To Apply for this Job Click Here
Governance, Risk & Compliance (GRC) Specialist
Location: Houston, TX (Hybrid: 3 days onsite, 2 remote) OR Chicago, IL (Remote)
Duration: 6-Month Contract (Strong Extension/Conversion Potential)
Start Date: Approximately 3 Weeks from Offer
Overview
We are seeking a Governance, Risk & Compliance (GRC) Specialist to join a growing Information Security team supporting a large-scale critical infrastructure environment. This individual will play a key role in strengthening governance, risk management, compliance, and cybersecurity processes across corporate IT, cloud platforms, and operational technology (OT) environments.
This is a unique opportunity to help build and mature a cybersecurity governance program from the ground up while partnering closely with security, engineering, infrastructure, legal, procurement, and business stakeholders.
Key Responsibilities
- Support and maintain the organization’s governance, risk, and compliance program across IT, cloud, and OT environments.
- Develop, review, and maintain security policies, standards, procedures, and control documentation.
- Coordinate audit evidence collection for internal audits, external audits, compliance reviews, and customer assessments.
- Track audit findings, remediation plans, control deficiencies, policy exceptions, and risk acceptance activities.
- Perform control testing and compliance validation to ensure security controls are operating effectively.
- Assist with risk assessments, gap assessments, compliance readiness activities, and control maturity reviews.
- Support vendor and third-party risk management activities, including security questionnaires and risk reviews.
- Collaborate with IT, Security Operations, Infrastructure, Engineering, Legal, Procurement, Compliance, and Operations teams.
- Map security controls to frameworks including NIST, ISO 27001, SOC 2, and CIS Controls.
- Maintain risk registers, compliance calendars, control inventories, and audit repositories.
- Prepare compliance reports, dashboards, scorecards, and presentations for leadership.
- Monitor remediation efforts and work with control owners to ensure timely issue resolution.
- Support continuous improvement initiatives across the information security governance program.
- Stay informed on cybersecurity regulations, compliance trends, and industry best practices.
Required Qualifications
- 3+ years of experience in Governance, Risk & Compliance (GRC), cybersecurity compliance, IT audit, information security, or related disciplines.
- Strong knowledge of:
- NIST Cybersecurity Framework (CSF)
- NIST 800-53
- NIST 800-171
- ISO 27001
- SOC 2
- CIS Controls
- Experience supporting audits, evidence collection, control testing, remediation tracking, and compliance reporting.
- Ability to develop and maintain security policies, standards, procedures, and control documentation.
- Experience conducting risk assessments, gap assessments, and control reviews.
- Familiarity with third-party and vendor risk management processes.
- Strong documentation and communication skills with the ability to translate technical concepts into business-friendly language.
- Experience working with cross-functional teams across technology and business organizations.
- Knowledge of enterprise security controls including identity and access management, vulnerability management, incident response, and change management.
- Strong organizational skills and ability to manage multiple initiatives simultaneously.
Preferred Qualifications
- Experience within energy, utilities, renewable energy, power generation, critical infrastructure, or industrial environments.
- Knowledge of NERC CIP, FERC, or similar industry regulations.
- Exposure to OT/SCADA environments, substations, generation assets, EMS, DERMS, or industrial control systems.
- Certifications such as:
- CISA
- CISSP
- CISM
- CRISC
- Security+
- ISO 27001 Lead Auditor/Implementer
- Experience with GRC platforms such as:
- ServiceNow GRC
- Archer
- OneTrust
- AuditBoard
- LogicGate
- Drata
- Vanta
- Experience supporting SOC 2, ISO 27001, SOX ITGC, PCI, or customer security reviews.
- Experience creating executive dashboards, compliance scorecards, risk registers, and audit reporting.
Why Join?
- Opportunity to help build and define a new GRC function.
- High visibility within a growing Information Security organization.
- Exposure to both traditional enterprise IT and operational technology environments.
- Opportunity to contribute to the modernization of cybersecurity, risk, and compliance practices within a critical infrastructure environment.
- Strong potential for long-term conversion and career growth.
1464645_1788182827
