The Company
Serving the People Who Serve the People
Granicus is driven by the excitement of building, implementing, and maintaining technology that is transforming the Govtech industry by bringing governments and its constituents together. We are on a mission to support our customers with meeting the needs of their communities and implementing our technology in ways that are equitable and inclusive. Granicus has consistently appeared on the GovTech 100 list over the past 5 years and has been recognized as the best companies to work on BuiltIn.Over the last 25 years, we have served 5,500 federal, state, and local government agencies and more than 300 million citizen subscribers power an unmatched Subscriber Network that use our digital solutions to make the world a better place. With comprehensive cloud-based solutions for communications, government website design, meeting and agenda management software, records management, and digital services, Granicus empowers stronger relationships between government and residents across the U.S., U.K., Australia, New Zealand, and Canada. By simplifying interactions with residents, while disseminating critical information, Granicus brings governments closer to the people they serve—driving meaningful change for communities around the globe.Want to know more? See more of what we do here .
Job Summary
We are looking for a Senior Information Security Analyst with experience with vulnerability management and NIST 800-53 controls to join the information security and compliance team. You will report to the Senior Manager, Information Security Programs. You will perform analysis of vulnerability scan reports, improve the processes related to ticket creation and tracking, perform trend analysis of vulnerabilities and assets, lead discussions with product owners to address identified trends, and meet regularly with system owners to triage findings and drive closure. You will have experience with FedRAMP ConMon reporting, including completion of the PO&AM, DR tracker, and other ConMon documents. Your expertise will enable you to provide guidance to control owners regarding changes and implementation. You will also validate control implementation summaries and ensure playbooks and processes are up-to-date, effective, and comply with applicable compliance requirements.
What Your Impact Will Look Like
- Assess and improve current process to increase automation and effectiveness.
- Analyze vulnerability scan reports and tickets created, with an eye for trend analysis and improvements. This may include discussions with system owners about patching cadence, inventory management, system hardening, and change control processes.
- Provide guidance to control owners. Work with control owners to identify opportunities to improve control implementation and scalability.
- Collaborate with Security Engineering to improve ticket automation, including ticket assignments, components, labels, and other ticket fields.
- Assign tickets, append appropriate labels, and triage vulnerability tickets. This may include findings from vulnerability scans, penetration testing, customer security testing, threat intelligence findings, applicable CISA alerts, or other vulnerability notices.
- Lead improvements in metrics reporting. This will include internal security metrics and reporting as well as engaging product owners for improvements in product vulnerability reporting and tracking.
- Participate in change control review meetings to provide Security feedback and decisions.
- Partner with system and product owners to guide improved rationale and security impact analysis for deviation requests. Create playbooks for the system and product owners to utilize for improved deviation rationales.
- Author control implementation summaries and deviation rationales that support Granicus’ security posture and meet quality and content requirements.
- Support the information security team to track and maintain overall compliance with audited controls (which include controls from FedRAMP Moderate, TxRAMP, StateRAMP, ISO 27001, SOC 2, PCI, HIPAA, CJIS, and FISMA).
- Support compliance audits, including FedRAMP and ISO 27001. This will include participation in audit discussions, evidence collection and review, and planning.
You Will Love This Job If You Have
Knowledge/Skills/Abilities
- Experience working with software development and cloud operations teams at a SaaS and software company
- Experience with container vulnerability scans
- Direct experience with third party cloud security audits, such as FedRAMP
- Knowledge of common security frameworks, such as NIST 800-53, ISO 27001, PCI, HIPAA, SOC 2, and/or Cyber Essentials
- Understanding of audit frameworks and translating the control descriptions to system owners as actionable internal controls
- Strong communication skills, written and verbal
- Expertise with Jira query language and excel
- Drive to identify trends, inconsistencies, or other issues in order to resolve issues for effective vulnerability management, tracking, and reporting
- Experience working with a robust product set, including software and cloud services
- Ability to work with technical teams and non-technical teams
- Familiarity with AWS, Azure, and/or GCP cloud security and infrastructure
Experience/Credentials
- 7+ years in information security and compliance
- 5 years experience analyzing and tracking vulnerability scan reports
- Relevant security certifications are a plus, such as CISSP, SEC+, or equivalent.
About Us
Don’t have all the skills/experience mentioned above? At Granicus, we are trying to build diverse, inclusive teams. We do not have degree requirements for most of our roles. If you don’t meet every requirement above but are excited to learn more, we encourage you to apply. We might just be able to find another role that could be a perfect fit!
Security And Privacy Requirements
- Responsible for Granicus information security by appropriately preserving the Confidentiality, Integrity, and Availability (CIA) of Granicus information assets in accordance with the company's information security program.
- Responsible for ensuring the data privacy of our employees and customers, their data, as well as taking all required privacy training in a timely manner, in accordance with company policies.
The Team
- We are a remote-first company with a globally distributed workforce across the United States, Canada, United Kingdom, India, Armenia, Australia, and New Zealand.
The Culture
- At Granicus, we are building a transparent, inclusive, and safe space for everyone who wants to be a part of our journey.
- A few culture highlights include – Employee Resource Groups to encourage diverse voices
- Coffee with Mark sessions – Our employees get to interact with our CEO on very important and sometimes difficult issues ranging from mental health to work-life balance and current affairs.
- Microsoft Teams communities focused on wellness, art, furbabies, family, parenting, and more.
- We bring in special guests from time to time to discuss issues that impact our employee population
The Impact
- We are proud to serve dynamic organizations around the globe that use our digital solutions to make the world a better place — quite literally. We have so many powerful success stories that illustrate how our solutions are impacting the world. See more of our impact here .
The Benefits
At Granicus, we offer a
comprehensive and flexible benefits package
designed to support your well-being, growth, and work-life balance.Here’s what you can expect as a India-based team member:
Flexibility & Balance
- Paid Time Off– Take the time you need to rest, recharge, and live your life.
- Company-Wide Wellbeing Days – Paid days off to unplug and focus on your mental health.
- Work From Home Reimbursement – Support a productive home office environment.
Health & Wellness
- Private healthcare benefits - Comprehensive coverage for you and your family.
- On-Demand Mental Health Support – Access to Headspace and other wellness tools.
- Fitness Reimbursement & Cycle Program – Stay active, your way.
- Critical Illness and Life Insurance Benefits
Family & Future
- Paid Parental Leave - For both birthing and non-birthing parents.
- Pension plan with employer contributions
Growth & Recognition
- Online Learning Platforms – Fuel your professional development.
- Competitive Salary & Bonuses – Your contributions are valued and rewarded.