Senior GRC Analyst
CRG
Sr. GRC Analyst, Risk Management
Under the direction of and in collaboration with the GRC Manager, the Sr. GRC Analyst, Risk Management is the primary owner and operational steward of the Enterprise Risk Register. This role is responsible for ensuring all identified risk is accurately captured, properly rated, assigned to an accountable owner, actively worked, and driven to resolution across the Clayco organization. The analyst functions as the operational hub of the risk lifecycle — from initial intake and classification through remediation coordination, escalation, stakeholder accountability, and reporting. This is a high-accountability, process-driven role that demands both technical depth and organizational influence. The analyst transforms the risk register from a static document into a dynamic governance instrument — one that delivers a clear, current, and quantified view of organizational risk exposure to leadership. Additional responsibilities will be assigned as deemed necessary. Any travel is usually planned in advance, but issues may arise which warrant immediate travel to one or more satellite locations.
The Specifics of the Role:
- Assumes the ownership and maintenance of the Enterprise Risk Register as the authoritative system of record for all identified risks across the Clayco organization.
- Enforces rigorous data integrity standards: no missing owners, undefined due dates, stale entries, or incomplete risk descriptions.
- Establishes and maintains a consistent process for risk creation, categorization, severity rating, and treatment classification to ensure comparability and defensibility of the data set.
- Applies qualitative risk analysis methodologies, including likelihood/impact matrices to produce accurate, prioritized risk ratings.
- Conducts regular audits of the risk register to surface stale, incomplete, or improperly rated entries and drive timely corrections with risk owners.
- Maintains comprehensive documentation for each risk, including: risk description, affected assets and systems, threat source, inherent risk rating, current controls, residual risk, treatment decision, assigned owner, and target remediation date.
- Manages the full risk lifecycle from intake through closure, including periodic re-evaluation of accepted risks to confirm continued acceptability.
- Serve as the primary coordinator and driver of risk remediation and mitigation activities, ensuring every open risk has an actionable, time-bound treatment plan with a clearly accountable owner.
- Collaborates with risk owners and technical teams to develop realistic remediation plans that define specific tasks, milestones, resource requirements, and completion criteria.
- Coordinates corrective and preventive actions (CAPA) arising from audit findings, control failures, and policy exceptions, tracking each to verified closure.
- Tracks and monitors remediation progress across all open items; proactively identify blockers, resource gaps, and at-risk milestones before they result in missed deadlines.
- Escalates risks with insufficient remediation progress, missed SLAs, or unacceptable residual risk levels to the GRC Manager and relevant leadership with supporting data and recommended courses of action.
- Assumes operational ownership of Vulnerability Management and External Attack Surface Management (EASM) processes:
- In collaboration with SOC, ensures that Vulnerability Scanning output ingested into Workflow platform has high fidelity with accurate association with CI's
- In collaboration with SOC, ensures that EASM output ingested into Workflow Platform has high fidelity with accurate association with CI's
- Ensures effective tuning and appropriate scoring of Risk Rating algorithm
- Ensures effective execution of assignment Rules and track remediation activity
- Remediates Unknown/Unclassed CI's from scanning output and tune assignment Rules
- Ensures timely and accurate reporting of active Risk and Vulnerability by severity as well as performance against Remediation targets process.
- Collaborates cross-functionally with other Information Technology teams and Business Stakeholders across the Organization
- Engages as necessary in all GRC functions to maintain an understanding of process and procedures
- Provides leadership with comprehensive reports of compliance-focused activities and outcomes, as requested.
Requirements:
- 5-7+ years' experience in Risk & Compliance Assessment, Audit & Reporting, or similar functions, preferably within the Information Security or Technology fields
- 3-4+ years working specifically in Information Security roles involving Risk Analysis, Information System Security Assessment, Compliance Audit with Regulations, Frameworks, & Standards
- Bachelor's degree in Information Technology or related field, or equivalent experience
- Required Certifications: Certified in Risk & Information Systems Control (CRISC), Certified Information Systems Auditor (CISA), or Certified Information Systems Security Professional (CISSP) (Current status, or obtained within 9 months of assuming role)
- Strong experience leveraging auditing principles and methods to evaluate policies, processes, systems, and vendors to identify business risks and control gaps
- Experience in administering Risk management programs for technology and information security
- Strong, technical knowledge of modern Systems, Services, Cloud Applications/Platforms, Identity Services, and Data Storage/Handling and their areas of Risk and Threat exposure
- Experience with administering, maintaining, and leveraging a Risk Register to track and communicate identified Risk and its required remediation
- Knowledge of statistics, reporting and analytical tools to analyze and solve complex problems
- Proficiency in necessary productivity tools (i.e. Microsoft Excel, PowerPoint, Word etc.) for analytics and presentations
- Operate with strong integrity with ability to handle projects of a sensitive & confidential nature
- Excellent written and verbal communication skills with a proven ability to translate technical or abstract concepts into a narrative that is easily understood by clients.
- Ability to thrive in fast-paced environment.
