GRC Analyst – Rockville, MD
About us
Creative Information Technology Inc (CITI) is an esteemed IT enterprise renowned for its exceptional customer service and innovation. We serve both government and commercial sectors, offering a range of solutions such as Healthcare IT, Human Services, Identity Credentialing, Cloud Computing, and Big Data Analytics. With clients in the US and abroad, we hold key contract vehicles including GSA IT Schedule 70, NIH CIO-SP3, GSA Alliant, and DHS-Eagle II.
Join us in driving growth and seizing new business opportunities.
Roles & Responsibilities:
A. Policy Exception Administration – The contractor shall
- Review submitted policy exception requests for completeness.
- Verify required documentation has been submitted.
- Validate business justifications against County requirements.
- Request additional information from departments when necessary.
- Maintain exception records within ServiceNow.
- Track requests through each stage of the approval process.
- Monitor exception expiration dates.
- Coordinate renewals and closures.
- Produce status reports.
B. Risk Analysis - Using County-approved methodologies, templates and procedures, the Contractor shall:
- Review policy exception requests.
- Evaluate business impact.
- Evaluate likelihood and risk.
- Identify applicable compensating controls.
- Prepare written risk analyses.
- Prepare approval or denial recommendations for CISO review.
- Document analysis within ServiceNow.
C. Enterprise Risk Register - Maintain the County Information Security Risk Register by:
- Creating new risk records.
- Updating existing risk records.
- Recording risks identified by: o Third-party penetration tests
- Third-party security assessments
- Internal risk assessments
- Vulnerability scanning
- Policy Exceptions
- Security incidents
- Other approved sources
- Track mitigation activities.
- Monitor due dates.
- Update risk status.
- Maintain supporting documentation.
- Generate reports.
D. ServiceNow - Utilize ServiceNow IRM to:
- Process Policy Exceptions
- Maintain Risk Register records
- Track approvals
- Maintain documentation
- Generate reports
- Produce dashboards
E. Customer Service - The successful candidate will regularly communicate with:
- Department IT Staff
- Department Management
- Information System Owners
- County Leadership
- Office of Enterprise Information Security
Education & Certification:
Bachelor’s degree in:
- Cybersecurity
- Information Systems
- Information Technology
- Computer Science
- Business Information Systems
Certifications (not required/points awarded)
- CompTIA Security+ (Sec+)
- Certified Information Security Manager – Fundamentals (CISM‑F)
- NIST Cybersecurity Framework (NCSF) Practitioner
- ISACA IT Risk Fundamentals Certificate
- ISACA Cybersecurity Audit Certificate
- HIPAA Security Training or Compliance Certificates
Preferred experience
- One (1) year of professional Information Security, IT Governance, Compliance, Risk Management, Information Technology, Audit, or related experience.
- Recent graduate with relevant internship or equivalent experience.
- Experience using ServiceNow.
- Experience using Office 365 suite of products
- Experience with Governance, Risk and Compliance (GRC).
- Experience preparing technical documentation.
- Experience working in customer service environments.
- Experience with coordinating projects, tasks and/or workflows.
C. Knowledge
Basic understanding of:
- Cybersecurity principles
- Information Security
- Risk Management
- NIST Cybersecurity Framework
- Risk Scoring Systems/Risk Quantitative Frameworks
- HIPAA
