Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Sr. GRC Analyst

$115k - $125k

Addison Group

Job Description

Job Description

Senior GRC Analyst

Industry: Professional Services / Information Security

Location: Chicago, IL

Work Schedule: Hybrid – Onsite Monday, Wednesday & Thursday

Assignment Type: Contract-to-Hire

Start Date: ASAP

Pay: $115,000-$125,000

About the Opportunity

Our client, a national professional services organization, is seeking a Senior Governance, Risk & Compliance (GRC) Analyst to help build and mature its internal Information Security GRC program.

This is a net-new position within an evolving security organization. The environment is still developing from a GRC process and tooling perspective, so this is an opportunity for someone who enjoys building—not simply maintaining an already mature compliance program.

The Senior GRC Analyst will play a hands-on role across SOC 2, enterprise risk management, security risk assessments, policy management, NIST Cybersecurity Framework (CSF), audit readiness, remediation tracking, and executive reporting .

The ideal candidate is a hands-on problem solver who can walk into an environment where every process or tool may not yet exist, identify what needs to improve, and develop practical solutions.

This is a senior individual-contributor position with no direct reports . The Senior GRC Analyst will also provide guidance and mentorship to another GRC resource while working closely with senior Information Security leadership.

Key Responsibilities

SOC 2, Compliance & Audit

  • Help strengthen and drive the organization's SOC 2 compliance and readiness program .
  • Coordinate audit requests, evidence collection, and control-owner responses.
  • Perform or coordinate control testing and validation.
  • Identify control deficiencies and compliance gaps.
  • Track audit findings and corrective actions through closure.
  • Partner with control owners to develop practical remediation plans.
  • Coordinate directly with auditors and internal stakeholders throughout compliance activities.
  • Improve the overall structure and sustainability of the SOC 2 program.

Enterprise Risk Management

  • Establish and maintain the enterprise information security risk register .
  • Lead security risk assessments across the organization.
  • Perform control-gap analyses and security maturity assessments.
  • Identify, analyze, document, and prioritize security risks.
  • Develop risk-treatment and remediation plans.
  • Manage risk acceptance and security exceptions.
  • Identify and document compensating controls.
  • Track remediation activities through completion.
  • Translate technical security risks into clear, business-focused recommendations for leadership.

Governance & NIST CSF

  • Help operationalize the organization's information security governance program using NIST CSF 2.0 .
  • Apply NIST CSF to risk assessments, governance processes, controls, policies, and maturity evaluations.
  • Maintain governance calendars, control assessments, risk reviews, and reporting cycles.
  • Establish clear ownership and accountability for security controls.
  • Identify systemic control gaps and opportunities to improve the overall security program.
  • Help translate security frameworks into practical processes that can be consistently executed across the organization.

Policy Management

  • Own and improve the information security policy lifecycle .
  • Develop, review, update, and maintain security policies, standards, and procedures.
  • Coordinate policy review and approval processes.
  • Maintain policy publication, version control, and evidence retention.
  • Map policies, standards, and procedures to NIST CSF 2.0 and applicable compliance requirements.
  • Maintain policy exceptions and residual-risk documentation.
  • Help ensure security policies are operationalized rather than simply documented.

Reporting & Program Improvement

  • Develop GRC dashboards, metrics, KRIs and KPIs .
  • Provide leadership with clear reporting on:
    • Enterprise security risk
    • SOC 2 readiness
    • Compliance status
    • Policy governance
    • Remediation progress
  • Identify weaknesses in existing GRC processes and develop practical improvements.
  • Help establish repeatable, scalable GRC processes where formal processes or tooling may not yet exist.
  • Drive multiple GRC initiatives simultaneously using a strong project-management mindset.

The position owns key activities spanning risk assessments and the risk register, policy lifecycle management, SOC 2, security exceptions, remediation, reporting, and NIST CSF governance.

