Senior GRC Analyst
Clayco
Sr. GRC Analyst, Risk Management
Under the direction of and in collaboration with the GRC Manager, the Sr. GRC Analyst, Risk Management is the primary owner and operational steward of the Enterprise Risk Register. This role is responsible for ensuring all identified risk is accurately captured, properly rated, assigned to an accountable owner, actively worked, and driven to resolution across the Clayco organization. The analyst functions as the operational hub of the risk lifecycle — from initial intake and classification through remediation coordination, escalation, stakeholder accountability, and reporting. This is a high-accountability, process-driven role that demands both technical depth and organizational influence. The analyst transforms the risk register from a static document into a dynamic governance instrument — one that delivers a clear, current, and quantified view of organizational risk exposure to leadership. Additional responsibilities will be assigned as deemed necessary. Any travel is usually planned in advance, but issues may arise which warrant immediate travel to one or more satellite locations.
The Specifics of the Role:
- Assumes the ownership and maintenance of the Enterprise Risk Register as the authoritative system of record for all identified risks across the Clayco organization.
- Enforces rigorous data integrity standards: no missing owners, undefined due dates, stale entries, or incomplete risk descriptions.
- Establishes and maintains a consistent process for risk creation, categorization, severity rating, and treatment classification to ensure comparability and defensibility of the data set.
- Applies qualitative risk analysis methodologies, including likelihood/impact matrices to produce accurate, prioritized risk ratings.
- Conducts regular audits of the risk register to surface stale, incomplete, or improperly rated entries and drive timely corrections with risk owners.
- Maintains comprehensive documentation for each risk, including: risk description, affected assets and systems, threat source, inherent risk rating, current controls, residual risk, treatment decision, assigned owner, and target remediation date.
- Manages the full risk lifecycle from intake through closure, including periodic re-evaluation of accepted risks to confirm continued acceptability.
- Serve as the primary coordinator and driver of risk remediation and mitigation activities, ensuring every open risk has an actionable, time-bound treatment plan with a clearly accountable owner.
- Collaborates with risk owners and technical teams to develop realistic remediation plans that define specific tasks, milestones, resource requirements, and completion criteria.
- Coordinates corrective and preventive actions (CAPA) arising from audit findings, control failures, and policy exceptions, tracking each to verified closure.
- Tracks and monitors remediation progress across all open items; proactively identify blockers, resource gaps, and at-risk milestones before they result in missed deadlines.
- Escalates risks with insufficient remediation progress, missed SLAs, or unacceptable residual risk levels to the GRC Manager and relevant leadership with supporting data and recommended courses of action.
- Assumes operational ownership of Vulnerability Management and External Attack Surface Management (EASM) processes:
- In collaboration with SOC, ensures that Vulnerability Scanning output ingested into Workflow platform has high fidelity with accurate association with CI's
- In collaboration with SOC, ensures that EASM output ingested into Workflow Platform has high fidelity with accurate association with CI's
- Ensures effective tuning and appropriate scoring of Risk Rating algorithm
- Ensures effective execution of assignment Rules and track remediation activity
- Remediates Unknown/Unclassed CI's from scanning output and tune assignment Rules
- Ensures timely and accurate reporting of active Risk and Vulnerability by severity as well as performance against Remediation targets process.
- Collaborates cross-functionally with other Information Technology teams and Business Stakeholders across the Organization
- Engages as necessary in all GRC functions to maintain an understanding of process and procedures
- Provides leadership with comprehensive reports of compliance-focused activities and outcomes, as requested.
Requirements:
- 5-7+ years' experience in Risk & Compliance Assessment, Audit & Reporting, or similar functions, preferably within the Information Security or Technology fields
- 3-4+ years working specifically in Information Security roles involving Risk Analysis, Information System Security Assessment, Compliance Audit with Regulations, Frameworks, & Standards
- Bachelor's degree in Information Technology or related field, or equivalent experience
- Required Certifications: Certified in Risk & Information Systems Control (CRISC), Certified Information Systems Auditor (CISA), or Certified Information Systems Security Professional (CISSP) (Current status, or obtained within 9 months of assuming role)
- Strong experience leveraging auditing principles and methods to evaluate policies, processes, systems, and vendors to identify business risks and control gaps
- Experience in administering Risk management programs for technology and information security
- Strong, technical knowledge of modern Systems, Services, Cloud Applications/Platforms, Identity Services, and Data Storage/Handling and their areas of Risk and Threat exposure
- Experience with administering, maintaining, and leveraging a Risk Register to track and communicate identified Risk and its required remediation
- Knowledge of statistics, reporting and analytical tools to analyze and solve complex problems
- Proficiency in necessary productivity tools (i.e. Microsoft Excel, PowerPoint, Word etc.) for analytics and presentations
- Operate with strong integrity with ability to handle projects of a sensitive & confidential nature
- Excellent written and verbal communication skills with a proven ability to translate technical or abstract concepts into a narrative that is easily understood by clients.
