GRC Analyst
Golden Technology
Job Description: Senior Information Security GRC Analyst
While professional experience and qualifications are key for this role, make sure to check you have the preferable soft skills before applying if required.
Department: Information Security
Job Title: Senior Information Security Governance, Risk, and Compliance (GRC) Analyst
Reports To: Information Security GRC Manager / Head of Information Security
Location: Remote, Hybrid, or Office-Based as assigned
Line Management Responsibilities: None – Individual Contributor with senior-level advisory and coordination responsibilities
Job Purpose
The Senior Information Security GRC Analyst supports and advances the organization's information security governance, risk management, and compliance program. This role is responsible for performing complex risk assessments, supporting regulatory and customer assurance activities, maintaining risk and compliance documentation, tracking remediation, and partnering with business, technology, privacy, legal, quality, procurement, and audit stakeholders to ensure information security risks are identified, documented, communicated, and managed in alignment with business objectives and risk appetite.
Main Duties and Responsibilities
- Lead and perform information security risk assessments for applications, infrastructure, business processes, suppliers, and new technology initiatives, including identification of threats, vulnerabilities, likelihood, impact, control effectiveness, residual risk, and recommended treatment options.
- Maintain and update risk registers, issue logs, control gap trackers, audit findings, evidence repositories, policy exception records, and remediation plans to support accurate reporting and timely closure.
- Support the development, review, maintenance, and communication of information security policies, standards, procedures, control documentation, and supporting governance materials.
- Coordinate internal audits, external audits, regulatory reviews, customer security assessments, RFIs, due diligence questionnaires, and evidence requests by gathering documentation, validating responses, and tracking corrective actions.
- Support compliance with applicable frameworks, standards, legal, regulatory, contractual, and customer requirements, including ISO/IEC 27001, NIST, COBIT, ITIL, ISO 31000, GDPR, and other applicable cybersecurity and privacy obligations.
- Partner with application, infrastructure, security operations, privacy, legal, quality, procurement, internal audit, and business stakeholders to ensure security requirements are understood, implemented, and monitored.
- Support third-party and supplier risk management activities, including security due diligence, questionnaire reviews, contract security input, risk documentation, remediation follow-up, and exception management.
- Track remediation activities for security risks, audit findings, vulnerability findings, penetration testing results, control gaps, and compliance issues; follow up with owners and escalate overdue or high-risk items as appropriate.
- Develop dashboards, metrics, management reports, and status updates that communicate risk posture, control effectiveness, audit readiness, compliance obligations, remediation progress, and emerging issues.
- Support disaster recovery, business continuity, crisis management, and operational resilience activities through documentation, testing support, tabletop exercises, lessons learned, and improvement tracking.
- Provide senior-level guidance to stakeholders on security risk management, control expectations, policy compliance, evidence requirements, and risk treatment decisions.
- Monitor changes in information security laws, regulations, frameworks, threats, and industry best practices; recommend updates to policies, controls, procedures, and reporting practices as needed.
- Support continuous improvement of GRC processes, including automation, workflow optimization, evidence management, reporting enhancements, and adoption of GRC or Integrated Risk Management tooling.
- Promote a strong security and compliance culture through stakeholder engagement, awareness support, clear communication, and practical guidance.
- Maintain confidentiality of company, customer, employee, and supplier information and comply with all Information Security standards, procedures, and ethical requirements.
Qualifications and Experience
- Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Technology, Business, Risk Management, or a related field, or equivalent professional experience.
- 5+ years of experience in information security, cybersecurity risk management, IT audit, compliance, governance, or a related GRC role.
- Experience performing information security risk assessments, control reviews, audit support, compliance assessments, and remediation tracking.
- Strong working knowledge of information security and risk management frameworks such as ISO/IEC 27001, NIST Cybersecurity Framework, NIST 800-53, ISO 31000, COBIT, ITIL, and related control frameworks.
- Familiarity with privacy, regulatory, contractual, and customer assurance requirements such as GDPR, SOC 2, and other applicable obligations.
- Experience supporting customer security questionnaires, RFIs, supplier risk assessments, policy governance, audit evidence collection, and risk reporting.
- Experience with GRC, Integrated Risk Management, ticketing, workflow, dashboarding, or evidence management tools is preferred.
- Professional certifications such as CISA, CISM, CISSP, CRISC, ISO 27001 Lead Implementer, ISO 27001 Lead Auditor, or equivalent are preferred.
Knowledge, Skills, and Competencies
- Strong understanding of cybersecurity principles, risk management practices, compliance programs, control design, control testing, and audit readiness.
- Ability to assess risk severity and business impact using multiple sources of information, including assessment results, audit findings, vulnerability data, business context, and control effectiveness.
