GRC Analyst; AuditBoard
Dallas, Dallas County, Texas, 75215, USA
Listed on 2026-02-24
-
IT/Tech
Cybersecurity, Information Security
DETAILS
GRC Analyst (Audit Board) | 468968
Location
: 100% Remote
Position Type
: 6M C2H
Hourly / Salary
: $110K-$140K+ (based on experience level)
Travel
:
Minimal travel to Dallas, TX 75251 (1-2x annually)
Vaco is currently seeking a GRC Analyst for a 6M C2H opportunity that is 100% remote. The GRC Analyst will play a critical role in strengthening the security posture of a growing organization by designing, implementing, and managing control and risk workflows within Audit Board. The GRC Analyst will be pivotal in ensuring compliance with industry standards and regulations, identifying and mitigating risks, and supporting the overall security governance framework.
- Control / Risk Workflow Management – Design / Configure / Maintain Control Frameworks / Risk Workflows within Audit Board | Aligning Organizational Objectives / Compliance Requirements | Document / Develop Control Procedures (Mapped to Internal Policy / HIPPA / HITRUST / PCI Frameworks) | Monitor / Update Risk Registers in Audit Board (Accurate Tracking / Risk Prioritization) | Automate Workflows (Streamlining Control Testing / Evidence Collection / Remediation Processes)
- Compliance / Audit Support – Facilitate Audits / Assessments Leveraging Audit Board (Evidence Management / Reporting) | Prepare / Present Reports (Control Effectiveness / Risk Status / Compliance Gaps) to Leadership
- Risk Assessment / Mitigation – Conduct Risk Assessments to Identify Vulnerabilities / Document Findings in Audit Board | Develop / Implement Risk Mitigation Strategies / Tracking Progress within GRC Platform | Monitor / Report on KRIs | Proactively Address Emerging Risks
- Policy / Procedure Development – Create / Update Security Policies / Procedures / Standards to Support Compliance / Risk Management | Ensure Policies are Integrated into Audit Board for Tracking / Enforcement
- Training / Awareness – Support Development / Delivery of Security Awareness Training | Promote Culture of Security / Compliance Throughout the Organization
- Vendor / 3rd Party Risk Management – Evaluate 3rd Party Vendors for Security / Compliance Risks | Track Vendor Assessments working with Business Owners toward Remediation Action Plans / Activities
- Continuous Improvement – Identify Opportunities to Enhance GRC Processes / Workflows within Audit Board to Improve Efficiency / Effectiveness | Recommend Improvements to the Security Program
- Independent / Team Collaboration – Working Independently as a Standalone GRC Resource while Collaborating Cross-Functionally in a Fast-Paced / Small Business Environment
- Organization / Time Management – Strong Organizational Skills to Manage Multiple Priorities / Audit Deadlines / Control Testing Cycles Simultaneously
The GRC Analyst role is a newly created position within the IT Security Team and sits in a small but growing Risk & Compliance Team (currently the manager + this new hire, collaborating closely with Threat Management and Identity Governance teams). The GRC Analyst role is prioritized to drive immediate GRC maturation with the core focus on hands‑on Audit Board (GRC Platform) implementation and optimization, including design / control frameworks, mapping controls to standards, integrating evidence, developing procedures, automating workflows to eliminate manual work, managing the risk register, tracking exceptions / action plans, and handling reporting.
Beyond Audit Board, the GRC Analyst will lead the policies and procedures refresh project, advance third‑party risk management (vendor assessments / questionnaires / remediation tracking), conduct application / risk assessments, support internal / external audits / compliance (working with internal audit), monitor key risk indicators, contribute to the 2027 GRC roadmap, and support broader documentation / reporting across security.
The GRC Analyst is a high‑impact, proactive role emphasizing continuous improvement, spotting / automating inefficiencies, optimizing processes, rather than repetitive tasks. The GRC Analyst will own and grow the Audit Board‑driven compliance / risk workflows, refresh policies, strengthen vendor risk programs, and build a scalable GRC ecosystem. The ideal GRC…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).