- Ability to thrive in fast-paced environment.
Some Things You Should Know:
- No other builder can offer the collaborative design-build approach that Clayco does.
- We work on creative, complex, award-winning, high-profile jobs.
- The pace is fast!
- This position is classified as a safety-sensitive role in accordance with applicable state and federal laws. Candidates selected for this position will be subject to a comprehensive background check, which includes mandatory drug testing.
Why Clayco?
- 2025 Best Places to Work – St. Louis Business Journal, Los Angeles Business Journal, and Phoenix Business Journal.
- 2025 ENR Top 400 – Top Data Center Contractor (Top 3).
- 2025 ENR Top 100 Design-Build Firms – Design-Build Contractor (Top 5).
- 2025 ENR Top 100 Green Contractors – Green Contractor (Top 3).
Benefits:
- Discretionary Annual Bonus: Subject to company and individual performance.
- Comprehensive Benefits Package Including: Medical, dental and vision plans, 401k, generous PTO and paid company holidays, employee assistance program, flexible spending accounts, life insurance, disability coverage, learning & development programs and more!
Compensation:
- The salary range for this position considers a wide range of factors in making compensation decisions including but not limited to: Education, qualifications, skills, training, experience, certifications, internal equity, and location. Compensation decisions are dependent on the facts and circumstances of each case.
- Gilder Search Group is looking for a Sr. GRC Analyst focused on Third-Party & Human Risk Management in St. Louis, Missouri. The role ensures all human and third-party risks to Clayco are identified and treated appropriately. Key responsibilities include owning the TPRM...Senior
- Sky Mavis is seeking a Senior GRC Analyst focused on Third-Party and Human Risk Management in St. Louis, Missouri. This role requires 6-8+ years of experience in Risk Assessment and Information Security, with strong analytical skills. You will lead the Vendor Risk Management...Senior
- ...entertainment related building projects. The Role We Want You For Under the direction of and in collaboration with the GRC Manager, the Sr. GRC Analyst, Third‑Party & Human Risk Management (TPHRM) is a risk‑focused, highly analytical role that ensures all human and...SeniorImmediate startFlexible hours
- ...GRC Analyst Join our team as a GRC Analyst and play a key role in regulatory compliance, IT risk management, security. You'll assess risks, support audits, and develop policies that align with industry standards. If you have a solid IT security background, experience...SuggestedCasual workWork at officeWork from homeHome officeNight shiftWeekend work
$60 - $65 per hour
job summary: Our client in St. Louis, Missouri is looking for an Oracle GRC Analyst to join their team for a long term position. location: Telecommute job type: Contract salary: $60 - 65 per hour work hours: 9am to 5pm education: No Degree Required...SuggestedHourly payContract workTemporary workWork experience placementRemote work$124.8k - $135.2k
...compliance. Technologies: Cloud ERP Support Oracle RBAC SQL Security More: We are seeking an Oracle GRC Analyst for a long-term contract opportunity supporting our client in St. Louis, Missouri, with telecommute flexibility. The role is...Hourly payLong term contractFull timeContract workTemporary workRemote work- Delta-Denta is seeking a Governance, Risk & Compliance Analyst to help ensure client and regulatory requirements are met while identifying and managing IT risks. You will collaborate across Legal, Privacy, and Compliance, support audits, and drive policy development aligned...
- Focus Financial Partners is seeking a Senior Risk Operations Specialist to bolster its Cybersecurity program, focusing on Vulnerability Management and Risk Management. The role supports policy development, incident response, and deployment across multiple environments,...Senior
- ...MANTECH seeks a motivated, career and customer-oriented Senior GEOINT Analyst to join our team in St. Louis, MO! Job duties include, but are not limited to: Conduct GEOINT analysis on national security issues using imagery, geospatial data, and multi-INT...SeniorWork at officeRemote work
- Affirm is a remote-first fintech company reimagining consumer credit. As a Senior Analyst (L5) you will own the entire analytical lifecycle, from framing questions to delivering data-driven decisions that influence risk, product, and growth. You will collaborate with ML...SeniorRemote job
$126.8k - $211.4k
...Legal Compliance Senior Manager - Express Scripts - Remote Leads team of Analysts with full responsibility for team output including compliance to licensure regulations and associated reporting activity. Implements protocols for license management and record keeping...SeniorTemporary workWork at officeLocal areaRemote workWork from home- apturagroup is seeking an Accounts Receivable Manager to oversee billing and collections, enforce credit policies, and collaborate with internal departments to resolve outstanding balances. The role requires leadership of AR staff, handling AIA billing processes, and ensuring...Senior
- Oliver Wyman’s Property & Casualty Actuarial Practice is seeking a high-performing Principal to lead complex client engagements, drive growth, and shape the future of actuarial consulting through innovation and AI-enabled solutions. This leadership role combines deep actuarial...Senior
$85k - $115k
