Governance, Risk and Compliance Analyst
Core
Manage third-party and vendor security risk to strengthen the organization's cyber security, risk, and compliance capabilities.
Role type
GRC Analyst (Third-Party Risk Focus)
Builds
Vendor risk registers, security assessments, and compliance reports for the supplier ecosystem.
Domain
Non-profit sector / Information Security / Third-Party Risk Management
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
GRC experience, third-party risk management, stakeholder engagement, risk-based assessment, compliance monitoring
Preferred skills
ISO 27001 framework experience, CISA or CRISC certification
Technologies
AI and automation tools for assessments and reporting
Responsibilities
Perform security assessments for vendors using a risk-based approach; Maintain and uplift the third-party risk register and processes; Partner with procurement, legal, and business teams to embed security practices; Support risk management processes and compliance activities including ISO audits; Contribute to control assurance and governance practices.
Seniority
Mid-level (3+ years experience)