Senior IT GRC Analyst
CMG Financial
Description
The Senior IT GRC Analyst leads policy development and audit execution within CMG's IT Governance, Risk, and Compliance program, with particular emphasis on CMG's upcoming SOC 2 readiness effort. This role works closely with the GRC team and the broader IT department to plan and execute audit engagements, maintain the policy framework, and manage auditor relationships. The Senior IT GRC Analyst operates with a high degree of autonomy and is expected to navigate ambiguity in a regulated environment.
ESSENTIAL DUTIES and RESPONSIBILITIES, includes the following responsibilities, but not limited to:
- Lead CMG's SOC 2 readiness assessment, including scope definition, gap analysis, and control design, in partnership with the IT GRC Manager.
- Serve as a point of contact during audit engagements and regulatory exams.
- Develop, maintain, and update IT policies, standards, and procedures to align with NIST CSF and other applicable regulatory requirements.
- Plan and execute audit activities, including scheduling, control walkthroughs, evidence gathering, and findings documentation.
- Identify control gaps, coordinate remediation planning with control owners, tracking findings and remediation status through the risk register.
- Provide guidance to other GRC team members and IT leadership on audit and policy matters.
- Research regulatory and framework changes relevant to mortgage lending and financial services, and translate them into policy updates.
- Contribute to the ongoing development and improvement of GRC processes and tooling.
REQUIRED QUALIFICATIONS:
- Bachelor's degree in Information Technology, Cybersecurity, or a related field (equivalent experience considered).
- 5+ years of experience in IT audit, compliance, or GRC in an enterprise IT environment.
- Demonstrated experience managing SOC 2 audit cycles (Type I or Type II) from scoping through remediation.
- Direct experience in financial services, mortgage lending, or related regulated industries, with working knowledge of applicable regulations (GLBA, CFPB, NYDFS).
- Strong working knowledge of relevant IT compliance frameworks, such as NIST CSF, ISO 27001, or SOX.
- Strong policy writing and documentation skills.
- Ability to work independently amid ambiguity, exercising sound judgment on scope and prioritization.
- Excellent written and verbal communication skills, with the ability to explain technical and compliance matters to varied audiences.
- Relevant certifications preferred: CISA, CRISC, or GRCP.
SUPERVISORY RESPONSIBILITIES:
Direct Reports: N/A
PHYSICAL and ENVIRONMENTAL CONDITIONS
This role operates in an ADA compliant office environment, utilizing typical office equipment and tasks including computer work. The position may involve partial stationary positions and moving throughout the day. Flexibility to work overtime to meet project deadlines is required.
Base Compensation Information– This role is a remote position that is currently allocated for candidates within geographic regions that do not currently require base wage disclosure. The compensation range for this position will be provided upon request. (Due to their geographic location, residents of the states of CA & CO, and for NY are excluded from this role at this time.)
CMG Financial is an equal opportunity employer and does not unlawfully discriminate in employment decisions. CMG will consider all qualified applicants without regard to race, religion, national origin, sex, age, veteran status, disability, familial status, marital status, actual or perceived sexual orientation, or actual or perceived gender identity. Applicants requiring reasonable accommodation to the application and/or interview process should notify a representative of CMG Financial or reach out to Show email.
CMG MORTGAGE, INC. NMLS #1820 If you are a recruiter or placement agency, please do not submit resumes to any person or email address at CMG Financial prior to having a signed agreement . CMG Financial is not liable for and will not pay placement fees for candidates submitted by any agency other than its approved recruitment partners. Furthermore, any resumes sent to us without an agreement in place will be considered your company’s gift to CMG Financial and may be forwarded to our recruiters for their attention.
