Part Time
$8/hour
20
Aug 20, 2026
Position Summary
Worldwide GRC (WWGRC) is seeking a Cybersecurity Analyst with demonstrated hands-on cybersecurity experience to support security artifact review, technical evidence validation, and compliance assessments.
This is a cybersecurity-focused position — not a general audit or entry-level compliance role.
The ideal candidate has practical experience working with cybersecurity controls, security tools, system and network security, vulnerability management, security logs, cloud security, and/or security assessments. Experience in GRC, compliance, or auditing is valuable, but audit or compliance experience alone does not meet the requirements for this position.
You will serve as the human quality layer supporting our AI-powered review process by determining whether client-uploaded technical and security evidence actually demonstrates that required cybersecurity controls are implemented and operating effectively.
This requires the ability to understand the technical security purpose behind a control, not simply verify that a document or artifact exists.
Employment Details
- Type: Part-time / Contract-to-hire
- Hours: 10–20 hours per week initially, scalable based on client volume
- Location: Remote
- Language: Strong written and verbal English communication required
- Reports to: WWGRC Reviewer Lead / Compliance Manager
- Compensation: Hourly rate commensurate with cybersecurity experience; discussed during interview
Minimum Required Qualifications
Applicants must have professional cybersecurity or information security experience.
Cybersecurity Experience
- Minimum 1–3 years of professional experience in cybersecurity, information security, security engineering, security operations, security consulting, or a closely related technical security role
- Practical understanding of cybersecurity concepts, controls, threats, vulnerabilities, and risk
- Experience in at least several of the following areas:
- Vulnerability management and vulnerability assessment
- Security log analysis and monitoring
- SIEM platforms such as Microsoft Sentinel, Splunk, or similar tools
- Network security
- Network or Web Application Firewall (WAF) technologies
- Endpoint security / EDR
- Identity and Access Management (IAM)
- Cloud security
- Security configuration review
- I
- Penetration testing or security testing
- Security control implementation or validation
GRC / Framework Knowledge
Candidates should also have experience with or working knowledge of at least one recognized cybersecurity or compliance framework, such as:
- NIST Cybersecurity Framework (NIST CSF)
- NIST SP
- SOC 2
- PCI DSS
- HITRUST
- Secure Controls Framework (SCF)
Candidates must be able to understand how technical cybersecurity evidence maps to security and compliance requirements.
Artifact & Evidence Review
Candidates should be capable of reviewing technical evidence such as:
- Firewall and network security configurations
- SIEM alerts, queries, dashboards, and logs
- Vulnerability scan reports
- Endpoint security / EDR evidence
- IAM configurations and access-control records
- MFA configurations
- Cloud security configurations
- Security policies and procedures
- System configuration screenshots
- Change-management evidence
- I
- Penetration testing reports
- Security monitoring records
The analyst must be able to determine whether evidence actually demonstrates that the required security control is implemented, rather than simply confirming that a file or screenshot was submitted.
Additional Requirements
- Strong analytical and critical-thinking skills
- Strong attention to detail and ability to identify inconsistencies or insufficient technical evidence
- Excellent written English for reviewer comments and client-facing explanations
- Ability to clearly explain why evidence is sufficient or insufficient
- Ability to work independently in a remote environment
- Reliable internet connection and quiet workspace
- Ability to meet weekly commitments and proactively communicate progress through Slack and email
Preferred Qualifications
The following are strongly preferred:
- Previous experience as a:
- Cybersecurity Analyst
- Information Security Analyst
- SOC Analyst
- Security Consultant
- Security Engineer
- GRC Analyst with substantial technical cybersecurity responsibilities
- IT Auditor with substantial cybersecurity assessment experience
- Hands-on experience with Microsoft Sentinel, Splunk, or another SIEM
- Experience performing security log analysis
- Experience with network security or Web Application Firewalls
- Experience with vulnerability scanning and vulnerability management
- Experience reviewing penetration-testing results
- Experience with AWS, Microsoft Azure, Google Cloud, Okta, Microsoft Entra ID, GitHub, or similar environments
- Experience evaluating technical cybersecurity controls during security or compliance assessments
- CISA, CISM, CISSP, CRISC, Security+, CySA+, or other relevant cybersecurity certifications
Important Applicant Notice
Please apply only if you have professional cybersecurity or information security experience.
This position is not intended for candidates whose experience is limited primarily to general auditing, accounting/financial auditing, administrative compliance work, document collection, or checklist-based compliance reviews.
General audit or compliance experience without meaningful cybersecurity experience will not meet the minimum qualifications for this role.
Candidates should be prepared during the interview to discuss specific cybersecurity work they have personally performed, including the tools, technologies, security controls, and environments they have worked with.
How to Apply
Please send the following to
- Your current resume or LinkedIn profile
- A brief description of your hands-on cybersecurity experience
- The cybersecurity tools and technologies you have worked with
- The security or compliance frameworks you have experience with
- Any relevant cybersecurity certifications
- Examples of security assessments, artifact reviews, or technical security work you have performed (redacted examples are acceptable)
Applications that do not demonstrate relevant cybersecurity experience may not be considered.