Some Things You Should Know:
- No other builder can offer the collaborative design-build approach that Clayco does.
- We work on creative, complex, award-winning, high-profile jobs.
- The pace is fast!
- This position is classified as a safety-sensitive role in accordance with applicable state and federal laws. Candidates selected for this position will be subject to a comprehensive background check, which includes mandatory drug testing.
Why Clayco?
- 2025 Best Places to Work – St. Louis Business Journal, Los Angeles Business Journal, and Phoenix Business Journal.
- 2025 ENR Top 400 – Top Data Center Contractor (Top 3).
- 2025 ENR Top 100 Design-Build Firms – Design-Build Contractor (Top 5).
- 2025 ENR Top 100 Green Contractors – Green Contractor (Top 3).
Benefits:
- Discretionary Annual Bonus: Subject to company and individual performance.
- Comprehensive Benefits Package Including: Medical, dental and vision plans, 401k, generous PTO and paid company holidays, employee assistance program, flexible spending accounts, life insurance, disability coverage, learning & development programs and more!
Compensation:
- The salary range for this position considers a wide range of factors in making compensation decisions including but not limited to: Education, qualifications, skills, training, experience, certifications, internal equity, and location. Compensation decisions are dependent on the facts and circumstances of each case.
- Gilder Search Group is looking for a Sr. GRC Analyst focused on Third-Party & Human Risk Management in St. Louis, Missouri. The role ensures all human and third-party risks to Clayco are identified and treated appropriately. Key responsibilities include owning the TPRM...Senior
- The Role We Want You For Under the direction of and in collaboration with the GRC Manager, the Sr. GRC Analyst, Third-Party & Human Risk Management (TPHRM) is a risk focused, highly analytical role that ensures all human and third‑party risk to Clayco is identified, quantified...SeniorImmediate startFlexible hours
- ...GRC Analyst Join our team as a GRC Analyst and play a key role in regulatory compliance, IT risk management, security. You'll assess risks, support audits, and develop policies that align with industry standards. If you have a solid IT security background, experience...SuggestedCasual workWork at officeWork from homeHome officeNight shiftWeekend work
- ...Sky Mavis is seeking a Senior GRC Analyst focused on Third-Party and Human Risk Management in St. Louis, Missouri. This role requires 6–8+ years of experience in Risk Assessment and Information Security, with strong analytical skills. You will lead the Vendor Risk Management...Senior
$77.2k - $96.5k
...Time: Be the Linchpin of Security and Compliance at WWT As an Information Security (InfoSec) Governance, Risk, and Compliance (GRC) Analyst within Audit and Compliance, you will play a pivotal role in ensuring that WWT’s information security practices not only align...SuggestedFull timeContract workPart timeRemote workFlexible hoursShift work$100k - $179k
...About this role: Wells Fargo is seeking a Senior Risk Asset Review Specialist within Credit Risk as part of Corporate Risk. Learn more about the career areas and lines of business at wellsfargojobs.com ( . Credit Risk, which independently oversees the management...SeniorWork experience placementRelocation package- ...MANTECH seeks a motivated, career and customer-oriented Senior GEOINT Analyst to join our team in St. Louis, MO! Job duties include, but are not limited to: Conduct GEOINT analysis on national security issues using imagery, geospatial data, and multi-INT...SeniorWork at officeRemote work
$87.8k - $160.9k
...Risk Consulting - Digital Risk - Senior Consultant - Consumer & HealthcareLocation: New York Other locations: Anywhere in Region Salary: Competitive Date: Aug 8, 2026Job DescriptionAt EY, we're all in to shape your future with confidence. We'll help you succeed in a globally...SeniorSummer holidayFlexible hours- ...Spectrum Brands, Inc in St. Louis, MO is seeking a Senior Regulatory Affairs Specialist to drive product compliance and innovation for pet care products. This hybrid position involves collaboration with various teams to manage regulatory risks and ensure successful product...Senior
$126.8k - $211.4k
...Legal Compliance Senior Manager - Express Scripts - Remote Leads team of Analysts with full responsibility for team output including compliance to licensure regulations and associated reporting activity. Implements protocols for license management and record keeping...SeniorTemporary workWork at officeLocal areaRemote workWork from home- ...Tetra, Instant Ocean, Marineland, 8-in-1, Dingo, FURminator, Nature's Miracle, GloFish, DreamBone and SmartBones. Job Summary As a Senior Regulatory Affairs Specialist for the Pet Care team in our Earth City, MO office, you will be partnering across marketing, R&D, supply...SeniorWork at officeWork from homeWorldwideMonday to Friday
- BJC Medical Group is hiring a Senior Compliance Coordinator in St. Louis, MO. This remote position involves reviewing specialty provider documentation for billing accuracy and developing educational materials. The ideal candidate will have 5-10 years of experience, a high...SeniorRemote job
- ...Numerof & Associates, based in St. Louis, is looking for a Senior Analyst for their life sciences practice. This role requires 3-5 years of experience in a pharmaceutical or consultancy setting, with advanced analytical skills and a scientific degree. The position involves...Senior
$70.35k
