Cast & Crew LLC Logo

Cast & Crew LLC

GRC Analyst

Posted 2 Hours Ago
Be an Early Applicant
Remote
Hiring Remotely in United States
110K-120K Annually
Senior level
Remote
Hiring Remotely in United States
110K-120K Annually
Senior level
Manage third-party vendor risk, respond to security questionnaires, support SOC 1/2 audits, maintain compliance automation platforms, collect audit evidence, document policies and controls, track risk and remediation, and present risk findings to leadership.
The summary above was generated by AI

About Us

At Cast & Crew, we’ve empowered creativity and supported the global entertainment industry for decades. Together with our family of brands - Backstage, CAPS, Checks & Balances, Final Draft, Media Services, Sargent-Disc, and The TEAM Companies – we operate as a combined entertainment technology and services provider offering industry standard screenwriting accounting software, digital payroll products, data & reporting, and a host of creative tools.  The industry continues to move faster than ever, and the need for our expertise, our technology, and our people has never been greater.  We are a production’s best ally every step of the way. #OneCastOneCrew

Position Overview:

The GRC Analyst supports the Information Security Office by managing third-party vendor risk, processing security questionnaires, and assisting with audit and compliance activities across the enterprise. This role is well-suited for someone with a strong compliance background who is looking to grow within information security. The ideal candidate is detail-oriented, organized, and experienced working with compliance frameworks, audit processes, and GRC tools such as Drata or similar platforms. A willingness to learn security concepts and stay current on evolving practices is essential.

Essential Functions

  • Managing the end-to-end third-party vendor risk management program, including onboarding assessments, periodic reviews, and ongoing monitoring of vendor security posture.
  • Supporting an internal ISRM program focused on uncovering cybersecurity risk and adding it to a risk register for prioritization and acceptance and ownership or remediation
  • Completing and responding to inbound security questionnaires (e.g., SIG, CAIQ, custom questionnaires) from clients and partners in a timely and accurate manner.
  • Coordinating information gathering and interviewing of internal stakeholders to support third-party security questionnaire responses.
  • Supporting and maintaining the organization's compliance automation platforms (e.g., Drata and Andromeda), including evidence collection, control mapping, and readiness tracking.
  • Supporting SOC 1 Type 2 and SOC 2 Type 2 audits, including evidence collection, auditor coordination, and remediation of identified gaps.
  • Developing, maintaining, and improving security documentation, policies, standards, procedures, and runbooks.
  • Monitoring and reporting on internal control effectiveness and audit readiness posture.
  • Advising internal lines of business, IT partners, and third parties on how to remediate security gaps identified through assessments or audits.
  • Understanding applicable regulations, guidelines, and industry best practices to manage risk and ensure compliance.
  • Drafting and presenting risk reports and proposals to executive leadership and senior staff.
  • Performing other duties as directed.

Qualifications:

The following certifications are a plus, but are not expected at the time of hire:

  • CISA or CISM (compliance/audit-focused; strongly relevant to this role)
  • CRISC (risk and controls focus)
  • CISSP, GIAC/GSEC, or vendor certifications (AWS/Azure)

Requirements:

5+ years of experience in compliance, audit, GRC, or a related field, with exposure to information security concepts. Equivalent experience in risk management, regulatory compliance, or internal audit will be considered. Candidates should have working knowledge of the following:

  • Compliance frameworks, audit processes, or risk management programs
  • SOC 1 or SOC 2 audit support or audit evidence collection (direct audit experience a plus)
  • Development or maintenance of policies, procedures, and compliance documentation
  • Third-party or vendor risk processes (experience with formal TPRM programs a plus)
  • GRC or compliance automation tools (e.g., Drata, Andromeda, or similar platforms)

Communications:

  • Excellent oral communication skills and comfortable in group or small team settings
  • Excellent written communication skills
  • Ability to take highly technical material and present/communicate it to a non-technical audience

Relationship Building:

  • Builds excellent working relations with all IT colleagues and users, works effectively with department and executive management, and maintains a professional relationship with outside clients and vendors

Planning, Organizing, Prioritizing, Delivering:

