Lead Information Security Analyst
Job Description
Great Gray is seeking a Lead Information Security Analyst to drive IT governance, risk assessment, and security compliance activities within the Information Security team.
Responsibilities
- Lead and manage GRC activities, including compliance monitoring, audit management, and risk assessment
- Drive ongoing compliance with regulatory requirements and security frameworks such as SOC 2 and the NIST Cybersecurity Framework, plus applicable industry standards
- Prepare for and manage compliance audits, assessments, and regulatory reviews
- Maintain security documentation, compliance evidence, and audit trails to support audit readiness
- Develop, maintain, and enforce information security policies and procedures
- Perform Vendor Risk Management security assessments, onboarding reviews, and ongoing reviews
- Partner with cross-functional teams to embed security and compliance requirements into business processes
- Mentor and support Information Security Analysts across both analyst work and GRC responsibilities
- Monitor security posture, identify threats, and recommend remediation measures
- Conduct vulnerability assessments, penetration testing, and broader security assessments on systems and applications
- Participate in incident response activities and conduct post-incident analysis
- Track security trends, vulnerabilities, and emerging compliance requirements
Requirements
- Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related field
- 5+ years of relevant experience
- Strong knowledge of IT security control trends and auditing and compliance best practices
- Effective written and verbal communication skills for explaining complex IT controls and compliance issues to leadership and partners
- Relevant training and/or industry certifications in auditing, compliance, or IT security
- Ability to operate effectively in a fast-paced, dynamic environment while managing multiple priorities
- Comfort working in ambiguous situations
- Entrepreneurial mindset to introduce best-practice ideas to the team
- Alignment with core values: Growth Mindset, Disciplined Curiosity, Grit, Results Ownership, Collaboration
Technologies
- SOC 2
- NIST Cybersecurity Framework
- ISMS
Compensation
- Base pay range: USD 120,000 to 150,000 per year
- Base pay range may be modified in the future
- Pay-for-performance culture includes participation in an annual incentive bonus plan for this position (not included in the base pay range)
Benefits
- Group medical, dental, and vision insurance
- Employer-paid life and disability insurance
- Annual well-being stipend
- Eligible employees may contribute to a 401(k) plan with an advantageous employer contribution model
Location and Eligibility
- Remote position based in the United States
- Remote employment is restricted to candidates residing in states where Great Gray is registered as an employer
- Covered states: CA, CO, CT, DC, DE, FL, GA, IL, IN, MA, MD, MI, MN, NC, NH, NJ, NV, NY, OH, PA, RI, SC, TN, TX, VA
- Visa sponsorship or transfer of an existing visa is not available
- Applicants must be authorized to work directly for any employer in the United States without visa sponsorship or transfer