Required Qualifications

  • 5+ years of experience in Information Security, GRC, IT Risk, Security Compliance, Audit, or a related discipline.
  • Strong hands-on experience with SOC 2 compliance and readiness .
  • Experience taking meaningful ownership of SOC 2 activities—not solely collecting audit evidence.
  • Experience coordinating controls, evidence, findings, remediation, and audit activities.
  • Demonstrated experience leading security risk assessments .
  • Experience identifying and evaluating control gaps.
  • Hands-on experience developing and maintaining risk registers .
  • Experience developing risk-treatment and remediation plans.
  • Ability to drive identified risks and remediation items through closure.
  • Strong experience developing, reviewing, and maintaining information security policies, standards, and procedures .
  • Practical experience applying NIST Cybersecurity Framework (NIST CSF) .
  • Experience performing security maturity and/or gap assessments.
  • Demonstrated ability to operate successfully within an evolving or immature GRC environment .
  • Ability to create effective processes when mature tools or established workflows do not already exist.
  • Strong project-management and organizational skills.
  • Ability to manage multiple concurrent GRC initiatives.
  • Strong analytical and problem-solving capabilities.
  • Excellent written and verbal communication.
  • Ability to communicate effectively with technical teams, non-technical business stakeholders, and senior leadership.
  • Bachelor's degree in a relevant discipline or equivalent practical experience.

The formal qualifications specifically call for hands-on SOC 2, risk assessment/risk-register ownership, policy management, practical NIST CSF application, and the ability to build solutions in an immature GRC environment.

Preferred Qualifications

  • CISA
  • CRISC
  • CISM
  • CISSP
  • Security+ or comparable security/GRC certification
  • ISO 27001 experience
  • IT General Controls (ITGC) experience
  • Third-party risk management
  • Client security questionnaires / assurance
  • AI governance
  • Data protection / privacy-related security experience
  • Security awareness program experience
  • Experience with GRC and workflow technologies such as:
    • AuditBoard
    • ServiceNow GRC
    • OneTrust
    • Archer
    • Jira
    • SharePoint

Certifications are valued, but practical GRC experience and demonstrated ownership are more important for this position.

What We're Looking For

This is not a role for someone who needs an established GRC program, mature tooling, or highly defined processes in order to be successful .

The ideal candidate is comfortable hearing:

"We know this needs to be better—help us figure out how to fix it."

You should be able to assess the current state, identify gaps, prioritize what matters, develop a practical solution, gain stakeholder buy-in, and then drive the work through implementation.

We're particularly interested in candidates who can provide specific examples of personally:

  • Driving or significantly improving a SOC 2 program
  • Leading a security risk assessment
  • Building or improving an enterprise risk register
  • Identifying control gaps and developing remediation plans
  • Driving remediation through closure
  • Developing or restructuring security policies
  • Applying NIST CSF to a real-world security program
  • Building GRC processes without sophisticated tooling
  • Working directly with auditors
  • Coordinating technical and business stakeholders
  • Managing several GRC initiatives simultaneously

The goal of the position is to help turn an immature GRC environment into a more structured and sustainable program across SOC 2, risk management, remediation, policy governance, and NIST CSF.

Leadership & Mentorship

This is a senior individual-contributor position—not a people-management role .

The Senior GRC Analyst will:

  • Serve as a trusted GRC advisor to technical and business stakeholders.
  • Provide guidance and mentorship to another GRC Analyst.
  • Share GRC best practices and practical knowledge.
  • Help improve the consistency and quality of GRC work.
  • Partner closely with Information Security leadership.
  • Help drive accountability across control owners and stakeholders.

The position has no direct reports but is expected to provide mentorship and senior-level guidance.

Core GRC Focus Areas

  • SOC 2
  • NIST CSF 2.0
  • Enterprise Risk Management
  • Security Risk Assessments
  • Risk Registers
  • Risk Treatment
  • Control Gap Analysis
  • Security Maturity Assessments
  • Information Security Policy Management
  • Audit Readiness
  • Control Testing
  • Evidence Management
  • Findings & Remediation
  • Security Exceptions
  • Compensating Controls
  • KRIs / KPIs
  • Executive Reporting
  • Third-Party Risk
  • GRC Process Improvement

