Associate GRC Analyst - INFORMATION TECHNOLOGY

Sedgwick CountyWichita, KansasOn-siteFull-timeNew grad, 0–1 yearsListed 2 hours ago

Apply now

About this role

Department: Info Tech Srvcs

Job ID: 13354

Pay: $2,449.60 bi-weekly

Work Schedule:

Sedgwick County offers a comprehensive benefits package for full-time employees that includes health coverages, paid leave, regular compensation reviews, retirement plans, and professional development opportunities. For more detailed information, please visit our benefits page at SCBenefits .

The Associate Governance, Risk and Compliance (GRC) analyst works across IT, departments, vendors, and leadership to evaluate and monitor compliance with security frameworks and regulatory obligations, including NIST 800-53, CIS Controls, ISO 27001, PCI, HIPAA, CJIS, and data privacy. The role performs audits, reviews controls and evidence, documents findings, and coordinates and tracks corrective recommendations and actions to improve the county’s overall risk management and compliance program. The Associate GRC Analyst also supports the organization’s governance, risk, and compliance activities by helping to maintain security policies and track risks.

Governance and policy administration

- Maintain current knowledge of evolving compliance requirements and best practices.

- Review policies, procedures, technical controls, and user practices for alignment with applicable standards.

- Assist with policy development, control documentation, and security awareness efforts.

Compliance monitoring and audit support

- Conduct security and compliance audits for systems, processes, and departments subject to PCI, HIPAA, and CJIS requirements.

- Conduct audit of ERP operations, ensuring alignment with compliance standards.

- Track deadlines for audits, reviews, certifications, and remediation items.

- Collect, validate, and maintain audit evidence for internal and external assessments.

- Prepare and communicate audit findings, remediation plans, and status reports for leadership.

- Coordinate with IT staff, departmental users, vendors, and security partners to resolve deficiencies.

- Monitor corrective action plans and follow up on remediation activities.

Risk and control analysis

- Identify compliance gaps, control weaknesses, and potential security risks.

- Track control assessment and risk mitigation efforts.

- Support incident response, risk assessments, and annual compliance reviews as needed.

- Assist in documenting security systems.

- Participate in organizational emergency response planning activities

- Cross training with other systems to serve as back-up as needed.

- Other duties as needed

Minimum Qualifications: Two (2) years of relevant experience in the cybersecurity audit field, including experience conducting internal audits, vendor reviews, or control self-assessments. This experience can be substituted by education in the fields of IT cybersecurity with one year of education substituting for each one year of experience. Experience or education used to qualify must be from within the last five years. Working knowledge of NIST 800-53, CIS Controls, ISO 27001, PCI DSS, HIPAA Security and Privacy Rules, or CJIS security requirements. Strong analytical, organizational, project management, multi-tasking and written communication skills.

Preferred Qualifications: Four (4) years of relevant experience in the cybersecurity audit field. Four (4) years of experience in security compliance, auditing, risk management, or information security. Familiarity with risk registers, policy management, and remediation tracking tools. Experience supporting security awareness training or privacy compliance programs. Working knowledge of NIST 800-53, CIS Controls, ISO 27001, PCI DSS, HIPAA Security and Privacy Rules, and CJIS security requirement. Bachelor’s degree in information systems, cybersecurity, auditing, accounting, criminal justice, public administration, or a related field. Professional certifications such as CISA, CISSP, CISM, Security+, HCISPP, or similar.

Applicants have rights under Federal Employment Laws. Please find more information under the following link. Apply for a Job | Sedgwick County, Kansas