2 дня назад
Senior Risk and Compliance Analyst (IT GRC)
96 700 - 148 100$
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Risk and Compliance Analyst (IT GRC): Advancing IT risk, compliance, and third-party risk management programs through vendor assessments, due diligence, monitoring, remediation, and risk reporting with an accent on information security governance and regulatory frameworks. Focus on assessing residual risk from security evidence, maintaining risk registers and KRIs/KPIs, and automating GRC workflows.
Location: Rochester, New York, with additional locations in Chicago, Illinois, and San Antonio, Texas. The primary work environment is a professional corporate office, with occasional commercial and international travel.
Salary: $96,700–$148,100 per year.
Company
operates an enterprise IT organization supported by governance, risk, compliance, information security, procurement, legal, and business functions.
What you will do
- Advise IT and business stakeholders on IT governance, risk, and compliance initiatives.
- Lead and enhance the IT third-party risk management program across vendor onboarding, assessments, monitoring, remediation, and offboarding.
- Review SOC reports, ISO certifications, security questionnaires, policies, and other third-party security evidence to assess control maturity and residual risk.
- Partner with Information Security, the SOC, IT, Procurement, Legal, and business teams to evaluate vendors, applications, services, threats, and supply-chain risks.
- Support risk intake, risk-register maintenance, escalation, internal risk assessments, and compliance activities.
- Develop security metrics, dashboards, KRIs, KPIs, and automated workflows to improve GRC efficiency and reporting.
Requirements
- At least 4 years of experience in information security, risk management, audit, IT governance, IT compliance, or a related discipline.
- Experience leading and maturing an IT third-party risk management program across the vendor lifecycle.
- Generalist knowledge of information security risk, audit, policy, and third-party risk management.
- Working knowledge of NIST, ISO, CIS, PCI-DSS, SOX, GDPR, CCPA, and HIPAA frameworks and regulations.
- Ability to analyze manual processes and implement technical solutions, with strong ownership and self-direction.
- Work is based at a professional corporate office in the listed US locations; ability to travel commercially and internationally is required.
Nice to have
- Bachelor’s degree in business administration, compliance, information systems, privacy, or a related field.
- CRISC, CISSP, CISA, CISM, CGEIT, GCCC, GSEC, or GISP certification.
- Experience with LogicGate, Optro, OneTrust, Workiva, or other GRC platforms.
- Strong written and verbal communication skills for presenting complex risk and compliance topics.
- Proficiency in Microsoft Excel, Word, and PowerPoint.
Culture & Benefits
- Collaboration across IT, Information Security, Procurement, Legal, OT, and business functions.
- Professional corporate office environment with extended desk and computer work.
- Comprehensive benefits package for eligible employees.
- Paid time off and medical, dental, and vision insurance.
- 401(k) and other eligible employee benefits.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
1 день назад
Sr Manager, InfoSec Governance Risk and Compliance (GRC)
112 000 - 208 000$
1 день назад
Senior IT GRC Analyst (Governance, Risk, and Compliance)
131 000 - 131 000$
3 дня назад
Technology Risk & Compliance Analyst (Cybersecurity)
85 000 - 105 000$
7 дней назад
GRC/IT Compliance Analyst
108 000 - 130 000$
2 дня назад
Analyst, IT Compliance and Governance (Cybersecurity)
114 400 - 131 000$
Plaid
1 день назад
Security Analyst, Third-Party Ecosystem Risk Management
119 000 - 176 000$