Governance Risk & Compliance Analyst
Lakewood, CO
Experience: 0
Category: Scientific & Clinical
Contractor Work Model: Hybrid
Brand: Joulé
Job ID: 375588
Date Posted: 06/17/2026
Shortcut: http://jobs.systemone.com/ZgnQAr
Job Title: Governance Risk & Compliance Analyst
Location: Lakewood, CO
Work Model: Hybrid – onsite and remote
Overview
System One is seeking a GRC Analyst for an opportunity in Lakewood, CO. The GRC Analyst is a member of the Governance, Risk & Compliance function within the Global Information Security Office and supports the implementation of company?wide security governance, risk management, and compliance programs. Under the direction of the GRC Functional Leader, the analyst contributes to policy development, risk oversight, and continuous improvement of the organization’s security posture. The role also works closely with regional Information Security Officers (ISOs) and cross?functional teams to support the deployment of global standards and local regulatory requirements.
Responsibilities
- Support information security risk assessments for new projects, systems, and business processes.
- Assist in conducting internal control reviews (e.g., J?SOX), preparing audit materials, and coordinating responses to internal and external auditors.
- Track and follow up on remediation actions to ensure timely closure of identified risks.
- Contribute to drafting, updating, and maintaining global information security policies, standards, and procedures.
- Review relevant laws, regulations, and industry frameworks (e.g., ISO 27001, NIS2) and incorporate stakeholder feedback into documentation.
- Support the rollout and implementation of policies across regions.
- Monitor adherence to security and regulatory requirements, including ISO 27001, NIS2, and GDPR.
- Collect and organize compliance evidence, track corrective actions, and support certification and regulatory readiness efforts such as ISO 27001/42001 and NIS2 programs.
- Conduct third party security risk assessments by distributing questionnaires, analyzing responses, verifying controls, and documenting results in the GRC tracking systems.
- Identify and escalate high risk findings to the GRC Functional Leader and support follow up mitigation activities.
- Participate in the planning and implementation of security awareness programs for all associates.
- Create e-learning materials and training materials, conduct phishing email exercises, and distribute disseminated content on internal portals.
- Monitor and analyze global regulatory developments related to cybersecurity with a focus on industrial control systems (ICS), IT environments, and critical infrastructure.
- Assist in evaluating how new or updated regulations (e.g., NIS2, FDA cybersecurity expectations, industrial cybersecurity standards, or country specific critical infrastructure laws) impact company operations.
- Track emerging obligations, document requirements, and support gap assessments to ensure timely compliance.
- Assist in the preparation, maintenance, and continuous improvement of the CISO Dashboard by collecting, validating, and analyzing security metrics across the Global GRC function.
- Compile key performance indicators (KPIs) and key risk indicators (KRIs) related to compliance status, audit findings, supplier risk, incident trends, training completion, regulatory readiness, and other relevant security domains.
- Support the visualization and communication of security posture to senior leadership by ensuring data accuracy, timely updates, and clarity in reporting.
- Support the development and enforcement of governance controls for the secure use of artificial intelligence technologies across the organization.
- Identify risks related to AI systems—such as model security, algorithmic integrity, and misuse—and contribute to risk assessments and mitigation plans.
- Help evaluate third party AI tools.
- Support the development and improvement of GRC processes, tools, and documentation to enhance operational efficiency and standardization.
- Assist in preparing reports, presentations, and materials for leadership reviews, steering committees, and cross functional meetings.
- Participate in internal security projects and initiatives, including process automation, metrics development, and enhancements to governance workflows.
- Provide coordination and administrative support for security committees, working groups, and regional GRC activities.
- Perform additional duties as assigned to support the Global Information Security Office and the broader GRC program.
- 3 to 5+ years of experience in information security, governance, risk management, compliance, IT audit, or a related discipline.
- Experience supporting security programs in global or regulated environments is a plus.
- Understanding of global and regional information security regulations (e.g., data protection laws, cybersecurity requirements) and familiarity with security frameworks such as ISO 27001.
- Knowledge of internal control frameworks (e.g., JSOX) and IT governance practices is highly desirable.
- Experience supporting audit activities is preferred.
- Experience with risk assessment methodologies, control evaluation, and vulnerability or issue management processes.
- Strong analytical and problem-solving skills, with the ability to identify risks, assess impacts, and support the development and tracking of corrective actions.
