GRC Analyst
DeWinter Group
This role is with a DeWinter Investment Management Partner Boston, MA - Hybrid Role - We are targeting local candidates that can be in the Boston office 3 days per week. 12 Month + contract (or contract to hire, if desired) Candidate Profile We are looking for someone who can operate independently and execute effectively. The successful consultant will be comfortable gathering information from subject-matter experts, challenging incomplete responses, organizing evidence, interacting with auditors, managing competing deadlines, and driving issues through resolution. The role requires strong attention to detail while maintaining a practical, risk-based approach appropriate for an enterprise financial services environment. Position Overview We are seeking an experienced GRC Analyst to support the Governance, Risk, and Compliance function for a leading financial services organization. This is a hands-on consulting role focused on client and operational due diligence, audit and control support, risk management, policy governance, and third-party risk. The individual will work closely with Information Security, Technology, Legal and Compliance, Internal Audit, Operations, and client-facing teams. The ideal candidate is a pragmatic, detail-oriented GRC professional who can independently manage multiple requests, work effectively with technical and business stakeholders, and translate security and technology controls into clear responses for clients, auditors, and external parties. Key Responsibilities Coordinate and prepare responses to RFPs, RFIs, Due Diligence Questionnaires (DDQs), Operational Due Diligence (ODD) requests, and other client or prospect security and technology risk inquiries. Partner with subject‑matter experts to develop accurate responses and maintain reusable, approved security and technology due‑diligence content. Support third‑party assurance examinations (e.g., SOC 1, SOC 2, and internal/external audits), including evidence collection, auditor requests, control‑owner coordination, and remediation tracking. Support IT control frameworks and regulatory compliance activities, including control documentation, evidence collection, testing coordination, issue management, and remediation. Maintain and enhance GRC processes, including risk registers, control inventories, audit findings, remediation tracking, policies, standards, exceptions, and supporting evidence. Conduct and coordinate technology, cybersecurity, information‑security, and operational risk assessments and work with control owners to address identified gaps. Support third‑party risk management, including vendor security assessments, SOC report reviews, risk documentation, and ongoing monitoring. Support governance and oversight of data protection and information‑security controls, including control requirements, risk assessments, metrics, exceptions, and remediation. Develop clear risk, audit, control, and remediation reporting for management and key stakeholders. Identify opportunities to automate and streamline GRC, audit, evidence‑collection, and due‑diligence processes. Qualifications 3–6 years of relevant experience in GRC, information security, technology risk, IT audit, operational risk, or a related discipline. Demonstrated experience responding to RFPs, DDQs, ODD requests, client security questionnaires, or similar due‑diligence requests. Experience supporting internal and external audits, control assurance activities, or regulatory compliance testing. Working knowledge of risk assessments, control design and testing, issue and remediation management, and policy governance. Familiarity with security and control frameworks such as NIST CSF, ISO 27001, SOC, COBIT, CIS Controls, or similar frameworks. Familiarity with third‑party security and technology risk assessments. Strong written and verbal communication skills, with the ability to work effectively with technical teams, business stakeholders, auditors, and client‑facing teams. Strong organizational skills and the ability to independently manage multiple concurrent questionnaires, audits, assessments, and remediation activities. Experience within financial services, asset management, or another highly regulated industry is required. Preferred Qualifications Relevant certifications such as CISA, CRISC, CISM, CISSP, CIA, Security+, or ISO 27001. Experience with GRC platforms, questionnaire‑management tools, workflow/ticketing systems, or reporting and automation tools. Familiarity with information protection and data governance frameworks. Experience improving or automating manual GRC and due‑diligence processes. #J-18808-Ljbffr
