Associate GRC Analyst
IT
Richmond, VA, USA
USD 75k-101k / year + Equity
Job Description
Overview
CoStar Group (NASDAQ: CSGP) is a leading global provider of commercial and residential real estate information, analytics, and online marketplaces. Included in the S&P 500 Index, CoStar Group is on a mission to digitize the world’s real estate, empowering all people to discover properties, insights and connections that improve their businesses and lives.
We have been living and breathing the world of real estate information and online marketplaces for over 35 years, giving us the perspective to create truly unique and valuable offerings to our customers. We’ve continually refined, transformed and perfected our approach to our business, creating a language that has become standard in our industry, for our customers, and even our competitors. We continue that effort today and are always working to improve and drive innovation. This is how we deliver for our customers, our employees, and investors. By equipping the brightest minds with the best resources available, we provide an invaluable edge in real estate.
We are seeking an Associate GRC Analyst to help evolve and grow CoStar’s cybersecurity and information technology governance program. As an Associate on the CoStar Group IT Governance, Risk, and Compliance Team, you will learn and assist in day-to-day governance operations, and progress toward developing ownership and establishing expertise in areas of GRC engagement. You will work alongside and under the guidance of experienced team members, supporting functions such as our third-party risk and compliance programs, security awareness and marketing initiatives, audit and assurance support, and controls governance. In the course of your work, you will collaborate with stakeholders across Cybersecurity, Information Technology Operations, Product & Development, Human Resources, Finance, and Sales.
This position is located in Richmond, VA and is in office Monday through Thursday and work from home on Friday.
Responsibilities
- Perform routine governance operations such as periodic user access reviews, triage of anomalous control alerts, and audit support.
- Support third-party risk assessments for new and existing vendors — distributing and reviewing security questionnaires and performing initial reviews of SOC reports or equivalent control attestations.
- Draft clear, well-organized written summaries of assessments, risk findings and recommendations for both technical and non-technical audiences.
- Help maintain our GRC tooling and records — keeping vendor inventories, assessment trackers, and supporting documentation current, organized, and audit-ready.
- Contribute to security-awareness efforts across the company, generating bespoke and culture-relevant information security awareness materials and communications that help build and reinforce a healthy security culture.
- Arrive ready to learn, grow, and develop your career within Cybersecurity, adopting a continuous learning mindset.
Basic Qualifications
- Bachelor’s Degree required from an accredited, not for profit, in person, university or college.
- A track record of commitment to prior employers
- 1–3 years of experience in an adjacent field such as IT, audit, compliance, information security, or a related analytical or operational role.
- A genuine and demonstrated curiosity about technology and cybersecurity, paired with the self-motivation to take on unfamiliar challenges and see them through.
- Excellent written communication with meticulous attention to detail — you take pride in accurate, well-organized, polished work.
- Familiarity with core security concepts — for example, least privilege, defense in depth, the CIA triad (confidentiality, integrity, and availability), authentication versus authorization, encryption in transit and at rest, and common attack types such as phishing and social engineering.
- Strong organizational and time-management skills, with the ability to track many moving pieces without dropping detail.
- A collaborative, approachable style and a willingness to engage with people across the business.
Preferred Qualifications and Skills
- Excellent verbal communication and presentation skills, with a proven track record of communicating clearly to diverse audiences, including both non-technical and highly technical stakeholders.
- Entry-level certifications, or demonstrable progress toward them, such as CompTIA Security+ or ISC2 Certified in Cybersecurity (CC).
- Experience in a service-oriented technology role, such as an IT help desk or technical customer support function.
- Exposure to ticketing and workflow tools.
- Experience in developing automation – whether it is through standard scripting languages such as Python, PowerShell, or through applications such as Power Automate.
- Experience reading or summarizing SOC reports, security questionnaires (SIG, CSA CAIQ), or other vendor documentation.
- Hands-on experience applying AI to accomplish real work — for example, building or orchestrating agentic workflows, automating multi-step tasks, or integrating AI tools into business processes — rather than using AI as a substitute for a search engine.
What’s in it for You
When you join CoStar Group, you’ll experience a collaborative and innovative culture working alongside the best and brightest to empower our people and customers to succeed.
We offer you generous compensation and performance-based incentives. CoStar Group also invests in your professional and academic growth with internal training, and tuition reimbursement.
Our benefits package includes (but is not limited to):
- Comprehensive healthcare coverage: Medical / Vision / Dental / Prescription Drug
- Life, legal, and supplementary insurance
- Virtual and in person mental health counseling services for individuals and family
- Commuter and parking benefits
- 401(K) retirement plan with matching contributions
- Employee stock purchase plan
- Paid time off
- Tuition reimbursement
- On-site fitness center and/or reimbursed fitness center membership costs (location dependent)
- Access to CoStar Group’s Employee Resource Groups
- Complimentary gourmet coffee, tea, hot chocolate, fresh fruit, and other healthy snacks
The final salary or hourly rate offered for this role will fall within the range set forth below based on a variety of factors, including but not limited to, geographic location, skills, and competencies.
Base Compensation: $75,000 – $101,000 Annually
We welcome all qualified candidates who are currently eligible to work full-time in the United States to apply. However, please note that CoStar Group is not able to provide visa sponsorship for this position.
#LI-AR
CoStar Group is an Equal Employment Opportunity Employer; we maintain a drug-free workplace and perform pre-employment substance abuse testing