Senior GRC Analyst
Louisiana Blue
Job Title
Leads the validation, assessment, and authorization processes necessary to assure that existing and new information technology (IT) systems meet the organization's cybersecurity and risk requirements.
Qualifications
Education:
- Bachelor's in IT, Audit, and/or related fields required
- Four years of related experience can be used in lieu of a Bachelor's degree.
Work Experience:
- 4 years of relevant, specialized experience and highly developed proficiency within multiple disciplines including Governance, Risk, and Compliance required
Skills and Abilities:
- This position does not have any direct reports but is expected to mentor and lead the operational activities of junior team members.
- Requires excellent analytical, critical thinking, communication, marketing, and consulting skills.
- Hands-on technical expertise in cybersecurity, IT infrastructure (networking, server management, etc.), cloud technologies, or application development is highly desirable.
- Works under minimal supervision with latitude for independent judgment in a remote environment. Conducts tasks and assignments as directed or independently.
- Requires experience in and working knowledge of at least 2 of the following disciplines:
- Technology Risk Management
- Governance Documentation Management (i.e. Policies, Processes, and Procedures)
- Cybersecurity Awareness and Training
- Management of IT/Security Controls & Ensuring Compliance with Legal and Regulatory Requirements
- Auditing (Preferably IT Audit)
- Technical Management of IT Infrastructure (e.g. networking, server administration, cloud technologies, etc.)
- Cybersecurity Architecture, Incident, and Response
Licenses and Certifications:
- Multiple Cybersecurity, IT or Security Governance, Information Systems Audit, Compliance, Risk Management, or computer networking trainings and certifications are preferred (e.g. CISA, CRISC, CGEIT, CISM, CISSP, CompTIA Sec+, CIA, CRMA, COSO/ERM, etc., or other relevant certifications from reputable organizations such as GIAC, ISC2, ISACA, or Comp TIA).
Accountabilities and Essential Functions
- Collaborates and consults with a team of Cybersecurity and IT professionals to accomplish multiple of the following objectives as determined by management.
- Governance:
- Collaborates on the development and implementation of the annual strategic plan
- Develops Board-level reporting
- Maintains and ensures integration with the company's cybersecurity, control, and risk management frameworks
- Manages and maintains a functional, accessible, and protected control library and facilitates reviews with control owners
- Tracks pertinent laws and regulations and maps relationships between various legal, regulatory, and contractual requirements (HIPAA, SOC-2, SOC-1, AFRMR, etc.) and various security cybersecurity and control frameworks (NIST CSF, NIST 800-53, COBIT, etc.)
- Leads in the design of security controls to ensure alignment with the organization's risk appetite and tolerance levels to support business objectives
- Develops and maintains IT and Cybersecurity governance documentation assets including charters, policies, standards, processes, procedures, and artifacts
- Ensures alignment of controls with all supporting governance documentation
- Facilitates the identification of metrics and key performance indicators to enable the measurement of security controls performance in meeting business objectives
- Trains and promotes awareness to the workforce on cybersecurity responsibilities and protections through phishing simulations, remote awareness events, computer-based trainings, and frequent communications
- Develops, maintains, and reports on operational governance metrics
- Risk Management:
- Maintains risk alignment to the company's chosen cybersecurity framework
- Assesses BCBSLA's technical environment for alignment to the chosen Cybersecurity Framework and develops remediation efforts to close gaps and mature the cybersecurity control environment.
- Collaborates with Security Architecture, SIRT, and IT technical teams to identify and assess risk, perform security reviews, identify gaps in security architecture, and develop a security risk management plan
- Assesses risk for their inherent, target, and residual likelihood of occurrence and impact to the organization
- Develops comprehensive risk assessments for reporting to multiple audiences including business leaders, technical personnel, audit personnel, senior management, and the board of directors
- Applies Cybersecurity architecture concepts in the design of controls to effectively mitigate risk
- Recommends and coordinates security initiatives to mitigate risks to acceptable levels as defined by corporate appetite tolerances
- Provides enterprise cybersecurity risk management guidance and education. Integrates risk management with appropriate organizational functions.