- The TeamThe Analyst Governance, Risk, and Compliance, a member of the Information Security - Governance, Risk and Compliance (GRC) team, focuses on implementing and maintaining governance frameworks, managing risk remediation activities, and ensuring adherence to regulatory...SuggestedWork experience placementWork at officeLocal area
$130k - $170k
...performance and extend healthspan. The Governance, Risk, and Compliance (GRC) team helps ensure technology and cybersecurity risks are... ...an execution-oriented Senior Governance, Risk, and Compliance Analyst to lead the day-to-day execution and support the ongoing operation...SuggestedFull timeWork at officeRelocation$85k - $95k
...the best travel search engine to make it easier for everyone to experience the world. KAYAK is looking for a motivated Associate GRC Analyst to join our Cyber Governance, Risk, and Compliance team! This is an exciting opportunity for an early‑career professional to grow...SuggestedInternshipWork at officeFlexible hours2 days per week3 days per week- KAYAK, part of Booking Holdings, is seeking an Associate GRC Analyst to join our Cyber Governance, Risk, and Compliance team. This early‑career role develops skills in risk assessments, policy management, and control monitoring while modernizing GRC practices. The position...SuggestedWork at office3 days per week
- Babel Street is seeking a GRC Analyst to support cybersecurity governance, risk management, and compliance across multiple stakeholders. You will help maintain compliance with NIST CSF, CMMC, ISO/IEC 27001, SOC 2, and related controls, and support audits and policy management...Suggested
$70k - $80k
...As a GRC Cybersecurity Analyst (CA), you will play a pivotal role securing our clients’ infrastructure, data and software. Beyond helping our clients, you will also make a huge impact and help society as a whole by contributing to our fast moving, passionate efforts to...Full timeWork at office$119k - $193k
Forrester Research, Inc. is seeking a Senior Analyst based in Cambridge, Massachusetts. This role involves delivering strategic advice for risk management leaders and conducting impactful research. The ideal candidate will have 5-7 years of experience in risk management...- KAYAK is seeking an Associate GRC Analyst to join the Cyber Governance, Risk, and Compliance team in Cambridge/Concord, MA. Early‑career professional with a solid foundation in GRC and interest in automation will thrive here. The role focuses on risk assessments, policy...Work at office3 days per week
$100k - $140k
...performance and extend healthspan. The Governance, Risk, and Compliance (GRC) team helps ensure technology and cybersecurity risks are... ....WHOOP is seeking a Governance, Risk, and Compliance Analyst II, to lead the day-to-day operation and support the ongoing risk...Full timeWork at officeRelocation$80k - $125k
...Position Summary The Governance, Risk & Compliance (GRC) Analystis responsible forsupporting andmaintainingthe organization... ...regulatory, contractual, and industry security requirements. The GRC Analyst will assist in maintaining compliance with the NIST...Flexible hours$90k - $200k
Senior Manager, Financial Investigations Kroll's North American Investigations, Diligence and Compliance practice is seeking a Senior Manager based in the U.S. This is a wide-ranging role in the Financial Investigations team. The Senior Manager will develop and manage...Temporary workFlexible hours$110k - $140k
At Franklin Templeton, we believe success is built through powerful partnerships. As a forward thinking asset manager, we build dynamic relationships with clients, understand their goals, and navigate complex markets together. We leverage cutting edge strategies and deep...Full timeWork at officeLocal area3 days per week$119k - $193k
...future.About This Role:Forrester is currently looking for a Senior Analyst to conduct research and deliver strategic advice for risk... ...Expertise in compliance management, internal or external audit, and GRC platforms is strongly desired.The successful candidate researches...Full timeFor contractorsRemote work$109.04k - $163.56k
Sr Risk Analyst - KR07DEWe’re determined to make a difference and are proud to be an insurance company that goes well beyond coverages and policies. Working here means having every opportunity to achieve your goals - and to help others accomplish theirs, too. Join our team...Full timeTemporary workWork at office3 days per week- QUALIFICATIONSMaster’s degree in quantitative fields such as mathematics, statistics, analytics, computational finance, computer science, economics, financial engineering, physics, or another relevant field2+ years of hands-on experience in quantitative modeling using advanced...ApprenticeshipWork at officeEasy work
$160k - $180k