- Excellent written and verbal communication skills, with the ability to explain technical, risk, and compliance topics to both technical and non-technical stakeholders.
- Strong analytical, problem-solving, prioritization, and decision-making capabilities.
- Ability to manage multiple assignments, deadlines, stakeholders, and competing priorities with limited supervision.
- Demonstrated ability to influence stakeholders, drive accountability, and support timely remediation of risks and control gaps.
- Strong attention to detail and ability to produce clear, accurate, and audit-ready documentation.
- Commitment to delivering practical, business-aligned security guidance and high-quality stakeholder service.
Success Measures
- Risk assessments, control reviews, and audit support activities are completed accurately and within agreed timelines.
- Risk registers, remediation trackers, evidence repositories, policy records, and compliance documentation remain current, complete, and audit-ready.
- Security risks, control gaps, and audit findings are clearly communicated, appropriately assigned, tracked, and escalated when required.
- Stakeholders receive timely, practical, and business-aligned guidance on security, risk, and compliance requirements. xhyhwjd
- GRC reporting, metrics, and dashboards provide leadership with accurate visibility into risk posture, compliance status, remediation progress, and emerging issues.
- ...Join to apply for the Junior GRC Risk Analyst role at Jobright.ai . Jobright is an AI-powered career platform that helps job seekers discover top opportunities in the US. We are NOT a staffing agency. Jobright does not hire directly for these positions; we connect you...SuggestedFull time
- WHO WE ARE Relation Insurance is a leading, innovative company with a strong commitment to excellence and a passion for delivering cutting-edge solutions to our clients. As a key player in the insurance market, we pride ourselves on our dynamic culture, collaborative...SuggestedFull timeWork at officeLocal area
- Job Description:Note: Fidelity will not provide immigration sponsorship for this position.Do you want to help shape the future of AI governance and risk management across the enterprise?The AI Center of Excellence within Enterprise Technology Risk and Analytics (ETRA) is...SuggestedFull time
- ...certification preferred, with responsibility to support and participate in ISO peer audit reviews.Knowledge of Governance, Risk, and Compliance (GRC) tools, such as Archer is preferredYour excellent verbal and written communication skills enabling you to prepare and present...SuggestedFull time
- ...shape enterprise risk decisions? As a Principal Technology Risk Analyst, you will play a critical role in advancing Fidelity's technology... ...with cloud security models (AWS, Azure, SaaS, PaaS) and GRC platforms such as Archer (preferred)Professional certifications...SuggestedFull time
$81.07k - $129.71k
...statistical analyses and calculations. Calculates premiums and reserves of new and existing plans of insurance. Provides support to senior analysts or actuaries as required. Retrieves and validates data for rate filings and actuarial models. Builds model enhancements and...Work at officeLocal areaRemote workFlexible hours2 days per week- At Wolfspeed, we do amazing things in a human way. We know that the achievements of our organization are due to the passion, hard work and creativity of our employees. We celebrate different perspectives to foster excellence across our organization, and our goal is to make...Full timeWork at officeLocal area
- ...Descriptive Summary TrueBridge Capital Partners is seeking a Data Impact Analyst to fill a full-time position on its Operations Team. Reporting to the Data Impact Manager, the Data Impact Analyst is a self-motivated, multi-talented and well-rounded individual who desires...Full time
- ...Role: GIS Analyst Location: Raleigh NC Position : Hybrid Duration: Long Term The candidate will need to come on-site on the first day to collect equipment. All candidates must be local to the Triangle region of North Carolina. - do not submit candidates...Local area
- Are you ready to work for a more active world? At Bioventus, our business depends on developing our people. We invest in you and challenge you to be the best. We value our colleagues for their different perspectives and individual contributions, and our leaders listen. ...Full timeWork at office
- ...Risk Analyst The experienced Risk Analyst role executes the VA Enterprise Risk Analysis process using a custom ERA tool to identify... ...Things (IoT) Experience with Governance, Risk, and Compliance (GRC) Experience with Assessment and Authorization (A&A) and eMASS...For contractorsWork experience placement
$140.2k - $390.6k
Overview IQVIA is seeking a Director, Managed Access Regulatory Strategy to help build a regulatory strategy offering supporting patient access programs for investigational therapies outside of traditional clinical trial settings. This role will support Expanded Access ...Full timePart timeImmediate startWorldwide$220.9k - $291.5k
“Members of the Legal organization at select locations will generally be expected to follow a hybrid work model, which includes two days of in-office attendance each week, with limited exceptions.”Meet the TeamThe Regulatory Affairs & Compliance team within Cisco’s Legal...Full timeTemporary workWork at officeLocal areaFlexible hours- Labcorp is a global leader in laboratory services, providing the insights and answers that help healthcare providers, patients, researchers, pharmaceutical companies and health systems make confident decisions and improve outcomes. Through our unparalleled science, data...Temporary workCasual workInternshipWork at officeFlexible hours