...Senior Crime Analyst REJIS is seeking a highly skilled Senior Crime Analyst to serve as the lead individual contributor within our Crime Analysis Unit. In this role, you will conduct advanced tactical, strategic, investigative, and administrative analyses to support...Senior- ...Sr. Internal Controls AnalystThe Sr. Internal Controls Analyst will support the Internal Controls Manager to develop and maintain an effective internal controls environment within Bunzl North America through active engagement within the risk assessment, control creation...SeniorWork at office
- ...Senior Program Analyst On-Site | Scott Air Force Base, IL | Active Secret Clearance Required Why This Role Exists The work we do has real impact, and the people behind it matter just as much. D&G Solutions is seeking a highly motivated Senior Program Analyst...SeniorFlexible hours
- CEdge Inc in Saint Louis, MO is looking for a Lead Analyst / Project Manager to drive SOW project execution. This role requires strong leadership and project management skills to oversee project activities and client interaction. Candidates should have at least 3 years...SeniorRemote job
- ...Your adventure begins now-unleash your potential with MANTECH! ManTech seeks a motivated, career and customer-oriented Senior Imagery Analyst to join our team in St. Louis, MO ! Responsibilities include, but are not limited to: Conduct advanced multi-...SeniorWork at officeLocal area
$91k - $321.5k
...code of conduct, and independence requirements. The Opportunity As a Risk Management - Contract Specialist - Managed Services - Senior Manager, you will lead initiatives in enterprise risk management, focusing on business continuity, risk model implementation, and...SeniorContract workH1b$91k - $121k
...Job Overview: The Senior Incentive Analyst is a hands-on role that will play a key part in managing and supporting ongoing incentive compensation needs. This individual will focus on the analysis, evaluation, creation, and implementation of compensation programs designed...SeniorTemporary workRelocationRelocation package$126.7k - $166.3k
...Senior Business Analyst At Accenture Federal Services, nothing matters more than helping the US federal government make the nation stronger and safer and life better for people. Our 13,000+ people are united in a shared purpose to pursue the limitless potential of technology...SeniorLocal areaRelocation$91k - $121k
...Job Overview: The Senior Compensation Analyst is a strategic advisor responsible for designing, implementing, and managing compensation programs that align with the organization's business objectives, talent strategy, and market competitiveness. This role partners closely...SeniorTemporary workLocal areaRelocationRelocation package- ...practices Ensure data products align with business needs and organizational goals Job Description: Insight Global is seeking a Senior Data Analyst for a leading media and advertising technology organization. This individual will serve as a critical bridge between business...Senior
- ...June 2024, data as of December 2023. Compensation provided for using, not obtaining, the rating. Overview Finance is seeking a Senior Analyst to support the Accounting Department in a variety of controllership capabilities for our Canadian Trust Company, including accounting...SeniorTemporary workWork experience placementWork at officeHome officeFlexible hours
- Responsibilities Kforce's client, a global organization located in the Saint Louis, MO area is seeking a Senior Internal Controls Analyst to support the development, implementation, and continuous improvement of its internal controls framework. This hybrid role partners...SeniorHourly payContract workWork at office
$123.5k - $229.5k
Technical Visionary For Next Generation Power DistributionWe're looking for people who put their innovation to work to advance our success – and their own. Join an organization that ensures a more secure world through connecting and protecting our customers with inventive...SeniorMinimum wageFull timeTemporary workLocal areaRelocation packageFlexible hoursShift work$110k - $125k
...Position Summary The Senior Business Analyst, Wealth Technology is responsible for leading the definition, documentation, and execution of business processes and technology initiatives across the organization, with a primary focus on Salesforce initiatives for advisor...SeniorWork at officeLocal area3 days per week$126.7k - $166.3k
...positive, lasting change that moves missions and the government forward! Business Analyst – Application Migration Team Job Overview: We are seeking a highly skilled and motivated Senior Business Analyst to join our dynamic application migration team. In this critical...SeniorLive inWork at officeLocal areaRelocation$75k - $110k
...growth for employees, customers, and shareholders. Opportunity: We are currently seeking a Forensic Accountant at the Staff or Senior level who has 1-5 years of public accounting experience. This role is based out of St. Louis. The majority of our engagements...SeniorWork experience placementLocal areaFlexible hoursNight shift- We are seeking an experienced Cybersecurity GRC Analyst for a 6-month engagement to support our ongoing security compliance and governance initiatives. The ideal candidate will have strong hands-on experience with ISO 27001 , including audit support, policy development,...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior GRC Analyst. Be the first to apply!
- senior associate attorney Saint Louis, MO
- senior developer Saint Louis, MO
- senior aws cloud engineer Saint Louis, MO
- remote senior salesforce administrator Saint Louis, MO
- senior marketing operations manager Saint Louis, MO
- senior manager tax Saint Louis, MO
- senior property accountant Saint Louis, MO
- senior medical assistant Saint Louis, MO
- senior tax Saint Louis, MO
- senior helpdesk technician Saint Louis, MO





