The GRC Analyst will integrate security governance, risk management, and compliance practices into the software development lifecycle for Azure-based applications. They will collaborate with engineering and DevOps teams to implement security controls, conduct threat modeling, and maintain compliance documentation.
This is a remote position.
Position Overview
MBC Technology Group (MBCTG) is seeking a motivated and detail-orientedGRC Analystto support a private-sector client engaged in modernfull-stack application development on Microsoft Azure.
This role focuses on integratingsecurity governance, risk management, and compliance practices into the software development lifecycleto ensure applications are designed, built, and deployed securely.
The GRC Analyst will work closely withsoftware engineers, DevOps teams, and security architectsto ensure that development practices align withsecure coding standards, cloud security requirements, and industry frameworks.
Key Responsibilities
Support the development and implementation ofSecure Software Development Lifecycle (SSDLC) practicesacross full-stack development projects.
Collaborate withsoftware engineers, DevOps teams, and architectsto embed security and compliance requirements into development workflows.
Assist in implementingsecurity controls aligned with frameworks such as NIST SSDF, NIST CSF, and OWASP best practices.
Assist with documenting and maintainingsecure coding standards and application security policies.
Identify and tracksecurity risks related to application development, cloud infrastructure, and third-party components.
Maintainrisk registers, control mappings, and compliance documentationfor SSDLC processes.
Support vulnerability management by helping track remediation activities for issues discovered duringcode scanning, penetration testing, or security reviews.
Assist with the implementation and monitoring ofAzure security services and controls, includingAzure Defender, Azure Policy, and identity management controls.
Prepare documentation and evidence forsecurity assessments, internal audits, and client compliance reviews.
Track and reportsecurity metrics for development teams, including vulnerability remediation timelines and SSDLC maturity.
Requirements
Experience:
SDLC: 2 years (Required)
DevOps: 2 years (Preferred)
NIST standards: 2 years (Preferred)
ISO 27001: 2 years (Preferred)
Minimum Qualifications
2+ years of experience in cybersecurity, GRC, or application security.
Understanding ofSecure Software Development Lifecycle (SSDLC)andDevSecOps practices.
Familiarity withapplication security principles, including common vulnerabilities (OWASP Top 10).
“I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!”