Senior IT GRC Analyst
CMG Financial
The Senior IT GRC Analyst leads policy development and audit execution within CMG's IT Governance, Risk, and Compliance program, with particular emphasis on CMG's upcoming SOC 2 readiness effort. This role works closely with the GRC team and the broader IT department to plan and execute audit engagements, maintain the policy framework, and manage auditor relationships. The Senior IT GRC Analyst operates with a high degree of autonomy and is expected to navigate ambiguity in a regulated environment.
ESSENTIAL DUTIES and RESPONSIBILITIES, includes the following responsibilities, but not limited to:
- Lead CMG's SOC 2 readiness assessment, including scope definition, gap analysis, and control design, in partnership with the IT GRC Manager.
- Serve as a point of contact during audit engagements and regulatory exams.
- Develop, maintain, and update IT policies, standards, and procedures to align with NIST CSF and other applicable regulatory requirements.
- Plan and execute audit activities, including scheduling, control walkthroughs, evidence gathering, and findings documentation.
- Identify control gaps, coordinate remediation planning with control owners, tracking findings and remediation status through the risk register.
- Provide guidance to other GRC team members and IT leadership on audit and policy matters.
- Research regulatory and framework changes relevant to mortgage lending and financial services, and translate them into policy updates.
- Contribute to the ongoing development and improvement of GRC processes and tooling.
REQUIRED QUALIFICATIONS:
- Bachelor's degree in Information Technology, Cybersecurity, or a related field (equivalent experience considered).
- 5+ years of experience in IT audit, compliance, or GRC in an enterprise IT environment.
- Demonstrated experience managing SOC 2 audit cycles (Type I or Type II) from scoping through remediation.
- Direct experience in financial services, mortgage lending, or related regulated industries, with working knowledge of applicable regulations (GLBA, CFPB, NYDFS).
- Strong working knowledge of relevant IT compliance frameworks, such as NIST CSF, ISO 27001, or SOX.
- Strong policy writing and documentation skills.
- Ability to work independently amid ambiguity, exercising sound judgment on scope and prioritization.
- Excellent written and verbal communication skills, with the ability to explain technical and compliance matters to varied audiences.
- Relevant certifications preferred: CISA, CRISC, or GRCP.
SUPERVISORY RESPONSIBILITIES:
Direct Reports: N/A
PHYSICAL and ENVIRONMENTAL CONDITIONS
This role operates in an ADA compliant office environment, utilizing typical office equipment and tasks including computer work. The position may involve partial stationary positions and moving throughout the day. Flexibility to work overtime to meet project deadlines is required.
Base Compensation Information – This role is a remote position that is currently allocated for candidates within geographic regions that do not currently require base wage disclosure. The compensation range for this position will be provided upon request. (Due to their geographic location, residents of the states of CA & CO, and for NY are excluded from this role at this time.)
$80.05k - $165k
About the Role:Responsible for leading Cybersecurity and IT governance, risk, and compliance efforts, including the establishment and... ...prioritization, assignment, remediation tracking, and closure of GRC-related issues in ServiceNow, ensuring timely resolution, appropriate...SeniorFull timeWork at office- Dorsey & Whitney LLP is seeking a Senior GRC Information Security Systems Analyst to strengthen our Information Security program across audits, risk, governance, and compliance. You will lead client and pre-contract security assessments, manage internal ISMS audits, and...SeniorContract work
- Procore Technologies in Austin, TX is seeking a Senior Cybersecurity Risk Analyst to join the GRC organization. You will manage technical risk across the cloud... ...assets, collaborating with security, engineering, IT and business teams. The role emphasizes AI-enabled risk...Senior
- A leading utility provider in Pennsylvania seeks a GRC Cybersecurity Senior Analyst to ensure compliance with regulatory obligations. This role involves collaboration with various departments to implement governance and risk management processes. The ideal candidate has...Senior
- ...Prussia, PA or Denver, PA Our client is seeking a Senior Cybersecurity Governance, Risk & Compliance (GRC) Analyst to support cybersecurity governance, regulatory... ...monitoring and reporting. Collaborate with IT stakeholders to monitor cybersecurity exceptions and...SeniorHourly payPermanent employmentFull timeLocal areaRemote work
