Senior GRC Analyst
$95k - $110kBlackkite
ABOUT BLACK KITE
Black Kite is the global leader in third‑party cyber risk intelligence, trusted by more than 3,000 organizations worldwide. We give security and business leaders a continuous, outside‑in view of their entire vendor ecosystem — translating complex cyber, financial, and compliance signals into clear, actionable risk intelligence. We go beyond open standards‑based cyber ratings. Black Kite helps organizations make smarter risk decisions, strengthen business resilience, and scale their third‑party cyber risk management programs in an increasingly complex digital environment. Our work has earned consistent recognition from customers and industry analysts alike.WHY BLACK KITE
We’re a fast‑moving, high‑impact team solving one of the most critical challenges in cybersecurity today. If you’re looking to do meaningful work alongside sharp, collaborative people — and grow your career in a space that matters — you’re in the right place.THE OPPORTUNITY
The Senior GRC Analyst reports to the Director of Information Security and owns three primary functions: the compliance platform (Vanta), inbound customer security assessments, and FedRAMP ConMon execution support. This is an independent practitioner role — direction comes from the Director, but you own your work without step‑by‑step guidance. The “Senior” in this title is earned by the scope, not just the experience level. Owning the compliance platform means auditors see your work directly. Owning customer assessments means your responses are read by enterprise security teams before they sign. Supporting FedRAMP ConMon means authorization status depends in part on what you produce monthly. The stakes are real.WHAT YOU’LL OWN
Compliance platform (Vanta) — primary owner Own the compliance platform end-to-end: evidence library currency, control mapping accuracy, framework completeness across SOC 2, ISO 27001, FedRAMP, and GDPR Evidence is current year-round — not assembled at audit time; no stale or missing evidence in any active certification domain Customer security assessments — primary owner Own the inbound customer assessment intake and response process — all RFPs and security questionnaires are assigned, tracked, and responded to within defined SLA Collaborate with sales, legal, and technical teams on complex questionnaire responses; escalates novel or sensitive items to the Director Maintain and improve the questionnaire response library across all active frameworks FedRAMP ConMon — execution support Support monthly ConMon reporting — vulnerability scan results, POA&M updates, and evidence — as primary executor Maintain POA&M tracking accuracy; flag aging items to the Director before they breach defined thresholds TPCRM and compliance support Support third‑party risk identification, assessment, and monitoring activities as directed Monitor compliance framework and regulatory changes; assess impact and surface findings to the Director with a recommended response Support internal audit processes — evidence coordination, control testing documentation, and auditor request responsesWHAT YOU BRING
2–4 years of hands‑on experience in GRC, compliance, or information security Practical working knowledge of SOC 2, NIST, or ISO 27001 applied in a real compliance environment Experience producing compliance evidence, contributing to audit cycles, or managing specific framework control domains independently Familiarity with cloud services principles and their security and compliance implications General knowledge of core security domains: network security, email security, endpoint protection, vulnerability scanning, access controls, log management Strong written communication — audit‑ready documentation produced independentlyPREFERRED
Hands‑on experience administering Vanta or an equivalent compliance platform as a primary owner — not just a user Direct experience with FedRAMP ConMon — monthly reporting, POA&M tracking, evidence production Experience owning or significantly contributing to a customer security questionnaire response program Familiarity with TPCRM programs and vendor questionnaire workflows Active or in‑progress certification: CompTIA Security+, CISA, CRISC, ISO 27001 Lead Auditor/Implementer, or equivalent The expected base salary range for this role is $95,000-$110,000 per year. Compensation at Black Kite is more than just base pay — we offer a total rewards program that includes performance‑based bonuses, equity, flexible healthcare options, paid time off, and retirement savings programs. The annual base salary range for this position represents a nationwide market range and reflects a broad spectrum of salaries for this role across the United States. Actual compensation will depend on factors such as qualifications, skills, experience, and the scope, complexity, and location of the role. #J-18808-Ljbffr BlackkiteVacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the Senior GRC Analyst in Boston, MA vacancy