...Risk Audit & Compliance (GRAC) team as a Technology Senior Risk Analyst. In this newly created role, the Technology Senior Risk Analyst... ...experience in Technology risk, Technology audit/compliance, or cyber GRC.Experience running RCSAs, defining KRIs/KPIs, and presenting...Temporary workFlexible hours$154.4k - $242.55k
By clicking the “Apply” button, I understand that my employment application process with Takeda will commence and that the information I provide in my application will be processed in line with Takeda’s Privacy Notice and Terms of Use. I further attest that all information...Minimum wageTemporary workLocal areaRemote workWorldwide$170.9k - $231.3k
OverviewThe Associate Director of Regulatory Affairs Strategy will serve as US Regional Lead or Global Regulatory Lead for our early/mid/late-stage CNS programs. The role will lead the regulatory strategy and facilitate submission of data packages to the US. The role is...Full timeTemporary workLocal areaFlexible hours2 days per week$170.9k - $231.3k
Overview The Associate Director, Regulatory Affairs CMC Development is responsible for developing and implementating global CMC regulatory strategies for development-stage programs. This role will play a critical part in shaping regulatory strategies for emerging therapeutic...Full timeTemporary workWork at officeLocal areaFlexible hours$154.4k - $242.55k
By clicking the “Apply” button, I understand that my employment application process with Takeda will commence and that the information I provide in my application will be processed in line with Takeda’s Privacy Notice and Terms of Use. I further attest that all information...Minimum wageTemporary workLocal areaRemote work- Company DescriptionBy working at Harvard University, you join a vibrant community that advances Harvard's world-changing mission in meaningful ways, inspires innovation and collaboration, and builds skills and expertise. We are dedicated to creating a diverse and welcoming...Work at officeLocal area
$160k - $190k
...management related to regulatory adoption or compliance changesAudit or certification readinessFamiliarity or direct experience with GRC/Cybersecurity solutions, tools and technologiesControl design or maturation for high-demand technical areas such as ERP, Identity and...Permanent employment- Job-ID31521196Reference25-04484 The Global Regulatory Affairs (GRA) is responsible for obtaining approval for new products and ensuring that approval is maintained throughout the product lifecycle. GRA serves as the interface between the regulatory authorities and the program...
$190.4k - $285.6k
Job DescriptionGeneral Summary:The Director, Chemistry Manufacturing Controls (CMC) leads a Regulatory CMC team responsible for developing and executing global regulatory strategies across multiple investigational and commercial products in the small molecule portfolio....Full timeSummer workRemote workFlexible hours2 days per week$171k - $273k
Job TitleHead of Regulatory, AM & DJob DescriptionHead of Regulatory, Ambulatory Monitoring & DiagnosticsThe Head of Regulatory for Ambulatory Monitoring & Diagnostics will develop and execute global regulatory strategies aligned with business objectives, serving as the...Full timeWork at officeImmediate startWork visaRelocation package3 days per week$145k - $215k
Who we are:Kymera is a clinical-stage biotechnology company pioneering the field of targeted protein degradation (TPD) to develop medicines that address critical health problems and have the potential to dramatically improve patients’ lives. Kymera is deploying TPD to address...$182k - $275k
Company OverviewRhythm is a global, commercial-stage biopharmaceutical company committed to transforming the lives of patients living with rare neuroendocrine diseases. We develop medicines for previously untreatable or undertreated diseases. We recognize the courage it...Work at office$163.5k - $281.6k
Job ID: R-108617Company: LillyLocation: Boston, Massachusetts, United States of AmericaJob Type: Full TimeCategory: Research & DevelopmentPosted Date: 2026-07-15At Lilly, the work is demanding because patients are waiting. We unite caring with discovery to help make life...For contractorsWork at officeFlexible hours$172.5k - $222.5k
Circle (NYSE: CRCL) is one of the world’s leading internet financial platform companies, building the foundation of a more open, global economy through digital assets, payment applications, and programmable blockchain infrastructure. Circle’s platform includes the world...Flexible hours- Job-ID31695693Reference26-00031 Responsibilities: The primary job responsibility for this position is overseeing the day-to-day functions of the Dentsply Sirona Essential Dental Solutions team This role develops regulatory strategies for existing, new, and modified medical...Work at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to GRC Analyst. Be the first to apply!

