure compliance with security standards. 25%
4) Develop and maintain compliance documentation and reporting. 25%
Position Type
Legal and Regulatory Administration
Additional Information
Northeastern University considers factors such as candidate work experience, education and skills when extending an offer.
Northeastern has a comprehensive benefits package for benefit eligible employees. This includes medical, vision, dental, paid time off, tuition assistance, wellness & life, retirement- as well as commuting & transportation. Visit https://hr.northeastern.edu/benefits/ for more information.
All qualified applicants are encouraged to apply and will receive consideration for employment without regard to race, religion, color, national origin, age, sex, sexual orientation, disability status, or any other characteristic protected by applicable law.
Compensation Grade/Pay Type: 110S
Expected Hiring Range: $75,210.00 - $106,230.00
With the pay range(s) shown above, the starting salary will depend on several factors, which may include your education, experience, location, knowledge and expertise, and skills as well as a pay comparison to similarly-situated employees already in the role. Salary ranges are reviewed regularly and are subject to change.
Founded in 1898, Northeastern University is a private research university located in the heart of Boston. Northeastern is a leader in worldwide experiential learning, urban engagement, and interdisciplinary research that meets global and societal needs. Our broad mix of experience-based education programs?our signature cooperative education program, as well as student research, service learning, and global learning?build the connections that enable students to transform their lives. The University offers a comprehensive range of undergraduate and graduate programs leading to degrees through the doctorate in nine colleges and schools.