Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Experienced or Senior GRC Analyst

Hotman Group LLC

About the Role


Hotman Group is a boutique cybersecurity and GRC consulting firm doing meaningful work for clients who need GRC done right ranging from Fortune 1000 companies to high-growth startups. We are looking for an experienced GRC practitioner who is ready to work directly with clients, own deliverables end to end, and contribute to a team that holds itself to a high standard. This is not an entry point. We expect you to bring your expertise and use it.


This is a full-time, remote, contract-to-hire position. Top performers move into permanent roles within 6 months.


What You Will Do


As an Experienced or Senior GRC Analyst at Hotman Group you will work directly with clients to help them build, mature, and sustain their cybersecurity and compliance programs. This is active delivery work. You will:

  • Lead assessments and audits of security and IT control environments
  • Design, implement, and mature cybersecurity and compliance programs
  • Develop risk registers, conduct risk assessments, and track remediation efforts
  • Create and refine policies, standards, and procedures aligned with top frameworks including SOC 2, ISO 27001, NIST CSF, HIPAA, HITRUST, CMMC, and others
  • Prepare clients for internal audits and external assessments
  • Translate technical, regulatory, and business requirements into clear, actionable deliverables for client stakeholders
  • Communicate findings, manage client feedback, and drive outcomes even when stakeholders push back
  • Mentor junior analysts and contribute to the growth of our GRC practice
  • Participate in peer review of deliverables before they go to clients - your work will be reviewed and you will review others
You will work across multiple industries on diverse engagements. No two projects are the same and no day looks exactly like the last.


What You Bring
  • Hands-on GRC experience with a track record of owning deliverables, producing frameworks-based documentation, and driving remediation -- not just supporting programs from the inside
  • Deep working knowledge of compliance standards including SOC 2, ISO 27001, NIST CSF, HIPAA, and HITRUST
  • Experience communicating findings and recommendations directly to clients or senior internal stakeholders -- you can hold a room, manage pushback, and present complex findings in plain language
  • Excellent writing skills -- your deliverables are clear, polished, and do not require heavy editing before they go to a client
  • Strong critical thinking and professional judgment -- you know when to escalate, when to hold your position, and when to ask for help
  • A high level of accountability and ownership -- you manage your own workload, communicate proactively, and hold yourself to deadlines without being managed closely
  • Comfort working independently in a fully remote environment with minimal hand-holding
  • A default toward communication - you keep the team informed, you acknowledge quickly, and you do not go dark on a deliverable or a client
Active certifications such as CISA, CISM, CISSP, or CRISC are strongly preferred. If you do not currently hold a relevant certification, we expect you to be actively pursuing one.


This role requires direct accountability for work product and outcomes. If your experience has been primarily internal, supporting programs from the inside without stakeholder-facing delivery responsibility, this role will be a significant adjustment.


Requirements
  • Permanent authorization to work in the U.S. -- no sponsorship of any kind now or in the future
  • Able to pass a background check
  • Reliable high-speed internet and a secure, private remote workspace

Our Hiring Process


Our process is designed to be straightforward but rigorous. In addition to a written questionnaire and video responses, finalists will complete a practical skills assessment before advancing to a panel interview with our delivery team. The assessment reflects the type of work you will do on day one. If you are confident in your GRC expertise, this is your opportunity to show it.


Why Hotman Group


At Hotman Group we are not just another consulting firm. You will work alongside people who care about the craft and push each other to do better. No politics, no silos, no hierarchy between you and the people making decisions.


You will touch more GRC frameworks, more industries, and more client situations in one year here than most practitioners see in five. You will grow because the work demands it.


The clients you serve will actually notice your work. You are not a number on a headcount. Your name is on the deliverable.


If you want to do real GRC work, get better at it every day, and work with a team that holds itself to a high standard - this is the place.


No phone calls or emails please.
Vacancy posted 6 days ago
Similar jobs that could be interesting for youBased on the Experienced or Senior GRC Analyst in United States vacancy
  •  ...and services!Job SummaryThe Governance Risk & Compliance (GRC) Cybersecurity Senior Analyst plays a critical role in ensuring that UGI Utilities Inc...  ...The ideal candidate is detail-oriented, analytical, and experienced in compliance, risk management frameworks, and... 
    Senior
    For contractors

    UGI Corporation

    Denver, PA
    4 days ago
  •  ...the #1 best company for remote workers Responsibilities Workato is seeking a detail-oriented, driven, and technically experienced Senior GRC Analyst to strengthen and advance its security governance, risk, and compliance (GRC) program - with a primary focus on FedRAMP... 
    Senior
    Remote work
    Flexible hours

    Workato

    Palo Alto, CA
    5 days ago
  • Crunchyroll is seeking an experienced Risk Analyst to support our Information Security GRC team. This role emphasizes governance, risk, and compliance, ensuring technology evolution aligns with employee needs and strategic goals. Successful candidates will have over 8... 
    Senior
    Flexible hours