Senior Third Party Risk Analyst (St Louis - In Office) This range is provided by Bruin. Your actual pay will be based on your skills and experience — talk with your recruiter to learn more. Base pay range $85,000.00/yr - $115,000.00/yr Direct message the job poster from...SeniorFull timeContract workWork experience placementWork at officeRelocation$150.5k - $204k
...experience framework that can serve the needs of the growing customer base while managing the financial risk exposure for Intuit. As a senior member in the risk team, your focus is to enhance and develop policies across the journey of the customer in offerings like...SeniorWorldwide- Spectrum Brands, Inc in St. Louis, MO is seeking a Senior Regulatory Affairs Specialist to drive product compliance and innovation for pet care products. This hybrid position involves collaboration with various teams to manage regulatory risks and ensure successful product...Senior
$100k - $120k
...Focus Financial Partners is seeking a proactive and detail-oriented Senior Risk Operations Specialist to support and strengthen our... ...5+ years of experience in cybersecurity, policy development, or GRC (governance, risk, and compliance). Familiarity with cybersecurity...SeniorWork at officeLocal area- Ameren Services, on behalf of Ameren Corporation, seeks a Benefits Compliance and Legal Analyst to support employee benefit plans, including plan docs, regulatory filings, vendor agreements, and fiduciary governance. The role identifies compliance risks and provides guidance...Senior
- This job posting is anticipated to remain open for 30 days, from 27-Jul-2026. The posting may close early due to the volume of applicants. Join a financial services firm where your contributions are valued. Edward Jones is a Fortune 500 1 company where people come first...SeniorTemporary workWork experience placementWork at officeHome officeFlexible hours3 days per week
- BJC Medical Group is hiring a Senior Compliance Coordinator in St. Louis, MO. This remote position involves reviewing specialty provider documentation for billing accuracy and developing educational materials. The ideal candidate will have 5-10 years of experience, a high...SeniorRemote job
- The Doe Run Company, with a 160-year history, seeks a Sr Benefits Analyst to administer benefits communications, eligibility, reporting, billing, and compliance. Based at our Corporate Office in St. Louis, MO, the role supports medical, dental, vision, life, disability,...SeniorWork at office
- Bank of America is seeking a Financial Analysis & Monitoring Specialist to support underwriting and ongoing monitoring for new and existing clients. You will analyze financial statements, projections, and collateral, using multiple tools to prepare and review underwriting...Senior
$132.5k - $217k
...Senior Actuarial Analyst – Pricing Actuarial Team Zurich North America is seeking a Senior Actuarial Analyst to join the Pricing Actuarial Team. The role supports actuarial and underwriting leaders and is responsible for pricing Direct Markets accounts. Responsibilities...SeniorFull timeTemporary workApprenticeshipWork at officeRemote workVisa sponsorship- Refresco Beverages US Inc. seeks a Manager of Quality to lead the site quality department, drive food safety and quality programs, and ensure regulatory compliance. The role emphasizes GMP, HACCP, SQF, and cross‑functional collaboration with production and lab teams. You...Senior
- Ramboll Group A/S in St. Louis, MO seeks a Managing Consultant or Senior Managing Consultant to lead air quality projects within the Environment & Health Division. You will oversee consultant staff, interpret regulations, and prepare permit applications and reports for...Senior
- 3M HEALTHCARE is seeking an experienced Trade Compliance leader to govern and improve import/export programs for U.S. and Canadian businesses. The role focuses on policy, standards, training, and audit support, serving as the primary corporate contact for business compliance...Senior
- Consigli Construction Co., Inc. is looking for a Quality Control Manager in St. Louis, Missouri. The QCM will implement and manage the QC Program throughout project lifecycles, collaborating closely with the project team. This role requires strong communication skills, ...Senior
- An established security consulting firm is seeking a dedicated professional for their Information Risk Management department in St. Louis, Missouri. The role involves conducting risk assessments, advising on security measures, and contributing to the development of corporate...Senior
$70.35k
...Senior Crime Analyst REJIS is seeking a highly skilled Senior Crime Analyst to serve as the lead individual contributor within our Crime Analysis Unit. In this role, you will conduct advanced tactical, strategic, investigative, and administrative analyses to support...Senior- GreenGas is looking for a Contract Manager to oversee contract lifecycle management. This role involves managing contracts from initiation through execution, ensuring compliance, and improving contract processes. The ideal candidate will have a Bachelor's degree and over...SeniorContract workWork at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior GRC Analyst. Be the first to apply!
- senior lead project manager Saint Louis, MO
- senior robotics software engineer Saint Louis, MO
- senior devops engineer remote Saint Louis, MO
- senior sas administrator Saint Louis, MO
- senior IT manager Saint Louis, MO
- senior director of client services Saint Louis, MO
- senior contracts analyst Saint Louis, MO
- sr project manager Saint Louis, MO
- senior windows systems engineer Saint Louis, MO
- consultant senior consultant Saint Louis, MO