- Ability to communicate security requirements, policies, and audit findings clearly and persuasively with stakeholders across regions and business units.
- Strong coordination skills to build consensus and drive compliance.
- Industry certifications such as CISSP, CISA, CISM, ISO 27001 Lead Implementer/Auditor, or similar are preferred but not required.
- Bachelor’s degree in information security, Cybersecurity, Information Systems, Computer Science, or a related field; or equivalent professional experience.
- Familiarity with governance, risk, and compliance tools (e.g., BitSight, Drata, OneTrust, Archer, or similar) for managing risks, audits, and compliance workflows.
- Working knowledge of cybersecurity concepts such as identity and access management, endpoint protection, vulnerability management, cloud security, and secure system design.
- Experience supporting cross-functional security or compliance initiatives, including requirements gathering, documentation, and progress tracking.
- Ability to interpret risk metrics, compliance data, and audit results.
- Experience with dashboards, KPI/KRI reporting, or data visualization tools is a plus.
- Awareness of emerging cybersecurity regulations (e.g., NIS2, AI governance frameworks, critical infrastructure rules) and their potential impact on enterprise operations.
System One, and its subsidiaries including Joulé and Mountain Ltd., are leaders in delivering outsourced services and workforce solutions across North America. We help clients get work done more efficiently and economically, without compromising quality. System One not only serves as a valued partner for our clients, but we offer eligible employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan.
System One is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, age, national origin, disability, family care or medical leave status, genetic information, veteran status, marital status, or any other characteristic protected by applicable federal, state, or local law.
#M-1
#LI-SG1
Ref: #558-Scientific
-
IRM GRC ServiceNow Developer Senior
Englewood, Colorado
Job Title: IRM GRC ServiceNow Developer Senior Location: Englewood, CO Type: Contract To Hire Compensation: 130-160K Contractor Work Model: On-site Security Clearance: Clearable for a secret clearance (but don't have to have a current one to start). Du...
Date Posted: 04/29/2026 Recommended
-
Principal SDET, Cybersecurity Test Engineer
Lakewood, CO
Job Title: Principal SDET, Cybersecurity Test Engineer Location: Lakewood, CO Type: Direct Hire Job Summary: System One is seeking a Principal SDET – Cybersecurity Test Engineer for a full-time/permanent opportunity in Lakewood, CO. As a Sr. Technical ...
Date Posted: 06/03/2026 Recommended
-
Cloud Security Engineer
Salisbury, MD
Job Title: Cloud Security Engineer Location: Salisbury, MD Type: Direct Hire Compensation: $126000 - $190000 annually Contractor Work Model: Onsite Position Summary We are seeking a skilled and detail-oriented Cloud Security Engineer to join our growin...
Date Posted: 05/13/2026 Recommended
-
Global Quality Digital Operations - Engineer 4 - SAP S4 Hana
Lakewood, Colorado
Global Quality Digital Operations – Engineer 4 – SAP S4 Hana Direct Hire Lakewood, CO (Hybrid) Salary Range: $125,000 to $157,000, plus benefits. Salary commensurate with experience JOB SUMMARY The Engineer Level 4 – SAP S/4HANA Quality Engineer is a s...
Date Posted: 05/07/2026 Recommended
-
PKI Governance and Configuration Manager
Springfield, VA
Job Title: PKI Governance and Configuration Manager Location: Springfield, VA Required Security Clearance: Top Secret Responsibilities Oversee the integrity, security, and compliance of Department of State’s PKI and Credential hosting systems. Manage t...
Date Posted: 06/16/2026 Recommended
-
Senior Regulatory Affairs Specialist
Cary, Illinois
Job Title: Senior Regulatory Affairs Specialist Location: Cary, Illinois Type: Contract Compensation: $58- $64/hr Work Model: Onsite Overview Join a leading medical device organization as a Regulatory Affairs professional supporting global regulatory s...
Date Posted: 06/18/2026 Recommended
-
Global Regulatory Compliance Manager
Pine Brook, New Jersey
Job Title: Global Regulatory Compliance Manager Location: Pine Brook, New Jersey Type: Direct Hire Compensation: $115,000.00 - $155,000.00 per year Contractor Work Model: Hybrid – onsite and remote Hours: 9 AM - 5 PM EST Responsibilities Lead global pr...
