Governance Risk & Compliance Analyst

Lakewood, CO

Apply Apply with LinkedIn
Save

Type: Contract

Experience: 0

Category: Scientific & Clinical

Contractor Work Model: Hybrid

Brand: Joulé

Job ID: 375588

Date Posted: 06/17/2026

Shortcut: http://jobs.systemone.com/aMdJ7U


Job Title: Governance Risk & Compliance Analyst

Location: Lakewood, CO

Work Model: Hybrid – onsite and remote

Overview

System One is seeking a GRC Analyst for an opportunity in Lakewood, CO. The GRC Analyst is a member of the Governance, Risk & Compliance function within the Global Information Security Office and supports the implementation of company?wide security governance, risk management, and compliance programs. Under the direction of the GRC Functional Leader, the analyst contributes to policy development, risk oversight, and continuous improvement of the organization’s security posture. The role also works closely with regional Information Security Officers (ISOs) and cross?functional teams to support the deployment of global standards and local regulatory requirements.
Responsibilities

  • Support information security risk assessments for new projects, systems, and business processes.
  • Assist in conducting internal control reviews (e.g., J?SOX), preparing audit materials, and coordinating responses to internal and external auditors.
  • Track and follow up on remediation actions to ensure timely closure of identified risks.
  • Contribute to drafting, updating, and maintaining global information security policies, standards, and procedures.
  • Review relevant laws, regulations, and industry frameworks (e.g., ISO 27001, NIS2) and incorporate stakeholder feedback into documentation.
  • Support the rollout and implementation of policies across regions.
  • Monitor adherence to security and regulatory requirements, including ISO 27001, NIS2, and GDPR.
  • Collect and organize compliance evidence, track corrective actions, and support certification and regulatory readiness efforts such as ISO 27001/42001 and NIS2 programs.
  • Conduct third party security risk assessments by distributing questionnaires, analyzing responses, verifying controls, and documenting results in the GRC tracking systems.
  • Identify and escalate high risk findings to the GRC Functional Leader and support follow up mitigation activities.
  • Participate in the planning and implementation of security awareness programs for all associates.
  • Create e-learning materials and training materials, conduct phishing email exercises, and distribute disseminated content on internal portals.
  • Monitor and analyze global regulatory developments related to cybersecurity with a focus on industrial control systems (ICS), IT environments, and critical infrastructure.
  • Assist in evaluating how new or updated regulations (e.g., NIS2, FDA cybersecurity expectations, industrial cybersecurity standards, or country specific critical infrastructure laws) impact company operations.
  • Track emerging obligations, document requirements, and support gap assessments to ensure timely compliance.
  • Assist in the preparation, maintenance, and continuous improvement of the CISO Dashboard by collecting, validating, and analyzing security metrics across the Global GRC function.
  • Compile key performance indicators (KPIs) and key risk indicators (KRIs) related to compliance status, audit findings, supplier risk, incident trends, training completion, regulatory readiness, and other relevant security domains.
  • Support the visualization and communication of security posture to senior leadership by ensuring data accuracy, timely updates, and clarity in reporting.
  • Support the development and enforcement of governance controls for the secure use of artificial intelligence technologies across the organization.
  • Identify risks related to AI systems—such as model security, algorithmic integrity, and misuse—and contribute to risk assessments and mitigation plans.
  • Help evaluate third party AI tools.
  • Support the development and improvement of GRC processes, tools, and documentation to enhance operational efficiency and standardization.
  • Assist in preparing reports, presentations, and materials for leadership reviews, steering committees, and cross functional meetings.
  • Participate in internal security projects and initiatives, including process automation, metrics development, and enhancements to governance workflows.
  • Provide coordination and administrative support for security committees, working groups, and regional GRC activities.
  • Perform additional duties as assigned to support the Global Information Security Office and the broader GRC program.
Requirements
  • 3 to 5+ years of experience in information security, governance, risk management, compliance, IT audit, or a related discipline.
  • Experience supporting security programs in global or regulated environments is a plus.
  • Understanding of global and regional information security regulations (e.g., data protection laws, cybersecurity requirements) and familiarity with security frameworks such as ISO 27001.
  • Knowledge of internal control frameworks (e.g., JSOX) and IT governance practices is highly desirable.
  • Experience supporting audit activities is preferred.
  • Experience with risk assessment methodologies, control evaluation, and vulnerability or issue management processes.
  • Strong analytical and problem-solving skills, with the ability to identify risks, assess impacts, and support the development and tracking of corrective actions.
  • Ability to communicate security requirements, policies, and audit findings clearly and persuasively with stakeholders across regions and business units.
  • Strong coordination skills to build consensus and drive compliance.
  • Industry certifications such as CISSP, CISA, CISM, ISO 27001 Lead Implementer/Auditor, or similar are preferred but not required.
  • Bachelor’s degree in information security, Cybersecurity, Information Systems, Computer Science, or a related field; or equivalent professional experience.
  • Familiarity with governance, risk, and compliance tools (e.g., BitSight, Drata, OneTrust, Archer, or similar) for managing risks, audits, and compliance workflows.
  • Working knowledge of cybersecurity concepts such as identity and access management, endpoint protection, vulnerability management, cloud security, and secure system design.
  • Experience supporting cross-functional security or compliance initiatives, including requirements gathering, documentation, and progress tracking.
  • Ability to interpret risk metrics, compliance data, and audit results.
  • Experience with dashboards, KPI/KRI reporting, or data visualization tools is a plus.
  • Awareness of emerging cybersecurity regulations (e.g., NIS2, AI governance frameworks, critical infrastructure rules) and their potential impact on enterprise operations.