- Participates in the acquisition process as necessary, following appropriate risk management practices
- Verifies risk management documents, policies, and other governance products
- Develops, maintains, and reports on operational risk management metrics
- Compliance:
- Develops and maintains continuous control monitoring schedules and oversees security control assessments to verify effectiveness and efficiency
- Monitors controls to ensure controls remain within tolerances, function effectively and efficiently, and are appropriate
- Provides documentation and training to ensure security controls are effectively performed
- Serves as liaison to auditors, consultants, IT management, cybersecurity personnel, and other personnel as needed to ensure organizational compliance with applicable rules, laws, and regulations
- Tracks and manages audit findings for the IT Division to ensure accurate reporting and timely resolution
- Consults with control experts to provide documentation in support of internal and external audit activities
- Develops, maintains, and reports on operational compliance metrics
- General Governance, Risk, and Compliance (GRC) Support:
- Leads process analysis, development, & improvement efforts
- Assists in developing, testing, and delivering solutions, support, reporting, information, and relationship management to satisfy client requests
- Acts as a liaison between clients and others inside or outside of BCBSLA to facilitate solutions, information sharing, and effective communication
- Contributes to executive and Board-level reporting
- Provides overall support to all Technology GRC team efforts and serves as a resource to other team members
- Provides proactive and reactive subject matter expertise to all levels of the organization
- Interviews process owners and review process design to gain understanding of business requirements
Additional Accountabilities and Essential Functions The Physical Demands described here are representative of those that must be met by an employee to successfully perform the Accountabilities and Essential Functions of the job. Reasonable accommodations may be made to enable an individual with disabilities to perform the essential functions.
- Perform other job-related duties as assigned, within your scope of responsibilities.
- Job duties are performed in a normal and clean office environment with normal noise levels.
- Work is predominately done while standing or sitting.
- The ability to comprehend, document, calculate, visualize, and analyze are required.
An Equal Opportunity Employer
- ...to its workforce, Kokosing is the winning team.Job Description:We are looking for a Security Governance, Risk, and Compliance (GRC) Analyst to support and mature our security and compliance programs across a large construction organization. This role focuses on maintaining...SeniorFull timeFor contractors
$130k - $170k
...extend healthspan. The Governance, Risk, and Compliance (GRC) team helps ensure technology and cybersecurity risks... ...organization.WHOOP is seeking an execution-oriented Senior Governance, Risk, and Compliance Analyst to lead the day-to-day execution and support the ongoing...SeniorFull timeWork at officeRelocation$80.05k - $165k
...end-to-end issue management activities, including intake, validation, prioritization, assignment, remediation tracking, and closure of GRC-related issues in ServiceNow, ensuring timely resolution, appropriate evidence, and alignment with audit, risk, and regulatory...SeniorFull timeWork at office$138k - $173k
THE POSITIONOur roster has an opening with your name on itFanDuel is seeking a Senior Technology Governance, Risk & Compliance (GRC) Analyst to join its Technology GRC team as a strategic specialist supporting our first line of defense (1LOD) function. This role offers...SeniorTemporary workWork at officeLocal areaWorldwideShift work- ...ROLE, NOW OR IN THE FUTURE. (e.g., H-1B, STEM OPT, TN, etc.)About the RoleAs a member of the Information Security team, the IS GRC Senior Analyst - Risk & Compliance will be responsible for understanding the firm’s security risk and compliance requirements. You will...SeniorFull timeContract workWork experience placementH1bRemote workVisa sponsorshipRelocation packageMonday to Friday
- ...be a US Citizen or Green Card holder NO THIRD PARTIES Only local candidates will be contacted We are seeking a highly motivated GRC Analyst to support the modernization and transformation of our Governance, Risk, and Compliance (GRC) program. This role is ideal for someone...SeniorContract workLocal area
- ...Role Hotman Group is a boutique cybersecurity and GRC consulting firm doing meaningful work for clients who need GRC... .... What You Will Do As an Experienced or Senior GRC Analyst at Hotman Group you will work directly with clients to help them...SeniorPermanent employmentFull timeContract workRemote work
- ...Owning and advancing the governance, risk, and compliance program, the full-time Senior GRC Analyst will manage compliance frameworks, conduct risk assessments, and collaborate with cross-functional teams in a remote capacity. Key Responsibilities: Lead the GRC program...SeniorFull timeRemote work
- ...Senior GRC Analyst Location: Remote About Compyl Compyl is a high-growth, venture-backed GRC and automated security compliance platform built by security practitioners for security practitioners. Founded in 2020 by two former CISO's, we replace the spreadsheets...SeniorLocal areaRemote work
- ..., friends, and families in providing best-in-class products and services!Job SummaryThe Governance Risk & Compliance (GRC) Cybersecurity Senior Analyst plays a critical role in ensuring that UGI Utilities Inc. operates within its regulatory, legal, and compliance obligations...SeniorFor contractors
- ...Sr. GRC Analyst, Risk Management Under the direction of and in collaboration with the GRC Manager, the Sr. GRC Analyst, Risk Management is the primary owner and operational steward of the Enterprise Risk Register. This role is responsible for ensuring all identified...SeniorFor contractorsImmediate startFlexible hours
