- Company Name
- Axcelis Technologies
- Job Title
- IT GRC Analyst
- Job Description
-
Job title: IT GRC Analyst
Role Summary: Lead and support enterprise‑wide cybersecurity, audit, and compliance initiatives, ensuring adherence to frameworks such as NIST 2.0, CMMC, COBIT, ISO 27001, and SOX 404. Serve as the primary liaison among IT, finance, auditors, and stakeholders to maintain robust IT controls.
Expectations: Deliver accurate audit documentation, manage control self‑assessments, maintain compliance posture, oversee remediation, and continuously improve audit methodologies. Must be proactive, detail‑oriented, and able to coordinate cross‑functional projects.
Key Responsibilities
• Act as primary IT liaison for internal and external audits; schedule and coordinate information requests and meetings.
• Develop, document, and maintain IT General Controls (ITGC) and IT Application Controls (ITAC) aligned with NIST, CMMC, COBIT, ISO 27001, and SOX 404.
• Lead control self‑assessments and internal risk reviews; gather evidence, analyze results, and produce findings.
• Manage and enhance the NIST Cybersecurity Framework and CMMC compliance journey toward certification.
• Coordinate SOX testing with audit, IT, and finance teams; support operational, financial, and advisory engagements.
• Respond to customer security questionnaires and facilitate third‑party risk assessments.
• Oversee vulnerability management and penetration testing; track remedial actions and report metrics.
• Project manage corrective action plans to resolve control deficiencies.
• Monitor regulatory changes; develop and update security policies, standards, and procedures.
• Conduct root‑cause analysis and lead remediation for control gaps.
• Continuously evolve audit methods, tools, and practices.
Required Skills
• 7+ years in IT GRC, cybersecurity compliance, or IT audit.
• Deep knowledge of NIST, CMMC, SOX 404, ITGC, ITAC, and COBIT.
• Experience managing external audits and audit documentation.
• Proficiency with vulnerability management, risk assessments, and incident response.
• Strong written and verbal communication; stakeholder engagement.
• Project coordination and change‑management capabilities.
Required Education & Certifications
• Bachelor’s degree in information systems, cybersecurity, or related field.
• Certifications: CISA, CRISC, CISSP, or ISO 27001 Lead Auditor.
• Understanding of cloud security and data‑protection regulations is preferred; AI risk assessment experience is a plus.