Job Title
GRC Analyst PostingPosition Overview
GRC(GovernanceRisk Compliance)Analyst
The GRC Analyst will collaborate withsecurity and risk managementprocess owners internal auditors external auditors and other stakeholdersto assistin reviewing monitoring and resolving findingsandIT related vulnerabilitiesand risks. This includes helping theteam withthe NIST Cybersecurity Frameworkand SOC 2 Compliance programs. By supporting the implementation of internal and external assessments responding toand managing the full lifecycle of compliance audits and ensuring compliance with existing and emerging regulations andstandardsand other GRC activities the GRC Analyst will also contribute to the transformation of the companys IT compliance program.
Responsibilities:
Manage annual IT testing for internal and external audits risk assessments and regulatory legal and policycompliance
Lead preparation for annual IT testingactivities
Working with Communications teams ondisseminationof compliance policies
Technical writing and documentation of security and risk controls
Conduct IT Compliance training sessions to prepare for ITassessments
Collaborate with leadership on compliance-related concerns and present findings and suggestions tothem
Ensure prompt turnarounds by supporting internal and external auditrequests
Inform others about IT issues and shortcomings to ensure that remedial action plans are inplace
Make suggestions for repeatable quantifiable and long-lasting remediation programs and follow up on action plans until they arecompleted
Develop IT documentation for IT internal controls in consultation with IT including IT process narratives process flows and documented controlactions
Establish and sustain governance tools for risk and compliance to support IT complianceactivities
Ensure compliance with the IT frameworks by helping IT control owners implement and validatecontrols for the processes of access management release management change management and vendormanagement
Collaborate with ITstakeholderson how to efficiently adhere to IT standards and proactively reduce risksandvulnerabilities
Position Requirements:
BachelorsDegree orequivalentwork experience such as fiveyears experiencein audit security or risk managementrelated position in $100M companies.
Exceptional written andverbalcommunication skills.
Strong knowledge of andexperienceusingServiceNowor other CMDB.
Experience usingTenable and Microsoft Defender or otherequivalentvulnerability management tools.
Strong knowledge of andexperienceusingMicrosoft Purviewor other IT assetand datacompliance tools.
Strong analytical skills with the ability to collect organizeanalyzeand disseminatesignificant amounts of information with attention to detail and accuracy.
Adept atdataqueries report writing and presenting findings.
Team player and the ability to work with minimal supervision.
Competencies:
Execute Action Plan
Demonstrate Good Judgement
Innovate
Deliver Compelling Communication
LearnContinuously
Work Shift
8 Hr non-rotating shift Hrs fall to in punch day Observed Calendar shift starts AMRequired Experience:
IC
We are approximately 20,000 individuals bound together by a common vision to create a better future, for our customers, for our company, for our people, and for our communities. By combining deep market knowledge with new ways of thinking, we drive innovation into our business and set ... View more