GRC Analyst - Hybrid IT Compliance & Risk
W. R. Berkley Corporation
Company Details Berkley Regional Shared Services (BRSS) is the service provider for the Regional Segment of W. R. Berkley Corporation , a Fortune 500 Commercial Lines Insurance Company. With key locations across the United States, BRSS provides insurance service support to our six Regional Segment companies, allowing them to focus on their unique competitive advantages and differentiators within their local marketplaces. BRSS’s wide reach ensures that ideas and opinions are considered at every level of the organization to guarantee we find the best solutions possible. Driven by a commitment to collaboration, BRSS partners with our customers and Operating Units by providing comprehensive solutions that not only address the challenge at hand, but proactively plan for the “What’s Next” in our industry and beyond.Our mission is to drive transformation and provide exceptional capabilities and service to the operating units. BRSS generates meaningful and measurable value by delivering insights for our customers, partners, and shareholders using data and analytics. Our vision is to enable operating unit profit and growth objectives by designing and delivering scalable solutions. With a culture centered on innovation and service stewardship, BRSS stands as a community of leaders with eyes toward the future -- leaders who truly care about growing not only their team members, but themselves, and take pride in their employees who shine. BRSS offers endless ways to get involved and have the chance to grow your career into a wide range of roles. Come join us as we push forward into the future of industry leading technology and service solutions. This role will be based in the Glen Allen, VA location where we offer a hybrid work schedule with 4 days in the office; and 1 day remote. The company is an equal opportunity employer.#LI-hybrid, #LI-LD1 Responsibilities As a Governance, Risk, & Compliance Analyst , you willsupport the W. R. Berkley Regional Segment by executing and documenting IT governance, risk, and compliance activities across Regional Operating Units (OUs) and supporting systems. The role is primarily responsible for performing Sarbanes‑Oxley (SOX) IT control testing, supporting internal and external audit and regulatory inquiries, and assisting with remediation of control findings to ensure compliance with WRB Corporate, regulatory, and industry standards. In addition, the GRC Analyst assists in the development, maintenance, and standardization of RSS GRC processes and documentation; supports disaster recovery and business continuity planning and testing; and provides Third‑Party Risk Management (TPRM) coordination and support for Regional Segment OUs. The position works closely with RSS IT, WRB Corporate GRC, audit partners, and Regional OU stakeholders to gather evidence, document processes, and ensure that GRC policies, standards, and controls are consistently understood and applied. What you can expect: Culture of innovation, teamwork, supportive colleagues and leaders willing to invest in talent. Internal mobility opportunities. Visibility to senior leaders and partnership with cross functional teams. Opportunity to impact change.Benefits – competitive compensation, paid time off, comprehensive wellness benefits and programs, employer funded health savings account, profit sharing, 401k, paid parental leave, employee stock purchase plan, tuition assistance and professional continuing education. We'll count on you to: Execute WRB Corporate GRC Control Assessments (SOX): Execute WRB Corporate IT GRC control assessments for applications and systems subject to SOX requirements. Perform quarterly WRB Corporate‑mandated compliance testing, including control procedures, user access reviews, and evidence validation. Evaluate new GRC, audit, and regulatory requests to ensure testing approaches and documentation adequately support required responses. Participate in GRC review meetings to validate completeness and accuracy of test documentation and evidentiary materials prior to submission in GRC tracking systems. Maintain a working knowledge of applicable compliance tools, methodologies, and subject business systems. Assist with GRC Process and Standards Development: Assist in the research, development, and documentation of RSS GRC standards, procedures, and guidelines. Review and evaluate new or proposed internal and external compliance requirements to ensure RSS GRC processes align with evolving standards. Support efforts to standardize GRC practices across Regional OUs and recommend process improvements to