Cybersecurity Governance Risk and Compliance Analyst

3 days ago


Reston, Virginia, United States The Clorox Company Full time
About the Role

We are seeking a highly skilled and motivated Cybersecurity Governance, Risk & Compliance (GRC) Analyst to support and improve our company's cybersecurity program. The successful candidate will focus on driving improvements in cyber risk management related to sensitive data, systems, third-party vendors, and cloud environments.

Key Responsibilities
  • Assess cyber risks related to vendors, systems, and services associated with technology and operational projects.
  • Support day-to-day operations by identifying potential areas of cybersecurity compliance risks and ensuring appropriate escalation and coordination of effective corrective actions.
  • Collaborate with various technical and non-technical teams to evaluate the effectiveness of security controls, identify and categorize risks, provide improvement recommendations, and communicate outcomes of those activities.
  • Educate teams across the organization on cyber risk and governance methodologies for maintaining a secure enterprise and meeting regulatory compliance requirements.
  • Facilitate the development of security policies and standards, collaborate with internal subject matter experts to ensure policies are up to date, and lead interactions with Internal Audit.
  • Manage relevant regulatory requirements, assist in the development of management responses, track, and monitor remediation progress until closure.
  • Challenge the first line of defense, validate the required assessments and attestations, report on compliance internally, and provide guidance on compliance as necessary.
  • Provide oversight of identifying, classifying, remediating, and mitigating vulnerabilities and the policy exception request process.
  • Communicate emerging issues, potential risks, and audit results to key stakeholders, assist in the review, and formulate responses to issues and findings from all sources.
  • Develop metrics and reports that provide management visibility into the current cyber risk and compliance posture and trends.
  • Work closely with business, technology, and compliance counterparts to understand business objectives, initiatives, and ensure alignment with security policies and best practices.
  • Build relationships with business units to deliver security-by-design controls incorporated into projects, architecture, infrastructure, and applications.
  • Build relationships with senior leaders to accelerate the adoption of compliance and security initiatives.
  • Design and execute a comprehensive security awareness strategy tailored to the organization's needs.
  • Create and maintain engaging content for security awareness campaigns, including newsletters, webinars, workshops, and e-learning modules.
  • Collaborate with internal stakeholders to ensure that security awareness training aligns with business goals and addresses specific risks.
  • Conduct regular training sessions and workshops for employees at all levels to promote awareness of security policies, procedures, and best practices.
  • Develop customized training materials for various departments, roles, and teams to address specific security risks and compliance requirements.
  • Stay updated on the latest cybersecurity threats and trends to continually improve training materials and methods.
  • Monitor the effectiveness of security awareness programs through surveys, assessments, and metrics.
  • Report on key performance indicators (KPIs) related to the security awareness program to management and stakeholders.
  • Identify areas for improvement in security awareness initiatives based on feedback and monitoring results.
  • Ensure that all security awareness activities comply with relevant laws, regulations, and industry standards.
  • Collaborate with the legal and compliance teams to integrate security awareness into the organization's overall compliance framework.
Requirements
  • Bachelor's degree with 5+ years of experience in governance risk and compliance management.
  • Risk assessment methods and procedures.
  • Track, monitor, and report risk.
  • Governance risk & compliance.
  • Strong English communication and writing abilities.
  • Cybersecurity risk management function including third-party cyber risk.
  • Cybersecurity controls management.
  • Controls testing and automation.
  • Governance risk and compliance management.
  • Experience with Cybersecurity Risk Frameworks (NIST CSF/RMF, ISO 27001/27002, SOC (1,2,3), and Global Privacy regulations (e.g., CCRP, GDPR, etc.).
  • Experience in drafting security policies and standards.
  • Excellent communication and presentation skills, with the ability to convey complex security concepts to a non-technical audience.
  • Proficient in using e-learning platforms, training tools, and content creation software.
  • Analytical skills to measure the effectiveness of training programs and identify areas for improvement.
  • Ability to work independently and manage multiple projects simultaneously.
  • Experience in using/supporting ServiceNow Integrated Risk Management module (or related GRC platform).
  • Cyber Risk Certifications (CISA, CISM, CRISC, CISSP).
About Us

The Clorox Company is a leader in the consumer goods industry, committed to growth for our people and our brands. We believe every one of us can make a positive impact on consumers, communities, and teammates. We are a company that values diversity, equity, and inclusion, and we strive to create a workplace where every person can feel respected, valued, and fully able to participate in our Clorox community.

We offer comprehensive, competitive benefits that prioritize all aspects of wellbeing and provide flexibility for our teammates' unique needs. This includes robust health plans, a market-leading 401(k) program with a company match, flexible time off benefits, inclusive fertility/adoption benefits, and more.

We are committed to fair and equitable pay and are transparent with current and future teammates about our full salary ranges. We use broad salary ranges that reflect the competitive market for similar jobs, provide sufficient opportunity for growth as you gain experience and expand responsibilities, while also allowing for differentiation based on performance.

This job is also eligible for participation in Clorox's incentive plans, subject to the terms of the applicable plan documents and policies.



  • Reston, Virginia, United States Skywalk Global Full time

    Job Title: Governance, Risk & Compliance (GRC) SOX AnalystAbout the Role:We are seeking a highly skilled Governance, Risk & Compliance (GRC) SOX Analyst to join our team at Skywalk Global. As a key member of our organization, you will be responsible for ensuring the effective implementation and maintenance of our SOX IT controls.Key Responsibilities:Access...


  • Reston, Virginia, United States Allied Consultants, Inc. Full time

    Job SummaryAllied Consultants, Inc. is a premier provider of technical and business professionals to clients in Texas. We are seeking an experienced Data Security Analyst to be a key resource on a technical services team.Key ResponsibilitiesReview and analyze transactions to detect and mitigate fraud, ensuring compliance with applicable laws and...


  • Reston, Virginia, United States Bluebird Staffing Full time

    Job Title: Advanced Security AnalystJob Summary:We are seeking an experienced Advanced Security Analyst to join our team at Bluebird Staffing. The successful candidate will be responsible for maintaining Governance, Risk, and Compliance functions as they relate to Cybersecurity in our Health System network.Key Responsibilities:Assist in ensuring all defined...


  • Reston, Virginia, United States LHH Full time

    Cybersecurity Supply Chain Risk Management (C-SCRM) AnalystLocation: Portland, OR (Hybrid)LHH is partnering with a leading industrial business in Portland, Oregon, to find an exceptional Cybersecurity Supply Chain Risk Management (C-SCRM) Analyst. Our client operates across multiple locations, providing vital support for infrastructure, defense, and energy...


  • Reston, Virginia, United States SPECTRAFORCE Full time

    Job Title: Senior Cybersecurity Policy AnalystJob Summary:The Senior Cybersecurity Policy Analyst will be responsible for developing and maintaining policies, standards, and procedures for cybersecurity controls and processes within the organization. This includes partnering with the business, IT, and security organizations to coordinate developing,...


  • Reston, Virginia, United States The One 23 Group Full time

    Job OverviewThe One 23 Group, a leading government contractor, is seeking a highly skilled Cybersecurity Policy and Compliance Certified Professional to join our team. As a key member of our cybersecurity team, you will be responsible for ensuring the security and compliance of our enterprise systems and networks.Key Responsibilities:Provide support for A&A,...

  • Cyber Risk Analyst

    3 weeks ago


    Reston, Virginia, United States Red Gate Group Full time

    Job Title: Cyber Risk AnalystWe are seeking a highly skilled Cyber Risk Analyst to join our team at Red Gate Group. As a Cyber Risk Analyst, you will play a critical role in identifying and mitigating cyber risks for mission-critical DoD systems and networks.Key Responsibilities:Assess and mitigate cyber risks for DoD programs and develop tailored mitigation...

  • Cybersecurity Specialist

    38 minutes ago


    Reston, Virginia, United States ECS Full time

    Job Title: Security Analyst/Documentation SMEJob Summary:ECS is seeking a talented Security Analyst/Documentation SME to join our team in Fairfax, VA. As a key member of our cybersecurity team, you will be responsible for assessing security risks, analyzing security data, and developing and implementing security strategies to protect our technology...


  • Reston, Virginia, United States The AZEK Company Full time

    Cyber Security Governance Risk AnalystThe AZEK Company is seeking a highly skilled Cyber Security Governance Risk Analyst to join our team. As a key member of our cyber security team, you will be responsible for developing and implementing enterprise-wide cyber security policies, standards, and controls to mitigate risks and comply with applicable laws and...


