×
Register Here to Apply for Jobs or Post Jobs. X

Information Security GRC Analyst

Job in Milford, Worcester County, Massachusetts, 01757, USA
Listing for: Waters Corporation
Full Time position
Listed on 2026-03-12
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security, IT Consultant, Data Security
Salary/Wage Range or Industry Benchmark: 60000 - 80000 USD Yearly USD 60000.00 80000.00 YEAR
Job Description & How to Apply Below

Overview

We are seeking a GRC Analyst with CMMC experience to support CMMC 2.0 Level 2 readiness, certification, and ongoing compliance efforts. This role is ideal for a cybersecurity or compliance professional with hands‑on exposure to CMMC or NIST SP 800-171, who is ready to deepen their expertise while working alongside senior assessors and advisors.

You will contribute to CMMC readiness and assessment activities for Government Contractors and commercial organizations, while gaining exposure to broader cybersecurity risk and compliance engagements such as cyber risk assessments, compliance program development, and Information Security support.

This role emphasizes execution, documentation quality, and learning, with increasing responsibility for Waters' broader GRC information security program over time.

Responsibilities CMMC & Compliance Execution
  • Support CMMC 2.0 Level 2 readiness and assessment activities under the guidance of Information Security and Business Leadership.
  • Assist with interpreting NIST SP 800-171 and CMMC requirements and mapping them to client or internal controls.
  • Help develop, update, and maintain:
    • System Security Plans (SSPs)
    • Plans of Action & Milestones (POA&Ms)
    • Policies, procedures, and evidence artifacts
  • Participate in gap assessments and risk reviews; help track remediation activities and evidence collection.
  • Support mock assessments, internal audits, and formal C3

    PAO assessments by preparing documentation and responding to evidence requests.
  • Assist with CUI scoping, boundary definitions, and DFARS 252.204‑7012 documentation activities.
Delivery & Cyber Advisory Support
  • Contribute to cybersecurity and risk engagements such as:
    • CMMC readiness and assessments
    • Cyber risk and controls assessments
    • Compliance program implementation
    • Information security program support
  • Prepare work papers, evidence mappings, and draft assessment documentation in accordance with firm methodology.
  • Translate technical and compliance requirements into clear, well‑organized documentation.
  • Maintain a strong service mindset while operating in a complex business environment.
Governance Risk And Compliance Operations (GRC)
  • Participate in Waters risk management program, including vendor assessments, reviews, remediation follow‑up, and monitoring.
  • Participate in reporting security risk to IT senior leadership and other key organizational stakeholders.
  • Maintain and improve the organization’s risk register and compliance documentation.
  • Conduct risk assessments and control gap analyses; develop mitigation strategies and track remediation efforts.
Audit & Customer Response
  • Prepare and support internal and external audits, including evidence collection and response coordination.
  • Support responding to security questionnaires and demonstrating IT compliance with security frameworks.
  • Draft and maintain clear, consistent, and audit‑ready documentation, including policies, control responses, program updates and reports.
Learning, Collaboration & Practice Development
  • Work closely with senior analysts, managers, and assessors to learn assessment techniques and best practices.
  • Participate in internal training on CMMC, NIST, ISO, SOC, and emerging cyber standards.
  • Contribute to improving templates, checklists, and documentation standards.
  • Share lessons learned and ask questions—this role is designed to grow technical and professional maturity.
What Success Looks Like In This Role
  • High‑quality SSPs, POA&Ms, and evidence artifacts that stand up to assessment scrutiny.
  • Consistent progress toward CMMC Level 2 readiness and certification.
  • Increasing independence in handling assigned controls, domains, and documentation tasks.
  • Strong feedback from senior team members and clients on reliability, accuracy, and professionalism.
Qualifications

Required Qualifications
  • Associate's degree, or higher in Information Security, Information Systems, Cybersecurity, Computer Science, or a related field.
  • 2–4 years of experience in one or more of the following:
    • Cybersecurity, GRC, or IT risk roles.
    • Compliance or audit support.
    • SSP development or security documentation.
    • Internal controls or implementation of policy.
  • Foundational knowledge of CMMC 2.0 and NIST SP 800-171.
  • Experien…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)

Job Posting Language
Employment Category
Education (minimum level)
Filters
Education Level
Experience Level (years)
Posted in last:
Salary