- A leading utility provider in Pennsylvania seeks a GRC Cybersecurity Senior Analyst to ensure compliance with regulatory obligations. This role involves collaboration with various departments to implement governance and risk management processes. The ideal candidate has...Senior
- ...opportunities, and inclusive programs that enable you to perform at your best. Together we win! The Opportunity The Senior GRC Information Security Analyst role will be part of the Information Security Governance, Risk, & Compliance (GRC) team at Banc of California. The...SeniorLocal areaImmediate startFlexible hours
$95k - $105k
...Job Description Job Description Sr. GRC Analyst About Subsplash Subsplash is an exciting... ...work every day. Don't take our word for it—head to Glassdoor and see for yourself!... ...spend under budget. About the Role The Senior GRC Analyst acts as a strategic lead to advance...SeniorTemporary workCurrently hiringRemote workRelocation$110k - $120k
...Overview: PrizePicks is seeking an experienced and detail-oriented Senior GRC Analyst to join our expanding governance programs. This role will help... ...continued development and maturation of the organization's IT and Security governance, risk, and compliance initiatives. You...SeniorFull timeRemote workWork visaFlexible hours- ...Tire Rack is seeking a Senior Information Security GRC Analyst to support and advance our Information Security Governance, Risk, and Compliance (GRC) program. In this role, you will assess and strengthen IT and security controls across the organization while ensuring alignment...SeniorMonday to Friday
- ...Time Title SAP Application Security and GRC Analyst (Sr.) - U.S. Citizenship Required Location... ..., United States Summary CGI is seeking a Senior SAP GRC and Application Security Analyst... ...environments. Experience as a leader for major IT programs involving multiple teams and...SeniorPermanent employmentFull timeContract workWork at officeLocal area
- ...Overview The IT GRC Analyst operates within the enterprise Cybersecurity Operations function and supports the Information Technology, Information Systems, and other technology teams aligned under the Chief Information Officer. This role executes governance, risk, and...Work at officeRemote work
$89.6k - $194k
...Position Description CGI is seeking a Senior SAP GRC and Application Security Analyst to join an SAP S/4HANA Greenfield implementation project for a large... ...dynamic environments. Experience as a leader for major IT programs involving multiple teams and projects, with the...SeniorContract workWork at officeLocal area2 days per week- ...Trustmark in Ridgeland, MS is seeking an IT GRC Analyst to oversee governance, risk, and compliance activities. The role includes coordinating compliance efforts, executing IT assessments, and developing policies. The ideal candidate will hold a Bachelor's in information...Remote work
$110k - $140k
Senior GRC Analyst - Accounting - $110,000 - $140,000 You get to build the GRC function from scratch at a nationally recognized, PE-backed company in a major growth phase. This is a greenfield opportunity. There is no inherited mess to untangle, no legacy processes holding...Senior- ...standards, and procedures Report on our compliance posture to senior leadership Scale our GRC function with AI and automation, building quick wins and... ...the rest Requirements 5+ years of experience in GRC, IT audit, or information security compliance Prior experience...Senior
- ...The GRC Cybersecurity Analyst III is a senior level contributor responsible for leading ICCU’s Governance, Risk, and Compliance (GRC) initiatives within the scope of the IT domain. This role provides strategic oversight of cyber and IT operational risk assessments, regulatory...Full timeWork experience placementWork at office
- ...is currently seeking a highly motivated and detail-oriented Sr. GRC Analyst to support the organization’s Governance, Risk & Compliance... ...functional teams to maintain audit readiness and compliance across the IT and Information Security environment. #J-18808-LjbffrSenior
$140k - $165k
...for the dreamers and builders in the world. We’re looking for a Senior GRC Analyst to serve as the primary architect for our expanding ISO... ...actionable, testable controls, for engineering, product, and IT teams. Project Management: You have strong project management...Senior- ## Senior GRC AnalystApplylocations: Westerville, OHtime type: Full timeposted on: Posted... ...Governance, Risk, and Compliance (GRC) Analyst to support and mature our security and... ...policies, standards, and updates* Partner with IT, legal, and business teams to embed...SeniorFor contractors
- ...the design and management of control frameworks, the full-time Senior GRC Analyst will implement risk workflows, conduct third-party risk... ...experience in governance, risk, and compliance functions within IT or information security Certifications such as Certified Information...SeniorFull timeRemote work