senior RSS GRC leadership. Maintain and update documentation related to GRC review schedules, evidence sources, and assessment artifacts. Support Audit Response and Issue Remediation: Analyze GRC assessment results, audit findings, and exception requests and coordinate with senior RSS GRC personnel on appropriate responses. Monitor WRB Corporate IT GRC findings and support remediation tracking and response documentation. Assist in responding to regulatory inquiries affecting Regional OUs, including coordination of corrective actions and supporting documentation. Disaster Recovery & Business Continuity Planning: Support the maintenance and updating of Regional OU‑specific and RSS IT disaster recovery and business continuity plans. Participate in DR/BCP testing activities and document results, gaps, and follow‑up actions. Assist the RSS GRC Manager in developing and refining DR/BCP processes, procedures, and supporting documentation. Third‑Party Risk Management (TPRM) Support: Assist Regional OU stakeholders with initiating TPRM reviews for new third‑party engagements or material changes in vendor scope. Serve as a liaison between Regional OUs, WRB TPRM teams, and third parties to facilitate information and evidence exchange. Support documentation and evidence collection during TPRM assessments and reviews. Escalate identified information security incidents or compliance concerns to RSS GRC leadership for coordination with TPRM and Information Security teams. Assist in validating third‑party findings, remediation plans, and closure activities. Qualifications What you need to have: Bachelor’s Degree in relevant discipline or equivalent combination of education and experience. Experience with SOX and/or GRC control assessment and responding to internal/external audit inquiries, including development of remediation plans as needed. Experience evaluating and applying risk management principles with a focus on information security and data privacy. Experience with Disaster Recovery (DR) and Business Continuity Planning (BCP) concepts, development, and testing. Knowledge/understanding of COBIT, COSO-ICIF, ITIL, ISO 27001, and/or Model Audit Rule 205 frameworks as well as other applicable legislation – e.g. SOX, GDPR, HIPAA, NY DFS, etc. Strong computer skills, including Microsoft M365 products and related analytical/presentation tools (e.g. Excel, PowerPoint, Visio, etc.) as well as Artificial Intelligence (AI) concepts and tools. Knowledge of SQL, PowerBI, Python, and/or other analytical/development tools. Knowledge of data management, reporting tools, and their use in compiling needed GRC information. Working knowledge of Software Development Life Cycle (SDLC) and Agile development frameworks. Reasoning Ability: Solve practical problems, interpret varied instructions, and apply critical thinking to evaluate information and produce accurate, clear, and relevant conclusions. Communication Skills: Communicate effectively in a professional environment, including reading and interpreting business and regulatory materials, writing clear documentation, and presenting information to diverse audiences. Organizational Skills: Prioritize and manage workload, develop and execute project plans, and work effectively across multiple concurrent tasks to meet deadlines. Personal Qualities and Characteristics: Demonstrate agility, accountability, independence, initiative, sound judgment, collaboration, and strategic thinking while adapting to change and aligning work with business objectives. Additional Company Details We do not accept any unsolicited resumes from external recruiting agencies or firms. The company offers a competitive compensation plan and robust benefits package for full time regular employees. The actual salary for this position will be determined by a number of factors, including the scope, complexity and location of the role; the skills, education, training, credentials and experience of the candidate; and other conditions of employment. Sponsorship Details Sponsorship not Offered for this Role #J-18808-Ljbffr W. R. Berkley Corporation
- ...Job title: Business System Analyst Location: Richmond, VA (Hybrid) Duration: Longterm Job... ...description: Our SOX control Risk Associates are Masters of Risk Management... ...Assist our wider team in ensuring compliance with control standards while...RiskContract work
$158.4k - $180.8k
Manager- Finance Data Risk Advisor (Hybrid) Capital One is seeking a motivated professional for a Manager position within the Finance Risk... ...risk and influencing risk stakeholders, i.e., risk offices, compliance, internal audit, and regulators. FRM strives to enable a strong...RiskFull timePart timeWork at officeLocal areaMonday to FridayFlexible hours2 days per week3 days per week$96.5k - $110.1k
