2

Remote Isso Jobs in Canton, GA (NOW HIRING)

This is a fully remote position open to Contract or Full-Time candidates. Key Responsibilities * Conduct control assessments and gap analyses against frameworks including NIST CSF, NIST 800-53, ISO ...

Remote Isso information

See Canton, GA salary details

$43.4K

$111.7K

$174.2K

How much do remote isso jobs pay per year?

As of Aug 7, 2026, the average yearly pay for remote isso in Canton, GA is $111,722.00, according to ZipRecruiter salary data. Most workers in this role earn between $89,700.00 and $130,300.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Remote ISSO?

To thrive as a Remote ISSO (Information Systems Security Officer), candidates need a robust understanding of information security principles, risk management frameworks (such as NIST), and compliance requirements, often backed by a degree in cybersecurity or a related field. Familiarity with security tools like vulnerability scanners, SIEM platforms, and certifications such as CISSP or CISM are highly valued. Excellent written communication, analytical thinking, and the ability to work independently are crucial soft skills in this remote context. These attributes enable effective oversight of organizational security, ensure compliance, and facilitate collaboration while working off-site.

What is a Remote ISSO?

A Remote ISSO (Information Systems Security Officer) job involves managing and ensuring the security of an organization's IT systems while working remotely. Responsibilities include implementing security policies, conducting risk assessments, ensuring compliance with regulations like NIST and FISMA, and responding to security incidents. Remote ISSOs collaborate with IT teams to safeguard sensitive data and maintain system integrity. Strong knowledge of cybersecurity frameworks and federal compliance standards is essential for this role.

What are some common challenges faced by Remote ISSOs and how can they be overcome?

Remote ISSOs often face the challenge of maintaining strong oversight of security protocols and compliance across distributed teams and systems without being onsite. To overcome this, successful ISSOs utilize secure remote access tools, implement robust communication practices, and foster strong relationships with IT and compliance stakeholders. Regular virtual meetings, clear documentation, and proactive incident response planning help ensure security standards are consistently met. Staying updated on evolving cyber threats and engaging in continuous professional development also help remote ISSOs remain effective and adaptable in a dynamic environment.

What cities near Canton, GA are hiring for Remote Isso jobs? Cities near Canton, GA with the most Remote Isso job openings:
Infographic showing various Remote Isso job openings in Canton, GA as of August 2026, with employment types broken down into 81% Full Time, 8% Part Time, 3% Temporary, and 8% Contract. Highlights an 100% Remote job distribution, with an average salary of $111,722 per year, or $53.7 per hour.

GRC Analyst

Merci Technologies - Talent

Atlanta, GA • Remote

Full-time

Re-posted 12 days ago


Job description

About the Role
Merci Technologies is seeking a GRC Analyst to support the governance, risk, and compliance program for one of our enterprise clients. This role sits at the intersection of security, audit, and business operations, translating complex regulatory and framework requirements into practical controls that teams can actually implement and sustain. You will be the person who knows where the control gaps are, what the auditors are going to ask for, and how to keep the organization audit-ready year round rather than scrambling at assessment time.

The work is varied and visible. In a given month you might run a control assessment against NIST CSF, prepare evidence for a SOC 2 examination, complete a vendor risk review for a new SaaS purchase, and brief stakeholders on the status of open findings. You will maintain the policy library, track risk to closure, and act as a trusted advisor to engineering and business teams who need to understand what compliance requires of them. This is a strong fit for someone who is organized, detail-driven, and comfortable holding teams accountable to commitments. This is a fully remote position open to Contract or Full-Time candidates.

Key Responsibilities

  • Conduct control assessments and gap analyses against frameworks including NIST CSF, NIST 800-53, ISO 27001, SOC 2, and CMMC
  • Plan and support internal and third-party audits, including scoping, evidence collection, and walkthroughs
  • Track audit and assessment findings to remediation and closure, escalating risks where needed
  • Develop, maintain, and version-control security policies, standards, and procedures
  • Perform vendor and third-party risk assessments and document risk acceptance decisions
  • Build and maintain the risk register and report risk posture to leadership and stakeholders
  • Support regulatory, customer, and compliance reporting requests
  • Help operationalize new framework or regulatory requirements as they emerge

Required Qualifications

  • 3 to 5 years of experience in governance, risk, and compliance, IT audit, or information security
  • Working knowledge of one or more frameworks: NIST CSF, NIST 800-53, ISO 27001, SOC 2, or CMMC
  • Demonstrated experience supporting audit cycles and risk assessments end to end
  • Ability to read a control requirement and translate it into clear, actionable guidance
  • Strong documentation, organization, and stakeholder communication skills

Preferred Qualifications

  • CISA, CRISC, ISO 27001 Lead Auditor, or CISSP certification
  • Hands-on experience with GRC platforms such as Archer, ServiceNow GRC, or OneTrust
  • Familiarity with defense, healthcare, or financial-services compliance requirements
  • Experience with CMMC readiness and assessment preparation

What You Will Bring
You are the kind of person who reads the fine print and keeps the spreadsheet honest. You can push a remediation owner for an update without burning the relationship, and you can explain to a busy engineer why a control matters in language they care about. You treat compliance as a way to make the organization genuinely more secure, not just to pass an audit.