$114k - $163k
...Senior GRC Analyst Department: Compliance & Fraud Employment Type: Full Time Location: Pittsburgh Onsite Compensation: $114,000 - $163,000 / year Description Role Summary Wolfe is a Pittsburgh-based FinTech company operating consumer gifting and...SeniorFull timeContract workTemporary work- ...Sr. GRC Analyst, Third-Party & Human Risk Management Clayco is a full-service, turnkey real estate development, master planning, architecture, engineering, and construction firm that safely delivers clients across North America the highest quality solutions on time,...SeniorFor contractorsImmediate startFlexible hours
- Wiz is seeking a Remote Senior Governance, Risk, and Compliance Analyst - Governance to join our team. You will report to the Manager, Governance, Risk, & Compliance and collaborate with a cross-disciplinary Wizards group to align governance with business needs and enhance...SeniorRemote job
- Crunchyroll is seeking an experienced Risk Analyst to support our Information Security GRC team. This role emphasizes governance, risk, and compliance, ensuring technology evolution aligns with employee needs and strategic goals. Successful candidates will have over 8 years...SeniorFlexible hours
- A leading cybersecurity firm is seeking an Experienced or Senior GRC Analyst to join their remote team. The successful candidate will lead audits, design compliance programs, and guide clients in cybersecurity strategies. Applicants should have 5+ years of relevant experience...SeniorRemote jobPermanent employment
- Ellenco Estágios e Treinamentos is seeking a Senior Information Security GRC Analyst to manage security audits and compliance efforts. The role requires over 10 years of experience in information security and a strong understanding of NIST standards. This position allows...SeniorRemote job
- Gilder Search Group is looking for a Sr. GRC Analyst focused on Third-Party & Human Risk Management in St. Louis, Missouri. The role ensures all human and third-party risks to Clayco are identified and treated appropriately. Key responsibilities include owning the TPRM...Senior
- A staffing agency based in Dallas, Texas is seeking a Senior Security Analyst to identify and mitigate security risks within the IT environment.... ...Information Security or IT and at least 3 years of experience in GRC/risk management. Competitive compensation and benefits...Senior
- Sky Mavis is seeking a Senior GRC Analyst focused on Third-Party and Human Risk Management in St. Louis, Missouri. This role requires 6-8+ years of experience in Risk Assessment and Information Security, with strong analytical skills. You will lead the Vendor Risk Management...Senior
- The Trade Desk in New York, NY seeks a Technology Governance & Risk Senior Analyst to lead global governance, risk, and compliance initiatives across SOX, SOC, CCPA, and PADFAA. You will partner with engineering, legal, and business teams to assess risk, design and test...SeniorWorldwide
- Illumia is seeking an experienced Business Risk Analyst to support information security compliance, GRC workflow, and risk management initiatives. The role involves risk assessments, business continuity planning, and coordinating audits with external auditors and internal...SeniorRemote job
- Sky Mavis seeks a Sr. GRC Analyst in Phoenix, AZ, to manage Third-Party and Human Risk Management. This analytical role involves vendor risk assessment, security awareness training, and compliance evaluation, ensuring holistic risk management. Candidates should have significant...Senior
- Gilder Search Group is looking for a Sr. GRC Analyst focusing on Third-Party & Human Risk Management in Atlanta, Georgia. This role involves risk analysis, compliance assessments, vendor management, and developing security awareness training. The ideal candidate has 6-8...Senior
- Lennox is seeking a seasoned SAP GRC professional to bridge IT and business for a secure, compliant SAP environment. You will support governance, risk assessments, and control implementations across SAP modules including EWM and FI. The role requires deep SAP GRC experience...Senior
$110k - $140k
Senior GRC Analyst - Accounting - $110,000 - $140,000 You get to build the GRC function from scratch at a nationally recognized, PE-backed company in a major growth phase. This is a greenfield opportunity. There is no inherited mess to untangle, no legacy processes holding...Senior- Gilder Search Group is looking for a Sr. GRC Analyst to manage Third-Party & Human Risk while ensuring risks are identified and treated satisfactorily. The role requires 6-8 years in risk assessment, with a bachelor's degree and required certifications expected. You'll...SeniorFlexible hours
- ...reporting Manage the maintenance of our compliance policies, standards, and procedures Report on our compliance posture to senior leadership Scale our GRC function with AI and automation, building quick wins and scoping requirements for Engineering to fully automate the...Senior
- Bloomin' Brands is seeking an experienced information security leader to drive risk management, compliance and governance across the organization. You will develop policies, assess controls, and oversee risk management initiatives to protect data and systems. The role requires...Senior
- Bloomin' Brands, Inc. is seeking a Sr. GRC Analyst in Tampa, FL to support governance, risk, and compliance efforts across the organization. The role combines onsite and remote work in a hybrid schedule at the Tampa Restaurant Support Center. You will develop policies,...SeniorRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior GRC Analyst. Be the first to apply!
- grc analyst United States
- senior groundskeeper United States
- senior maintenance supervisor United States
- senior operations associate United States
- senior safety specialist United States
- lcb senior living United States
- senior technology project manager United States
- senior c++ developer United States
- remote senior business analyst United States
- senior internal tool engineer United States