...Senior Risk Associate, Upmarket & Discover Card - Card Risk(Hybrid) Capital One is seeking highly motivated Senior Risk Associates interested in supporting... ...disability/vet) committed to non-discrimination in compliance with applicable federal, state, and local laws....RiskFull timePart timeLocal area$120.8k - $137.9k
...divh2Card Risk Principal Associate (Hybrid)/h2pRisk Managers at Capital One are highly motivated Risk Management professionals with excellent organizational... ...partners, and other assurance functions (i.e. legal compliance), to drive meaningful reductions in risk/liliSupport...RiskFull timePart timeLocal area- ...institution in Richmond, VA is seeking a Principal Associate - Card Risk. The role requires you to facilitate risk assessments and manage... ..., while a Bachelor's Degree is preferred. The position offers a hybrid work model and competitive benefits package. #J-18808-Ljbffr...Risk
$96.5k - $110.1k
...Senior Risk Associate, Upmarket & Discover Card - Card Risk (Hybrid) Capital One is seeking highly motivated Senior Risk Associates interested in supporting... ...disability/vet) committed to non-discrimination in compliance with applicable federal, state, and local laws....RiskFull timePart timeLocal area- COMFORT SYSTEMS is looking for a Principal Associate Payments Governance Advisor. This hybrid role involves overseeing payments risk management, ensuring compliance with corporate and regulatory standards while working closely with various stakeholders across the enterprise...Risk
- The Fair Banking Oversight & Senior Risk Advisor is responsible for serving as a Second Line of Defense (2LOD) Fair and Responsible... ...models, monitoring strategies, and documentation aligned to the Compliance Management Program (CMP). Matures Fair Banking governance...RiskWork experience placementWork at officeFlexible hours
$151.9k - $173.4k
...Overview Manager, Risks Data & Analytics - Hybrid The Enterprise Payments Governance and Oversight team is seeking a dynamic Manager who... ...including disability/vet) committed to non-discrimination in compliance with applicable federal, state, and local laws. Capital...RiskFull timePart timeWork at officeLocal area- ...Industrial CyberSecurity Analyst Location: Glen Allen, VA - Hybrid The Cybersecurity Consultant... ...Information Technology (IT) and Industrial Control... ...Framework (CSF), NIST Risk Management Framework (RMF... ...industry or data specific compliance frameworks and...Risk
$85 per hour
...Information Technology - Business Analyst (IT) Location: Chicago, IL... ...willing to go onsite in a hybrid setting, 3 days a week. Required... ...to support development of Risk Metrics Dashboards for... ...and document KPIs, KRIs, and compliance metrics across security domains...RiskContract workWork experience placementLocal area3 days per week- ...Position Description The Manager, SOX Compliance IT, assists the Director of Sox Compliance,... ...application controls, and technology-related risks. This role partners closely with IT,... ...reporting processes. Experience with GRC platforms and audit management tools....RiskWork experience placement
- ...managerial position involves providing effective oversight and risk management for payment types, advocating for a strong risk culture... ...to build relationships across various business units. This hybrid role requires three days in-office work per week. #J-18808-Ljbffr...RiskWork at office
- ...Association is seeking a Manager for Platform Governance in Richmond, VA. This hybrid role involves leading technology governance initiatives, simplifying technical environments, and managing risk across the enterprise. Ideal candidates will have at least 4 years of...Risk
- Capital One National Association is seeking a Fraud Risk Manager for its Business Cards and Payments team. This hybrid role involves overseeing a team responsible for... ..., with preferred qualifications in AML compliance, Six Sigma Certification, and strong communication...Risk
$109.9k - $125.4k
...Principal Associate, Risk Manager - Issues & Events Management (Hybrid) As a Principal Risk Specialist within the Card... ...is a self-contained project; it requires analysis of the underlying... ...recovery Partner with Legal and Compliance to deeply understand exposure from...RiskFull timePart timeLocal area- ...ODGA - Data Protection Analyst HYBRID Position Summary: We are currently seeking a Data Protection Analyst which will report to the Director... ...focused on providing expert insight into data analytics and risk, developing team members, and effective oversight of data...RiskWork at office
