As a member of the Information Security team, the IS GRC Risk & Compliance Senior Analyst will support the firm's Governance, Risk, and Compliance (GRC) program by managing security risks, maintaining the risk register, conducting risk assessments, coordinating control testing, and supporting audit activities. The role partners closely with IT leadership, business stakeholders, and third-party vendors to ensure security and compliance objectives are achieved.
Key Responsibilities
Security Risk Management
Support the CISO with annual and periodic security risk assessments.
Manage and maintain the enterprise risk register.
Conduct security risk assessments and evaluate risk and control effectiveness.
Track remediation activities through closure and report status to leadership.
Interview SMEs and gather information for risk assessments.
Develop and support risk mitigation strategies with cross-functional teams.
Conduct third-party security risk assessments, including review of:
Security questionnaires
Supporting documentation
Independent audit reports
Identify vendor security gaps, assign risk ratings, and recommend mitigations.
Control Framework & Compliance Testing
Design, execute, and monitor security control testing.
Ensure compliance with contractual, regulatory, and internal security requirements.
Partner with IT and business control owners.
Prepare audit evidence and documentation for internal and external audits.
Report metrics and compliance status to the IS GRC Manager, Director, and CISO.
Improve and automate GRC processes where possible.
Perform additional responsibilities as assigned.
Required Qualifications
Bachelor's degree in Information Technology or a related field (or equivalent experience).
3+ years of professional experience.
Experience in one or more of the following:
Information Security
Governance, Risk & Compliance (GRC)
IT Risk
Information Technology
Audit
Experience with security frameworks or regulations such as:
ISO 27001
SOC 2
PCI DSS
HIPAA
Other global security/compliance standards
Strong experience in:
Risk assessments
Risk registers
Control testing
Security compliance
Third-party/vendor risk management
Excellent analytical, communication, and documentation skills.
Experience with Microsoft Office Suite.
ServiceNow experience is preferred.
Preferred Certifications
CISSP (Preferred)
CISA (Preferred)
CRISC (Nice to have)
Willingness to pursue security certifications is highly valued.
Additional Information
Core business hours: 8:30 AM 5:30 PM (Monday Friday).
Occasional work outside standard business hours may be required.
Hybrid work schedule:
Onsite: Tuesday, Wednesday & Thursday
Remote: Monday & Friday
No relocation assistance or benefits are provided for this contract position.