Job Description
Position Summary
The GRC Analyst supports the organization’s governance, risk, and compliance program by maintaining policy and control documentation, coordinating risk assessments, tracking audit and compliance activities, and helping align the information security program with applicable regulatory and industry frameworks. This position partners with Information Security, IT, Human Resources, system owners, and business stakeholders to identify risks, monitor remediation, and maintain a mature, consistent, and auditable security posture.
Essential Functions
- Maintain and update information security and identity and access management policies, standards, procedures, control narratives, and supporting documentation in alignment with applicable frameworks, including the NIST Cybersecurity Framework and CIS Controls.
- Manage the risk register and risk acceptance process, including documenting identified risks, approved exceptions, compensating controls, owners, remediation plans, and periodic reviews.
- Coordinate customer and vendor risk assessments and security questionnaires; maintain an organized library of approved responses, supporting artifacts, and reusable evidence.
- Review customer, contractual, regulatory, and audit requirements to identify new or revised controls and documentation needs.
- Support SOC 2 and other internal or external audits by assisting with planning, control walkthroughs, control mapping, evidence collection, issue tracking, and remediation follow-up.
- Collect, validate, organize, and submit audit evidence, including access lists, approval records, recertification documentation, tickets, logs, and other control artifacts.
- Develop and maintain audit procedures, workpapers, and runbooks to promote consistent and repeatable audit execution.
- Prepare clear risk and compliance updates, metrics, and presentation materials for leadership, audit committees, and other stakeholders.
- Perform periodic access reviews within Active Directory, Microsoft Entra ID, Oracle, and other in-scope applications to identify inaccurate, stale, orphaned, excessive, or unauthorized access.
- Review joiner, mover, and leaver activities to validate that access is provisioned, modified, and removed timely and in accordance with least-privilege principles and job responsibilities.
- Cross-reference HR and contractor data with system records to validate timely deprovisioning, appropriate contract end dates, and recurring access recertification.
- Audit privileged and administrative account inventories, approvals, business justification, emergency access activity, time-bound access, and privileged access recertifications.
- Review roles and entitlement combinations for segregation-of-duties conflicts, excessive access, and opportunities to simplify role design and reduce role sprawl.
- Document audit findings, control gaps, discrepancies, risk decisions, remediation actions, owners, and target dates; maintain regular follow-up with responsible stakeholders.
- Support role-based access provisioning workflows and periodic reviews of both role definitions and user assignments.
- Perform other related duties as assigned to support the ongoing needs of the organization.
Minimum Requirements
- Bachelor’s degree in Information Security, Cybersecurity, Business, Computer Science, Information Technology, or a related field, or an equivalent combination of education and relevant experience.
- Three or more years of experience in governance, risk, and compliance; IT audit; identity and access management audit; risk management; or information security compliance.
- Working knowledge of at least one recognized information security or control framework, such as the NIST Cybersecurity Framework or CIS Controls.
- Practical experience with Active Directory and Microsoft Entra ID, including user, group, role, and access reviews.
- Knowledge of risk assessment methods, control design, control testing, audit evidence, and remediation tracking.
- Ability to interpret technical and control information and communicate findings clearly to technical and non-technical stakeholders.
- Experience using GRC, ticketing, workflow, or audit management tools, such as Jira, ServiceNow GRC, or Archer, and proficiency with standard Microsoft Office applications.
- Strong organization, documentation, analytical, and follow-up skills with the ability to manage multiple concurrent audits, assessments, policy reviews, and remediation activities.
- Ability to handle sensitive and confidential information with appropriate discretion.
Preferred Qualifications
- Experience in a regulated industry, such as energy, utilities, financial services, healthcare, or critical infrastructure.
- Knowledge of NERC CIP or other critical infrastructure compliance requirements.
- Experience supporting SOC 2, SOX, or similar internal or third-party audits, including identity and access management control testing and evidence collection.
- Experience with third-party or vendor risk management programs.
- Relevant certification or progress toward certification, such as CISA, CRISC, CompTIA Security+, or ISO 27001 Lead Implementer.
Core Competencies
- Analytical Thinking and Risk Evaluation
- Attention to Detail and Documentation Quality
- Integrity, Confidentiality, and Sound Judgment
- Written and Verbal Communication
- Cross-Functional Collaboration
- Planning, Organization, and Follow-Through
- Problem Solving and Continuous Improvement
- Customer and Stakeholder Focus
- Self-Motivation and Accountability
- Ability to follow Company safety rules and all other Company policies.
Physical Demands
The physical demands described are representative of those that must be met by an employee to perform the essential functions of this position. While performing the duties of this job, the employee is regularly required to communicate and frequently required to sit, stand, walk, use hands and fingers to operate a computer and other office equipment, and reach with hands and arms. The employee may occasionally be required to lift or move standard office materials and equipment. Reasonable accommodations may be made to enable qualified individuals with disabilities to perform the essential functions.
Work Environment
This position is primarily performed in a professional office or remote-work environment and routinely uses computers, video conferencing, and standard office equipment. The employee is not ordinarily exposed to significant adverse environmental conditions. Occasional travel to company locations or other business sites may be required based on organizational needs.
Our Benefits
- Medical, dental and vision insurance
- HSA, dependent care and medical flexible spending accounts
- Employee Assistance Program (EAP)
- 401(k) with company match
- Life insurance, and short-term and long-term disability
- Paid time off, paid holidays, and family and medical leave
If this sounds like you, come join the PIKE family.
About Us
Founded in 1945, Pike is a leading provider of construction, repair and engineering services for electric and gas utilities, as well as telecommunications companies with a growing portfolio of turnkey renewable projects. We work with hundreds of utility clients across the country, and we continuously expand our offerings to supply our customers with the ideas, technology, experience, workforce and equipment to perform any job.
"Essential" is the one word that sums up who we are, the work we do and what our people mean to us. Each of our employees plays a critical role in ensuring that infrastructure systems are up and running when people and businesses need them.
Pike is a family-oriented workplace with a strong culture of safety, collaboration, innovation and exceptional customer service.
Equal Employment Opportunity
Pike Enterprises, LLC, is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin and/or status as a protected veteran or individual with a disability.