    Crunchyroll

    Dallas, TX
    3 days ago
  • Berry Appleman & Leiden (BAL) is seeking an experienced GRC/Audit professional to help manage security, privacy, and AI governance across the firm. You will lead audits, shape ISMS/PIMS maintenance, and align controls with global standards. You will collaborate with cross... 
    Senior

    Berry Appleman & Leiden

    Richardson, TX
    5 days ago
  • Bloomin' Brands is seeking an experienced information security leader to drive risk management, compliance and governance across the organization. You will develop policies, assess controls, and oversee risk management initiatives to protect data and systems. The role requires... 
    Senior

    Bloomin' Brands

    Tampa, FL
    1 day ago
  • Illumia is seeking an experienced Business Risk Analyst to support information security compliance, GRC workflow, and risk management initiatives. The role involves risk assessments, business continuity planning, and coordinating audits with external auditors and internal... 
    Senior
    Remote job

    Illumia

    Atlanta, GA
    3 days ago
  • $117.2k - $176.7k

     ...Salesforce.The ExperienceLocation: San Francisco, CAThe Senior Security GRC Analyst role is part of our Assurance team, sitting at the intersection...  ...concurrent deadlines, and are comfortable guiding less experienced team members.Even Better If...You hold one or more... 
    Senior
    Full time
    Work at office

    Salesforce

    San Francisco, CA
    5 days ago
  •  ...industry experience and culture at weaver.com. Position Profile Weaver is looking for a Governance, Risk, and Compliance (GRC) Experienced Associate or Senior Associate to join our growing contract compliance practice. Our contract compliance practice performs franchise... 
    Senior
    Contract work
    Flexible hours

    Weaver

    Dallas, TX
    2 days ago
  • $130k - $170k

     ...extend healthspan. The Governance, Risk, and Compliance (GRC) team helps ensure technology and cybersecurity risks...  ...organization.WHOOP is seeking an execution-oriented Senior Governance, Risk, and Compliance Analyst to lead the day-to-day execution and support the ongoing... 
    Senior
    Full time
    Work at office
    Relocation

    WHOOP

    Boston, MA
    2 days ago
  • $80.05k - $165k

     ...end-to-end issue management activities, including intake, validation, prioritization, assignment, remediation tracking, and closure of GRC-related issues in ServiceNow, ensuring timely resolution, appropriate evidence, and alignment with audit, risk, and regulatory... 
    Senior
    Full time
    Work at office

    Columbia Bank

    Tacoma, WA
    4 days ago
  •  ...ROLE, NOW OR IN THE FUTURE. (e.g., H-1B, STEM OPT, TN, etc.)About the RoleAs a member of the Information Security team, the IS GRC Senior Analyst - Risk & Compliance will be responsible for understanding the firm’s security risk and compliance requirements. You will... 
    Senior
    Full time
    Contract work
    Work experience placement
    H1b
    Remote work
    Visa sponsorship
    Relocation package
    Monday to Friday

    AlixPartners

    Detroit, MI
    4 days ago
  • $138k - $173k

    THE POSITIONOur roster has an opening with your name on itFanDuel is seeking a Senior Technology Governance, Risk & Compliance (GRC) Analyst to join its Technology GRC team as a strategic specialist supporting our first line of defense (1LOD) function. This role offers... 
    Senior
    Temporary work
    Work at office
    Local area
    Worldwide
    Shift work

    FanDuel

    Atlanta, GA
    6 days ago
  •  ...Leading policy development and audit execution, the full-time Senior IT GRC Analyst will manage SOC 2 readiness efforts, maintain IT policies, and coordinate audit engagements in a remote environment. Key responsibilities Lead SOC 2 readiness assessments, including scope... 
    Senior
    Full time
    Remote work

    Virtual Vocations Inc

    United States
    1 day ago
  •  ...Senior GRC Analyst Wolfe is a Pittsburgh-based FinTech company operating consumer gifting and payments brands, and we are actively embedding AI across our products, our internal processes, and the way our teams work day-to-day. As Senior GRC Analyst, you will be the... 
    Senior

    Wolfe

    Pittsburgh, PA
    5 days ago
  •  ...special. We strive for nothing less than the very best information security program. The Role Support and advise the Director of GRC and the CISO on all related to risk and compliance for the enterprise. Support and coordinate the annual risk assessment and the... 
    Senior
    Odd job
    Remote work
    Flexible hours

    Hitachi

    United States
    3 days ago
  •  ...Owning and advancing the governance, risk, and compliance program, the full-time Senior GRC Analyst will manage compliance frameworks, conduct risk assessments, and collaborate with cross-functional teams in a remote capacity. Key Responsibilities: Lead the GRC program... 
    Senior
    Full time
    Remote work

