GRC Analyst
Momentum
Momentum is a respected collection of independent companies, including PMG, Koddi, Further. We serve as a premier global business transformation partner for over 125 of the Fortune 500 brands. With 1,400 global employees and $5B in media spend under management, we foster a fast-growing, values-driven, people-first environment where you can thrive.
Our portfolio of companies partners with some of the world's most iconic and ambitious brands. We combine scalability with a solutions-oriented approach to deliver fast-paced, innovative results for our customers while creating meaningful growth opportunities for our teams. If you are looking for opportunities to grow in your career and are passionate about being at the forefront of data and technology, and driving rapid innovation in the future of commerce, we would love to talk with you about joining Momentum. We believe that a culture of belonging, inclusion, and diversity is key to empowering our team members to thrive both personally and professionally. Living out our values is not just a goal; it's a daily practice! For more information, please visit The OpportunityWe are hiring a Security GRC & Risk Analyst to own the governance, risk, and compliance execution layer across a holding company and portfolio of businesses. This is a build-oriented role with a defined scope: you will be the internal anchor for our SOC 2 Type II audit, NIST CSF remediation roadmap, security policy library, vendor risk program, and client-facing security questionnaires. You will work directly with the Cybersecurity Manager and a vCISO partner, collaborate with the Data Privacy legal team as a peer on overlapping policy areas, and engage regularly with portfolio company stakeholders. A dedicated internal Data Privacy legal team owns regulatory compliance - GDPR, CCPA, breach notification, and data subject rights. This role owns the technical controls layer: the evidence, the frameworks, the audit coordination, and the vendor risk program. Join us in this full-time role, based in our Dallas Office at the Link: 2601 Olive Street, Dallas, TX. Be part of a vibrant community where amazing people, data & insights, and perpetual innovation converge to shape the future of digital commerce! About This Role at Momentum What You'll Do SOC 2 & NIST CSF Program
- Own the internal SOC 2 Type II evidence collection process, keeping controls audit-ready year-round. Manage the audit timeline, day-to-day liaison with the external auditor, and remediation finding closure between cycles.
- Own the NIST CSF remediation roadmap: maintain the gap register, report progress to the VP and vCISO on a defined cadence, and coordinate with portfolio company IT teams to assess and close control gaps.
- Build and maintain a unified controls library mapping SOC 2 Trust Services Criteria, NIST CSF subcategories, and applicable regulatory requirements.
- Prepare the organization for bi-annual NIST CSF assessments, ensuring controls are documented and defensible.
- Operationalize the enterprise-wide information security policy library across the corporate entity and portfolio companies. Inventory gaps against SOC 2, NIST CSF, and applicable regulations; draft, publish, and version-control policies in coordination with the vCISO.
- Build and maintain annual policy attestation workflows across all employees. Bridge with the Data Privacy legal team on overlapping areas: data classification, retention, and incident notification.
- Develop and maintain the AI governance framework: tool intake review, data handling risk assessment, and acceptable use policy. Evaluate AI tools proposed across the corporate entity and portfolio companies against security and compliance standards.
- Own AI-related policy documentation and track emerging regulatory requirements including the EU AI Act and NIST AI RMF.
- Build and maintain a risk register with risk-to-control mapping. Define and document formal risk tolerance and appetite in coordination with the vCISO and leadership.
- Own the third-party risk management program. Define and implement a tiered due diligence model (critical, high, medium, low) and conduct recurring reviews of critical service providers.
- Manage vendor risk assessments for tools under evaluation - SASE, CASB, DLP, AI governance tooling, and security platform consolidation. Coordinate with the Data Privacy legal team on vendors with material data processing obligations.
- Lead operationalization of the GRC platform (OneTrust) for centralized vendor inventory, risk scoring, and lifecycle management.
- Manage and respond to inbound security questionnaires from portfolio company clients (SIG, CAIQ, and custom formats). Build and maintain a response library to improve turnaround time and accuracy.
- Coordinate with the Cybersecurity Operations Engineer to validate technical control responses and keep answers current as the security stack evolves.
- Own ITGC audit controls across identity, endpoint, cloud, and SaaS platforms. Support internal audit responses and evidence requests beyond the annual SOC 2 cycle.
- Own BCP/DR formalization: develop a business continuity charter, coordinate Business Impact Analysis across the corporate entity and portfolio companies, define RTO/RPO for critical operations, and ensure crisis management is embedded in the IR framework.
- Manage the KnowBe4 security awareness training program: campaign management, phishing simulations, completion tracking, and leadership reporting.
- Manage the security testing program as the organization transitions from annual to continuous autonomous pentesting. Own vendor relationships, track findings to remediation, and produce executive-ready reporting.