Work Environment

  • Hybrid position based in downtown Chicago
  • Onsite Monday, Wednesday, and Thursday
  • Contract-to-hire
  • Highly visible position within the internal Information Security organization
  • Significant interaction with IT, Legal, Privacy, HR, and business leadership
  • Opportunity to directly influence how the organization's GRC program is built and matured

Additional Details

  • Net-new position
  • ASAP start
  • Senior individual-contributor role
  • No direct reports
  • Two-step interview process:
    • Initial video interview with Information Security leadership
    • Final onsite interview with additional team stakeholders
  • Strong emphasis on practical experience, ownership, communication, and problem solving

Benefits

Eligible consultants may receive:

  • Medical and prescription drug coverage
  • Dental insurance
  • Vision insurance
  • Health Savings Account (HSA)
  • Flexible Spending Accounts (FSA)
  • Short-Term and Long-Term Disability Insurance
  • Supplemental Life Insurance
  • 401(k)
  • Weekly pay

If you're a hands-on Senior GRC Analyst who has personally driven SOC 2, risk assessments, policy management, remediation, and NIST CSF initiatives—and you enjoy building programs rather than simply maintaining them—apply today to learn more.

Addison Group is an Equal Opportunity Employer. Addison Group provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, gender, sexual orientation, national origin, age, disability, genetic information, marital status, amnesty, or status as a covered veteran in accordance with applicable federal, state and local laws. Addison Group complies with applicable state and local laws governing non-discrimination in employment in every location in which the company has facilities. Reasonable accommodation is available for qualified individuals with disabilities, upon request.

Vacancy posted 11 days ago
Similar jobs that could be interesting for youBased on the Sr. GRC Analyst in Chicago, IL vacancy
  • $76k - $134k

     ...driven decisions, mitigate risks & deliver projects on time & within budget. Position Responsibilities Responsibilities: As a Senior GRC Analyst, you will support assessment, audit readiness, cloud security compliance, risk management, & security tooling across SaaS/cloud... 
    Senior
    Contract work
    Temporary work
    For contractors

    Deltek

    Chicago, IL
    4 days ago
  •  ...GRC Analyst The GRC Analyst is a member of the IT Security team and works closely with other IT teams and business stakeholders in the development and automation of core functions supporting the Information Security program. The GRC Analyst will work to support the... 
    Suggested

    1872 Consulting

    Chicago, IL
    6 days ago
  • $109k - $131k

     ...geographic footprint and value the talent that comprises each of our locations. Benesch is proud to announce the opening for a GRC Analyst in our Chicago office! This position is hybrid and has work from home flexibility. Position Summary Are you an experience cybersecurity... 
    Suggested
    Full time
    Work at office
    Local area
    Work from home

    Benesch, Friedlander, Coplan & Aronoff

    Chicago, IL
    5 days ago
  • A leading recruitment firm is seeking a Governance, Risk & Compliance (GRC) Analyst in Chicago to enhance risk management strategies within the healthcare sector. The successful candidate will coordinate vendor assessments, manage audits, and maintain compliance with regulatory... 
    Suggested

    recruit22

    Chicago, IL
    6 days ago
  • $58.8k - $102.1k

     ...Job Description Position Summary The Logistics Trade Compliance Sr Analyst is responsible for executing and coordinating key operational trade compliance activities while providing guidance to cross-functional partners on import/export compliance requirements, documentation... 
    Senior
    Minimum wage
    Full time
    Remote work
    Shift work

    Constellation Brands

    Chicago, IL
    16 hours ago
  • $70.6k - $149.6k

    At HCSC, our employees are the cornerstone of our business and the foundation to our success. We empower employees with curated development plans that foster growth and promote rewarding, fulfilling careers. Join HCSC and be part of a purpose-driven company that will ...
    Senior
    For contractors

    Health Care Service Corporation

    Chicago, IL
    4 days ago
  • $112.2k - $202.6k

    Job SummaryThis position is responsible for managing the implementation, maintenance and critical review and analysis of models, studies and systems which use actuarial principles for the purposes of pricing, underwriting, statistics, reserving, forecasting and other actuarial...
    Senior
    Work at office
    Visa sponsorship
    3 days per week