  • Reston, Virginia, United States Excentium Full time

    Cybersecurity Analyst Job DescriptionExcentium, Inc. is a Service-Disabled Veteran owned small business that provides Cyber Security Engineering, Information Assurance (IA), management, Certification and Accreditation (C&A), and other IT services to government and commercial organizations.We are seeking a highly skilled Cybersecurity Analyst to support the...

  • Cyber Risk Analyst

    3 days ago


    Reston, Virginia, United States Booz Allen Hamilton Full time

    Job Opportunity: Cyber Risk AnalystAbout the Role:We are seeking a highly skilled Cyber Risk Analyst to join our team. As a Cyber Risk Analyst, you will be responsible for working with DoD programs to identify and assess cyber risks, develop mitigation plans, and provide technical expertise to clients.Key Responsibilities:Conduct risk assessments and develop...

  • Governance Analyst

    3 weeks ago


    Reston, Virginia, United States Hire Counsel Full time

    About the RoleWe are seeking a highly skilled Governance Analyst to join our team at Hire Counsel. As a Governance Analyst, you will be responsible for providing subject matter expertise to our governance program, ensuring compliance with Firm policies and client outside counsel guidelines.Key ResponsibilitiesProvide subject matter expertise to the...


  • Reston, Virginia, United States MiSource Full time

    Job Title: Risk AnalystAt MiSource, we are seeking a highly skilled Risk Analyst to join our team. This role is crucial in ensuring the security and integrity of our products, aligning them with the topmost standards of safety and compliance, including FDA guidelines for risk management.Key Responsibilities:Perform thorough risk assessments targeting...


  • Reston, Virginia, United States Koniag Data Solutions, LLC Full time

    Cybersecurity Analyst-Project Manager Job DescriptionKoniag Data Solutions, LLC, a Koniag Government Services company, is seeking a Cybersecurity Analyst-Project Manager with a Secret clearance to support KDS and our government customer in Fairfax, VA.We offer competitive compensation and an extraordinary benefits package, including health, dental, and...


  • Reston, Virginia, United States LanceSoft, Inc. Full time

    Job Title: Cybersecurity Vulnerability AnalystJob Summary:LanceSoft, Inc. is seeking a highly skilled Cybersecurity Vulnerability Analyst to join our team. As a key member of our security team, you will play a critical role in ensuring our systems meet compliance and security standards.Key Responsibilities:Analyze vulnerability scan data and security...


  • Reston, Virginia, United States INSPYR Solutions Full time

    Job Title: Governance Risk SpecialistLocation: Merrifield, VADuration: Initial 6 Month ContractCompensation: $55-82/HRWork Requirements: US Citizen, GC Holders or Authorized to Work in the USJob Summary:We are seeking a Governance Risk Specialist to collaborate in the coordination, delivery, and continuous maturation of our Governance, Risk, and Compliance...


  • Reston, Virginia, United States GlobalSource IT Full time

    OT Compliance Analyst Job DescriptionWe are seeking a highly skilled OT Compliance Analyst to join our team at GlobalSource IT. As an OT Compliance Analyst, you will play a critical role in creating comprehensive technical documentation for our industrial control systems.Key Responsibilities:Develop and document workflows and processes for IT and OT systems...


  • Reston, Virginia, United States Applied Research Associates (ARA) Full time

    Cyber Analyst Job DescriptionWe are seeking a highly skilled Cyber Analyst to join our team at Applied Research Associates (ARA). As a Cyber Analyst, you will play a critical role in identifying, monitoring, and assessing foreign cyber threats to Defense, Service, and Interagency information systems, networks, and critical infrastructure.Key...


  • Reston, Virginia, United States Applied Research Associates (ARA) Full time

    Cyber Analyst Job DescriptionWe are seeking a highly skilled Cyber Analyst to join our team at Applied Research Associates (ARA). As a Cyber Analyst, you will play a critical role in identifying, monitoring, and assessing foreign cyber threats to Defense, Service, and Interagency information systems, networks, and critical infrastructure.Key...

  • Cyber Risk Analyst

    3 days ago


    Reston, Virginia, United States Booz Allen Hamilton Full time

    Job Opportunity:We are seeking a highly skilled Cyber Risk Analyst to join our team at Booz Allen Hamilton. As a key member of our cybersecurity team, you will play a critical role in identifying and mitigating cyber risks for our clients.Key Responsibilities:Conduct thorough risk assessments and develop mitigation plans to address identified...