Back to all roles

GRC Analyst (AuditBoard REQUIRED) (468968)

Remote-first Full-time Now hiring

GRC Analyst (AuditBoard) | 468968 DETAILS Location: 100% Remote Position Type: 6M C2H Hourly / Salary: $110K-$140K+ (based on experience level) Travel: Minimal travel to Dallas, TX 75251 (1-2x annually) JOB SUMMARY Vaco is currently seeking a GRC Analyst for a 6M C2H opportunity that is 100% remote. The GRC Analyst will play a critical role in strengthening the security posture of a growing organization by designing, implementing, and managing control and risk workflows within AuditBoard. The GRC Analyst will be pivotal in ensuring compliance with industry standards and regulations, identifying and mitigating risks, and supporting the overall security governance framework.

  • Control / Risk Workflow Management – Design / Configure / Maintain Control Frameworks / Risk Workflows within AuditBoard | Aligning Organizational Objectives / Compliance Requirements | Document / Develop Control Procedures (Mapped to Internal Policy / HIPPA / HITRUST / PCI Frameworks) | Monitor / Update Risk Registers in AuditBoard (Accurate Tracking / Risk Prioritization) | Automate Workflows (Streamlining Control Testing / Evidence Collection / Remediation Processes)
  • Compliance / Audit Support – Facilitate Audits / Assessments Leveraging AuditBoard (Evidence Management / Reporting) | Prepare / Present Reports (Control Effectiveness / Risk Status / Compliance Gaps) to Leadership
  • Risk Assessment / Mitigation – Conduct Risk Assessments to Identify Vulnerabilities / Document Findings in AuditBoard | Develop / Implement Risk Mitigation Strategies / Tracking Progress within GRC Platform | Monitor / Report on KRIs | Proactively Address Emerging Risks
  • Policy / Procedure Development – Create / Update Security Policies / Procedures / Standards to Support Compliance / Risk Management | Ensure Policies are Integrated into AuditBoard for Tracking / Enforcement
  • Training / Awareness – Support Development / Delivery of Security Awareness Training | Promote Culture of Security / Compliance Throughout the Organization
  • Vendor / 3rd Party Risk Management – Evaluate 3rd Party Vendors for Security / Compliance Risks | Track Vendor Assessments working with Business Owners toward Remediation Action Plans / Activities
  • Continuous Improvement – Identify Opportunities to Enhance GRC Processes / Workflows within AuditBoard to Improve Efficiency / Effectiveness | Recommend Improvements to the Security Program
  • Independent / Team Collaboration – Working Independently as a Standalone GRC Resource while Collaborating Cross-Functionally in a Fast-Paced / Small Business Environment
  • Organization / Time Management – Strong Organizational Skills to Manage Multiple Priorities / Audit Deadlines / Control Testing Cycles Simultaneously

About the Project: The GRC Analyst role is a newly created position within the IT Security Team and sits in a small but growing Risk & Compliance Team (currently the manager + this new hire, collaborating closely with Threat Management and Identity Governance teams). The GRC Analyst role is prioritized to drive immediate GRC maturation with the core focus on hands-on AuditBoard (GRC Platform) implementation and optimization, including design / control frameworks, mapping controls to standards, integrating evidence, developing procedures, automating workflows to eliminate manual work, managing the risk register, tracking exceptions / action plans, and handling reporting. Beyond AuditBoard, the GRC Analyst will lead the policies and procedures refresh project, advance third-party risk management (vendor assessments / questionnaires / remediation tracking), conduct application / risk assessments, support internal / external audits / compliance (working with internal audit), monitor key risk indicators, contribute to the 2027 GRC roadmap, and support broader documentation / reporting across security. The GRC Analyst is a high-impact, proactive role emphasizing continuous improvement, spotting / automating inefficiencies, optimizing processes, rather than repetitive tasks. The GRC Analyst will own and grow the AuditBoard-driven compliance / risk workflows, refresh policies, strengthen vendor risk programs, and build a scalable GRC ecosystem. The ideal GRC Analyst will have 5+ years of hands-on experience, including extensive AuditBoard expertise, multi-framework knowledge, and proven risk / compliance project ownership. JOB REQUIREMENTS

  • GRC Tool Administration – Proficiency in Configuring / Customizing / Managing Workflows in AuditBoard/GRC Platforms (Risk Registers / Control Libraries / Issue Tracking / Evidence Collection Workflows / Audit Management Modules)
  • Framework Expertise – Compliance Frameworks (NIST 800-53 / SOC 2 / HIPAA / HITRUST) | Control Mapping / Gap Assessments / Ongoing Monitoring Requirements
  • Risk Management (strong understanding) – Risk Management Principles and Methodologies (Inherent vs. Residual Risk / Risk Scoring Models / Control Effectiveness Evaluations / Risk Treatment Planning)
  • Technical Fou

Apply To This Job

More remote roles

[Remote] Intelligence Analyst - Digital Risk Monitoring (Remote)

Remote-first Full-time

Threat Intelligence Analyst- Remote in USA in Team Cymru Inc

Remote-first Full-time

Remote AI Security Analyst | Forensics & Threat Modeling

Remote-first Full-time

SOC Analyst, Information Security Operations (Remote - United States)

Remote-first Full-time

SOC Analyst - 100% Remote

Remote-first Full-time

Hiring: Tier 2 SOC Analyst (Full-Time)-(Remote- USA

Remote-first Full-time

[Remote] SOC Analyst (shift work)

Remote-first Full-time

SOC Analyst - Remote

Remote-first Full-time

Cybersecurity SOC Analyst L1 (AI-Assisted Monitoring)

Remote-first Full-time

Remote Health Writer – New Jersey IEC

Remote-first Full-time

Remote | Bond Markets & Rates Trading Consultant — $175–$225/hour

Remote-first Full-time

Experienced Customer Service Representative – Healthcare Advocate (Remote)

Remote-first Full-time

Experienced Virtual Data Entry Clerk – Remote Opportunity with arenaflex

Remote-first Full-time

Experienced Remote Chat Support Specialist – Delivering Exceptional Customer Experience in a Dynamic Healthcare Environment

Remote-first Full-time

Licensed Mental Health Counselor (LMHC-D) - Remote

Remote-first Full-time

[Remote] Presales Solution Architect - Amazon Connect

Remote-first Full-time

On-Call Research Associate

Remote-first Full-time

Customer Chat & Email Support Specialist – Entry-Level Friendly Customer Service Representative (Florida Residents Only, No Technical Experience Required)

Remote-first Full-time

UI/UX Software Design Intern

Remote-first Full-time

Manager National Sales

Remote-first Full-time