Senior GRC Analyst
Gilder Search Group
The Role We Want You For Under the direction of and in collaboration with the GRC Manager, the Sr. GRC Analyst, Third-Party & Human Risk Management (TPHRM) is a risk focused, highly analytical role that ensures all human and third‑party risk to Clayco is identified, quantified, documented, and treated to an acceptable level across the Clayco organization. This role will assume ownership of the Third-Party Risk Management (TPRM) process to gather details on the security practices and compliance levels for each third‑party being considered or contracted for a solution or services to assess the potential for compromise due to a control gap or exploitable misconfiguration as well as non‑compliance with legal and regulatory requirements. Additional contribution will be expected for internal assessments and third‑party audits to gather and submit discovery and transactional responses and artifacts. The Sr. GRC Analyst will also assume ownership of Human Risk Management (HRM) including the delivery of comprehensive security awareness education, the end‑to‑end execution of phishing simulation programs, and the technical maintenance and life‑cycle management of security awareness platforms. Beyond simple training, the position focuses on Human Risk Management (HRM), using data‑driven insights to identify high‑risk user groups and implementing targeted interventions to proactively mitigate human‑centric threats to cultivate a security‑first culture internally through education and behavioral change. Additional responsibilities will be assigned as deemed necessary. Any travel is usually planned in advance, but issues may arise which warrant immediate travel to one or more satellite locations. The Specifics of the Role Assumes operational ownership of the 3rd Party Vendor Risk Management program identifying, assessing, and mitigating risks associated with external vendors, suppliers, and service providers Conducts due diligence on new and existing vendors by reviewing security questionnaires, SOC reports, compliance certifications, and other supporting attestations Captures, analyzes, and recommends treatment, assignment, and tracking of identified issues Collaborates with legal and stakeholder teams to ensure contracts include specific clauses for data protection, service‑level agreements (SLAs), and AI governance Documents and communicates all relevant findings and recommendations to stakeholders Tracks, monitors, and reports on execution of remediation action plans and escalates inadequate responses or progress Assumes ownership of the Security Awareness program determining appropriate topics, themes, scopes, and timing of cyber awareness communications, events, and content delivery Conducts regular, simulated social engineering exercises to assess and improve employee recognition of real‑world attacks Develops engaging, simple materials—such as infographics, newsletters, and videos that translate complex technical risks into layman’s terms Maintains Security Awareness training and simulation platforms to support content delivery and End User interaction, including support for any Client‑side functionality (i.e., "Report Phish" button) Plans, coordinates, and executes activities for Cybersecurity month Partners with Employee Relations, Legal, and Marketing to ensure security messaging is integrated into the broader corporate culture Tracks Key Risk Indicators (KRI's) such as actual phishing click-through rates, failed simulations, and missed training as well as Key Performance Indicators (KPIs) like suspicious email reporting, passed simulations, and successful training completion status to measure program effectiveness for leadership Requirements 6‑8+ years’ experience in Risk & Compliance Assessment, Audit & Reporting, or similar functions, preferably within the Information Security or Technology fields 3‑4+ years working specifically in Information Security roles involving Risk Analysis, Information System Security Assessment, and/or Security Awareness and Human Risk Management Bachelor’s degree in Information Technology or related field, or equivalent experience Required Certifications: Certified in Risk & Information Systems Control (CRISC), SANS Security Awareness Professional (SSAP), and Certified Third‑party Risk Professional Certification (CTPRP) (Current status, or obtained within 9 months of assuming role) Strong experience leveraging auditing principles and methods to evaluate policies, processes, systems, and vendors to identify business risks and control gaps Strong knowledge of Regulations, Frameworks, and Standards such as NIST 800-171/CSF/RMF, ISO27001, CIS Critical Security Controls, etc. Strong, technical knowledge of modern Systems, Services, Cloud Applications/Platforms, Identity Services, and Data Storage/Handling and their areas of Risk and Threat exposure Experience with administering, maintaining, and leveraging a Risk Register to track and communicate identified Risk and its required remediation Knowledge of statistics, reporting and analytical tools to analyze and solve complex problems Proficiency in necessary productivity tools (i.e., Microsoft Excel, PowerPoint, Word etc.) for analytics and presentations Operate with strong integrity with ability to manage projects of a confidential nature Ability to translate technical or abstract concepts into a narrative that is easily understood Ability to thrive in fast‑paced environment. Some Things You Should Know This position is classified as a safety‑sensitive role in accordance with applicable state and federal laws. Candidates selected for this position will be subject to a comprehensive background check, which includes mandatory drug testing. Benefits Discretionary Annual Bonus: Subject to company and individual performance. Comprehensive Benefits Package Including: Medical, dental and vision plans, 401k, generous PTO and paid company holidays, employee assistance program, flexible spending accounts, life insurance, disability coverage, learning & development programs and more! Compensation The salary range for this position considers a wide range of factors in making compensation decisions including but not limited to: Education, qualifications, skills, training, experience, certifications, internal equity, and location. Compensation decisions are dependent on the facts and circumstances of each case. #J-18808-Ljbffr
- Gilder Search Group is looking for a Sr. GRC Analyst focused on Third-Party & Human Risk Management in St. Louis, Missouri. The role ensures all human and third-party risks to Clayco are identified and treated appropriately. Key responsibilities include owning the TPRM...Senior
- Sky Mavis is seeking a Senior GRC Analyst focused on Third-Party and Human Risk Management in St. Louis, Missouri. This role requires 6-8+ years of experience in Risk Assessment and Information Security, with strong analytical skills. You will lead the Vendor Risk Management...Senior
- ...Governance, Risk & Compliance (GRC) Analyst Job Category : Information Technology Requisition Number : GOVER001449 Posted : July 1, 2026 Full-Time Hybrid Locations Showing 1 location Join our team as a GRC Analyst and play a key role in regulatory compliance, IT risk...SuggestedFull timeCasual workWork at officeWork from homeHome officeNight shiftWeekend work
- Delta-Denta is seeking a Governance, Risk & Compliance Analyst to help ensure client and regulatory requirements are met while identifying and managing IT risks. You will collaborate across Legal, Privacy, and Compliance, support audits, and drive policy development aligned...Suggested
- Technology Partners, Inc. is seeking a Senior Analyst to support Oracle RMCS, access controls, and risk management. You will work with Finance, Internal Audit, Compliance, Security, and ERP teams to ensure compliant access management and effective risk mitigation. The...SeniorFull timeContract work
- Affirm is a remote-first fintech company reimagining consumer credit. As a Senior Analyst (L5) you will own the entire analytical lifecycle, from framing questions to delivering data-driven decisions that influence risk, product, and growth. You will collaborate with ML...SeniorRemote job
- ...MANTECH seeks a motivated, career and customer-oriented Senior GEOINT Analyst to join our team in St. Louis, MO! Job duties include, but are not limited to: Conduct GEOINT analysis on national security issues using imagery, geospatial data, and multi-INT...SeniorWork at officeRemote work
- Strategic Staffing Solutions in St. Louis, MO is seeking a Senior Business Analyst to support Oracle RMCS, risk management processes and SoD controls in a remote-capable contract role. The analyst will work with Finance, Internal Audit, Compliance, Security, and ERP teams...SeniorContract workRemote work
- apturagroup is seeking an Accounts Receivable Manager to oversee billing and collections, enforce credit policies, and collaborate with internal departments to resolve outstanding balances. The role requires leadership of AR staff, handling AIA billing processes, and ensuring...Senior
- ...BJC Medical Group is hiring a Senior Compliance Coordinator in St. Louis, MO. This remote position involves reviewing specialty provider documentation for billing accuracy and developing educational materials. The ideal candidate will have 5-10 years of experience, a...SeniorRemote work
$85k - $115k
Senior Third Party Risk Analyst (St Louis - In Office) This range is provided by Bruin. Your actual pay will be based on your skills and experience — talk with your recruiter to learn more. Base pay range $85,000.00/yr - $115,000.00/yr Direct message the job poster from...SeniorFull timeContract workWork experience placementWork at officeRelocation- Spectrum Brands, Inc in St. Louis, MO is seeking a Senior Regulatory Affairs Specialist to drive product compliance and innovation for pet care products. This hybrid position involves collaboration with various teams to manage regulatory risks and ensure successful product...Senior
- This job posting is anticipated to remain open for 30 days, from 27-Jul-2026. The posting may close early due to the volume of applicants. Join a financial services firm where your contributions are valued. Edward Jones is a Fortune 500 1 company where people come first...SeniorTemporary workWork experience placementWork at officeHome officeFlexible hours3 days per week
- Bank of America is seeking a Financial Analysis & Monitoring Specialist to support underwriting and ongoing monitoring for new and existing clients. The role focuses on preparing financial statement spreads, risk ratings, and qualitative analysis to support credit decisions...Senior
- Bank of America is seeking a Financial Analysis & Monitoring Specialist to support underwriting and ongoing monitoring for new and existing clients. You will analyze financial statements, projections, and collateral, using multiple tools to prepare and review underwriting...Senior
- The Doe Run Company, based in St. Louis, MO, is seeking a Sr Benefits Analyst to administer benefit communications, eligibility, reporting, billing, and compliance across medical, dental, vision, life, disability, and retirement plans. This role works from our corporate...SeniorWork at office
$91k - $121k
Job Overview: The Senior Compensation Analyst is a strategic advisor responsible for designing, implementing, and managing compensation programs that align with the organization’s business objectives, talent strategy, and market competitiveness. This role partners closely...SeniorTemporary workLocal areaRelocationRelocation package- Core & Main LP is seeking an experienced Internal Controls & Audit professional to plan and execute audits across people, process, and technology areas. You will identify control gaps and opportunities for improvements, and present actionable recommendations to leadership...Senior
$91k - $121k
Job Overview: The Senior Incentive Analyst is a hands-on role that will play a key part in managing and supporting ongoing incentive compensation needs. This individual will focus on the analysis, evaluation, creation, and implementation of compensation programs designed...SeniorTemporary workRelocationRelocation package- 3M HEALTHCARE is seeking an experienced Trade Compliance leader to govern and improve import/export programs for U.S. and Canadian businesses. The role focuses on policy, standards, training, and audit support, serving as the primary corporate contact for business compliance...Senior
- Refresco Beverages US Inc. seeks a Manager of Quality to lead the site quality department, drive food safety and quality programs, and ensure regulatory compliance. The role emphasizes GMP, HACCP, SQF, and cross‑functional collaboration with production and lab teams. You...Senior
- Ramboll Group A/S in St. Louis, MO seeks a Managing Consultant or Senior Managing Consultant to lead air quality projects within the Environment & Health Division. You will oversee consultant staff, interpret regulations, and prepare permit applications and reports for...Senior
- Consigli Construction Co., Inc. is looking for a Quality Control Manager in St. Louis, Missouri. The QCM will implement and manage the QC Program throughout project lifecycles, collaborating closely with the project team. This role requires strong communication skills, ...Senior
- GreenGas is looking for a Contract Manager to oversee contract lifecycle management. This role involves managing contracts from initiation through execution, ensuring compliance, and improving contract processes. The ideal candidate will have a Bachelor's degree and over...SeniorContract workWork at office
- Assured Consulting Solutions seeks a Senior Enterprise Schedule Analyst to lead schedule development for NGA and Mission Partners. You will collaborate with systems engineers and program managers to create integrated schedules, review data, and provide comprehensive visualization...Senior
- MANTECH is seeking a Senior GEOINT Analyst for its St. Louis, MO team. The role focuses on GEOINT analysis across national security issues, using imagery and multi-INT data to identify trends and support decision makers. The ideal candidate has 6+ years of GEOINT experience...Senior
- ...strong command of actuarial methods. Typical duties include projecting fee-for-service claims, reporting variances against budget, and supporting actuarial opinions and audits. Salary ranges and incentives reflect the senior scope and market in St. #J-18808-Ljbffr MedicaSenior
- Meaden & Moore, a leading accounting and advisory firm in St. Louis, seeks a Staff or Senior Forensic Accountant. You will analyze financial data, perform loss and damage assessments, and support insurance claim evaluations for commercial clients. 1-5 years public accounting...Senior
- Safety National, based in Saint Louis, MO, is seeking a Senior HR Total Rewards Analyst to strengthen retirement plan administration and governance within our Total Rewards program. You will partner with trustees, vendors, and internal stakeholders to ensure compliant,...SeniorWork at office
- St. Louis Public Schools seeks a Director of Accounting to oversee the district's financial operations, maintain GAAP-compliant records, and lead the accounting staff. The role requires strategic oversight of accounts, audits, and reporting to the CFO. The ideal candidate...Senior
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior GRC Analyst. Be the first to apply!
- senior network engineer remote Saint Louis, MO
- senior app developer Saint Louis, MO
- senior manager legal Saint Louis, MO
- sr project manager Saint Louis, MO
- senior account executive Saint Louis, MO
- senior staff systems engineer Saint Louis, MO
- senior commercial counsel Saint Louis, MO
- senior data manager Saint Louis, MO
- senior manager tax Saint Louis, MO
- senior construction accountant Saint Louis, MO


