Job Description
Who we are:
Globalstar pioneered personal safety by introducing its SPOT Satellite GPS Messenger in 2007. Today, leveraging its low-earth orbit (LEO) satellite constellation, Globalstar reliably connects and protects assets, transmits key operational data, and saves lives – from any location – for consumers, industrial companies and government agencies in over 120 countries. With a portfolio that includes SPOT GPS messengers, next-generation IoT products and modems, and cloud-based telematics solutions, Globalstar’s cost effective satellite-powered innovations give users visibility and intelligence for improving safety and operational efficiencies.
What we offer:
- Work/Life Balance: Paid Time Off, Paid Holidays
- Financial Benefits: 401(k) Plan with Company Match, Employee Stock Purchase Program, Voluntary and Company Paid Group Life Insurance, Short- and Long-Term Disability Insurance, Medical FSA, Dependent Care, Competitive Salaries
- Health & Wellness: Health Insurance, Dental Insurance, Vision Insurance, Employee Assistance Program, Comprehensive and Interactive Wellness Program
The IT GRC Analyst is responsible for supporting Globalstar's information security governance, risk, and compliance programs. This role executes control oversight activities, maintains compliance with applicable regulatory frameworks, supports internal and external audit readiness, and assists with vendor risk management. The IT GRC Analyst will leverage GRC tooling to automate and streamline compliance monitoring, produce highly accurate and consistent documentation, and serve as a knowledgeable resource across IT and business teams. Additionally, this role provides project coordination support for IT implementations and installations, assisting in the organization, scheduling, and communication of project activities as needed.
Supervisory Responsibilities:
Duties/Responsibilities:
Governance, Risk & Compliance
- Execute user access reviews, control evidence collection, and recurring risk reviews.
- Collect, review, and validate control evidence and supporting artifacts to assess completeness, accuracy, and alignment with defined requirements.
- Maintain and update the organization's risk register, documenting identified risks, current controls and recommended treatment options.
- Identify, document, and escalate control exceptions, discrepancies, and potential gaps to senior team members for evaluation and remediation.
- Monitor compliance with information security policies and assess potential risks associated with data handling and system changes.
- Support the maintenance of governance documentation and continuous improvement of department processes and procedures.
Audit & Regulatory Readiness
- Administer and support the organization's audit plan across SOC 2, ISO 27001, and SOX, ensuring controls are designed and operating effectively.
- Support internal and external audit activities by organizing evidence, coordinating with control owners, and responding to information requests.
- Assist with the preparation and maintenance of compliance artifacts.
- Coordinate with independent auditors and ensure the timely delivery of supporting documentation and data.
- Analyze audit results, prepare presentations of findings, and develop recommendations to reduce risk and increase protection of organizational assets.
- Review SOC reporting for third-party compliance and coordinate data privacy matters with the Data Protection Officer (DPO) as applicable.
Vendor & Third-Party Risk Management
- Support third-party risk management activities including vendor intake, security questionnaire review, ongoing monitoring, and follow-up with internal stakeholders.
- Evaluate vendors' security posture and assess residual risk for inclusion in procurement and program decisions.
- Maintain accurate and up-to-date information within vendor and control tracking systems.
Data Privacy Oversight
- Support oversight and ongoing management of Globalstar’s data privacy program, ensuring compliance with applicable privacy regulations including GDPR, CCPA, and other relevant privacy frameworks.
- Coordinate with the Data Protection Officer (DPO) and relevant stakeholders to monitor data privacy obligations, assess compliance posture, and track remediation of identified gaps.
- Support privacy impact assessments and data mapping activities to maintain an accurate record of personal data processing activities across the organization.
- Incorporate data privacy requirements into vendor risk assessments and third-party due diligence activities, ensuring vendors handling personal data meet applicable contractual and regulatory obligations.
GRC Tooling & Documentation
- Administer and maintain GRC platform(s) (Drata, OneTrust), including control mapping, evidence collection workflows, and compliance dashboards.
- Produce compliance posture reporting and audit readiness metrics for governance forums and leadership review.
- Recommend new or modified procedures that improve efficiency or compliance and mitigate risk or loss.
IT Project Coordination Support
- Provide coordination support for IT implementation and installation projects, including scheduling, stakeholder communication, task tracking, and follow-up on open items across internal teams and vendors.
- Serve as the primary point of contact for project coordination activities, ensuring timely communication of status, issues, and dependencies to relevant stakeholders.
- Assist in ensuring that IT implementations satisfy applicable compliance and control requirements prior to go-live.
Skills and Competencies:
- Excellent verbal and written communication skills, including the ability to interact clearly and concisely with all departments and levels of management with a focus on customer service
- Excellent organizational skills with attention-to-detail
- Ability to meet multiple deadlines in a fast-paced environment
- Ability to effectively manage time and prioritize tasks
- Ability to act with integrity, professionalism, and confidentiality
- Proficiency with Microsoft Office
- Strong problem-solving skills, especially under time constraints
- In-depth understanding of IT compliance frameworks and regulations such as NIST SP 800-53, SOC 2, SOX, CCPA, and GDPR
- Comprehensive knowledge of the concepts and principles of internal controls and regulatory compliance
Education, Experience, and Licenses/Certifications:
- Bachelor's degree in Business Administration, Information Systems, Risk Management, Security Management, or equivalent work experience.
- 2–5 years of progressive experience in IT governance, risk, and compliance, IT audit, or a closely related discipline.
- Demonstrated hands-on experience with SOC 2 and/or ISO 27001 audit or assessment cycles.
- IT security and privacy certifications such as CISA, CISSP, CRISC, CISM, CIPM, or CDPSE preferred.
Physical Requirements:
- Willingness and ability to travel as needed
- Willingness and ability to work after regularly scheduled hours as needed
- Ability to sit at a desk for prolonged periods working on a computer (4 to 8 hours)
- Ability to operate the equipment used for the job
- Ability to lift 15 pounds at times
- Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions of this job
Marginal Functions:
A review of this job description may have omitted some of the marginal functions of the position that are incidental to the performance of the job duties and responsibilities. This job description, in no way, states or implies that these are the only duties and/or responsibilities to be performed by the employee in this position. The employee in this position will be required to follow any other job-related instructions and to perform any other job-related duties requested by his/her supervisor.