Date Posted: 05/18/2026 Recommended
-
Regulatory Compliance Specialist
Pine Brook, New Jersey
Job Title: Regulatory Compliance Specialist Location: Pine Brook, NJ Type: Full-time Compensation: $85,000.00 – $115,000.00 per year Contractor Work Model: Hybrid – onsite and remote Hours: 9 AM- 5 PM EST Responsibilities Ensure products meet complex r...
Date Posted: 05/18/2026 Recommended
-
Security Engineer II
Milford, DE
Job Title: Security Engineer II Location: Milford, DE Type: Direct Hire Job Summary: System One is seeking a Security Engineer II for a permanent opportunity in Milford, DE. The Security Engineer will work Technology Services to managing escalated secu...
Date Posted: 05/15/2026 Recommended
-
Training Specialist - Cybersecurity awareness
Vienna, VA
Role Title: Training Specialist - Cybersecurity awareness Location: REMOTE Position Type: 6 + month contract – good chance of long term extensions Requirements Training Specialists with strong background in cybersecurity awareness and behavior-based tr...
Date Posted: 06/15/2026 Recommended
-
Compliance Specialist III
Sunnyvale, California
Job Title: Field Action Quality Specialist Location: Sunnyvale, CA Type: 6 month contract Compensation: $25/hr Contractor Work Model: Onsite Hours: M-F, 8-5 Overview We are seeking a Field Action Quality Specialist to support product recall and field a...
Date Posted: 06/12/2026 Recommended
-
DevSecOps Engineer & MBSE Modeler
Rockville, Virginia
DevSecOps Engineer & MBSE Compensation: $140,000 - 150,000 Security Clearance: Secret clearance required to start Must be able to obtain Top Secret Location: Rockville, MD with occasional travel locally (Aberdeen Proving Ground, Pentagon, CARDEROCK) We...
Date Posted: 05/27/2026 Recommended
-
Test Engineer
Weston, Florida
Job Title: Test Engineer Location: Weston, Florida Type: Contract Compensation: $40-46.66/hr Contractor Work Model: Hybrid Join a collaborative and innovation-driven medical technology organization as a Software Test Engineer supporting critical health...
Date Posted: 05/28/2026 Recommended
-
Sr. Business Analyst
St. Louis, Missouri
Job Title: Sr. Business Analyst Location: St. Louis, Missouri Type: Contract To Hire Contractor Work Model: Onsite Security Clearance: TS/SCI with ability to obtain polygraph within 90 days Responsibilities Provide senior program and project management...
Date Posted: 06/16/2026 Recommended
-
Director Medical Monitor
Parsippany, NJ
Job Title: Director Medical Monitor Location: Parsippany, NJ Type: Direct Hire Contractor Work Model: Hybrid – onsite Overview Responsibilities Provide medical oversight for assigned clinical studies from study start-up through closeout. Participate in...
Date Posted: 06/17/2026 Recommended
-
Cybersecurity Engineer ( W2 direct hire, US citizen or Green cards only, no C2C )
Pittsburgh, Pennsylvania
*** This is a direct hire role - W2 salary with full benefits - with our company itself - NOT for our client *** ONLY US CITIZENS -or- US PERMANENT RESIDENTS ( GREEN CARD ) - NO C2C candidates, NO 3rd parties - NO visa sponsorship, NO green card sponso...
Date Posted: 06/08/2026 Recommended
-
SAP Master Data Specialist
Parkville, Missouri
Job Title: Master Data Compliance Specialist Location: Parkville, Missouri Type: Direct Hire Compensation: $100K-$130K Contractor Work Model: Onsite – onsite Hours: M-F (8-5) with some evenings and weekend required Overview We are seeking a detail-orie...
Date Posted: 06/02/2026 Recommended
-
HR Consultant - OMBP
San Antonio, TX
Job Title: HR Consultant – OMBP Location: Hybrid Work Model Reporting to San Antonio, TX Monday - Friday is required in the office in the beginning for training, then will switch to a hybrid position of 3 days a week on-site. Pay Rate: $48/hr. W2 Posit...
Date Posted: 06/02/2026 Recommended
-
Oracle HCM Functional/Technical Consultant
Vienna, VA
Job Title: Oracle HCM Functional/Technical Consultant Location: Hybrid Work Model Reporting to Vienna, VA Pay Rate: Open to Both C2C and W2 options Position Type: Multiyear Contract Description Seeking a highly experienced Oracle HCM Functional/Technic...
