Spire
Finance / FinServ
GRCAnalyst
Neural analysis suggests this role is
optimal for Senior candidates.
“GRC Analyst at Spire. Skills: GRC Analyst, cybersecurity governance, risk, IT, framework interpretation, contract requirement analysis, NIST SP 800-171, NIST SP 800-53. Contribute to a shared control inventory used by compliance, security, and program teams.. Interpret framework language and authoritative guidance (NIST publications, DoD guidance, regulator FAQs) in the context of specific company systems and business scenarios.”
What You'll Achieve.
Established a repeatable contract review intake process with legal and sourcing, including a maintained library of standard cybersecurity flow-down clauses and review turnaround expectations.; Produced an end-to-end Requirements Traceability Matrix for at least one active federal program, traceable from contract clauses through framework controls to evidence sources.; Stood up the operational risk register and routine risk reporting cadence, with at least one full assessment cycle completed and risk treatment decisions documented.; Maintained the ISMS documentation set in audit-ready condition through at least one external assessment or surveillance cycle.
Industry & Context.
Interpret framework language and authoritative guidance; escalate ambiguity for formal risk decisions; remediation planning
background check, criminal history and employment verification
What They're Looking For.
Must Have
Five or more years of progressive experience in cybersecurity governance, risk, and IT or a closely related discipline, with substantial hands-on exposure to framework interpretation and contract requirement analysis., Demonstrated working knowledge of NIST SP 800-171 and NIST SP 800-53, including control families, assessment procedures, and common implementation patterns., Experience contributing to SSP and POA
Nice to Have
medical, dental, vision, life, and disability a 401(K) health and wellness reimbursement and participation in Spire’s Employee Stock Purchase Plan.
What You'll Do.
Contribute to a shared control inventory used by compliance
Interpret framework language and authoritative guidance (NIST publications
regulator FAQs) in the context of specific company systems and business scenarios.
Escalate ambiguity for formal risk decisions when appropriate.
Track decisions and ensure follow-through on conditions or expirations.
Track open compliance findings and remediation activities.
Prepare status updates.
Flag aging or high-severity items for escalation.
Validate that evidence is accurate
and appropriately scoped before submission.
Participate in assessor and auditor interviews as a subject matter contributor on specific controls and artifacts.
How You'll Work.
Team & Collaboration
Partner with legal and sourcing on contract review, redlines, and flow-down.; Partner with security program management on milestones, schedules, and audit.; Partner with security engineering and IT on evidence, control implementation detail, and remediation planning.; Serve as a knowledgeable point of contact for internal teams seeking to understand what a given regulatory or contractual requirement means in practice.
Communication Scope
prepare status updates; flag aging or high-severity items for escalation; serve as a knowledgeable point of contact
Process & Methodology
milestones, schedules, remediation planning, risk reporting cadence, assessment cycle
Full Job Description
About the Role: The GRC Analyst, Federal contribute to a shared control inventory used by compliance, security, and program teams. Interpret framework language and authoritative guidance (NIST publications, DoD guidance, regulator FAQs) in the context of specific company systems and business scenarios and escalate ambiguity for formal risk decisions when appropriate. Governance, Policy track decisions and ensure follow-through on conditions or expirations. Track open compliance findings and remediation activities, prepare status updates, and flag aging or high-severity items for escalation. Third-Party validate that evidence is accurate, complete, and appropriately scoped before submission. Participate in assessor and auditor interviews as a subject matter contributor on specific controls and artifacts. Cross-Functional Collaboration Partner with legal and sourcing on contract review, redlines, and flow-down language; with security program management on milestones, schedules, and audit coordination; and with security engineering and IT on evidence, control implementation detail, and remediation planning. Serve as a knowledgeable point of contact for internal teams seeking to understand what a given regulatory or contractual requirement means in practice. What Success Looks Like in Year One Established a repeatable contract review intake process with legal and sourcing, including a maintained library of standard cybersecurity flow-down clauses and review turnaround expectations. Produced an end-to-end Requirements Traceability Matrix for at least one active federal program, traceable from contract clauses through framework controls to evidence sources. Stood up the operational risk register and routine risk reporting cadence, with at least one full assessment cycle completed and risk treatment decisions documented. Maintained the ISMS documentation set in audit-ready condition through at least one external assessment or surveillance cycle. Required Qualifications: Fi
Applying for this GRC Analyst role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
ANONYMOUS · UNFILTERED
What do employees actually say about Spire?
Real rants from real employees. Read before you apply.