$95k - $110k
Blackkite in Boston seeks a Senior GRC Analyst to manage compliance platforms and customer security assessments. The ideal candidate will have 2-4 years in GRC or information security, paired with skills in SOC 2 and ISO 27001. You'll support FedRAMP ConMon reporting and...Senior- ...GRC Program Operations Specialist Support day-to-day GRC program operations – manage and triage GRC intakes and accurate tracking through resolution. Perform and support third-party risk management activities, including vendor reviews, reassessments, partner coordination...Suggested
- Northeastern University is hiring a Governance, Risk and Compliance Analyst in Boston. This hybrid role involves supporting compliance initiatives and NIST frameworks in government and higher education environments. The ideal candidate will have a Bachelor's degree, 2-4...Suggested
$75 per hour
Job Description We’re looking for a hands‑on ServiceNow GRC Analyst to join a growing Security organization and support the implementation of an established security control framework across SaaS applications. This is an execution‑focused role, not a strategy or architecture...Suggested$75 per hour
Insight Global is seeking a ServiceNow GRC Analyst in Boston to join a growing Security team. This role will be responsible for operationalizing security controls in ServiceNow across SaaS applications, working closely with system owners and technical leads. The ideal candidate...Suggested$60k - $90k
As a GRC Analyst, Operations & Risk, you will support the WHOOP Governance, Risk, and Compliance program by helping manage GRC intake, coordinate third-party risk activities, strengthen operational workflows, and improve visibility across risk and compliance work. This...Full timeWork at officeRelocation$60k - $90k
Whoop is searching for a GRC Analyst in Boston, MA, to enhance the Governance, Risk, and Compliance program. This role involves managing GRC intake processes, coordinating third-party risk reviews, and ensuring effective compliance operations. The ideal candidate will have...$29.61 - $40.06 per hour
...people and members, Metro Credit Union is a place where your expertise can make a real impact. Position Summary The Risk & Compliance Analyst plays a critical role in safeguarding Metro Credit Union by independently driving enterprise‑wide risk monitoring, regulatory...SeniorWork at officeFlexible hours- A leading cancer research organization located in Brookline is seeking a Regulatory Compliance Director to develop and oversee a comprehensive compliance program. The ideal candidate will have significant experience in regulatory healthcare compliance and leadership. This...Senior
$90k - $115k
...Senior Risk Analyst The Washington Trust Company is seeking an experienced Senior Risk Analyst to support our fraud strategy and reporting process. This position will own the configuration, testing, and validation of multiple fraud-prevention systems and produce quarterly...SeniorWork at office$109.04k - $163.56k
...Sr Risk Analyst - KR07DE We're determined to make a difference and are proud to be an insurance company that goes well beyond coverages... ...the future. We are seeking a highly skilled and motivated Senior Catastrophe Risk Modeling Analyst to join our Reinsurance team....SeniorTemporary workWork at office3 days per week$120k - $225k
Wellington Management Company is seeking a Principal Business Analyst in Risk Technology, located in Boston. This role involves leading the risk platform by enhancing risk data quality and collaborating with analytics teams to ensure effective risk management. The ideal...Senior- ...Job Title The Sr. Analyst/Associate will join Liberty Mutual Investments' Risk Management Team and play a key role in General Account... .... Produce monthly and quarterly portfolio risk reviews for senior stakeholders and committees; provide ad hoc deep dives to...SeniorWork experience placementLocal area
- Initial Therapeutics, Inc. is seeking a seasoned professional for a role in Global Regulatory Affairs, focusing on Chemistry Manufacturing & Controls. The successful candidate will lead the development of regulatory CMC strategies and manage submissions critical to product...Senior
- A medical device company in Cambridge, MA, is seeking a Regulatory Affairs professional to lead regulatory strategies for Class II medical devices. Responsibilities include managing FDA submissions, ensuring regulatory compliance throughout product development, and collaborating...Senior
$95.2k - $119k
...We're shaping it, one bold step at a time. To those who see AI as a driver of progress, come build the future together. As a Senior Analyst, Risk Analytics, you'll turn complex risk and customer data into strategic direction that strengthens our fraud prevention...SeniorFull timeImmediate start$119k - $193k