$48 - $58 per hour
...position is not eligible for sponsorship. About the Role: A leading technology consulting firm is seeking a Senior Business Analyst / Project Manager to support the implementation of an Asset Performance Management (APM) system for a renewable energy client. This...Hourly payFull timeContract workFor contractorsLocal area- ...Sales Support Analyst Hybrid/Remote based out of Raleigh $80-90k with bonus potential Bell and Associates is partnering with a Real Estate Investment firm based in the Raleigh area looking to fill a newly created Sales Support Analyst position. This role will be...Remote work
- Labcorp is a global leader in laboratory services, providing the insights and answers that help healthcare providers, patients, researchers, pharmaceutical companies and health systems make confident decisions and improve outcomes. Through our unparalleled science, data...Temporary workCasual workInternshipWork at officeRemote workMonday to FridayFlexible hoursShift workNight shift3 days per week
$97.2k - $270.7k
Global Regulatory Science Program SupportThe individual will support one or more global development programs as part of our Global Regulatory Science organization. The specific therapeutic area and program assignment will be determined based on the candidate's experience...Full timePart timeWork at officeImmediate startWorldwide- Job Description:Note: Fidelity will not provide immigration sponsorship for this position. The Role In this role, you will work closely with data scientists, fraud strategists, and business stakeholders to support real-time fraud detection and prevention strategies. Your...Full time
$47.7k - $123k
Job Overview Perform tasks at a country level associated with Site Activation (SA) activities in accordance with applicable local and/or international regulations, standard operating procedures (SOPs), project requirements and contractual/budgetary guidelines. May also...Full timePart timeLocal areaImmediate startWorldwide- Position Overview TRC Talent Solutions client is seeking a detail-oriented DEA Compliance Specialist to support the controlled substance compliance program for a pharmaceutical distribution organization in Durham, NC. This position is responsible for monitoring controlled...Full timeWeekend workAfternoon shift
$174.88k - $233.17k
...compliance issues and ensure appropriate monitoring and remediation. Oversee corporate investigations team, including hotline analysts and internal investigators to ensure prompt response to compliance violations and allegations of misconduct. Prepare processes...Full timeTemporary work- Job Description:Note: Fidelity will not provide immigration sponsorship for this position.The RoleThe Director leads the administration and oversight of estate gifts and serves as subject matter expert on estate gift compliance for Fidelity Charitable. The position partners...Full time
$127k - $147k
Business Unit:Cubic DefenseCompany Details:A Mechanical Analyst applies in-depth professional knowledge and company objectives to tackle complex engineering challenges. The role handles projects or assignments requiring advanced technical evaluations, often determining...Full timeTemporary workImmediate start- ...Employee Resource Groups to local outreach.Who we’re looking for:Wolfspeed’s Human Resources business unit is seeking a Compensation Analyst to support activities to develop, implement and administer compensation policies and programs. This includes compensation program...Full timeLocal area
$89.17k - $142.68k
...measurement, and stakeholder engagement to identify opportunities to improve quality, cost, experience, and operational efficiency.The analyst develops reporting and analytical solutions that support care management programs, utilization management initiatives, quality...Full timeLocal areaRemote workFlexible hours- ...industry leaders in construction, building products manufacturing, and distribution.Higharc is seeking an accomplished Purchasing Analyst to serve as the primary contact for Builder purchasing teams and a right-hand to the VP of Purchasing as we build out and scale this...Full timeTemporary workRemote workHome officeFlexible hours
$118.69k - $189.91k
Job DescriptionResponsible for providing enterprise/divisional thought leadership on data visualization and analytic report development. This includes supporting/monitoring the team development and application of visualization best practices, and providing development and...Full timeLocal areaRemote workFlexible hours$88.3k - $220.9k
Summary: Our IQVIA team is seeking to hire an experienced Clinical Trials Feasibility Analyst to join an Advanced Analytics group within the Clinical Data Science department. Join this team dedicated to a Pharmaceutical client, focused on efforts in study feasibility analytics...Full timePart timeWork experience placementImmediate startWorldwide- Job-ID32495546Reference26-01077Remote50% Remote Roles & Responsibilities: Prior work experience working in pharma or other GMP setting. Strong working knowledge of analytical laboratory IT systems (i.e. Lab Vantage, Empower, Benching, Signals, L7, LabX, MODA, etc.). Solid...Work experience placementRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to GRC Analyst. Be the first to apply!