  • Exhibits mature organization and time management skills
  • Excellent problem-solving skills
  • Effectively planning and organizing daily work following priorities set by the Risk Manager
  • Demonstrates strong follow-up and follow-through skills in ensuring timely completion of projects
  • Self-starter who actively takes responsibility to resolve issues but also knows when to ask questions to avoid major delays in delivery of work product

Knowledge of:

  • SOC 1 Type 2 and SOC 2 Type 2 audit processes and control frameworks
  • GRC and compliance automation tools, with preference for Drata
  • Security questionnaire frameworks (e.g., SIG, CAIQ, NIST) and third-party risk methodologies
  • Evidence collection, reporting, and security documentation best practices

Skill In:

  • Coordinating SOC audit activities, evidence collection, and auditor communication
  • Working with compliance frameworks such as NIST CSF, NIST 800-53, or ISO/IEC 27001 (familiarity sufficient; deep expertise not required)
  • Completing or supporting security questionnaire responses (SIG, CAIQ, or similar)
  • Writing clear, well-organized compliance documentation and communicating requirements across teams

Physical Demands:

SEDENTARY - Exerts up to 30 lbs. of force occasionally and/or a negligible amount of force frequently or constantly to lift, carry, push, or pull. Involves sitting most of the time but may involve walking or standing for brief periods of time.

Benefits 

Cast & Crew provides a comprehensive package of employee benefits including: Medical, Dental, Vision, PTO, health and wellness programs, employee discounts, and more! Note: Cast & Crew benefits are subject to eligibility requirements.

Cast & Crew is an equal opportunity employer committed to hiring a diverse workforce and sustaining an inclusive culture. It is our policy to provide equal employment opportunities to all individuals based on job-related qualifications and ability to perform a job, without regard to age, gender, gender identity, sexual orientation, race, color, religion, creed, national origin, disability, genetic information, veteran status, citizenship or marital status, and to maintain a non-discriminatory environment free from intimidation, harassment or bias based upon these grounds.

CA residents
Your personal information may be collected in connection with certain services provided by Cast & Crew or its affiliated companies.  A summary of your California privacy rights can be found at: https://www.castandcrew.com/privacy-policy/

Compensation is commensurate with various factors including, but not limited to, relevant experience, qualifications, skills, training, licensure, certifications, geographic cost of labor, and other business and organizational needs. Compensation range for candidates in other locations may differ based on the cost of labor in that location. The compensation range for this position is: $110,000.00 - $120,000.00 per year.

Similar Jobs

3 Hours Ago
Remote
United States
110K-120K Annually
Senior level
110K-120K Annually
Senior level
Fintech • News + Entertainment • Software
Manage third-party vendor risk program, complete and respond to security questionnaires, support compliance automation (Drata/Andromeda), collect SOC 1/2 audit evidence, maintain security policies and controls, monitor audit readiness, advise stakeholders on remediation, and report risks to leadership.
Top Skills: AndromedaAWSAzureCaiqDrataIso/Iec 27001Nist 800-53Nist CsfSigSoc 1Soc 2
3 Hours Ago
In-Office or Remote
75K-80K Annually
Mid level
75K-80K Annually
Mid level
Healthtech
Support development and maintenance of security controls and compliance programs. Manage frameworks (SOC 2, HIPAA, NIST), optimize Drata, support audits, perform vendor risk assessments, maintain risk register, track remediation, and promote security awareness across the organization.
Top Skills: DrataHipaaHitechIso/Iec 27000Nist CsfNist Sp 800Soc 2
8 Days Ago
Remote
United States
Senior level
Senior level
Information Technology
Lead and manage GRC activities including internal/external audits, risk assessments, DR/BCP, third-party risk, and remediation. Develop and maintain policies, conduct BIAs, run tabletop exercises, mentor junior analysts, and collaborate with stakeholders to improve compliance posture and reporting across business and technology teams.
Top Skills: Business ContinuityCloud EnvironmentsColocationDisaster RecoveryGrc ToolsHipaaIso 27001NetworkingNist CsfPci-DssSoc1Soc2

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account