Senior GRC Analyst
Gilder Search Group
The Role We Want You For Under the direction of and in collaboration with the GRC Manager, the Sr. GRC Analyst, Third-Party & Human Risk Management (TPHRM) is a risk focused, highly analytical role that ensures all human and third‑party risk to Clayco is identified, quantified, documented, and treated to an acceptable level across the Clayco organization. This role will assume ownership of the Third-Party Risk Management (TPRM) process to gather details on the security practices and compliance levels for each third‑party being considered or contracted for a solution or services to assess the potential for compromise due to a control gap or exploitable misconfiguration as well as non‑compliance with legal and regulatory requirements. Additional contribution will be expected for internal assessments and third‑party audits to gather and submit discovery and transactional responses and artifacts. The Sr. GRC Analyst will also assume ownership of Human Risk Management (HRM) including the delivery of comprehensive security awareness education, the end‑to‑end execution of phishing simulation programs, and the technical maintenance and life‑cycle management of security awareness platforms. Beyond simple training, the position focuses on Human Risk Management (HRM), using data‑driven insights to identify high‑risk user groups and implementing targeted interventions to proactively mitigate human‑centric threats to cultivate a security‑first culture internally through education and behavioral change. Additional responsibilities will be assigned as deemed necessary. Any travel is usually planned in advance, but issues may arise which warrant immediate travel to one or more satellite locations. The Specifics of the Role Assumes operational ownership of the 3rd Party Vendor Risk Management program identifying, assessing, and mitigating risks associated with external vendors, suppliers, and service providers Conducts due diligence on new and existing vendors by reviewing security questionnaires, SOC reports, compliance certifications, and other supporting attestations Captures, analyzes, and recommends treatment, assignment, and tracking of identified issues Collaborates with legal and stakeholder teams to ensure contracts include specific clauses for data protection, service‑level agreements (SLAs), and AI governance Documents and communicates all relevant findings and recommendations to stakeholders Tracks, monitors, and reports on execution of remediation action plans and escalates inadequate responses or progress Assumes ownership of the Security Awareness program determining appropriate topics, themes, scopes, and timing of cyber awareness communications, events, and content delivery Conducts regular, simulated social engineering exercises to assess and improve employee recognition of real‑world attacks Develops engaging, simple materials—such as infographics, newsletters, and videos that translate complex technical risks into layman’s terms Maintains Security Awareness training and simulation platforms to support content delivery and End User interaction, including support for any Client‑side functionality (i.e., "Report Phish" button) Plans, coordinates, and executes activities for Cybersecurity month Partners with Employee Relations, Legal, and Marketing to ensure security messaging is integrated into the broader corporate culture Tracks Key Risk Indicators (KRI's) such as actual phishing click-through rates, failed simulations, and missed training as well as Key Performance Indicators (KPIs) like suspicious email reporting, passed simulations, and successful training completion status to measure program effectiveness for leadership Requirements 6‑8+ years’ experience in Risk & Compliance Assessment, Audit & Reporting, or similar functions, preferably within the Information Security or Technology fields 3‑4+ years working specifically in Information Security roles involving Risk Analysis, Information System Security Assessment, and/or Security Awareness and Human Risk Management Bachelor’s degree in Information Technology or related field, or equivalent experience Required Certifications: Certified in Risk & Information Systems Control (CRISC), SANS Security Awareness Professional (SSAP), and Certified Third‑party Risk Professional Certification (CTPRP) (Current status, or obtained within 9 months of assuming role) Strong experience leveraging auditing principles and methods to evaluate policies, processes, systems, and vendors to identify business risks and control gaps Strong knowledge of Regulations, Frameworks, and Standards such as NIST 800-171/CSF/RMF, ISO27001, CIS Critical Security Controls, etc. Strong, technical knowledge of modern Systems, Services, Cloud Applications/Platforms, Identity Services, and Data Storage/Handling and their areas of Risk and Threat exposure Experience with administering, maintaining, and leveraging a Risk Register to track and communicate identified Risk and its required remediation Knowledge of statistics, reporting and analytical tools to analyze and solve complex problems Proficiency in necessary productivity tools (i.e., Microsoft Excel, PowerPoint, Word etc.) for analytics and presentations Operate with strong integrity with ability to manage projects of a confidential nature Ability to translate