GRC Analyst
Momentum
Momentum is a respected collection of independent companies, including PMG, Koddi, Further. We serve as a premier global business transformation partner for over 125 of the Fortune 500 brands. With 1,400 global employees and $5B in media spend under management, we foster a fast-growing, values-driven, people-first environment where you can thrive.
Our portfolio of companies partners with some of the world's most iconic and ambitious brands. We combine scalability with a solutions-oriented approach to deliver fast-paced, innovative results for our customers while creating meaningful growth opportunities for our teams. If you are looking for opportunities to grow in your career and are passionate about being at the forefront of data and technology, and driving rapid innovation in the future of commerce, we would love to talk with you about joining Momentum. We believe that a culture of belonging, inclusion, and diversity is key to empowering our team members to thrive both personally and professionally. Living out our values is not just a goal; it's a daily practice! For more information, please visit The OpportunityWe are hiring a Security GRC & Risk Analyst to own the governance, risk, and compliance execution layer across a holding company and portfolio of businesses. This is a build-oriented role with a defined scope: you will be the internal anchor for our SOC 2 Type II audit, NIST CSF remediation roadmap, security policy library, vendor risk program, and client-facing security questionnaires. You will work directly with the Cybersecurity Manager and a vCISO partner, collaborate with the Data Privacy legal team as a peer on overlapping policy areas, and engage regularly with portfolio company stakeholders. A dedicated internal Data Privacy legal team owns regulatory compliance - GDPR, CCPA, breach notification, and data subject rights. This role owns the technical controls layer: the evidence, the frameworks, the audit coordination, and the vendor risk program. Join us in this full-time role, based in our Dallas Office at the Link: 2601 Olive Street, Dallas, TX. Be part of a vibrant community where amazing people, data & insights, and perpetual innovation converge to shape the future of digital commerce! About This Role at Momentum What You'll Do SOC 2 & NIST CSF Program
- Own the internal SOC 2 Type II evidence collection process, keeping controls audit-ready year-round. Manage the audit timeline, day-to-day liaison with the external auditor, and remediation finding closure between cycles.
- Own the NIST CSF remediation roadmap: maintain the gap register, report progress to the VP and vCISO on a defined cadence, and coordinate with portfolio company IT teams to assess and close control gaps.
- Build and maintain a unified controls library mapping SOC 2 Trust Services Criteria, NIST CSF subcategories, and applicable regulatory requirements.
- Prepare the organization for bi-annual NIST CSF assessments, ensuring controls are documented and defensible.
- Operationalize the enterprise-wide information security policy library across the corporate entity and portfolio companies. Inventory gaps against SOC 2, NIST CSF, and applicable regulations; draft, publish, and version-control policies in coordination with the vCISO.
- Build and maintain annual policy attestation workflows across all employees. Bridge with the Data Privacy legal team on overlapping areas: data classification, retention, and incident notification.
- Develop and maintain the AI governance framework: tool intake review, data handling risk assessment, and acceptable use policy. Evaluate AI tools proposed across the corporate entity and portfolio companies against security and compliance standards.
- Own AI-related policy documentation and track emerging regulatory requirements including the EU AI Act and NIST AI RMF.
- Build and maintain a risk register with risk-to-control mapping. Define and document formal risk tolerance and appetite in coordination with the vCISO and leadership.
- Own the third-party risk management program. Define and implement a tiered due diligence model (critical, high, medium, low) and conduct recurring reviews of critical service providers.
- Manage vendor risk assessments for tools under evaluation - SASE, CASB, DLP, AI governance tooling, and security platform consolidation. Coordinate with the Data Privacy legal team on vendors with material data processing obligations.
- Lead operationalization of the GRC platform (OneTrust) for centralized vendor inventory, risk scoring, and lifecycle management.
- Manage and respond to inbound security questionnaires from portfolio company clients (SIG, CAIQ, and custom formats). Build and maintain a response library to improve turnaround time and accuracy.
- Coordinate with the Cybersecurity Operations Engineer to validate technical control responses and keep answers current as the security stack evolves.
- Own ITGC audit controls across identity, endpoint, cloud, and SaaS platforms. Support internal audit responses and evidence requests beyond the annual SOC 2 cycle.
- Own BCP/DR formalization: develop a business continuity charter, coordinate Business Impact Analysis across the corporate entity and portfolio companies, define RTO/RPO for critical operations, and ensure crisis management is embedded in the IR framework.
- Manage the KnowBe4 security awareness training program: campaign management, phishing simulations, completion tracking, and leadership reporting.
- Manage the security testing program as the organization transitions from annual to continuous autonomous pentesting. Own vendor relationships, track findings to remediation, and produce executive-ready reporting.
- 5-7 years in GRC, security compliance, risk management, or a closely related security function.