- ...candidates will be contacted We are seeking a highly motivated GRC Analyst to support the modernization and transformation of our Governance... ...GRC tooling Partner with Risk, Security, Compliance, and IT stakeholders to translate manual processes into scalable automated...SeniorContract workLocal area
- Senior GRC Analyst Location: Overland Park, KS, US; Cary, NC, US Company: Black & Veatch Family of Companies Opportunity Type: Staff... ...resilience, and compliance certifications and measuring compliance in IT and security architecture and operations. Support...SeniorContract workFlexible hours
- ...0 employees are all united by one mission: For the People. Senior GRC Analyst Reports To: Director of Business Continuity Department:... ...management authority What We’re Looking For 4–6+ years in GRC, IT audit, compliance, or information security Deep hands‑on...SeniorFull timeLocal area
- ...Sr. GRC Analyst, Risk Management Under the direction of and in collaboration with the GRC Manager, the Sr. GRC Analyst, Risk Management is the primary owner and operational steward of the Enterprise Risk Register. This role is responsible for ensuring all identified...SeniorFor contractorsImmediate startFlexible hours
- The Role We Want You For Under the direction of and in collaboration with the GRC Manager, the Sr. GRC Analyst, Third-Party & Human Risk Management (TPHRM) is a risk-focused, highly analytical role that ensures all Human and Third-Party risk to Clayco is identified, quantified...SeniorImmediate startFlexible hours
- ...Senior GRC Analyst job at Quantexa. New York, NY. What we’re all about. We find, when we come together in the pursuit of excellence, great things... ...for audit readiness. Collaborate Across Teams Partner with IT, legal, and compliance teams to align on priorities, translating...SeniorContract workTemporary workWork experience placementImmediate start
- Gilder Search Group is looking for a Sr. GRC Analyst focused on Third-Party & Human Risk Management in St. Louis, Missouri. The role ensures all human and third-party risks to Clayco are identified and treated appropriately. Key responsibilities include owning the TPRM...Senior
- Gilder Search Group is looking for a Sr. GRC Analyst focusing on Third-Party & Human Risk Management in Atlanta, Georgia. This role involves risk analysis, compliance assessments, vendor management, and developing security awareness training. The ideal candidate has 6-8...Senior
$161.6k - $202k
...that scales with the business. We're building out our dedicated GRC team to improve and mature our program! You'll join the Security... ...leadership. Partner cross-functionally with Privacy, Legal, IT, and Engineering to embed compliance into how Headway operates —...SeniorWork from homeFlexible hours- ...Oura is seeking a Senior Governance, Risk, Compliance (GRC) Analyst to join the Security Team in New York City. This role involves leading GRC initiatives, managing... ...of compliance frameworks, and familiarity with IT environments. Oura offers competitive salary packages,...SeniorRemote workFlexible hours
$130k - $170k
...performance and extend healthspan. The Governance, Risk, and Compliance (GRC) team helps ensure technology and cybersecurity risks are... ...Collaborate with Security Engineering, Product Security, Legal, IT, and business teams to evaluate new initiatives, technology changes...SeniorFull timeWork at officeRelocation- Gravity Engineering Services Pvt Ltd. is offering a remote position within the Information Security Office at The University of Texas at Austin. This role is crucial for supporting governance, risk, and compliance programs in cybersecurity. You'll work with an intelligent...Work at officeRemote work
- ...C2 Labs is hiring a Senior FedRAMP Consultant (GRC Analyst III equivalent) to act as a lead technical writer for FedRAMP authorization packages and ongoing... ...). Preferred / nice to have • Bachelors degree in IT, Cybersecurity, or related field • Prior experience...SeniorFor contractorsRemote work
$130k - $150k
...Crusoe. About This Role We’re seeking a GRC Analyst to support the day-to-day execution of our... ...due diligence requests with guidance from senior team members Maintaining and updating... ...experience in GRC, information security, IT audit, or a related compliance role Foundational...SeniorTemporary work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior IT GRC Analyst. Be the first to apply!
- grc analyst United States
- sr hr business partner United States
- senior lighting artist United States
- senior planner United States
- senior hvac project manager United States
- senior piping designer United States
- senior case manager United States
- home instead senior care United States
- research associate senior research associate United States
- senior technical product manager United States



