GRC Analysts I
Boost your chances before you apply.
Jün Cyber
FL
Summary
The GRC Analyst will support compliance monitoring, control testing, and evidence validation to ensure adherence to cybersecurity frameworks. They will also assist in maintaining documentation, tracking remediation activities, and preparing for internal and external audits.
Job Description
Junior-Level GRC Analysts
Department: Governance, Risk & Compliance (GRC)
Reports To: Compliance Manager
Location: Hybrid (St.Petersburg, Florida Applicants Only)
Working Hours: U.S. Eastern Time (ET) business hours
Employment Type: Full-Time
Level: Entry / Early Career
About Jun Cyber
Jun Cyber is a cybersecurity and compliance services company focused on helping organizations strengthen their cybersecurity programs, meet regulatory and contractual requirements, and achieve and maintain compliance with frameworks such as CMMC, NIST, SOC 2, and ISO 27001.
Our team works across Governance, Risk & Compliance (GRC), managed IT services, cybersecurity, continuous monitoring, and compliance program management to help clients build secure, sustainable, and audit-ready environments.
Position Summary
Jun Cyber is seeking a Junior-Level GRC Analysts to support our Governance, Risk & Compliance team in delivering cybersecurity compliance and assessment services.
The Compliance Analyst will support routine compliance monitoring, control testing, evidence collection and validation, documentation, remediation tracking, audit preparation, and reporting activities. This is an early-career role designed for a highly organized and detail-oriented professional who is interested in developing a career in cybersecurity, GRC, and compliance.
The successful candidate will work under established procedures and guidance while collaborating with GRC analysts, compliance managers, technical teams, and client stakeholders to help ensure that cybersecurity controls are properly implemented, documented, monitored, and supported by sufficient evidence.
Key Responsibilities
Compliance Monitoring & Control Testing
-
Perform periodic reviews of cybersecurity controls against applicable requirements.
-
Conduct basic control assessments and document test results.
-
Monitor compliance activities and identify missing or incomplete requirements.
-
Assist with monthly and quarterly compliance monitoring activities.
-
Track remediation activities and outstanding compliance issues.
Evidence Management
-
Request, collect, organize, and validate compliance evidence.
-
Maintain evidence repositories and ensure documentation is complete and current.
-
Identify missing, outdated, or insufficient evidence and escalate as appropriate.
-
Maintain evidence traceability to applicable controls and requirements.
Policy & Documentation
-
Assist with maintaining cybersecurity policies, standards, procedures, and supporting documentation.
-
Review documentation for consistency with established compliance requirements.
-
Maintain compliance records, assessment workpapers, and control documentation.
Risk & Remediation Support
-
Assist with identifying compliance gaps and control deficiencies.
-
Track POA&Ms, corrective actions, and remediation activities.
-
Follow up with control owners regarding outstanding remediation items.
-
Escalate overdue or significant issues to the Compliance Manager.
Assessments & Audits
-
Support internal and external audits and assessments.
-
Prepare requested evidence and documentation.
-
Assist with auditor requests and maintain audit request trackers.
-
Participate in assessment preparation activities.
Reporting
-
Prepare routine compliance status reports and dashboards.
-
Maintain compliance metrics and tracking spreadsheets.
-
Escalate significant compliance issues or trends.
Qualifications
-
1–3 years of experience in cybersecurity, IT, audit, risk, compliance, or a related field.
-
Basic understanding of cybersecurity concepts and controls.
-
Familiarity with one or more frameworks such as NIST CSF, NIST SP 800-53, NIST SP 800-171, CMMC, ISO 27001, SOC 2, HIPAA, or PCI DSS.
-
Strong documentation and organizational skills.
-
Ability to analyze information and identify inconsistencies or gaps.
-
Strong written and verbal communication skills.
-
Proficiency with Microsoft Office or comparable productivity tools.
Preferred Certifications
-
Security+
-
ISC2 CC
-
CISA — preferred but not required
-
Other cybersecurity or compliance certifications
Success Measures
-
Accurate and timely completion of assigned compliance activities.
-
Quality and completeness of collected evidence.
-
Timely identification and escalation of compliance gaps.
-
Accurate maintenance of compliance records.
-
Successful completion of assigned audit and assessment activities.
Jun Cyber is a Service Disabled Veteran Owned Business and Florida Certified Veterans Business Enterprise and Minority Business Enterprise that provides full spectrum IT, cybersecurity, and digital services to small and medium businesses.
Our team has been trusted by clients from many different industries. From data analytics, defense contractors, and law firms, Jun Cyber is your go-to source for “Service” and “Integrity” with all of our cybersecurity offerings.
We know the value of being forthright and getting to the point quickly to create efficient and effective plans of action for our clients. Our team is built of military veterans and cybersecurity professionals that boast over 25+ years of experience in the industry. From penetration testing to building information security programs from the ground up, we have the knowledge and experience to give our clients what is needed with no fluff.
Founded
2019
Company size
11-50 employees
Industry
IT Services and IT Consulting
Org type
Privately Held
Headquarters
St Petersburg, Florida
Jun Cyber is a Service Disabled Veteran Owned Business and Florida Certified Veterans Business Enterprise and Minority Business Enterprise that provides full spectrum IT, cybersecurity, and digital services to small and medium businesses.
Our team has been trusted by clients from many different industries. From data analytics, defense contractors, and law firms, Jun Cyber is your go-to source for “Service” and “Integrity” with all of our cybersecurity offerings.
We know the value of being forthright and getting to the point quickly to create efficient and effective plans of action for our clients. Our team is built of military veterans and cybersecurity professionals that boast over 25+ years of experience in the industry. From penetration testing to building information security programs from the ground up, we have the knowledge and experience to give our clients what is needed with no fluff.
Founded
2019
Company size
11-50 employees
Industry
IT Services and IT Consulting
Org type
Privately Held
Headquarters
St Petersburg, Florida