Date Posted: 06/16/2026 Recommended
-
Senior Systems Architect
Scott AFB, Maryland
Job Title: Senior Systems Architect Location: Scott AFB, Maryland Contractor Work Model: Onsite – onsite Security Clearance: Secret clearance Overview Responsibilities Support a specialized enterprise architecture team in designing, developing, and eva...
Date Posted: 05/28/2026 Recommended
-
Risk and Compliance Systems Analyst
Merrifield, VA
Job Title: Risk and Compliance Systems Analyst Location: Vienna, VA Work schedule: hybrid onsite 3 days (remote 2 days) Pay Rate: Open to Both W2 and C2C Position Type: Multiyear Contract We are looking for candidates with 5-7 years of professional exp...
Date Posted: 05/27/2026 Recommended
-
REMOTE Cybersecurity Engineer ( W2 direct hire, US citizen or GC only, no C2C )
Atlanta, Georgia
*** This is a direct hire role - W2 salary with full benefits - no contractors *** ONLY US CITIZENS -or- US PERMANENT RESIDENTS ( GREEN CARD ) - NO C2C candidates, NO 3rd parties - NO visa sponsorship, NO green card sponsorship - NO F1 visa students, N...
Date Posted: 06/16/2026 Recommended
-
REMOTE Cybersecurity Engineer ( W2 direct hire, US citizen or GC only, no C2C )
Washington, District Of Columbia
*** This is a direct hire role - W2 salary with full benefits - no contractors *** ONLY US CITIZENS -or- US PERMANENT RESIDENTS ( GREEN CARD ) - NO C2C candidates, NO 3rd parties - NO visa sponsorship, NO green card sponsorship - NO F1 visa students, N...
Date Posted: 06/16/2026 Recommended
-
Application Architect
Bethesda, MD
Job Title: Application Architect Location: Bethesda, MD Type: Permanent salaried position Compensation: 170- 190K Contractor Work Model: Hybrid (2 to 3 days on site in Bethesda MD) The Senior Application Architect is responsible for developing and evol...
Date Posted: 04/17/2026 Recommended
-
Sr. Cloud Security Specialist (AWS)
Washington, DC
Senior Cloud Security Specialist 100% ONSITE in Washington DC Per Federal contract U.S. Citizenship Required Must be able to pass enhanced FBI background screening (criminal, financial and finger printing) for Public Trust clearance Performance Period:...
Date Posted: 04/28/2026 Recommended
-
NQA-1 Lead Auditor & Auditor
Cheswick, PA
NOW HIRING – NQA-1 Lead Auditors & Auditors System One is seeking experienced Nuclear Quality Assurance (NQA-1) Lead Auditors and Auditors to support supplier and program audits at locations across the United States. Required Experience Candidates must...
Date Posted: 06/11/2026 Recommended
-
Criminal Justice Data Scientist
Gaithersburg, Maryland
Job Title: Criminal Justice Data Scientist Location: Gaithersburg, Maryland Hybrid Schedule: 2 Days Onsite and 3 Days Remote Type: 12 month Contract with option to extend Approximate Start Date: July 13, 2026 Compensation: W-2 or C2C is negotiable All ...
Date Posted: 06/08/2026 Recommended
-
Quality Engineer
Latrobe, Pennsylvania
Job Title: Quality Engineer Location: Latrobe, Pennsylvania Type: Direct Hire Compensation: $75,000.00 - $85,000.00 Contractor Work Model: Onsite – onsite Hours: 40.0 Security Clearance: Not specified Overview Support the maintenance of the Quality Man...
Date Posted: 06/09/2026 Recommended
-
Cybersecurity Engineer ( W2 direct hire, US citizen or Green cards only, no C2C )
Pittsburgh, Pennsylvania
*** This is a direct hire role - W2 salary with full benefits - with our company itself - NOT for our client *** ONLY US CITIZENS -or- US PERMANENT RESIDENTS ( GREEN CARD ) - NO C2C candidates, NO 3rd parties - NO visa sponsorship, NO green card sponso...
Date Posted: 06/16/2026 Recommended
-
Regulatory Specialist / Food Science
Hershey, PA
Job Title: Regulatory Specialist / Sr. Regulatory Specialist – Salty Snacks Location: Hershey, PA Type: Contract Compensation: N/A Contractor Work Model: Hybrid – onsite and remote Hours: 40.0 Responsibilities Support Regulatory Affairs activities for ...
Date Posted: 05/27/2026 Recommended