System One, and its subsidiaries including Joulé and Mountain Ltd., are leaders in delivering outsourced services and workforce solutions across North America. We help clients get work done more efficiently and economically, without compromising quality. System One not only serves as a valued partner for our clients, but we offer eligible employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan.







System One is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, age, national origin, disability, family care or medical leave status, genetic information, veteran status, marital status, or any other characteristic protected by applicable federal, state, or local law.




#M-1




#LI-SG1

Ref: #558-Scientific

  • IT Project Coordinator

    Virginia, VA

    Job Title: Project Coordinator Type: Contract Compensation: 50.00-60.00/hr W2 Work Model: Remote Hours: 40.0 Security Clearance: Not specified in the job description or fields Responsibilities Support project strategy, planning, scheduling, and coordin...

    Date Posted: 07/29/2026 Recommended

  • Senior Enterprise Data Privacy Analyst

    Merrifield, VA

    Job Title: Senior Enterprise Privacy Governance and Risk Management Analyst Location: Vienna, VA Work Schedule: Hybrid, onsite 3 days a week Pay Rate: Open to W2 and established 1099's (no c2c) Position Type: Multiyear Contract We are currently seeking...

    Date Posted: 08/12/2026 Recommended

  • IT Assurance Manager

    The Woodlands, TX

    Title: IT Assurance Manager Location: The Woodlands (onsite daily) Direct Hire Summary We are seeking an experienced, hands-on Manager to lead IT Audit, IT SOX, and IT Risk initiatives for a rapidly growing, publicly traded construction client in The W...

    Date Posted: 08/20/2026 Recommended

  • Principal Government & Defense Technology Architect

    NA, VA

    Principal Government & Defense Technology Architect Client: DHL Location: Remote, United States Work Authorization: Candidates must be authorized to work in the United States without current or future sponsorship Position Summary System One IT is seeki...

    Date Posted: 08/14/2026 Recommended

  • Information Security Analyst

    Bellevue, WA

    Job Title: Information Security Analyst Location: Bellevue, WA Type: Contract Contractor Work Model: Onsite Responsibilities Support the company’s Incident Response procedures to facilitate appropriate, timely, and consistent response activities, inclu...

    Date Posted: 08/03/2026 Recommended

  • Compliance Administrator

    Sunnyvale, CA

    Job Title: Compliance Administrator Location: Sunnyvale, CA Type: Contract Compensation: $25.00 - $30.00 Work Model: Hybrid Overview Established Medical Device company is looking to hire a Compliance Administrator to assist their field action team with...

    Date Posted: 08/12/2026 Recommended

  • Principal SDET, Cybersecurity Test Engineer

    Lakewood, CO

    Job Title: Principal SDET, Cybersecurity Test Engineer Location: Lakewood, CO Type: Direct Hire Job Summary: System One is seeking a Principal SDET – Cybersecurity Test Engineer for a full-time/permanent opportunity in Lakewood, CO. As a Sr. Technical ...