- Hands-on experience owning or supporting a SOC 2 Type II audit: evidence collection, control mapping, and auditor coordination.
- Solid working knowledge of NIST CSF: gap assessments, control mapping, and remediation tracking.
- Demonstrated experience building or formalizing a security policy library, not just updating existing documents.
- Experience managing third-party and vendor risk assessments using a tiered risk model.
- Experience responding to client security questionnaires: SIG, CAIQ, or similar formats.
- Clear understanding of the boundary between GRC and legal/privacy functions. Proven ability to work alongside a legal team without blurring lanes.
- Strong written communication: you can translate technical controls into clear, accurate language for clients, auditors, and executives.
- Disciplined project management: you own timelines, follow up without being asked, and don't let things fall through.
- Active daily use of AI and automation. We operate at 100% internal AI adoption. Non-negotiable.
- GRC platforms: OneTrust, Drata, Vanta, Whistic, or similar.
- Security awareness platforms: KnowBe4 or equivalent.
- ITGC working knowledge across identity (Okta), SaaS (Google Workspace), cloud (AWS, GCP, Azure), and endpoint (CrowdStrike).
- BCP/DR frameworks: BIA methodology, RTO/RPO definition, and tabletop exercise facilitation.
- AI governance frameworks: NIST AI RMF or EU AI Act.
- Familiarity with CASB, DLP, or cloud security posture tooling from a compliance and documentation standpoint.
- Private equity, holding company, or multi-entity compliance environment experience strongly preferred.
Vacancy posted 1 day ago
Similar jobs that could be interesting for youBased on the GRC Analyst in Dallas, TX vacancy
- Governance, Risk & Compliance (GRC) Analyst (AI Training) About the Role We're partnering with the world's leading AI research labs to build smarter, more trustworthy AI - and we need practitioners who know how GRC actually works in the real world. Your expertise...SuggestedHourly payOngoing contractContract workFreelanceRemote workFlexible hours
- ...Crunchyroll is seeking an experienced Risk Analyst to support our Information Security GRC team. This role emphasizes governance, risk, and compliance, ensuring technology evolution aligns with employee needs and strategic goals. Successful candidates will have over 8...SuggestedFlexible hours
- A leading staffing firm is seeking a GRC Analyst for a 100% remote opportunity. This role involves designing, implementing, and managing controls and risk workflows using AuditBoard while ensuring compliance with industry standards. The successful candidate will need over...SuggestedRemote work
- Vanguard is seeking a Governance, Risk & Compliance Analyst in Dallas, Texas to lead the modernization of GRC efforts. This role involves conducting risk assessments, developing security policies, and collaborating with stakeholders to enhance compliance strategies. The...Suggested
- ...Senior Governance, Risk, and Compliance (GRC) Process Analyst Boeing is seeking a detail-oriented and analytical Senior Governance, Risk, and Compliance (GRC) Process Analyst to support governance, risk, and compliance initiatives for Infrastructure team at our Mesa...SuggestedWork experience placement
- The Vanguard Group is seeking a Governance, Risk & Compliance Analyst, Specialist in Dallas, Texas. This role focuses on delivering GRC modernization initiatives, conducting risk assessments, and shaping security policies across the enterprise. The ideal candidate will...Visa sponsorship
- ...Ellation, Inc. is seeking a Risk Analyst to enhance its corporate Information Security GRC team. The role focuses on defining processes and implementing technologies to support a comprehensive security program. You will partner across teams to ensure designed technologies...Flexible hours
- ...Role: Governance Risk and Compliance Risk Register Analyst Location: 100% Remote, Work Location With-in the United States. Need consultant who having state experience- State of TX experience is plus Contract role Job description:...Contract workFor contractorsRemote work
- ...backbone of DTCC, leaders who stand at the forefront of DTCC's competitive endeavors across the globe. From accountants and financial analysts to internal consultants and workplace designers, the CFO Organization employs diverse individuals who work together to help make...
