Summary
What you’ll impact
The Cybersecurity / GRC Security Analyst role in Houston, TX is a W2 contract position requiring extensive experience in cybersecurity, GRC, incident response, and vulnerability management. The analyst will work with cloud security platforms and services, and various compliance frameworks to support senior leadership and business teams.
Responsibilities
What you'll do
- Incident investigation, alert triage, threat hunting, endpoint response, and vulnerability management.
- Risk assessments, internal audits, TPRM, compliance testing, gap analysis, and security policies.
- Supporting Azure, AWS, and on-premises environments.
Requirements
What you’ll bring
- 10+ years of experience in Cybersecurity, Information Security, GRC, Incident Response, and Vulnerability Management.
- Strong hands-on experience with Microsoft Sentinel, Microsoft Defender, Azure Entra ID/IAM, KQL, and PowerShell.
- Experience in incident investigation, alert triage, threat hunting, endpoint response, and vulnerability management.
- Strong GRC experience including risk assessments, internal audits, TPRM, compliance testing, gap analysis, and security policies.
- Experience with ISO 27001, NIST CSF, NIST 800-53, GDPR, CMMC, NERC CIP, and PCI-DSS.
- Hands-on experience with Tenable Nessus, Qualys, and OneTrust.
- Strong communication and stakeholder-management skills with senior leadership, clients, legal, and business teams.
- Experience supporting Azure, AWS, and on-premises environments.
- Bachelor’s degree in Computer Information Systems, Cybersecurity, IT, or related field preferred.
- ISO 27001 Lead Implementer certification is a plus.
- Incident Response
- Microsoft Azure
- GAP Analysis
- Amazon Web Services
- Incident Management
- Team Management
- leadership
- Identity and Access Management
- communication skills
- Information Technology
- Safety Principles
- Windows PowerShell
- Risk Analysis
- Auditing Skills
- GDPR
- PCI Data Security Standards
- Security Policies
- Triage
- Cyber Security
- Kusto Query Language
- ISO/IEC 27001
- National Institute of Standards and Technology
- Qualys
- Azure Active Directory
- Governance Risk Management and Compliance
- IT Security Standards
- Software Vulnerability Management
- Cybercrime
- Conformance Testing
- IEC 62443
- Microsoft Antivirus
- Microsoft Sentinel
- Tenable Nessus