    Date Posted: 06/03/2026 Recommended

  • Analytical Chemist

    Silver Spring, MD

    Job Title: Analytical Chemist Location: Silver Spring, MD Work Model: Onsite Hours: M-F normal business hours Compensation: $40.00 - $50.00/hr Type: 6+ month contract Overview Seeking an Analytical/Cosmetic Manufacturing Chemist with deep chemistry exp...

    Date Posted: 08/21/2026 Recommended

  • Junior Security Control Assessor

    Bethesda, Maryland

    Location: Bethesda, MD (mostly remote, occasional onsite required) Work schedule: 40 hrs/week Compensation: $100,000–$115,000/year Target start: by end of August 2026 Clearance / Public Trust: Public Trust eligibility (Tier 2/3) required About the role...

    Date Posted: 07/24/2026 Recommended

  • CTM/Clinical Trial Manager

    Toronto, Ontario

    Job Title: Clinical Trial Manager Location: Hybrid, Metro Toronto (Burlington) - 50% per month onsite Type: 12 months contract Pay: 50 to 60 per hour CAD Join a dynamic clinical research team as a Clinical Trial Budgets & Contracts Specialist, where yo...

    Date Posted: 08/12/2026 Recommended

  • Information Systems Security Officer

    20701, Virginia

    Title: Information Systems Security Officer (ISSO) Location: Annapolis Junction, MD Type: Direct Hire Compensation: $200,000/year (salary) Schedule: 40 hours/week Clearance Required: Active TS/SCI with FSP Role Overview We’re hiring an Information Syst...

    Date Posted: 07/21/2026 Recommended

  • Strategic Planning Specialist

    Virginia, VA

    Job Title: Strategic Planning Specialist Location: Remote Pay Rate: W2 only (no c2c) Position Type: Multiyear Contract Candidates must live in the United States. This role requires someone with 7-10 years of experience working in a PMO, Program Managem...

    Date Posted: 07/30/2026 Recommended

  • Data Architect- Wealth Management

    Naperville, Illinois

    Job Title: Data Architect- Wealth Management Location: Naperville, IL Type: Direct Hire Compensation: Open Work Model: Onsite Hours: 40.0 Security Clearance: N/A Responsibilities Design and maintain the end to end data architecture for the Wealth Manag...

    Date Posted: 07/15/2026 Recommended

  • UX Designer

    Washington, District Of Columbia

    Job Title: UX Designer Location: Washington, DC Type: Direct Hire Work Model: 3 days onsite Security Clearance: DOD Secret Clearance Required Role Overview: Actively searching for a UX Designer with an active DOD Secret Clearance to join our team. The ...

    Date Posted: 07/14/2026 Recommended

  • Desktop Governance Analyst

    Vienna, Virginia

    Job Title: Desktop Governance Analyst Location: Vienna, VA Type: Contract Work Model: Hybrid – onsite and remote Responsibilities Support governance, risk, and compliance activities focused on elevated access controls, audit readiness, remediation supp...

    Date Posted: 08/13/2026 Recommended

  • Lead DevSecOps Engineer

    Pittsburgh, Pennsylvania

    Job Title: Lead DevSecOps Engineer Location: Pittsburgh, PA Responsibilities Lead the integration of security into CI/CD pipelines, architect secure cloud environments, and guide teams in adopting modern DevSecOps practices to ensure a secure-by-design...

    Date Posted: 06/29/2026 Recommended

  • Lead DevSecOps Engineer

    Dallas , Texas

    Job Title: Lead DevSecOps Engineer Location: Dallas, Texas Responsibilities Lead the integration of security into CI/CD pipelines, architect secure cloud environments, and guide teams in adopting modern DevSecOps practices to ensure a secure-by-design ...

    Date Posted: 06/29/2026 Recommended

  • Lead DevSecOps Engineer

    Strongsville, Ohio

    Job Title: Lead DevSecOps Engineer Location: Strongsville, OH Type: Fulltime Responsibilities Lead the integration of security into CI/CD pipelines, architect secure cloud environments, and guide teams in adopting modern DevSecOps practices to ensure a...

    Date Posted: 06/29/2026 Recommended

  • Sr Cyber Security Engineer

    Washington, DC

    Job Title: Sr Cyber Security Engineer Location: Washington, DC Type: Contract Compensation: $79.55 Work Model: Hybrid Hours: 40.0 Responsibilities Install, configure, and customize SailPoint Identity IQ (IIQ) to support Governance Policies and procedur...

    Date Posted: 08/03/2026 Recommended

  • Director Medical Monitor

    Parsippany, NJ

    Job Title: Director Medical Monitor Location: Parsippany, NJ Type: Direct Hire Contractor Work Model: Hybrid – onsite Overview Responsibilities Provide medical oversight for assigned clinical studies from study start-up through closeout. Participate in...

    Date Posted: 07/20/2026 Recommended

  • Scrum Master

    Roswell, Georgia

    Scrum Master Employment Type: Permanent Full-Time Location: Atlanta, GA Position Description This position is located at the client site in Atlanta, GA. Your Future Duties and Responsibilities Facilitate Agile ceremonies, including sprint planning, dai...

    Date Posted: 07/24/2026 Recommended

  • Cybersecurity Engineer ( W2 direct hire, no C2C )

    Alpharetta, Georgia

    *** This is a direct hire role ( W2 salaried, permanent, full-time position ) in our own IT department *** NO C2C candidates, NO 3rd parties, NO visa sponsorship available, NO green card sponsorship available, NO candidates with temporary work authoriz...

    Date Posted: 08/19/2026 Recommended

  • Cybersecurity Engineer ( W2 direct hire, no C2C )

    Atlanta, Georgia

    *** This is a direct hire role ( W2 salaried, permanent, full-time position ) in our own IT department *** NO C2C candidates, NO 3rd parties, NO visa sponsorship available, NO green card sponsorship available, NO candidates with temporary work authoriz...

    Date Posted: 08/19/2026 Recommended

  • Training Associate - CC

    Indianapolis, IN

    Job Title: Training Associate Location: Indianapolis, IN Type: 6-7-month contract Compensation: $42.50 - $49.50 per hour Work Model: Onsite Hours: 40.0 hours per week Responsibilities: The position is accountable for platform-specific curriculum design...

    Date Posted: 08/21/2026 Recommended

  • MOSA System Integration Lead / Architect

    Baltimore, MD

    Job Title: MOSA System Integration Lead / Architect Location: Aberdeen, San Antonio, or Remote. Hybrid if less than 40 miles from Aberdeen Proving Ground or Crystal City. Type: Direct Hire / Perm Security Clearance: Secret We are seeking a Modular Open...

    Date Posted: 08/13/2026 Recommended

  • AWS Cloud Security Engineer

    Mclean, Virginia

    AWS Cloud Security Engineer Remote What You Will Do We are seeking an AWS Cloud Security Engineer to support a large-scale cloud modernization effort for a federal client. This role will focus on securing AWS environments, strengthening cloud security ...

    Date Posted: 06/22/2026 Recommended

  • Cybersecurity Engineer ( W2 direct hire, no C2C )

    Pittsburgh, Pennsylvania

    *** This is a direct hire role *** NO C2C candidates, NO 3rd parties For immediate consideration, please connect with me on LinkedIn at https://www.linkedin.com/in/dpotapenko and then email your resume, current location, availability, and compensation ...

    Date Posted: 08/18/2026 Recommended

  • Training Associate

    Indianapolis, IN

    Job Title: Training Associate Location: Indianapolis, IN Work Model: Onsite Hours: M-F 8am-5pm Compensation: $45.00 - $49.65/hr Type: 7-month contract Overview The Training Associate is accountable for platform-specific curriculum design, development, ...

    Date Posted: 08/20/2026 Recommended

  • EHS Manager

    Elmira Heights, NY

    Job Title: EHS Manager Location: Elmira Heights, NY Type: Direct Hire Compensation: $95,000.00 - $105,000.00 Work Model: Onsite – onsite Hours: 40.0 Responsibilities Ensure full compliance with all applicable regulatory requirements including OSHA, DEC...

    Date Posted: 08/10/2026 Recommended

  • Cloud Engineer

    Indianapolis, IN

    Cloud Engineer Location: Indianapolis, IN Hybrid Onsite 3 days, fully remote if not local Employment Type: Contract, 6 months to start ( NO C2C W2 Only) Schedule: 40 hours/week Duration: Through January 22, 2027 Pay: $92.00 - $105.00/HR Position Summar...

    Date Posted: 06/25/2026 Recommended