technical or abstract concepts into a narrative that is easily understood Ability to thrive in fast‑paced environment. Some Things You Should Know This position is classified as a safety‑sensitive role in accordance with applicable state and federal laws. Candidates selected for this position will be subject to a comprehensive background check, which includes mandatory drug testing. Benefits Discretionary Annual Bonus: Subject to company and individual performance. Comprehensive Benefits Package Including: Medical, dental and vision plans, 401k, generous PTO and paid company holidays, employee assistance program, flexible spending accounts, life insurance, disability coverage, learning & development programs and more! Compensation The salary range for this position considers a wide range of factors in making compensation decisions including but not limited to: Education, qualifications, skills, training, experience, certifications, internal equity, and location. Compensation decisions are dependent on the facts and circumstances of each case. #J-18808-Ljbffr Gilder Search Group
$138k - $173k
THE POSITIONOur roster has an opening with your name on itFanDuel is seeking a Senior Technology Governance, Risk & Compliance (GRC) Analyst to join its Technology GRC team as a strategic specialist supporting our first line of defense (1LOD) function. This role offers...SeniorTemporary workWork at officeLocal areaWorldwideShift work- Gilder Search Group is looking for a Sr. GRC Analyst focusing on Third-Party & Human Risk Management in Atlanta, Georgia. This role involves risk analysis, compliance assessments, vendor management, and developing security awareness training. The ideal candidate has 6-8...Senior
- Illumia is seeking an experienced Business Risk Analyst to support information security compliance, GRC workflow, and risk management initiatives. The role involves risk assessments, business continuity planning, and coordinating audits with external auditors and internal...SeniorRemote job
- ...collect evidence, and manage remediation across Legal, Regulatory, Internal Audit and other stakeholders. The role emphasizes scalable GRC processes and cross‑functional collaboration. In this position you will drive third‑party risk assessments, support SOC 2, PCI and...SeniorRemote job
- ...continues to expand its technology capabilities and strengthen its security posture. We are seeking a Governance, Risk & Compliance (GRC) Analyst to support critical governance, risk management, compliance, and audit readiness initiatives. This role is ideal for a detail-...Suggested
- ...GRC Analyst (Governance, Risk & Compliance) We are seeking a mid-level GRC Analyst with strong client-facing experience to support governance, risk, and compliance initiatives across enterprise environments. The ideal candidate will have prior experience working with...
- ...possible. Job Summary The Cybersecurity Vulnerability Governance Analyst is responsible for governing and overseeing the organization's... ...governance or vulnerability management programs. Experience with GRC platforms such as Archer, ServiceNow, MetricStream, or similar solutions...Full timeImmediate startFlexible hours
- ...who can contribute to the excellence of our academic community. Description JOB DESCRIPTION: The Senior IT GRC (Governance, Risk, and Compliance) Analyst oversees technical design, implementation, maintenance, and responsibilities for multiple information security...SeniorWork experience placementRemote workWork from homeFlexible hours
- Merci Technologies is seeking a GRC Analyst to support governance, risk, and compliance for an enterprise client. The role sits at the intersection of security, audit, and business operations, translating complex regulatory requirements into practical controls that teams...Remote jobFull timeContract work
- ...both rules designer and workbench.Responsibilities:Work directly with external client companies, internal data scientists, business analysts, and other underwriters to develop and build out accelerated underwriting (AUW) programs. Heavy emphasis on best in class rules...SeniorShift work
$119k - $193k
...extraordinary future.About This Role:Forrester is currently looking for a Senior Analyst to conduct research and deliver strategic advice for risk... ...in compliance management, internal or external audit, and GRC platforms is strongly desired.The successful candidate...SeniorFull timeFor contractorsRemote work- ...stakeholders to drive impact; develops and communicates a compelling vision and inspires actionBuilds trust-based relationships with senior leaders within and outside of the team; collaborates generously with others and is sought after as a key thought partnerStrong...SeniorApprenticeshipWork at office
$73.36k - $118.77k
MorganFranklin Consulting LLC is seeking a qualified professional to join their Risk & Regulatory team in Atlanta, GA. This role involves assisting clients with Sarbanes-Oxley compliance, conducting risk assessments, and supporting internal audit initiatives. The ideal ...Senior$73.36k - $118.77k