    Health Care Service Corporation

    Chicago, IL
    3 days ago
  • $60k - $75k

     ...stakeholders. Strategize on building models and assist with deployments into production. Doing ad-hoc analysis and presenting results to Sr. Management Why you’re at fit: ~ Bachelor's Degree in Technology, Statistics, Business Analytics, related field, or its... 
    Senior
    Summer work
    Work at office
    Flexible hours
    Weekend work

    Avant

    Chicago, IL
    13 hours ago
  • $268.5k - $398.75k

     ...everything we do - and they push us to ensure we take care of ourselves, each other, and our communities.Job Summary:PayPal is seeking a Sr. Director, US Regulatory Legal. This individual will provide strategic legal leadership across PayPal’s US federal and state... 
    Senior
    Full time
    Work at office
    Local area
    Immediate start
    Flexible hours

    PayPal

    Chicago, IL
    9 days ago
  •  ...has been recognized by various market research firms, including Forrester and Gartner. We are looking for experienced Credit Risk Analyst to join its credit risk strategy team. This role will focus on credit card portfolio management, credit line strategies, and developing... 
    Senior
    Work at office
    Local area

    Tiger Analytics

    Chicago, IL
    3 days ago
  • $89.8k - $112.2k

     ...Job Description Role / Title: The Senior Analyst of Warehouse Operations is the main point of contact for their respective sites, working closely with both internal and external partners to deliver results. They are responsible for managing the day-to-day metrics and... 
    Senior
    Flexible hours

    The Kraft Heinz Company

    Chicago, IL
    8 hours ago
  • $112.2k - $202.6k

    At HCSC, our employees are the cornerstone of our business and the foundation to our success. We empower employees with curated development plans that foster growth and promote rewarding, fulfilling careers. Join HCSC and be part of a purpose-driven company that will...
    Senior
    Work at office
    Visa sponsorship
    3 days per week

    Health Care Service Corporation

    Chicago, IL
    5 days ago
  • $192.56k - $264.77k

    Job Description: Job Purpose/Overview Packaging Sustainability has rapidly emerged as a significant threat to our business with concerns from government regulators, customers and consumers as to the impact of packaging waste on the natural environment. While facing...
    Senior
    Local area
    Chicago, IL
    6 days ago
  • $61k - $136k

     ...valued so your life can be as rewarding as your career. One of the largest Health insurers in the country is in search of a Sr Actuarial Analyst. This individual will run complicated models, perform detailed analysis of the results, and present findings for decision making... 
    Senior
    Remote work

    DW Simpson

    Chicago, IL
    8 days ago
  •  ...Sr Regulatory Compliance Analyst (EPIC) Inspired by faith. Driven by innovation. Powered by humankindness. CommonSpirit Health is building a healthier future for all through its integrated health services. As one of the nation's largest nonprofit Catholic healthcare... 
    Senior
    Shift work

    Common Spirit Health

    Chicago, IL
    4 days ago
  •  ...Sr. BSA/AML Compliance Analyst The Symicor Group is a boutique talent acquisition firm based in Lincolnshire, IL & Rockport, TX. Our nationally unique value proposition centers around providing the very best available banking and accounting talent. In fact, most of... 
    Senior
    Work at office

    The Symicor Group

    Chicago, IL
    3 days ago
  • Senior Regulatory Specialist Join the Regulatory Advisor and Interpretations Department, within Cboe's Regulatory Division, that helps advance the Division's mission of creating trusted markets through regulatory program support, rule interpretation, and coordination...
    Senior
    Contract work

    Insight Global

    Chicago, IL
    2 days ago
  • $98.18k - $127.05k

     ...applicable rules and regulations governing Exchange Members and Trading Permit Holders (“TPHs”). THE ROLE The Senior Surveillance Analyst performs analysis of daily and pattern-based surveillances of trading activity on the Cboe Exchanges to detect possible violations... 
    Senior
    Immediate start

    Cboe Global Markets

    Chicago, IL
    13 hours ago
  • 5+ years of legal and/or financial markets experience in a professional, administrative or analyst role. Change management experience and strong documentation skills Strong organizational & communication skills Knowledge of financial markets and relevant exchange, SEC,... 
    Senior
    Contract work

    Insight Global

    Chicago, IL
    5 days ago
  •  ...Get AI-powered advice on this job and more exclusive features. IDR is seeking a Senior Data Analyst to join one of our top clients fully remote. This role is perfect for a seasoned professional with a strong background in data analytics and software development, who... 
    Senior
    Full time
    Contract work
    Remote work

    IDR, Inc.

