Position : Jr. Security Analyst
Location : Remote
Overview
Our client is currently looking for a Jr. Security Analyst to join their team in a long term contract capacity focusing on an increase in compliance and audit work heading into the new year. This person will be brought on to support an established information security and compliance team. This role is ideal for someone looking to grow in TPA (Third Party Assessment), audit support, compliance operations, NIST frameworks, and GRC practices.
Below is a breakdown of what our enterprise client is looking for in their potential candidate!
Key Responsibilities
- Support Third Party Assessments (TPAs) by gathering evidence, tracking documentation, and helping review vendor security controls.
- Participate in internal and external audit readiness tasks including evidence collection, control testing preparation, remediation tracking, and audit log review coordination.
- Assist with vulnerability scan reporting, ticket creation, and follow-up with technical teams on remediation tasks.
- Support intake, documentation, and status tracking of new compliance and security projects.
- Help maintain dashboards, risk registers, and compliance reporting metrics within the GRC tool.
- Participate in annual assessment activities including contingency plan exercises, incident response tests, access reviews, and other required security program tasks.
- Assist with audit log reviews and routine monitoring processes as assigned.
- Maintain structured, accurate documentation to support continuous compliance efforts.
Minimum Qualifications
1–3 years of experience in security, IT, audit, or compliance support roles (internships or rotational experience accepted).Foundational knowledge of NIST frameworks, FISMA requirements, or other security compliance standards (HIPAA, SOC 2, ISO 27001 a plus).Experience with GRC platforms (ServiceNow, Archer, OneTrust, ZenGRC, etc.) OR strong interest in learning.Strong attention to detail with the ability to create, edit, and maintain structured documentation.Proficiency with Microsoft Office and basic workflow tracking tools (Excel, SharePoint, Confluence, Smartsheet, etc.).Familiarity with basic cybersecurity terminology and frameworks (e.g., CIS Controls).Experience supporting compliance evidence collection or policy documentation.Interest in security governance, risk, and compliance as a long-term career path.