GRC Analyst (Remote - LATAM)

10 hours, 23 minutes ago
Contract
Junior
Cybersecurity
Atmosera

Atmosera

Atmosera is a trusted global cloud partner offering Azure managed cloud services with a focus on security and compliance for critical business applications worldwide.

IT Services
51-250
Founded 1995

Description

  • Validate client environments against Managed GRC baselines and relevant security and compliance frameworks.
  • Maintain governance documentation, compliance tracking, and organized evidence for client audits.
  • Monitor security posture using Microsoft Defender for Cloud and Azure Policy, and track misconfigurations and compliance drift.
  • Assist with security questionnaires using standard response libraries and coordinate responses with internal teams.
  • Participate in client audits by gathering evidence, tracking requests, and coordinating with auditors and internal subject-matter experts.
  • Own monthly and quarterly Managed GRC reporting and maintain audit readiness documentation throughout the year.
  • Support readiness activities such as phishing simulations, tabletop exercises, penetration testing preparation, and remediation tracking.
  • Coordinate client penetration testing engagements, including scheduling, scope alignment, retesting, and evidence handoff.
  • Administer Purview Compliance Manager for subscribed clients, including control posture, evidence assignments, and remediation tracking.
  • Collaborate with Client Success Managers, security engineers, CyberSOC teams, and account teams while escalating issues as needed.

Requirements

  • 2+ years of experience in GRC, IT risk, compliance, or security operations support.
  • Hands-on experience with Microsoft Purview Compliance Manager, including control mapping, evidence tasks, and regulatory templates.
  • Familiarity with Microsoft Defender for Cloud, including secure score, recommendations, and compliance dashboards.
  • Working knowledge of Azure Policy concepts, including assignments, compliance scanning, and remediation tasks.
  • Familiarity with NIST frameworks, SOC 2 concepts, CIS Controls, and HIPAA compliance.
  • Experience supporting audits, questionnaires, or compliance programs.
  • Strong documentation, evidence collection, and organizational skills.
  • Ability to manage multiple client workstreams simultaneously.
  • Strong public speaking and presentation skills using Microsoft PowerPoint.
  • SC-900 Microsoft Certified: Security, Compliance, and Identity Fundamentals within 90 days of hire.
  • Prior experience in a managed services or MSSP environment, preferred.
  • Experience coordinating penetration tests or annual security testing cycles, preferred.
  • Ability to translate technical findings into clear business-oriented summaries, preferred.
  • Familiarity with Entra ID, Azure RBAC, Conditional Access, and cloud governance fundamentals, preferred.
  • Certifications such as SC-100, CISSP, CGRC, GRCP, CRISC, CISA, or CISM are preferred.

Benefits

  • Remote LATAM work arrangement.
  • Defined service hours of Monday through Friday, 8am–5pm PT.
  • Opportunity to work on a broad client portfolio across compliance, security assurance, and governance activities.
  • Access to coordination with Atmosera cybersecurity experts and subject-matter experts.
  • Exposure to Microsoft cloud security and governance tooling in a managed services environment.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Information Security Analyst

ClearCapital.com, 1-10 Real Estate

Clear Capital is hiring an Information Security Analyst to protect its on-premise and cloud environment, strengthen threat detection and incident response, and support enterprise security risk and compliance efforts.

Cisco Linux macOS Palo Alto SIEM Windows Server
10 hours, 8 minutes ago

Sr. Cybersecurity Analyst III

MetroStar 251-1K IT Services

MetroStar is hiring a Sr. Cybersecurity Analyst III to support government clients in obtaining and maintaining system Authority to Operate (ATO) approvals while safeguarding systems against security risks and incidents.

Cybersecurity
10 hours, 8 minutes ago

Risk & Controls Analyst

Centrapay 51-250 Diversified Financial Services

Centrapay is seeking a Risk professional to help strengthen controls, reporting, compliance, and third-party risk management across its fintech payments platform and Payap app.

10 hours, 8 minutes ago

Cyber Security Analyst

CallTek 51-250 Internet Software & Services

Mid-Level Cyber Defense Analyst at an internal and cloud security environment, responsible for investigating security events, determining incident scope, and driving initial containment and response.

Cybersecurity Network Security SIEM
10 hours, 23 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers