HOME Compliance & Risk Management Cyber GRC Analyst
  • SAIC
  • Flexwork,
  • Full-Time
  • 45 days ago
SAIC VERIFIED EMPLOYER

Cyber GRC Analyst.

Remote Compliance & Risk Management Full-Time

Cyber GRC Analyst: our view in 3 lines...

  • The Role:This role is for a Cyber GRC Analyst who combines quality assurance with governance, risk, and compliance work in a security operations context.
  • The Person:The person will review and test automation and analyst work, maintain control documentation, assess exceptions and failures, and help refine governance policies, playbooks, workflows, and technical controls.
  • Requirements:The ideal candidate has experience with NIST Risk Management practices outlined in 800-39, GenAI governance, Torq workflows, user acceptance testing, regression testing, and control documentation.

About the role

SAIC is looking for a Quality Assurance and Governance Analyst. This role combines responsibilities for analyst and ticket quality with a strong focus on technical QA and governance. The position is designed as a blended role, bridging Quality Assurance (QA) processes with Governance, Risk, and Compliance (GRC), while expanding beyond traditional Tier 1 ticket reviews. The successful candidate will act as a quality and control layer between Tier 0 automation, Tier 1 analysts, Engineering, and GRC stakeholders. They will provide hands-on experience in workflow design, access and control decisions, testing, integrations, governance practices, and technical documentation, while helping to maintain the highest levels of automation and analyst performance quality within the Security Operations Center (SOC). This opportunity can be worked 100% remote for the right candidate.

 

Responsibilities 

Governance, Risk, and Compliance:

  • Perform governance and oversight functions in accordance with NIST Risk Management practices outlined in 800-39.
  • Support AI governance and oversight by establishing rigorous testing, approval, documentation, and periodic review processes for GenAI-supported workflows. Key focus areas include accuracy, traceability, hallucination risk, data handling, and human-in-the-loop requirements.
  • Maintain detailed control documentation, including testing evidence, workflow approvals, QA standards, and change records to support internal governance and compliance assessments (e.g., NIST, FedRAMP, CJIS, or CMMC frameworks).
  • Participate in policy analysis and contribute to the development and refinement of security, technical, and AI governance policies.
  • Technical QA and Workflow Assessment:
  • Conduct Tier 0 and automation quality assurance, validating Torq workflows, decision points, enrichment steps, outputs, escalation logic, and ticket creation to ensure automation is functioning as intended.
  • Perform technical workflow testing, including user acceptance testing (UAT) and regression testing related to updates in Torq workflows, playbooks, integrations, or Sentinel rules.
  • Analyze and address exceptions and failures in automated workflows to determine root causes, collaborating with Engineering to identify whether issues stem from logic errors, data quality gaps, integration failures, or analyst handling.
  • Develop QA metrics to identify and delineate analyst quality issues versus automation quality issues, providing data-driven insights into Tier 0 performance, consistency, and contribution to SLA adherence.
  • Conduct regular reviews and evaluations of analyst investigations and ticket handling to ensure they meet defined QA standards and provide feedback to continuously improve performance.

Continuous Improvement:

  • Use QA findings to recommend updates and improvements to playbooks, Torq workflows, automation rules, escalation criteria, and technical controls. Focus on preemptive improvement rather than solely identifying gaps after implementation.
  • Communication and Collaboration:
  • Facilitate communication and collaboration among Tier 0 automation systems, Tier 1 analysts, Engineering teams, and Governance, Risk, and Compliance stakeholders to align work outcomes with organizational objectives.
  • Act as the key point of coordination for QA and technical review discussions, ensuring integration across all stakeholders and establishing a unified path toward continuous improvement.

SAIC is a premier mission integrator focused on advancing the power of technology and innovation to serve and protect our world. Our robust portfolio of offerings across the defense, space, intelligence, and civilian markets includes secure high-end solutions in mission IT, enterprise IT, engineering services, and professional services. We integrate emerging technology, rapidly and securely, into mission critical operations that modernize and enable critical national imperatives.


We are approximately 23,000 strong; driven by mission, united by purpose, and inspired by opportunities. SAIC is an Equal Opportunity Employer. Headquartered in Reston, Virginia, SAIC has annual revenues of approximately $7.3 billion. For more information, visit saic.com. For ongoing news, please visit our newsroom.
Published July 29, 2026
Location Flexwork, United States of America
Job Type Full-Time