Senior GRC Analyst
Core
Senior GRC Analyst shaping enterprise governance, risk, and compliance programs, acting as a trusted advisor to leadership and cross-functional stakeholders to ensure the organization's risk posture aligns with evolving regulatory and threat landscapes.
Role type
Senior IC GRC Analyst
Builds
Enterprise risk registers, control libraries aligned to frameworks (NIST CSF, ISO 27001, SOC 2, GDPR), GRC platform processes, and audit evidence packages.
Domain
Information Security / Regulatory Compliance
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
GRC program ownership, risk assessment and scoring, policy development and exception management, audit engagement coordination, control testing and gap analysis, third-party vendor risk management, regulatory impact assessment, GRC platform administration, security questionnaire response, incident response compliance.
Preferred skills
Cloud security frameworks (AWS, Azure, GCP), data privacy regulations (GDPR, CCPA), AI laws and regulations experience.
Technologies
Archer, Vanta, Drata, ServiceNow GRC
Responsibilities
Develop and maintain security policies and procedures; own and maintain the enterprise risk register; map and maintain control libraries for NIST CSF, ISO 27001, SOC 2, and GDPR; coordinate internal and external audit engagements; administer the GRC platform; lead responses to customer security questionnaires and due diligence requests; serve as the primary GRC point of contact for IT, Legal, HR, and Finance teams.
Seniority
Senior, hands-on IC
