Назад
Company hidden
2 дня назад

Senior Risk and Compliance Analyst (IT GRC)

96 700 - 148 100$
Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
US
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Risk and Compliance Analyst (IT GRC): Advancing IT risk, compliance, and third-party risk management programs through vendor assessments, due diligence, monitoring, remediation, and risk reporting with an accent on information security governance and regulatory frameworks. Focus on assessing residual risk from security evidence, maintaining risk registers and KRIs/KPIs, and automating GRC workflows.

Location: Rochester, New York, with additional locations in Chicago, Illinois, and San Antonio, Texas. The primary work environment is a professional corporate office, with occasional commercial and international travel.

Salary: $96,700–$148,100 per year.

Company

hirify.global operates an enterprise IT organization supported by governance, risk, compliance, information security, procurement, legal, and business functions.

What you will do

  • Advise IT and business stakeholders on IT governance, risk, and compliance initiatives.
  • Lead and enhance the IT third-party risk management program across vendor onboarding, assessments, monitoring, remediation, and offboarding.
  • Review SOC reports, ISO certifications, security questionnaires, policies, and other third-party security evidence to assess control maturity and residual risk.
  • Partner with Information Security, the SOC, IT, Procurement, Legal, and business teams to evaluate vendors, applications, services, threats, and supply-chain risks.
  • Support risk intake, risk-register maintenance, escalation, internal risk assessments, and compliance activities.
  • Develop security metrics, dashboards, KRIs, KPIs, and automated workflows to improve GRC efficiency and reporting.

Requirements

  • At least 4 years of experience in information security, risk management, audit, IT governance, IT compliance, or a related discipline.
  • Experience leading and maturing an IT third-party risk management program across the vendor lifecycle.
  • Generalist knowledge of information security risk, audit, policy, and third-party risk management.
  • Working knowledge of NIST, ISO, CIS, PCI-DSS, SOX, GDPR, CCPA, and HIPAA frameworks and regulations.
  • Ability to analyze manual processes and implement technical solutions, with strong ownership and self-direction.
  • Work is based at a professional corporate office in the listed US locations; ability to travel commercially and internationally is required.

Nice to have

  • Bachelor’s degree in business administration, compliance, information systems, privacy, or a related field.
  • CRISC, CISSP, CISA, CISM, CGEIT, GCCC, GSEC, or GISP certification.
  • Experience with LogicGate, Optro, OneTrust, Workiva, or other GRC platforms.
  • Strong written and verbal communication skills for presenting complex risk and compliance topics.
  • Proficiency in Microsoft Excel, Word, and PowerPoint.

Culture & Benefits

  • Collaboration across IT, Information Security, Procurement, Legal, OT, and business functions.
  • Professional corporate office environment with extended desk and computer work.
  • Comprehensive benefits package for eligible employees.
  • Paid time off and medical, dental, and vision insurance.
  • 401(k) and other eligible employee benefits.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →