Governance Risk & Compliance Analyst
System One Holdings, LLC
Governance Risk & Compliance Analyst
System One is seeking a GRC Analyst for an opportunity in Lakewood, CO. The GRC Analyst is a member of the Governance, Risk & Compliance function within the Global Information Security Office and supports the implementation of company wide security governance, risk management, and compliance programs. Under the direction of the GRC Functional Leader, the analyst contributes to policy development, risk oversight, and continuous improvement of the organization's security posture. The role also works closely with regional Information Security Officers (ISOs) and cross-functional teams to support the deployment of global standards and local regulatory requirements.
Responsibilities include:
- Support information security risk assessments for new projects, systems, and business processes.
- Assist in conducting internal control reviews (e.g., JSOX), preparing audit materials, and coordinating responses to internal and external auditors.
- Track and follow up on remediation actions to ensure timely closure of identified risks.
- Contribute to drafting, updating, and maintaining global information security policies, standards, and procedures.
- Review relevant laws, regulations, and industry frameworks (e.g., ISO 27001, NIS2) and incorporate stakeholder feedback into documentation.
- Support the rollout and implementation of policies across regions.
- Monitor adherence to security and regulatory requirements, including ISO 27001, NIS2, and GDPR.
- Collect and organize compliance evidence, track corrective actions, and support certification and regulatory readiness efforts such as ISO 27001/42001 and NIS2 programs.
- Conduct third party security risk assessments by distributing questionnaires, analyzing responses, verifying controls, and documenting results in the GRC tracking systems.
- Identify and escalate high risk findings to the GRC Functional Leader and support follow up mitigation activities.
- Participate in the planning and implementation of security awareness programs for all associates.
- Create e-learning materials and training materials, conduct phishing email exercises, and distribute disseminated content on internal portals.
- Monitor and analyze global regulatory developments related to cybersecurity with a focus on industrial control systems (ICS), IT environments, and critical infrastructure.
- Assist in evaluating how new or updated regulations (e.g., NIS2, FDA cybersecurity expectations, industrial cybersecurity standards, or country specific critical infrastructure laws) impact company operations.
- Track emerging obligations, document requirements, and support gap assessments to ensure timely compliance.
- Assist in the preparation, maintenance, and continuous improvement of the CISO Dashboard by collecting, validating, and analyzing security metrics across the Global GRC function.
- Compile key performance indicators (KPIs) and key risk indicators (KRIs) related to compliance status, audit findings, supplier risk, incident trends, training completion, regulatory readiness, and other relevant security domains.
- Support the visualization and communication of security posture to senior leadership by ensuring data accuracy, timely updates, and clarity in reporting.
- Support the development and enforcement of governance controls for the secure use of artificial intelligence technologies across the organization.
- Identify risks related to AI systems—such as model security, algorithmic integrity, and misuse—and contribute to risk assessments and mitigation plans.
- Help evaluate third party AI tools.
- Support the development and improvement of GRC processes, tools, and documentation to enhance operational efficiency and standardization.
- Assist in preparing reports, presentations, and materials for leadership reviews, steering committees, and cross functional meetings.
- Participate in internal security projects and initiatives, including process automation, metrics development, and enhancements to governance workflows.
- Provide coordination and administrative support for security committees, working groups, and regional GRC activities.
- Perform additional duties as assigned to support the Global Information Security Office and the broader GRC program.
Requirements include:
- 3 to 5+ years of experience in information security, governance, risk management, compliance, IT audit, or a related discipline.
- Experience supporting security programs in global or regulated environments is a plus.
- Understanding of global and regional information security regulations (e.g., data protection laws, cybersecurity requirements) and familiarity with security frameworks such as ISO 27001.
- Knowledge of internal control frameworks (e.g., JSOX) and IT governance practices is highly desirable.
- Experience supporting audit activities is preferred.
- Experience with risk assessment methodologies, control evaluation, and vulnerability or issue management processes.
- Strong analytical and problem-solving skills, with the ability to identify risks, assess impacts, and support the development and tracking of corrective actions.
- Ability to communicate security requirements, policies, and audit findings clearly and persuasively with stakeholders across regions and business units.
- Strong coordination skills to build consensus and drive compliance.
- Industry certifications such as CISSP, CISA, CISM, ISO 27001 Lead Implementer/Auditor, or similar are preferred but not required.
- Bachelor's degree in information security, Cybersecurity, Information Systems, Computer Science, or a related field; or equivalent professional experience.
- Familiarity with governance, risk, and compliance tools (e.g., BitSight, Drata, OneTrust, Archer, or similar) for managing risks, audits, and compliance workflows.
- Working knowledge of cybersecurity concepts such as identity and access management, endpoint protection, vulnerability management, cloud security, and secure system design.
- Experience supporting cross-functional security or compliance initiatives, including requirements gathering, documentation, and progress tracking.
- Ability to interpret risk metrics, compliance data, and audit results.
- Experience with dashboards, KPI/KRI reporting, or data visualization tools is a plus.
- Awareness of emerging cybersecurity regulations (e.g., NIS2, AI governance frameworks, critical infrastructure rules) and their potential impact on enterprise operations.
System One, and its subsidiaries including Joulé and Mountain Ltd., are leaders in delivering outsourced services and workforce solutions across North America. We help clients get work done more efficiently and economically, without compromising quality. System One not only serves as a valued partner for our clients, but we offer eligible employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan. System One is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, age, national origin, disability, family care or medical leave status, genetic information, veteran status, marital status, or any other characteristic protected by applicable federal, state, or local law.
- ...Governance, Risk & Compliance (GRC) Analyst (AI Training) About the Role We're partnering with the world's leading AI research labs to build smarter, safer AI - and we need practitioners who know how GRC actually works in the real world. If you've spent time...SuggestedHourly payOngoing contractContract workFreelanceRemote work10 hours per weekFlexible hours
- ...to expand our team across the board. York Space Systems is seeking a Cyber Risk & Compliance Specialist to support the execution and administration of the company's cybersecurity governance, risk, and compliance programs. This role will work closely with...SuggestedPermanent employmentWork at officeLocal areaWorldwide
$87k - $97k
...Reporting to the Sr Manager, AI Solutions & Delivery, the **AI Governance & Risk Analyst** will establish the policies, controls, risk assessments,... ...to build practical guardrails, evaluate AI risk, support compliance, and champion responsible AI practices. The ideal...SuggestedTemporary workWork at officeImmediate startRemote workFlexible hours- System One in Lakewood, CO is seeking a Governance Risk & Compliance Analyst to join their Global Information Security Office. This hybrid role involves supporting security governance, risk management, and compliance programs while contributing to policy development and...SuggestedWork at office
$65k - $75k
...to fill the position of a full-time Information Security Risk and Compliance Analyst at our Denver, CO location. The salary range for... ...monitoring activities according to established schedules and governance expectations. Perform additional risk and compliance...SuggestedFull time$100k - $123k
...analysis that contributes to and advances Risk Management programs and processes... ...Operational Risk and Resilience, Product Governance, AI Risk Governance, and Risk Governance... ...to benchmark industry standards, monitor compliance, and track adherence to policies and procedures...Full timeWork at officeWork visaFlexible hours$128k - $165k
...Transamerica Corporate, which includes Finance, People and Places, General Counsel, Risk, Internal Audit, Strategy and Development, and Corporate Affairs, which covers Communications, Brand, and Government and Policy Affairs. Transamerica employs nearly 7,000 people. It’s part of...Full timeContract workWork at officeRemote workWorldwideVisa sponsorshipRelocation package3 days per week$110k - $135.3k
...analysis that contributes to and advances one or more Enterprise Risk Management (ERM) programs to assist CoBank in managing credit/... ...include, but are not limited to Risk Assessment, Product Governance, Portfolio Analytics, Risk Governance, Derivative Risk Modeling...Full timeWork at officeWork visaFlexible hours$132k - $178k
...driven and detail-oriented Enterprise Risk Analyst to support two distinct but interconnected... ...with engineering, security, legal, compliance, and operations teams to help identify,... ...briefings, external assessor interactions, and government partner reviews. Qualifications...Permanent employmentContract workWork at office- Columbia Bank is looking for a Trust Compliance Administrator in Denver, Colorado to support risk and compliance practices across Columbia Private Trust. This role works cross-functionally to identify and mitigate risks while providing data analysis and issue resolution...
- ...Model Risk Analyst Sunflower Bank is seeking a Model Risk Analyst to join its Enterprise Risk Management Department. The Analyst will be responsible for supporting the bank-wide Model Risk Management (MRM) program, focusing on the annual assessment process, maintaining...
- ...Job Description Job Description Summary The Governance and Regulatory Compliance Officer is responsible for overseeing key regulatory governance... ...and working cross-functionally with business, technology, risk, and senior management to ensure effective risk...Contract workWork at office
$105.4k - $124k
...our team as a Data Validation Analyst within the Consumer & Business Banking (CBB) Risk organization. This role plays a... ...integrity of data used to demonstrate compliance with regulatory and internal... ...practices adhere to enterprise governance, compliance, and data...Full timeLocal area$130k - $160k
...System which makes everything possible.The Senior Cybersecurity Risk Analyst is responsible for executing third-party and supplier risk... ...risk, enterprise risk management, vendor security, or related governance work.It would be a plus if you also possess previous...Full timeRemote workWork from homeFlexible hours$30 per hour
...monitor that all claims are handled in compliance with state regulations and company policies... ...certification such as - Certified Risk Manager (CRM); Associate in Risk Management... ...in E-Verify and will provide the federal government with your Form I-9 information to confirm...Hourly payWork at office$100k - $123k
...awards Essential Functions Contributes to the research and development of financial models incorporating credit and/or market risk elements. Contributes to or owns the ongoing management of existing models, which includes maintenance of data/documentation/parameters...Work experience placementWork at officeWork visaFlexible hours$60k
...operating, and improving essential government systems and services, with proven... ...national status required. The Risk, Quality, and Performance Analyst serves as the Risk, Quality, and Performance... ...management activities to ensure compliance with contract requirements and...Contract workRemote work$62k - $80k
...Compliance Analyst Denver As a Compliance Analyst at Convera, you will help promote a sound Compliance culture across the organisation... ...is an effective AML programme that effectively mitigates the risk of onboarding customers which are outside of Convera's risk appetite...Work experience placementLocal area$125k - $145k
...Bancorporation is seeking an experienced Sr. Risk Officer to join the Data, Technology and... ...will primarily be responsible for key governance and oversight practices related to... ...combination of the following: risk management, compliance, audit, governance, or other directly...Temporary workH1bLocal areaFlexible hours- ...apply for other labor markets outside of NCAL.Support Health Plan Risk Adjustment strategy through data analysis, performance monitoring, and business insights that drive operational excellence, compliance readiness, and program effectiveness. Analyze trends, identify...
$96k - $181k
...the Director of Cybersecurity Risk Oversight, the Sr.... ...corresponding Business Risk and Control Analysts.This position is responsible... ...domains, operations, architecture, governance, information security, and... ...effective oversight and compliance with risk management requirements...Full timeWork at officeFlexible hoursNight shift$109.6k - $191.7k
Senior Risk ConsultantRemote - USAProvides loss control support for Property & Casualty underwriters and insurance customers in AXA... ...engaging our external partners, and evolving our sustainability governance and reporting.AXA Hearts in Action: We have established...For contractorsWork at officeFlexible hours$99k - $124k
...’re on a mission to transform chronic conditions by identifying risk earlier, coordinating thoughtful care, and supporting people through... ...our offerings, click here. What You'll DoWe are seeking a Lead Analyst, Risk Adjustment Analytics to join our high-performing, insights...Work at officeRemote workWork from homeFlexible hours2 days per week- ...Cybersecurity Compliance Analyst We are hiring a Cybersecurity Compliance Analyst to ensure organizational... ...standards. The candidate will assess risks, perform security audits, and work with... ...Vulnerability Management SIEM Tools Governance, Risk & Compliance (GRC) Security...
$84.74k - $138.67k
...26-08-10 Position Title: Actuarial Analyst II Job Description: Actuarial Analyst... ...policy updates, ensuring ongoing compliance * Coordinates/directs special actuarial... ...verifies, analyzes and models data including risk reporting and forecasting. Minimum Requirements...Full timeWork at officeLocal areaDay shift2 days per week1 day per week$79k - $150k
...Description Job Description Market Risk Analyst (Gas & Power) BKV Corporation (NYSE... ...patterns. Limit Monitoring & Governance ~ Track adherence to notional, tenor,... ...risk perspective. Risk Controls & Compliance ~ Ensure compliance with the Market...Work at office- ...as it relates to hazards, controls, and management. They will need to evaluate how a company identifies and manages their inherent risk factors. Additionally they are expected to differentiate the account from others in similar classes of business. In this role the consultant...Full timeLocal areaLong distanceNight shift
- ...region. Lower salary ranges will apply for other labor markets outside of NCAL.Support Health Plan Risk Adjustment operations through government audit readiness, compliance oversight, and internal quality assurance reviews. Perform coding validation, documentation review...Work experience placement
- ...you will The Information Security GRC Analyst with a Risk and Policy focus is responsible for assisting... ...program and supporting policy governance. This role takes the lead in conducting... ...reviewing systems/processes for policy compliance. Risk Assessment Execution: Conduct...Contract workImmediate start
$78.9k - $123.3k
...seeking a detail-oriented cybersecurity compliance professional to support system authorization... ...Plan of Action and Milestones (POA&Ms) Risk Assessments Continuous Monitoring... ...Substitutions Substitutions are subject to government customer review and approval. Mid to senior...Permanent employmentFull timePart timeWork at officeLocal areaRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Governance Risk & Compliance Analyst. Be the first to apply!
- risk analyst Denver, CO
- risk officer Denver, CO
- it risk analyst Denver, CO
- senior quantitative risk analyst Denver, CO
- operational risk specialist Denver, CO
- risk consultant Denver, CO
- operational risk consultant Denver, CO
- compliance analyst Denver, CO
- regulatory compliance analyst Denver, CO
- coding compliance specialist Denver, CO