    Chicago, IL
    3 days ago
  • $61.5k - $136.1k

    Job Summary This position is responsible for participating in implementation, maintenance and more detailed analysis of models, studies and systems which use actuarial principles for the purposes of pricing, underwriting, statistics, reserving, forecasting and other...
    Senior
    Remote job

    Health Care Service Corporation

    Chicago, IL
    3 days ago
  •  ...- Excellent leadership, communication, and stakeholder management abilities. Reports to - Sr. Director of Rewards, P&O Admin & Compliance Direct Reports - Compliance Analyst, P&O SC Rep III The base pay range for this position is $107,176 to $171,0336 annually. Actual... 
    Senior
    Local area
    Work visa

    Wells Enterprises

    Chicago, IL
    5 days ago
  • $61.5k - $136.1k

    Job Summary The position involves participating in implementation, maintenance, and detailed analysis of actuarial models, studies, and systems used for pricing, underwriting, statistics, reserving, forecasting, and other actuarial functions. The role also requires running...
    Senior
    Work at office
    3 days per week

    Health Care Service Corp.

    Chicago, IL
    4 days ago
  • All locations Boise, United States; Chicago, United States; Denver, United States; Philadelphia, United States; Phoenix, United States; Location: Remote, USA Job Description Responsible for working with both HSB and Munich Re Underwriters to support profitable...
    Remote work

    Munich Reinsurance America, Inc.

    Chicago, IL
    2 days ago
  • Sr Business AnalystChicago, IL - OnsiteRequired:Ability to understand, communicate and engage effectively with multiple stakeholders...  ...experience highly preferredSummary:The Sr. Business Analyst will be working with motivated teams on highly visible and valuable... 
    Senior

    Echo IT Solutions

    Chicago, IL
    3 days ago
  • Crowe is seeking a Senior Staff to assess third party information security postures and coordinate end-to-end assessments at client or partner sites. The role involves engaging with client IS and business leadership, as well as vendors and service providers, to identify...
    Senior
    Remote work

    Crowe

    Chicago, IL
    5 days ago
  • $102.85k - $133.1k

     ...Paralegal Certificate preferred. ~ Five or more years of legal and/or financial markets experience in a professional, administrative or analyst role. The ability to: Interact in a professional manner with internal and external contacts; use tact and diplomacy;... 
    Senior
    Full time
    Contract work
    Work at office
    Immediate start

    Cboe Global Markets

    Chicago, IL
    4 days ago
  • Job Title: Sr. Business Analyst Job ID: 2023-12430 Job Location: Chicago, IL Job Travel Location(s): # Positions: 1 Employment Type: W2 Candidate Constraints: Duration: Long term # of Layers: Work Eligibility: Key Technology: PBM, Analysis, workflows Job Responsibilities... 
    Senior

    Highbrow LLC

    Chicago, IL
    3 days ago
  • $164.6k - $288k

    About Northern TrustAs a global leader in innovative wealth management, asset servicing, asset management and banking services, Northern Trust (Nasdaq: NTRS) is proud to guide the world’s most successful individuals, families, corporations and institutions. Since 1889, ...
    Senior
    Full time
    H1b
    Worldwide
    Flexible hours

    Northern Trust

    Chicago, IL
    6 days ago
  •  ...Sr. Research Analyst The Advanced Electron Microscopy Facility's mission is to develop and apply cutting-edge cryo-preservation techniques that capture biological samples in their near-native 'live' state, enabling ultrastructural analysis through 3D electron tomography... 
    Senior
    Work experience placement

    University of Chicago

    Chicago, IL
    5 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Sr. GRC Analyst. Be the first to apply!