Point your AI agent at freehire and let it find you a job.

Get the CLI →

OTSI

NewBe an early applicant

Information Security Sr Anlyst

Discussion

Summary

Senior GRC information security analyst working onsite in Cary, NC or Overland Park, KS: reviewing client contract security clauses, supporting independent audits and certifications (NIST CSF, ISO 27001, AICPA SOC), running cyber and third-party risk assessments, and building risk metrics, ideally leveraging ServiceNow and GenAI tooling.

Object Technology Solutions, Inc (OTSI) has an immediate opening for a Sr. Information Security Analyst - GRC


Sr. Information Security Analyst – GRC (Cary, NC- Onsite)

Other Location: Overland Park, KS - Onsite


MAJOR RESPONSIBILITES:

Contract Risk Management

Proven experience reviewing client contract provisions related to data security, breach reporting, cyber resilience, and compliance certifications and measuring compliance in IT and security architecture and operations.

Regulatory Compliance Risk Management

Support independent certification and audit by working with D&IT peer groups and lines of business to collect documentation and evidence of security policies and operations

Request and review documentation and evidence from control owners to certify and validate compliance to standards and industry-accepted best practice

Monitor regulatory and legal landscape at a global scale and across market sectors and maintain awareness of compliance requirements

IT Governance

Act as an informed voice in development of policy and ensure alignment with regulatory, legal, and contractual requirements

Assist establishment and enforcement of standards of practice documentation to be referenced by architecture and operations teams

Contribute process and subject matter expertise in governance forums and cross-functional committees

Cyber Risk Management

Support establishment, collection, and ongoing improvement of metrics to measure effectiveness of cyber risk management and provide data-driven insight to decision makers and control owners

Collaborate with peer D&IT groups to collect KPI’s, KRI’s and drive efficiency through automation and other means

Supplier/Third Party Risk Management

Contribute subject matter expertise through third party risk assessment process

Identify and communicate risk of vendor engagements and mitigation actions to business owners and D&IT stakeholders

Assist review of client security requirements in contracts and aggregate relevant clauses to inform contractual risk

Miscellaneous:

Assist development of user training aligned with cyber threat landscape, establish and implement metrics, and propose enhancements

Support internal audit

Assist with security certification/attestations/audits to demonstrate control effectiveness to independent service auditors/assessors and C3PAO’s

Assist in development of risk treatment plans and monitoring progress of actions.

Collaborate with members of the GRC team to ensure timely and quality deliverables to internal and external customers

Contribute subject matter expertise in review and response to internal and external sourced GRC related requests



SKILLS AND ABILITIES REQUIRED:

Bachelor’s degree in information systems, Information Security, or a related field

7–10 years of experience in GRC executing or auditing against standards, frameworks, and industry regulations

Demonstrated experience supporting GRC functions for global companies

Solid proficiency in risk assessment methodologies and frameworks

Proven ability to assess alignment of internal policy, process, control design and operations, and cyber risk management with regulatory standards and frameworks

Strong collaboration with IT teams

Familiarity with industry standards and frameworks (e.g., NIST CSF and supporting SP’s, ISO 27001, AICPA SOC)

Working knowledge of cyber and privacy laws and regulations

Solid understanding of information security principles and concepts

Strong desire to create task and functional efficiencies through use of technology and tools, especially GenAI

Preferred Qualifications

Strong analytical, organizational, and communication skills

Professional certifications such as CRISC, CISSP or others

Experience with ServiceNow Risk Management platform

Knowledge of FAR, DFARS, CMMC

Experience with GRC platforms and risk management methodologies

Ability to work independently and collaboratively as required

Competencies

Attention to detail and critical thinking

Ethical judgment and integrity

Ability to manage multiple tasks and deadlines

Strong interpersonal and stakeholder engagement skills


About us


About us:

OTSI is a global technology partner providing enterprise IT consulting, digital solutions, and managed services. We help organizations modernize complex technology landscapes, harness the power of data, and build scalable AI-led ecosystems to accelerate innovation and business growth. With over 26 years of experience, we consistently turn complex challenges into success stories through our strong technical capabilities and deep industry knowledge. Our global team of 1,800+ professionals, spread across 6 countries, delivers cutting-edge solutions for customers across Banking, Financial Services, Insurance, Transportation & Logistics, Energy & Utilities, Healthcare & Life Sciences, Government, Hi-Tech, Telecom & Media, Manufacturing, and more.


Our focused technology areas:

· AI/ML (Agentic AI Solutions, GenAI/LLMs, Natural Language Processing, Intelligent Processing, Physical Intelligence)

· Data & Analytics (Data Architecture, Data Engineering, Data Migration, Data Modernization, Big Data, Analytics and BI)

· Cloud (Cloud Computing, Cloud Migration, Cloud-Native Architecture, Hybrid and Multi-Cloud)

· Digital Engineering (Application Modernization, Product Engineering, Platform Engineering, DevSecOps)

· Quality Engineering (Manual Testing, Nonfunctional testing, Test Automation, Digital Testing)

· Enterprise Platforms (SAP, Microsoft, Oracle, etc.)

Our focused industries and target segments:

· Banking, Financial Services, & Insurance

· Manufacturing, Transportation, & Logistics

· Energy & Utilities

· Telecom & Media

· Healthcare & Lifesciences

· Government & Public Sector (FED, SLED, & Partners)

· Hi-Tech



See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available