- Capital One is seeking a Card Vertical Risk Manager, Principal Associate, to support Card Data leadership. The role involves overseeing risk assessments, developing reports, and partnering with internal clients on project delivery. The ideal candidate will possess 1+ years...Risk
$109.9k - $125.4k
A leading financial services company is seeking a Principal Risk Associate in Richmond, VA to manage data risks and enhance data management practices across the organization. This role requires strong analytical, data management, and process management skills, along with...Risk$151.9k - $173.4k
...Fraud Risk Manager - Business Cards and Payments, Hybrid Business Cards & Payments manages Capital One's Corporate and Small Business credit, charge cards... ...innovative risk mitigation solutions that ensure compliance, and enables frictionless customer experiences. This...RiskFull timePart timeLocal area- ...Manager-Finance Risk Analytics (HYBRID--Richmond, VA or REMOTE: VA/PA/MD/DC/NC/SC/GA only) Position... ...and performance of financial analysts on the team Ensure appropriate accounting... ...operations, products, services and related compliance/regulations. Knowledge of data...RiskRemote jobFull timeWork experience placementFlexible hours
$87.7k - $100.1k
A financial services company in Richmond, VA is seeking a Senior Risk Associate for its Enterprise Data Risk Management team. This role involves testing data management controls, analyzing data risks, and collaborating on strategic objectives. Candidates should have a...Risk- CarMax is seeking an Analyst II for Information Risk Management at the Richmond, VA Technology Innovation Center. The essential duties include coordinating data subject access requests and implementing privacy risk management programs. Ideal candidates will have a relevant...Risk
- An IT service provider in Richmond, Virginia is seeking a Project Manager to lead project oversight for various technology... ...projects, with a strong background in project planning and risk management. This hybrid position requires excellent communication skills and the...Risk
$109.9k - $125.4k
...Principal Auditor (Experienced Senior Auditor) Corporate Compliance Audits (Hybrid) Capital One's Audit function is a dedicated group of professionals... ...following areas: banking or financial services industry, risk management, or consumer compliance. At least 1 year of...RiskFull timePart timeLocal area3 days per week$138.1k - $157.7k
...Risk Manager - Customer Identity Management Team (Hybrid) Do you like working in the spotlight? Are you ready to work... ...teams including Ops, Tech, Product, Compliance, and Intent High level of... ...evaluation of data provided by team analysts Drive and deliver results and...RiskFull timePart timeLocal area- A leading financial services firm in Richmond is seeking a Principal Risk Specialist to manage data risk within their enterprise risk organization. The successful candidate will ensure compliance with enterprise data standards, develop key relationships with stakeholders...Risk
$111.2k - $126.9k
...Finance Product and Data Solutions Risk Advisor Capital One is... ...programs, other risk offices, compliance, internal audit, and regulators... ...related to product or IT project management; ~ Education... ...: $111,200 - $126,900 for Sr. Analyst, Capital Markets & Risk Richmond...RiskFull timePart timeWork at officeLocal areaFlexible hours$87.7k - $100.1k
...Senior Staff Auditor, Compliance (Hybrid) Capital One's Audit function is a dedicated group of professionals focused on delivering top-quality... ...the annual audit plan. Responsibilities: Perform risk-based reviews and assessments of compliance with federal, state...RiskFull timePart timeLocal area3 days per week- ...Private Client Risk Advisor Job Category: Outside - Sales/Travel Full-Time Hybrid Location: Glen Allen, VA 23060, USA Description Join us at Towne Insurance! Your Career. Your Future. Your Towne. Towne Insurance is hiring a Private Client Risk Advisor...RiskFull time
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to GRC Analyst - Hybrid IT Compliance & Risk. Be the first to apply!
- it risk analyst Glen Allen, VA
- risk analyst Glen Allen, VA
- risk officer Glen Allen, VA
- risk consultant Glen Allen, VA
- risk underwriter Glen Allen, VA
- risk assurance Glen Allen, VA
- technology risk Glen Allen, VA
- information technology Glen Allen, VA
- IT account executive Glen Allen, VA
- IT contractor Glen Allen, VA