- Dorsey & Whitney LLP is seeking a Senior GRC Information Security Systems Analyst to safeguard the firm and clients through governance, risk, and compliance initiatives. You will drive ISMS audits, maintain policies aligned with ISO 27001, and oversee authorization services...Senior
$109.99k - $142.34k
Join Dorsey's Information Security team as a Senior GRC Information Security Systems Analyst to help safeguard our firm and clients by driving high-impact security... ...-53. oClient-request assessment, audit experience and IT/Security technology, software security risk assessment...SeniorContract workTemporary workCurrently hiringWork at officeWorldwideFlexible hours- ...TXEmployment Type: Full TimeIndustry: Computer SoftwareClient: WiproContact: Meghana GorusuCompany: SRI Tech SolutionsJob Title: Technical GRC Analyst with SQL DBDuration: Full timeLocation: Austin TX - Locals onlyJob Description:Skills: Technical GRC Analyst and SQL DBStrong...Local area
$130k - $170k
...Governance, Risk, and Compliance (GRC) team helps ensure technology and cybersecurity... ...is seeking an execution-oriented Senior Governance, Risk, and Compliance Analyst to lead the day-to-day execution... ..., Product Security, Legal, IT, and business teamsto evaluate new...SeniorFull timeWork at officeRelocation- Job Summary:The IT Governance, Risk, and Compliance (GRC) Lead Analyst serves as a subject matter expert responsible for leading the design, implementation, maturity... ...The GRC Lead Analyst serves as a trusted advisor to senior leadership, influencing risk-based decision-making...Full timeWork at office3 days per week
$99k - $225k
Enterprise Cybersecurity GRC Governance AnalystThe Opportunity: The Enterprise Cybersecurity (ECS) Governance, Risk, and Compliance... ...RSA Archer, CSAM, or Telos XactaAbility to engage and influence senior and executive leadershipAbility to use a strong analytical mindset...Full timeContract workPart timeWork at officeLocal areaRemote work- ...that's not us. Join the Governance, Risk, and Compliance (GRC) team as a Senior Analyst on the Compliance Assessment team, where you'll own the Common... ...Framework (CCF) from the ground up: maturing it, running it, and testing control effectiveness so it keeps pace with evolving...SeniorFull timeWork experience placementWork at office
$138k - $173k
...an opening with your name on itFanDuel is seeking a Senior Technology Governance, Risk & Compliance (GRC) Analyst to join its Technology GRC team as a strategic... ...to risk appetite.In-depth understanding of various IT platform and systems including but not limited to AWS...SeniorTemporary workWork at officeLocal areaWorldwideShift work- ...existing and new information technology (IT) systems meet the organization's cybersecurity... ..., technical personnel, audit personnel, senior management, and the board of directors... ...General Governance, Risk, and Compliance (GRC) Support Leads process analysis, development...SeniorWork experience placementWork at officeLocal areaRemote workRelocation
$183k - $205k
...guide the company from foundational Governance, Risk & Compliance (GRC) maturity through to steady-state operations, leveraging AI to... ...implementation of our controls framework and evidence collection to support it Collaborate with Legal, Enterprise Applications, and Gusto...SeniorFull timeWork at officeLocal area2 days per week3 days per week- ...com.Position ProfileWeaver is looking for a senior associate or a supervisor to join our team in the Governance, Risk, and Compliance (GRC) department. Our GRC team works with our... ...regulatory compliance requirements with a focus on IT functions in this role. Our GRC Services...SeniorFull timeFlexible hours
- ...Senior GRC Analyst job at Quantexa. New York, NY. What we’re all about. We find, when we come together in the pursuit of excellence, great things... ...for audit readiness. Collaborate Across Teams Partner with IT, legal, and compliance teams to align on priorities, translating...SeniorContract workTemporary workWork experience placementImmediate start
- ...The Role We Want You For Under the direction of and in collaboration with the GRC Manager, the Sr. GRC Analyst, Third-Party & Human Risk Management (TPHRM) is a risk focused, highly analytical role that ensures all human and third‑party risk to Clayco is identified, quantified...SeniorImmediate startFlexible hours
$93.8k - $121.8k
...current authorization to work in the United States on a full-time basis.Reporting to the Manager or Sr.Manager, IT Risk and Compliance, the Senior GRC analyst will be responsible for supporting the day to day IT compliance, data governance, and IT risk management...SeniorFull timeWork at officeFlexible hours- ...Plano and Richardson. You will work with client and internal teams to resolve incidents, assess infrastructure, and design scalable IT solutions. The role requires governance, risk, and controls experience in financial services, strong project management, and the ability...
