cover image
Rootshell Inc

GRC Analyst

Hybrid

Santa clara, United states

Freelance

05-12-2025

Share this job:

Skills

Network Security Encryption Monitoring Configuration Management Attention to detail Architecture Security Architecture SDLC

Job Specifications

Hello All,

Greetings from Rootshell Inc.

Rootshell Enterprise Technologies Inc. is a recognized provider of professional IT Consulting services in the US. We are actively seeking GRC Analyst for one of our client, Please share your resume with current location & full contact info

Job Title: GRC Analyst

Location: Santa Clara, CA - Hybrid

Employment Type: Contract

Key Responsibilities:

Skills:

Excellent understanding and practical application of industry security frameworks including SANS Critical Security Controls, CIS Controls, ISO 27001, NIST SP 800-53, PCI DSS, and SOC2.

Great understanding of IT control frameworks (COBIT) and IT general controls

Strong knowledge of information security concepts, risk and controls concepts

Strong knowledge of standards such as ISO 27001/2, NIST CSF, NIST 800-53, TSC 2017 (SOC2), PCI DSS, etc.

Strong knowledge of security control domains such as Asset Management, Configuration Management, SDLC, Logging and Monitoring, Data Security, Network Security, Security Governance, Identity Access Management, Vulnerability Management, etc.

Proficiency in a wide spectrum of technical security controls encompassing logical access control, encryption , data loss prevention, secure coding practices, security architecture, vulnerability management, and network security technologies.

Expert in conducting Vendor risk assessments and understand risk exposure of technology deficiencies and translating them to business impact

Strong domain experience in security risk assessments

Working knowledge of risk treatment and exception processes

Strong knowledge of Security architecture design and review including key security controls related to authorization, authentication, and encryption of data in transit/at rest

One or more certifications such as CISSP, CISA, CISM, CEH, ISO 27001 Lead Auditor and Lead Implementer

Open to learning and working on new domains and technology

Good written and spoken communications skills to explain and articulate technical concepts effectively to stakeholders including system engineers, and auditors

Strong attention to detail and diligence

With regards

Naveen | Talent Acquisition

Rootshell Enterprise Technologies Inc.

Naveen@rootshellinc.com | www.rootshellinc.com

About the Company

Founded in 2000, we are an IT consulting and solutions company Headquartered in Santa Clara, California with branch offices in Pennsylvania. We have been serving clients across US, India, Singapore, and Middle East. Rootshell is highly focused, dedicated and specialized as a consulting company for proving the most incredible experience in Information Technology, Product development and Niche IT skills. We are headquartered in Silicon Valley and maintain our offshore center in Hyderabad, India. We understand that technology i... Know more