Information Security Analyst I, ITC
WHO YOU’LL WORK WITH
The GRC Information Security Analyst 1 works with the ITC GRC Director and collaborates with the Global GRC team at PHK in Beaverton, Oregon. This role is designed as an Analyst 1 GRC Athlete—an entry-level position executing intake, hygiene, and support tasks in whichever stream (Governance, Risk, Compliance, or Technical Recovery) is needed, while learning the GRC discipline under close guidance from Seniors, Leads, and Principals.
WHO WE ARE LOOKING FOR
We are looking for an entry-level analyst who is eager to launch a career in Governance, Risk, and Compliance. You bring self-initiative, a willingness to learn, and the discipline to close loops on standard tasks with review from more senior teammates. You are comfortable working within established procedures, using fact-finding and basic analysis to solve problems that fit within normal operating processes.
- Experience — 0–1 years of professional experience in cybersecurity, IT audit, compliance, technology risk, or GRC. Recent graduates, internships, co-ops, and rotational-program candidates encouraged.
- GRC Athlete willingness — Genuine interest in learning across all four streams (Governance, Risk, Compliance, Technical Recovery); willing to pick up work in the stream where the demand is highest with a playbook and coaching.
- Governance basics — Awareness of risk register, policy, and controls concepts; willingness to build depth in ServiceNow GRC.
- Compliance basics — Awareness of IT controls, evidence, and testing concepts (SOX ITGC exposure through coursework, internship, or certification is a plus).
- Cybersecurity frameworks (awareness) — Introductory awareness of NIST CSF, ISO 27001, or comparable frameworks; willingness to build depth.
- Risk & remediation basics — Willingness to track issues, chase evidence, and follow up to closure; able to keep clean records under guidance.
- Technical Recovery basics — Willingness to learn DR/BCP concepts (RTO/RPO, test types, evidence).
- Tools — Comfortable with Excel/Google Sheets, documentation tools, and standard collaboration platforms; exposure to ServiceNow (or comparable GRC/ITSM platform) is a plus.
- Analytical mindset — Applies fact-finding, clarification, and basic analysis to solve problems that fit within normal operating processes and policies.
- Communication — Shares standard information clearly; asks clarifying questions and produces clean notes and artifacts.
- Follow-through — Uses self-initiative to prioritize own work within standardized rules; comfortable operating with frequent review.
- Education — Bachelor’s degree in Information Security, Computer Science, Information Systems, Business, or a related field preferred (or equivalent experience); relevant certifications a plus (e.g., Security+, ITIL Foundation, ISO 27001 Foundation).
WHAT YOU’LL WORK ON
- Support the day-to-day GRC work that keeps the program healthy as an Analyst 1 GRC Athlete—intake, hygiene, tracking, and evidence-collection tasks in whichever stream is hottest. Learn the GRC discipline by doing, with close guidance from Analysts, Seniors, Leads, and Principals.
- GRC Athlete support — Execute foundational intake, hygiene, and support tasks in the stream with the most demand (Governance, Risk, Compliance, or TRM), under the direction of a Senior or Lead.
- Governance stream — Support risk register hygiene (data quality, updates, closure evidence) in ServiceNow GRC; assist with policy, standards, exceptions, and attestation cycles; prepare inputs for governance forums.
- Risk stream — Support remediation tracking, TPRM intake tasks, audit finding tracking, and cybersecurity risk assessment task work.
- Compliance stream — Support SOX ITGC evidence collection, testing coordination logistics, issue tracking, and Converse/geo compliance tasks.
- Technical Recovery stream — Support recovery planning documentation, exercise coordination, evidence collection, and program tracking.
- ServiceNow GRC — Maintain accurate records in ServiceNow GRC (controls, risks, issues, attestations, evidence) under guidance; adhere to workflows and hygiene standards.
- Evidence & artifacts — Produce standard work products (trackers, evidence packets, meeting notes, status updates) with review from Seniors and Leads.
- Stakeholder coordination — Coordinate with control owners, engineers, and vendors on well-defined tasks; escalate anything unclear or blocked through your Senior or Lead.
- Continuous learning — Build breadth across GRC streams; work through playbooks and coaching to become productive in new streams.