Highspring (Formerly MorganFranklin Consulting) in Atlanta, GA is seeking a professional with experience in risk management and internal audits. The role involves assisting companies with Sarbanes-Oxley compliance, executing audits, and providing best practices on risk ...Senior- ...career where your contributions are valued, your growth is supported, and your work makes a lasting impactJob Summary:The Senior Risk Management Analyst is responsible for collecting, analyzing, validating, and presenting the Company's exposure, claims, and insurance data...SeniorFull time
$96k - $181k
Location:4910 Tiedeman Road, Brooklyn OhioAbout the JobThe Senior Compliance Officer, Horizontal Compliance is responsible for assisting the applicable Compliance Executive in overseeing compliance risk mitigation and discouraging actions that may expose KeyCorp and its...SeniorFull timeWork at officeFlexible hours- LGE Community Credit Union is seeking an experienced fraud investigator to apply and enforce loss prevention policies and programs. The role focuses on managing fraud prevention strategies and conducting investigations to safeguard assets while maintaining a positive member...Senior
$50 - $55 per hour
Georgia Tech Research Institute (GTRI) is seeking a (GRC) Cybersecurity Analyst for a W2 full-time role in Atlanta, GA. The position offers hybrid work and compensation of $50.00 - $55.00 per hour with strong emphasis on governance, risk and compliance in security operations...Hourly payFull time$50 - $55 per hour
Position: (GRC) Cybersecurity Analyst Client: Georgia Tech Research Institute (GTRI) Employment Type: W2 Only Location: Atlanta, GA (Hybrid) Ideal Candidate Profile Experience 5-7+ years in IT/Cybersecurity Technical background (Engineering > GRC preferred) Experience...Hourly pay$72k - $141k
...matter and are part of something important, ensuring the abilities of all employees are used to their fullest potential. The Compliance Senior Consultant is a strategic individual contributor role designed to lead and support Corporate Compliance operations and programs....SeniorFull timeWork experience placementWork at office- Posted 4 days agoSenior P&C Consulting Actuary opening in Atlanta, Boston, Charlotte, Chicago, Dallas, Houston, Los Angeles, Montreal, New York, or Philadelphia. Manage client projects involving your choice of Reserving, Pricing, and/or Capital Modeling. Consult to (re)...Senior
- Senior IT Risk & Security Compliance Officer Emory University is hiring for the role of Senior IT Risk & Security Compliance Officer, Atlanta... ...for this Cybersecurity role in Atlanta , one of the metros GRC Careers tracks for governance, risk, and compliance hiring. See...SeniorWork at officeLocal areaRelocation package
- ...Electric Transmission Planning Engineer / Senior EngineerPerforms transmission planning and power system studies, including power flow, steady state, short circuit, dynamic and transient stability and contingency analyses. Provides technical expertise and analytical support...Senior
- ...the region and perform compliance oversight to protect Invesco from regulatory, reputational, and financial risk.About the role: The Senior Compliance Officer position assists Invesco's Americas business operations with respect to compliance with applicable state,...SeniorFull timeWork at officeFlexible hours
- ...Voyix is headquartered in Atlanta, Georgia, and serves customers in more than 35 countries worldwide.Position Summary The Senior Trade Compliance Analyst supports NCR Voyix’s global trade compliance program by ensuring adherence to U.S. import and export laws and...SeniorFull timeWorldwideFlexible hours
$163k - $204k
Position Summary: AIG’s Investments group is responsible for managing the investment assets of AIG, including affiliated insurance companies, through internal and external managers. The Investments Compliance team provides compliance and regulatory support to AIG’s Investments...SeniorFull timeWork at office$65.11k - $85k
A leading educational institution in Atlanta is seeking an Enterprise Risk Associate Senior to enhance the Enterprise Risk Management (ERM) program. This role involves aiding in governance, risk identification, assessment and ensuring proper alignment of risk practices...SeniorFull time- WestRock Company in the United States seeks a Senior Risk Analyst to support the ERM program by identifying, assessing, monitoring, and reporting risks across the enterprise. This role strengthens linkages between enterprise risks, mitigation plans, and internal audit activities...Senior
- Affirm is seeking a Senior Analyst (L5) to own the entire analytical lifecycle—from question to business decision—in a remote-first setting across the United States. You will translate regulatory and economic insights into actionable strategies, collaborating with ML,...SeniorRemote job
- 0011 Checkout LLC in Atlanta, Georgia is looking for an individual with expertise in underwriting and financial analysis to enhance business models and support credit risk management. This role involves collaborating with internal departments and providing mentorship to...Senior
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior GRC Analyst. Be the first to apply!
- grc analyst Atlanta, GA
- senior operations associate Atlanta, GA
- senior safety specialist Atlanta, GA
- senior technology project manager Atlanta, GA
- remote senior business analyst Atlanta, GA
- senior director fp&a Atlanta, GA
- senior manager clinical operations Atlanta, GA
- senior supervisor Atlanta, GA
- senior researcher Atlanta, GA
- senior leadership Atlanta, GA