    Virtual Vocations Inc

    United States
    3 days ago
  •  ...Senior GRC Analyst Location: Remote About Compyl Compyl is a high-growth, venture-backed GRC and automated security compliance platform built by security practitioners for security practitioners. Founded in 2020 by two former CISO's, we replace the spreadsheets... 
    Senior
    Local area
    Remote work

    Compyl

    United States
    1 day ago
  •  ...including business leaders, technical personnel, audit personnel, senior management, and the board of directors Applies Cybersecurity...  ...metrics General Governance, Risk, and Compliance (GRC) Support: Leads process analysis, development, & improvement... 
    Senior
    Work experience placement
    Work at office
    Remote work

    Louisiana Blue

    United States
    3 days ago
  •  ...The Role We Want You For Under the direction of and in collaboration with the GRC Manager, the Sr. GRC Analyst, Third-Party & Human Risk Management (TPHRM) is a risk-focused, highly analytical role that ensures all Human and Third-Party risk to Clayco is identified, quantified... 
    Senior
    Immediate start
    Flexible hours

    Gilder Search Group

    Phoenix, AZ
    5 days ago
  •  ...Sr. GRC Analyst, Risk Management Under the direction of and in collaboration with the GRC Manager, the Sr. GRC Analyst, Risk Management is the primary owner and operational steward of the Enterprise Risk Register. This role is responsible for ensuring all identified... 
    Senior
    For contractors
    Immediate start
    Flexible hours

    CRG

    Phoenix, AZ
    6 days ago
  • Ellenco Estágios e Treinamentos is seeking a Senior Information Security GRC Analyst to manage security audits and compliance efforts. The role requires over 10 years of experience in information security and a strong understanding of NIST standards. This position allows... 
    Senior
    Remote job

    Ellenco Estágios e Treinamentos

    New York, NY
    4 days ago
  • Gilder Search Group is looking for a Sr. GRC Analyst focused on Third-Party & Human Risk Management in St. Louis, Missouri. The role ensures all human and third-party risks to Clayco are identified and treated appropriately. Key responsibilities include owning the TPRM... 
    Senior

    Gilder Search Group

    Saint Louis, MO
    4 days ago
  • Gilder Search Group is looking for a Sr. GRC Analyst focusing on Third-Party & Human Risk Management in Atlanta, Georgia. This role involves risk analysis, compliance assessments, vendor management, and developing security awareness training. The ideal candidate has 6-8... 
    Senior

    Gilder Search Group

    Atlanta, GA
    4 days ago
  • Sky Mavis seeks a Sr. GRC Analyst in Phoenix, AZ, to manage Third-Party and Human Risk Management. This analytical role involves vendor risk assessment, security awareness training, and compliance evaluation, ensuring holistic risk management. Candidates should have significant... 
    Senior

    Sky Mavis

    Phoenix, AZ
    1 day ago
  • Senior Compensation Analyst (Experienced Professional)Build a Career That Matters with One of the World’s Most Respected Employers!- - - - - - - - - - - -The Opportunity We are seeking a Senior Compensation Analyst to join our Compensation & Total Rewards team and help... 
    Senior

    Michelin

    Greenville, SC
    3 days ago
  • BERRY Appleman & Leiden (BAL) is seeking a GRC/Information Security professional to lead internal audits and manage ISO 27001/27701 programs from its Richardson, TX location. You’ll drive risk-based audits, support privacy operations, and help shape AI governance and vendor... 
    Senior

    BAL

    Richardson, TX
    3 days ago
  • Sky Mavis is seeking a Senior GRC Analyst focused on Third-Party and Human Risk Management in St. Louis, Missouri. This role requires 6-8+ years of experience in Risk Assessment and Information Security, with strong analytical skills. You will lead the Vendor Risk Management... 
    Senior

    Sky Mavis

    Saint Louis, MO
    1 day ago
  • Bloomin' Brands, Inc. is seeking a Sr. GRC Analyst in Tampa, FL to support governance, risk, and compliance efforts across the organization. The role combines onsite and remote work in a hybrid schedule at the Tampa Restaurant Support Center. You will develop policies,... 
    Senior
    Remote work

    Bloomin' Brands, Inc.

    Tampa, FL
    4 days ago
  •  ...reporting Manage the maintenance of our compliance policies, standards, and procedures Report on our compliance posture to senior leadership Scale our GRC function with AI and automation, building quick wins and scoping requirements for Engineering to fully automate the... 
    Senior

    Jobtailor

    New York, NY
    3 days ago
  • A global beverage solutions provider is seeking a Sr IT Governance Risk and Controls Analyst in Tampa, Florida. This role focuses on maintaining and improving the IT governance, risk, and compliance program, particularly in SOX compliance. Responsibilities include conducting... 
    Senior

    Refresco

    Tampa, FL
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Experienced or Senior GRC Analyst. Be the first to apply!