IT Security, Risk & Compliance Analyst
Summary
IT Security, Risk & Compliance Analyst supporting internal GRC controls, endpoint security triage, vendor/client security reviews, and policy maintenance using EDR, MDM, and SOC 2/ISO 27001 frameworks.
JOB OVERVIEW
Plan A Technologies is seeking a proactive, organized, and detail-oriented IT Security, Risk & Compliance Analyst. In this role, you will support the hands-on operation and continuous improvement of our internal enterprise security program, working directly with the IT Security, Risk & Compliance Manager.
Working closely with senior leadership and engineering teams—as well as cross-functional stakeholders in IT, HR, and Project Management—you will help execute routine internal controls, track remediation efforts, assist with vendor and client security evaluations, and triage endpoint security events.
This is a versatile role combining internal Governance, Risk, and Compliance (GRC) execution with practical endpoint security oversight, ideal for a practitioner looking to grow their career across both security operations and GRC.
Please note: you must have at least 3+ years of hands-on experience in Information Security, IT Audit, Technical Support, or GRC roles to be considered for this role.
JOB RESPONSIBILITIES
Internal Control Execution & Tracking: Maintain and execute the periodic InfoSec controls calendar (monitoring workstation OS/app patching status, EDR status, vulnerability scans, and infrastructure/web maintenance).
Cross-Functional Stakeholder Coordination: Partner persistently with diverse teams (HR, IT, Software Engineering, Project Management) to enforce security requirements and drive open remediation items to completion (e.g., onboarding training compliance, vulnerability findings, process action items).
Policy & Documentation: Help write, update, and maintain IT security policies, standard operating procedures (SOPs), and user guidelines.
Incident Response & Triage: Assist senior engineers and leadership in monitoring, investigating, and triaging security events and potential incidents at both the endpoint and application levels.
Vendor & Partner Reviews: Perform baseline security evaluations and risk questionnaires for third-party vendors and software tools.
Client Security Support & DDQs: Assist in completing Client Due Diligence Questionnaires (DDQs) and help review security-related clauses in client and vendor contracts.
Technical Security Advisory & Awareness: Provide guidance to internal teams on security best practices, and help organize/deliver security awareness training and campaigns to end-users.
Continuous Improvement & Metrics: Track security metrics, logs, and remediation efforts to continuously strengthen the organization's posture.
EXPERIENCE
3+ years of hands-on experience in Information Security, IT Audit, Technical Support, or GRC roles.
Working familiarity with Endpoint Detection & Response (EDR) platforms, Mobile Device Management (MDM, like Microsoft Intune), and patch management processes.
Experience organizing, executing, and tracking user information security awareness campaigns and training for both technical and non-technical staff.
Fundamental understanding of cloud ecosystems, SaaS tools, source control workflows, and baseline networking concepts.
Baseline working knowledge of major security frameworks (SOC 2, ISO 27001) and privacy regulations.
Exceptional organizational skills with strong, professional follow-up habits to coordinate tasks across multiple departments.
Fluent in written and spoken English with clear communication skills to collaborate with internal teams and external clients.
Strong analytical problem-solving skills with a high degree of attention to detail.
Ability to prioritize tasks, handle multiple assignments, and meet deadlines in a fast-paced environment.
Collaborative mindset with a customer-first attitude when advising internal stakeholders and clients.
Initiative and drive to do great things.
Nice to Have
GRC Experience: Prior experience implementing and maintaining corporate information security programs aligned with international standards (such as ISO 27001 or SOC 2).
Certifications: Entry-to-mid certifications such as CompTIA Security+, Associate of ISC², GIAC, or vendor-neutral GRC/security certifications.
Scripting Skills: Basic scripting skills (PowerShell, Python, or Bash) for automation and evidence gathering.
ABOUT THE COMPANY/BENEFITS
Plan A Technologies is an American software development and technology advisory firm that brings top-tier engineering talent to clients around the world. Our software engineers tackle custom product development projects, staff augmentation, major integrations and upgrades, and much more. The team is far more hands-on than the giant outsourcing shops, but still big enough to handle major enterprise clients.
Read more about us here: www.PlanAtechnologies.com .
Location: Work From Home 100% of the time, or come in to one of our global offices. Up to you.
Great colleagues and an upbeat work environment: You'll join an excellent team of supportive engineers and project managers who work hard but don't ever compete with each other.
Benefits: Vacation, Brand New Laptop, and More: You’ll get a generous vacation schedule and other goodies.
If this sounds like you, we'd love to hear from you!