Overview:
As a GRC Analyst at Karhu, you will support real client engagements from your first week, helping clients meet frameworks like CMMC, CJIS, HIPAA, and FedRAMP. You will help build the documentation, map the controls, and assemble the evidence that must stand up to an assessor's review.
This is an entry-level or internship role, so you will work alongside more senior analysts who will train you on the frameworks and the methodology behind defensible compliance work. Your focus will be writing clearly, keeping engagement documentation accurate and organized, and following your work through to the finish. If you are early in your career and want work that genuinely matters, this is where you will find it. Our clients support missions that are critical to the nation, and the work you do helps keep them secure.
What you'll do:
- Support client evidence collection across compliance engagements
- Help draft and maintain security framework plans, policies, and procedures
- Assist with control mapping and system boundary artifacts
- Draft and maintain findings and remediation entries under guidance
- Track evidence requests and keep engagement documentation accurate, organized, and audit-ready
- Research framework updates and contribute to internal templates and the knowledge base
What we're looking for:
- Pursuing or recently completed a degree in cybersecurity, IT, or a related field.
- Strong writing and documentation skills.
- A drive to learn, grow, and do work that matters. This work helps protect organizations against real threats, and we want people who care about that and want to get better every week.
- Attention to detail. In compliance, the evidence must match reality, and the details decide whether a control holds up.
- Solid IT fundamentals: Working knowledge of networking, operating systems, and how systems talk to each other.
- Familiarity with core security concepts.
- Comfortable working independently and owning your work. You ask good questions, then run with the answer.
Nice to have:
- Familiarity with a compliance framework (CMMC, CJIS, HIPAA, NIST or FedRAMP)
- Microsoft 365 or Azure exposure
- CompTIA Security+, in progress or completed
- Exposure to a GRC platform or documentation tooling
- Scripting basics (PowerShell, Python, Bash)
Pay: $44,000.00 - $60,000.00 per year
Benefits:
- 401(k)
- Dental insurance
- Flexible schedule
- Health insurance
- Paid time off
- Parental leave
- Professional development assistance
- Referral program
- Vision insurance
Application Question(s):
- Are you a US Citizen (required for compliance)?
Work Location: In person