TEKsystems has a client looking to add a GRC Analyst that is responsible for establishing, maintaining, and operationalizing governance, risk, and compliance programs across regulated automotive and defense environments. This role ensures ongoing compliance with TISAX Assessment Level 2, NIST CSF 2.0, NIST SP 800 171, and CMMC 2.0, while reducing audit fatigue, legal risk, and operational disruption. The position requires a strong technical understanding of security controls across IT, OT, and engineering environments, combined with the ability to produce audit grade documentation and evidence that withstands third party and government assessments.
*Skills*
Compliance, Risk management, Audit, Nist, Risk assessment, CMMC, TISAX, Security, Information security, Risk analysis
*Additional Skills & Qualifications*
Governance, Risk & Compliance Management
*Own and maintain compliance programs aligned to:
oTISAX 6.0 (Assessment Level 2)
oNIST Cybersecurity Framework (CSF) 2.0
oNIST SP 800 171
oCMMC 2.0 (Level 1 & Level 2)
*Operationalize the NIST CSF 2.0 "Govern" function, including policy integration, leadership reporting, and measurable risk outcomes.
*Perform control gap assessments and coordinate remediation activities with IT, OT, Engineering, and Legal teams.
Audit & Assessment Readiness
*Prepare and manage self assessments and third party audits, including:
oTISAX AL2 assessments and remote audits
oCMMC Level 2 C3PAO readiness
*Develop and maintain:
oSystem Security Plans (SSPs)
oPlans of Action & Milestones (POA&Ms)
oSPRS documentation and submissions
*Serve as the primary point of contact for auditors, assessors, and internal stakeholders.
Technical Control Validation
*Validate the implementation and effectiveness of security controls across:
oIdentity & Access Management (IAM), MFA, RBAC, PAM
oLogging, monitoring, and audit logging (SIEM concepts)
oEndpoint and server security (hardening, patching, EDR)
oNetwork security (segmentation, firewalls, remote access)
oIncident response and tabletop exercises
*Review system configurations and technical artifacts to ensure they meet control intent and audit expectations.
Preferred Qualifications
*Experience supporting automotive OEMs or defense contractors
*Direct involvement in TISAX AL2 or CMMC Level 2 assessments
*Familiarity with GRC platforms (e.g., Archer, ServiceNow GRC, similar tools)
*Certifications such as:
oCISSP, CISM, CRISC
oCMMC RP, CMMC CCP
oISO 27001 Lead Implementer/Auditor
*Job Type & Location*
This is a Contract position based out of Auburn Hills, MI.
*Pay and Benefits*The pay range for this position is $53.00 - $58.00/hr.
Eligibility requirements apply to some benefits and may depend on your job
classification and length of employment. Benefits are subject to change and may be
subject to specific elections, plan, or program terms. If eligible, the benefits
available for this temporary role may include the following:
...Illinois Professional Educator License with a secondary endorsement in English (9-12). Competitive salary based on education and experience will be determined according to the upcoming Collective Bargaining Agreement.#J-18808-Ljbffr Indian Prairie School District 204
...live-in nanny/family assistant for their two children- an 8-year-old girl and 3-year-old boy. This role provides five-day live-in accommodations, and the candidate should be able to return to their own home on weekends. The general schedule is 7:30am-6pm, with some...
...Assembler Location: Near Ballston Spa, NY Pay Rate: $19.00 per hour Employment Type: Temp-To-Hire | Full-Time | Onsite Position Overview Our growing manufacturing client is seeking a dependable and detail-oriented Assembler to support production...
...are seeking an experienced and motivated Safety Manager to join our team in Phoenix,... ...equipment, and work practices Evaluate environmental conditions such as air quality, noise, ventilation... ...across the company Environmental Health & Industrial Hygiene Support...
...Inside Sales Representative Position Summary The Inside Sales Representative drives revenue growth for the Network & Security Services team by owning day-to-day prospecting, lead qualification, opportunity development, and deal progression. This role is responsible...