- ...Governance, Risk & Compliance Analyst, Specialist In this role, you will help deliver on our investment in GRC modernization. You will lead risk assessments, design and scale forward-looking governance, risk, and compliance programs, and serve as a trusted advisor who...Work experience placement
- ...services, industry experience, and culture at weaver.com. Position Profile Weaver is looking for a Governance, Risk, and Compliance (GRC) Senior Associate to join our growing firm. This position is responsible for day-to-day project management of 1-6 concurrent...Flexible hours
- Job Description Job Description ASAP Personnel is Hiring: Risk Assessment Specialist Location: Addison, TX Hours: M-F 7:30AM - 4:30PM In Office Pay:$45,000 - $50,00 (DOE) ASAP Personnel is seeking a highly analytical, professional, and detail-oriented...Work at officeImmediate start
- Senior Manager and Compliance Officer, BSA/AML Job Locations US-TX-Dallas ID 2026-3882 Category Regulatory Position Type Regular Full-Time Overview The Senior Manager, Financial Compliance and Touchpay Compliance ...Full timeTemporary workWork at officeLocal areaFlexible hours
- Job Description Job Description Healthcare Fraud Investigator Employment Type: Full-Time, Mid-Level Department: Litigation Support CGS is seeking a Healthcare Fraud Investigator to provide Legal Support for a large Government Project in Nashville, TN. The ...Full timeWork experience placementWork at officeLocal area
- divh2Credentialing Risk Compliance Specialist/h2pIntegrative Emergency Services, LLC (IES) is looking for a Credentialing Risk Compliance Specialist. The focus of this role is to proactively identify, prioritize, and resolve credentialing-related risks that may impact ...Work at officeShift workAfternoon shiftEarly shift
$77k - $202k
PwC is seeking a Senior Associate in Cybersecurity to design and develop risk programs. You will analyze complex problems, mentor junior team members, and maintain high standards in deliverables. A Bachelor's degree and 3 years of experience are required, while CISSP or...- Affirm is seeking a Compliance Analyst II to support its compliance governance and oversight program. Responsibilities include reviewing consumer complaints, addressing compliance concerns, and supporting process improvements. The ideal candidate has 3 to 5+ years of experience...Remote jobFlexible hours
- Mercor is seeking experienced regulatory compliance and risk management professionals to evaluate AI performance in compliance and risk-specific tasks. The role demands expertise in compliance frameworks and risk management. Candidates will review outputs, create scenarios...Remote job
$77k - $202k
Specialty/Competency: Cybersecurity & Privacy Industry/Sector: Not Applicable Time Type: Full time Travel Requirements: Up to 60% At PwC, our people in risk and compliance focus on maintaining regulatory compliance and managing risks for clients, providing advice, and...Full time- Goldman Sachs Group, Inc. is seeking an Associate in Dallas for their Compliance, Global Banking & Markets Compliance team. Responsibilities include overseeing compliance risk assessments and governance of the regulatory change management program while managing multiple...
$55.67k - $94.63k
ICF is seeking an experienced Program Support Specialist in Dallas, TX, to assist Head Start and Early Head Start grantees with programmatic support and compliance. The ideal candidate must have a Bachelor's degree in Education or a related field, with 5+ years of relevant...Full time- Private Risk Advisor The USI Insurance Services Personal Risk Practice provides comprehensive risk management and insurance consultation to high net worth individuals and family offices with complex financial and insurance needs. The Private Risk Advisor is an outside...Work at officeLocal area
- ...practice, providing production support for US-specific applications. • Work with the Project Manager, Project Lead, Senior Business Analyst, Development team, and QA team to facilitate project implementation and support. • Manage day-to-day interactions with the GMS US...Local area
- ...Job Summary The Senior Risk Analyst: Lending & Card Services supports credit and fraud risk management across Populus Financial Group’s card services and consumer lending portfolios. This role focuses on model monitoring, underwriting policy execution, and portfolio analytics...Full timeLocal areaMonday to FridayShift workWeekend work
- Cyber Security Risk And Compliance Specialist The Cyber Security Risk and Compliance Specialist focuses on maintaining the appropriate operational security posture for our organization. This is an Information Security Systems Officer (ISSO) role, responsible for developing...
- ...POSITION SUMMARY We are building and scaling a high-performance consumer lending platform and are looking for a Fraud Risk Analyst to help protect the business from identity fraud, first-party fraud, and credit abuse. This role sits at the intersection of fraud...Work at officeRemote work
- ENTERPRISE RISK MANAGEMENT - Risk Architecture - Associate The Enterprise Risk Management team is responsible for ensuring that the firm's risks are managed systemically, such that the firm has a regular, comprehensive view of its risk profile as well as of key trends...
- RISK Goldman Sachs' Risk Division develops comprehensive programs and processes to identify, monitor, assess and manage financial and non-financial risks in support of the firm's risk appetite statement and strategic business plans. Risk teams play a critical function...Work experience placement
- Associate, Market Risk Job Duties: Associate, Market Risk with Goldman Sachs & Co. LLC in Dallas, Texas. Participate in the ongoing review of risk measures (VaR, greeks, stress tests) and interact with 1st line risk takers. Evaluate risk taking behavior and influence...
- Credit Risk Associate As part of Risk Management and Compliance, you are at the center of keeping JPMorgan Chase strong and resilient. You help the firm grow its business in a responsible way by anticipating new and emerging risks, and using your expert judgement to...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to GRC Analyst. Be the first to apply!
Related searches




