TheGovernance Risk and Compliance (GRC)Analyst supports theUWby contributing to the identification assessment and management of enterprise IT risk across universities and shared services. The GRC AnalystassistswithIT risk assessmentsmaintainsand supports centralized risk management tools and risk registers and develops clear documentation and reports to support informed IT risk decision-making. The role also supports the development and revision of information security policies and standards aligns program activities with recognized frameworks andassistswith audit andassessmentcoordination and follow-up.
This position emphasizes continuous improvement of IT risk management practices including the integration of emerging technology risks such as artificial intelligence and cloud services and ongoing professional development aligned with GRC and enterprise IT risk management responsibilities.
Enterprise IT Risk Management
Contribute to the continuous improvement of UWs IT risk management program by developing standardized processes workflows templates and guidance.
Identify assess document and monitor IT risks affecting universities and shared services.
Assist in the technical rollout and ongoing support of enterprise IT risk management tools.
Assist in developing program reports metrics and summaries
Third-Party IT Risk Management
Conduct IT risk assessments of third-party vendors services and technology solutions.
Develop written assessment reports to support informed IT risk decision making.
Integrate emerging technology risks including artificial intelligence and data privacy considerations into third-party IT risk reviews.
Policy and Audit Support
Assist in the creation and revision of enterprise information security policies standards and guidance.
Align policies and standards with National Institute of Standards and Technology (NIST) Frameworks.
Assist with coordinating internal and external risk assessments
Track assessment and audit findings and support remediation efforts
Analyze assessment audit and survey data to identify trends and opportunities for targeted improvements.
Professional Development
Stay informed of emerging technologies and evolving IT and cybersecurity risks.
Continuously develop skills through training and professional development opportunities aligned with enterprise IT risk management and GRC practices
Theworking titleisafull-timeexemptacademicstaffposition.
Well-qualified candidates can expect a starting annual salary withina rangeof$85000- $95000commensuratewith the candidates education related experience and qualifications.
Experience in information security IT risk management and/or third-party IT risk management.
Experience assessing and documenting risk related to IT systems applications or third-party technology solutions.
Working knowledge of IT and cybersecurity risk frameworks and assessment practices.
Experience communicating risk assessment results through written reports or documentation.
Experience working in a collaborative cross-functional or distributed environment.
Preferred Qualifications:
Bachelors degree in a related field.
Strong analytical organizational and problem-solving skills.
Experience conductingITriskassessments
Experience supporting IT audits or complianceefforts.
Hands-on experience operationalizing GRCtools(e.g.OneTrust ServiceNow)
Experience in higher education
Experience assessing IT risk related to emerging technologies such as artificial intelligence cloud services or data-driven platforms.
Familiarity with applicable standards and regulatory requirements (e.g. NIST CSF NIST SP 800-171 FERPA GLBA HIPAA).
Professional certification (e.g. CISSP CGRC CRISC) or willingness to pursue one.
The office location is in Madison WI.Telecommuting or hybrid work options may be available. Preference will be given to candidates thatresidewithin the State of Wisconsin and Madison metropolitanarea.
Applicant screening will beginimmediatelyand be ongoingthrough 11:59pmFebruary 27 2026. However applications may be accepted until the positionhas beenfilled.
To receive full consideration interested applicantsare required toapply online and provide a Resume (PDF Format) and Cover letter addressing your experience and education as it applies to all minimum and preferred qualifications (PDF Format).
Failing tosubmittherequired applicationdocuments may disqualify yourapplication.
Questions may be addressed to: Kristina Williston HR Generalistat
If you need to request an accommodation because of a disability you can find information about how to make a request by contacting .
This offer of employment is conditional pending the results of a criminal background check and a reference check process that includes questions regarding employee misconduct sexual violence and sexual harassment. If you have prior work history within the past 7 years with the Universities of Wisconsin your personnel file will also be reviewed for employee misconduct. If the results are unacceptable the offer will be withdrawn or if you have started employment your employment will be terminated.
Please note that successful applicants are responsible for ensuring their eligibility to work in the United States (i.e. a citizen or national of the United States a lawful permanent resident a foreign national authorized to work in the United States without the need of employer sponsorship) on before or after the effective date of appointment.
The Universities of Wisconsin will not reveal the identities of applicants who request confidentiality in writing except that the identity of the successful candidate will be released. See Wis. Stat. . 19.36(7).
Universities of Wisconsin employees receive an excellent benefits package. To learn more about the benefits package review the Faculty Academic Staff & Limited Appointees or University Staff Please see this link for total compensation information: Universities of Wisconsin Health & Retirement Contributions Estimator to provide you with total compensation information.
The Universities of Wisconsin provides statistics on campus crime in its Annual Security Report. For more information on university campus statistics see is an Equal Opportunity Employer Qualified applicants will receive consideration for employment without regard to race color religion sex sexual orientation gender identity national origin age pregnancy disability status as a protected veteran or any other bases protected by applicable federal or State law and UW System policies. We are committed to building a workforce that represents a variety of backgrounds perspectives and skills and encourage all qualified individuals to apply.
Required Experience:
IC