We're Hiring!
Senior GRC Security Analyst
- Remote, Texas, United States
- Full Time Exempt
Senior GRC Analyst – Security Compliance & Audit
This is a remote role.
Candidates must already live in the United States and be eligible to get a CJIS certificate, which requires US Citizenship.
At Lexipol, our mission is to create safer communities and empower the individuals on the front lines with market-leading content and technology. Our top-notch team works closely with law enforcement, fire, EMS, corrections, and local government professionals to tailor our solutions to better address today's challenges and keep first responders coming home safely at the end of each shift.
Working at Lexipol means making a difference — day in and day out.
The Work
Lexipol holds itself to the same standard of trust and accountability we ask of the agencies we serve. Two of our products require CJI (Criminal Justice Information) authorization, and Lexipol already maintains SOC 2 and CJIS compliance today. We are now pursuing GovRAMP authorization for the first time, and our control environment increasingly maps to the NIST 800-53 Rev. 5 (Moderate) baseline that GovRAMP is built on. Reporting to the VP, Internal Technology, the Senior GRC Analyst will own our security audit program end-to-end — maintaining what's already in place and leading GovRAMP from the ground up — while serving as the company's go-to expert on controls.
This role will contribute to Lexipol's security and compliance goals, including:
- Maintaining Lexipol's existing SOC 2 and CJIS compliance year over year, including CJI authorization for both current and next-generation versions of the affected product.
- Leading Lexipol's first-ever GovRAMP authorization from readiness through final assessment, as the primary point of contact for the assessor.
- Building and maintaining a single control framework and control library that maps Lexipol's practices to CJIS, GovRAMP, SOC 2, NIST 800-53 Rev. 5 (Moderate), and other frameworks as they arise.
- Standing up repeatable evidence-collection and control-testing processes so audits become faster and less disruptive each cycle.
- Acting as the company's internal subject matter expert on security and compliance controls, advising engineering, IT, and business teams throughout the year — not just during audit season.
- Tracking findings and corrective action plans to closure, and reporting audit status and control health to leadership.
Role Responsibilities:
- Own end-to-end planning and execution of Lexipol's ongoing SOC 2 (Type I/II) and CJIS audits, while also leading the company's first GovRAMP authorization (built on the NIST 800-53 Rev. 5 Moderate baseline) from scoping through final assessment.
- Maintain CJI authorization for both product lines that require it, including the newer version, ensuring neither lapses as the products evolve.
- Design, document, and maintain Lexipol's control framework, mapping shared controls across multiple compliance regimes to reduce duplicate work.
- Perform ongoing control testing and self-assessments between formal audit cycles to catch gaps before an auditor does.
- Partner with Engineering, IT, DevOps, and Product teams to translate audit and control requirements into practical, implementable safeguards.
- Maintain the risk register and control matrix, and drive remediation plans for identified gaps and findings to on-time closure.
- Serve as the internal SME on security and compliance controls, fielding questions from sales, customer success, and product teams responding to customer security questionnaires and due-diligence requests.
- Develop and maintain audit playbooks, policies, and procedures so institutional knowledge doesn't live in one person's head.
- Monitor changes to CJIS, GovRAMP, SOC 2, NIST 800-53 Rev. 5 (Moderate), and related frameworks, and advise the Head of IT and Enterprise Security and leadership on how those changes affect Lexipol's obligations.
- Support vendor and third-party risk assessments where they intersect with Lexipol's own control environment.
- Prepare clear, leadership-ready reporting on audit status, control posture, and open risk.
Requirements: To be considered for this role, you will have this experience:
- 5+ years of experience in information security compliance, IT audit, or GRC, with direct, hands-on experience running or supporting formal audits.
- Experience with NIST 800-53 Rev. 5 & GovRAMP are highly sought.
- Working knowledge of at least two of the following frameworks, with demonstrated ability to learn the others quickly: CJIS Security Policy, GovRAMP (formerly StateRAMP)/FedRAMP, SOC 2 (Trust Services Criteria), and NIST 800-53 Rev. 5 (Moderate baseline).
- Experience building or maintaining a control framework or control matrix, including mapping controls across multiple compliance frameworks.
- Ability to independently lead an audit from planning through final report, including managing auditor relationships and evidence requests.
- Strong understanding of security control domains such as access management, encryption, logging and monitoring, change management, and incident response.
- Experience translating technical controls into terms non-technical stakeholders can act on, and vice versa.
- Excellent organizational skills and comfort managing multiple concurrent audits and deadlines without close supervision.
- Strong written and verbal communication skills, including experience presenting audit status and risk to leadership.
Preferred Qualifications
- Relevant certification such as CISA, CISSP, CRISC, CCSK, or ISO 27001 Lead Auditor.