$55 - $80 per hour
IT GRC Analyst Remote, USA Compensation: $55 - $80 per hour Contract Length: 6-month Contract to Hire Hours: Standard full-time schedule... ...providing primary and post-acute care services to seniors across assisted living, life plan communities, independent living...Hourly payFull timeContract workWork at officeLocal areaImmediate startRemote workFlexible hours$55 - $80 per hour
IT GRC Analyst Remote, USA Compensation: $55 - $80 per hour Contract Length: 6-month Contract to Hire Hours: Standard full-time schedule... ...providing primary and post-acute care services to seniors across assisted living, life plan communities, independent living...Hourly payFull timeContract workWork at officeImmediate startRemote workFlexible hours- ...Job Description Job Description Description: Position Overview The IT GRC Analyst (CMMC Control Specialist) is responsible for the daily monitoring, operational testing, and ongoing compliance analysis of the organization’s cybersecurity controls. Rather than...For subcontractor
$55 - $60 per hour
...Type: 1099, C2CIndustry: Computer SoftwareClient: WiproContact: Meghana GorusuCompany: SRI Tech SolutionsTitle: SaaS Engineer ( GRC Analyst with IAM )Location: Phoenix AZ onsite onlyDuration: ContractKey ResponsibilitiesPerform security assessments of SaaS and third‑party...Hourly pay$65k - $75k
...System is seeking a Cybersecurity Governance, Risk & Compliance (GRC) Analyst to join our Information Security team. This position plays... .... Five years of professional experience in cybersecurity, IT risk management, compliance, or information security program support...Casual workWork at officeImmediate startRemote workMonday to FridayFlexible hoursAfternoon shift- ...community. Description JOB DESCRIPTION: The Senior IT GRC (Governance, Risk, and Compliance) Analyst oversees technical design, implementation,... ...assessment, risk remediation, continuous monitoring, and IT compliance documentation and reporting efforts. Coordinates...SeniorWork experience placementRemote workWork from homeFlexible hours
- UT Southwestern Medical Center seeks a Senior Governance Risk Compliance Analyst to lead information security governance, risk management, and compliance... ...will have 8+ years of governance experience, a BS in CS/IT, and professional certifications. #J-18808-Ljbffr UT Southwestern...Senior
- Nordstrom is seeking a Senior Analyst for the Governance, Risk and Compliance (GRC) program. You will own the Common Control Framework (CCF) from inception, mature it, run it, and test control effectiveness in a scalable, AI-enabled environment. This role requires cross...SeniorWork at office
- BERRY Appleman & Leiden (BAL) is seeking a GRC/Information Security professional to lead internal audits and manage ISO 27001/27701 programs from its Richardson, TX location. You’ll drive risk-based audits, support privacy operations, and help shape AI governance and vendor...Senior
- Gilder Search Group is looking for a Sr. GRC Analyst focusing on Third-Party & Human Risk Management in Atlanta, Georgia. This role involves risk analysis, compliance assessments, vendor management, and developing security awareness training. The ideal candidate has 6-8...Senior
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior IT GRC Analyst. Be the first to apply!
- grc analyst United States
- senior technical service engineer United States
- senior functional safety engineer United States
- senior technical consultant United States
- senior director product management United States
- senior vendor manager United States
- senior vice president human resources United States
- senior automation controls engineer United States
- senior grant accountant United States
- senior technical recruiter United States