.... About This Role: Forrester is currently looking for a Senior Analyst to conduct research and deliver strategic advice for risk management... ...in compliance management, internal or external audit, and GRC platforms is strongly desired. The successful candidate...SeniorFor contractors- Job Title Quantitative Risk Management, QRM Job Description Are you ready to make an impact at DTCC? Do you want to work on innovative projects, collaborate with a dynamic and supportive team, and receive investment in your professional development? At DTCC...SeniorRemote workFlexible hours
$77.7k - $146.9k
...professionally. There's no one like you and that's why there's nowhere like RSM. Role Overview The Technology Risk Advisory - AI Risk Senior Associate will play a key role in helping clients strengthen their technology, AI, and cybersecurity risk capabilities. You'll...SeniorWork experience placementInternshipLocal area- A leading consumer electronics company in Needham is seeking a Principal Electrical Engineer. The ideal candidate will have over 10 years of experience, particularly in power electronics and embedded systems. You'll lead technical decisions, mentor engineers, and ensure...Senior
$220k - $270k
Zealand Pharma U.S., Inc. in Cambridge is seeking a Principal or Senior Principal Scientist for Peptide & Bioconjugate Drug Discovery. This role involves leading the development of peptide drug discovery capabilities, with significant responsibilities for strategy and...Senior- ...to join their Public Markets Team in New York. The role requires a strong understanding of public markets and involves supporting senior investment professionals with research activities. Key responsibilities include conducting due diligence, creating investment documentation...Senior
$92.5k - $120k
...support the continued growth of our Risk Advisory for State & Local Government ( practice, an opportunity has been created for a Senior Associate to join our nationally distributed team performing risk and accounting consulting engagements. Our clients rely on our expertise...SeniorWork experience placementWork at officeLocal areaRemote work- Senior Regulatory Affairs Manager- REMOTE I'm looking for a senior manager, regulatory affairs to lead our growing, dynamic team through global phase 3 clinical trials of a certain product and support other clinical studies. This role includes driving global submission...SeniorFull timeRemote work
$137k - $215.27k
By clicking the “Apply” button, I understand that my employment application process with Takeda will commence and that the information I provide in my application will be processed in line with Takeda’s Privacy Notice and Terms of Use . I further attest that all information...SeniorMinimum wageFull timeTemporary workLocal areaImmediate startRemote workWorldwide- Mass General Brigham Incorporated. is seeking a Senior MassHealth Encounter Data Analyst in Somerville, MA. This hybrid role focuses on regulatory reporting and data analytics, bridging business with technical teams to ensure compliance. The position requires strong data...SeniorFlexible hours
$208.2k - $327.14k
A leading global R&D organization is seeking a Senior Director, Global Regulatory Lead - Oncology. This role involves leading global regulatory strategy and engaging with cross-functional teams to ensure the success of innovative oncology therapies. The successful candidate...Senior- ...with LMI Investment Business Units (IBUs) portfolio managers and analysts to support new investment reviews and portfolio changes,... ...constraints. Produce monthly and quarterly portfolio risk reviews for senior stakeholders and committees; provide ad hoc deep dives to...SeniorWork experience placement
- A global investment firm in Boston is seeking a Senior Principal to lead Talent Management. This role focuses on strategic and hands-on talent lifecycle management, fostering a high-performance culture. Candidates should have 10-15 years of experience across various human...Senior
$130k - $190k
Manager/Senior Manager Regulatory Affairs - Advertising, Labeling, and Promotion Cambridge, MA Added 2/13/2026 Company Overview Beam Therapeutics is a biotechnology company committed to establishing the leading, fully integrated platform for precision genetic medicines...Senior
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior GRC Analyst. Be the first to apply!
Related searches
- senior office manager Boston, MA
- senior automation controls engineer Boston, MA
- senior accounts payable Boston, MA
- senior brand designer Boston, MA
- senior financial advisor Boston, MA
- senior underwriter Boston, MA
- senior cost analyst Boston, MA
- senior business analyst contract Boston, MA
- senior app developer Boston, MA
- senior digital account manager Boston, MA