- Direct experience with CJIS compliance and CJI (Criminal Justice Information) authorization in a SaaS, law enforcement, or criminal-justice-adjacent environment.
- Direct experience achieving GovRAMP/StateRAMP or FedRAMP authorization for the first time — this is a net-new pursuit for Lexipol, so first-time-authorization experience is especially valuable — including assessment against the NIST 800-53 Rev. 5 Moderate control baseline.
- Experience responding to customer security questionnaires and supporting the sales cycle for public-sector customers.
- Background in public safety, law enforcement, fire, EMS, or government-related industries.
Employee Value Proposition
- Own a high-visibility program: you will be the name behind Lexipol's CJIS, GovRAMP, SOC 2, and NIST 800-53 Rev. 5 (Moderate) audits, with direct exposure to the Head of IT and Enterprise Security and senior leadership.
- Build something from the ground up: shape a control framework and audit program that doesn't yet exist in its current form, rather than maintaining someone else's system.
- Opportunity for Impact: strengthen the trust that law enforcement, fire, EMS, and government agencies place in Lexipol's technology.
- Be the recognized expert: serve as the company's go-to voice on controls, with your judgment sought out across security, engineering, and go-to-market teams.
- Full-time remote position with the opportunity to join cross-functional meetings at our home office.
- We strive to provide a professional, ethical, and collaborative environment that is largely a remote workforce. Video conferencing is standard practice.
- This position mostly has predictable weekday work hours, with occasional extended workdays around audit deadlines.
- Regular check-in meetings with the VP, Internal Technology.
- Cross-Departmental Synergy: this role touches Engineering, IT, DevOps, Product, Legal, and HR, offering broad visibility into the business beyond a typical individual-contributor security role.
Target Outcomes/Target Results for 2026 and Beyond
- Achieve Lexipol's first GovRAMP authorization, built on the NIST 800-53 Rev. 5 (Moderate) control baseline.
- Maintain clean, on-time SOC 2 and CJIS renewals with no material or repeat findings, including CJI authorization for both product lines that require it.
- Publish a documented, maintained control framework mapping shared controls across all four compliance regimes.
- Reduce audit preparation time year-over-year by standing up repeatable evidence-collection processes.
- Close 100% of audit findings and corrective action items within agreed remediation timelines.
- Establish a cadence of ongoing control self-assessments so gaps are caught between audits, not during them.
- Become the recognized internal SME that Engineering, IT, and go-to-market teams turn to first on control and compliance questions.
The Environment
- Our team is highly productive and works with urgency every day to provide the expected high-quality software solutions to our public safety professionals. Individuals who seek out additional responsibilities and have an action-oriented mindset thrive on this team.
- Dynamic, collaborative, and driven by a mission to make a difference. Our team enjoys the challenge of solving complex problems and implementing solutions that have a real impact.
- We celebrate our success, give praise, want to learn from one another, and are dedicated to each member of the team maximizing their potential.
- Our core values of Serve, Innovate, Collaborate, Empower, and Own It are not just words but the principles guiding every decision and action, fostering a culture of impact, growth, and mutual respect. Like the vital relationship between a ship and its crew, we prioritize our collective mission and the well-being of our teammates. This philosophy ensures we navigate challenges successfully and support each other in achieving personal and professional growth, reflecting our commitment to service and innovation.
Duties listed are not intended to be exhaustive or exclusive; other duties may be assigned. Management retains the discretion to add to or change the duties of the position at any time.
Compensation and Benefits
Lexipol offers a competitive base salary, monthly, quarterly, or annual incentive and a comprehensive benefits package including 401(k) with Company match and a flexible paid time off plan.
We are targeting a base salary near the range of $105-115k. Plus a bonus opportunity of 5%.
About Lexipol
Lexipol empowers first responders and public servants to best meet the needs of their residents safely and responsibly. We are the experts in policy, training and wellness support, committed to improving the quality of life for all community members. Our solutions include state-specific policies, online learning, behavioral health resources, grant assistance, and industry news and information offered through the websites Police1, FireRescue1, EMS1, Corrections1 and Gov1. Lexipol serves more than 2 million public safety and government professionals in over 12,000 agencies and municipalities. For additional information, visit www.lexipol.com.
Lexipol Is an Equal Opportunity Employer (EOE)
Lexipol, LLC provides equal employment opportunities (EEO) to all team members and applicants for employment without regard to race, color, religion, gender, national origin, age, sex, pregnancy, disability, sexual orientation, gender identity or expression, veteran status, genetic information, or any other non-job-related characteristic. Lexipol complies with applicable federal, state and local laws governing nondiscrimination in employment in every location in which the company has facilities. This policy applies to all terms and conditions of employment, including hiring, placement, promotion, termination, layoff, recall, transfers, leave of absence, compensation, and training.
Similar Jobs
There are currently no jobs matching this criteria