- 5-7 years in GRC, security compliance, risk management, or a closely related security function.
- Hands-on experience owning or supporting a SOC 2 Type II audit: evidence collection, control mapping, and auditor coordination.
- Solid working knowledge of NIST CSF: gap assessments, control mapping, and remediation tracking.
- Demonstrated experience building or formalizing a security policy library, not just updating existing documents.
- Experience managing third-party and vendor risk assessments using a tiered risk model.
- Experience responding to client security questionnaires: SIG, CAIQ, or similar formats.
- Clear understanding of the boundary between GRC and legal/privacy functions. Proven ability to work alongside a legal team without blurring lanes.
- Strong written communication: you can translate technical controls into clear, accurate language for clients, auditors, and executives.
- Disciplined project management: you own timelines, follow up without being asked, and don't let things fall through.
- Active daily use of AI and automation. We operate at 100% internal AI adoption. Non-negotiable.
- GRC platforms: OneTrust, Drata, Vanta, Whistic, or similar.
- Security awareness platforms: KnowBe4 or equivalent.
- ITGC working knowledge across identity (Okta), SaaS (Google Workspace), cloud (AWS, GCP, Azure), and endpoint (CrowdStrike).
- BCP/DR frameworks: BIA methodology, RTO/RPO definition, and tabletop exercise facilitation.
- AI governance frameworks: NIST AI RMF or EU AI Act.
- Familiarity with CASB, DLP, or cloud security posture tooling from a compliance and documentation standpoint.
- Private equity, holding company, or multi-entity compliance environment experience strongly preferred.
Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the GRC Analyst in Dallas, TX vacancy
$100.8k - $168k
McKesson is an impact-driven, Fortune 10 company that touches virtually every aspect of healthcare. We are known for delivering insights, products, and services that make quality care more accessible and affordable. Here, we focus on the health, happiness, and well-being...Suggested- ...simulations, analysis, and decision-making, accelerating discovery and driving faster innovation. THE POSITION NMC² is hiring a GRC Analyst to join the Information Security team, reporting to the GRC & Privacy Manager and based at our Dallas, TX offices at Victory Commons...SuggestedTemporary workFlexible hours
- Position Summary The Federal Exchange GRC Analyst owns federal Health Insurance Exchange and Enhanced Direct Enrollment compliance for the health business, including Audit Readiness Certification and Annual Marketplace Privacy Evaluation obligations and Centers for Medicare...SuggestedWork at officeLocal area
- BERRY Appleman & Leiden (BAL) is seeking a GRC/Information Security professional to lead internal audits and manage ISO 27001/27701 programs from its Richardson, TX location. You’ll drive risk-based audits, support privacy operations, and help shape AI governance and vendor...Suggested
- Crunchyroll is seeking an experienced Risk Analyst to support our Information Security GRC team. This role emphasizes governance, risk, and compliance, ensuring technology evolution aligns with employee needs and strategic goals. Successful candidates will have over 8 years...SuggestedFlexible hours
- Berry Appleman & Leiden (BAL) in Richardson, TX, is seeking an experienced Information Security, GRC, or Privacy professional to lead audits, risk assessments, and policy governance within our ISO-aligned program. You will partner with security, legal, and operations teams...
- Berry Appleman & Leiden (BAL) is seeking an experienced GRC/Audit professional to help manage security, privacy, and AI governance across the firm. You will lead audits, shape ISMS/PIMS maintenance, and align controls with global standards. You will collaborate with cross...
- NorthMark Compute & Cloud (NMC²) is seeking a GRC Analyst to join the Information Security team in Dallas. You will own the security change management review, conduct risk and vendor assessments, maintain the enterprise risk register, and manage the policy library. Day...
- NorthMark Strategies LLC is hiring a GRC Analyst to join the Information Security team in Dallas, TX. You will drive governance processes, risk assessments, policy library management, and cross‑functional coordination with Engineering, Product, Legal, and Operations. You...
- Integrity, headquartered in Dallas, TX, seeks a Federal Exchange GRC Analyst to own compliance for federal Health Insurance Exchange and Enhanced Direct Enrollment, including Audit Readiness Certification and Privacy Evaluation obligations. This role requires disciplined...
- ...OR ~4+ years of experience in Risk Management or Third-Party Risk Management (TPRM) with a strong focus on Information Security and GRC; OR ~4+ years of experience in Information Technology with a dedicated focus on Security or GRC. ~ Experience or familiarity with...
- NorthMark Compute & Cloud in Dallas, TX is seeking a GRC Analyst to join the Information Security team. You will manage security change reviews, perform risk and vendor assessments, and maintain the enterprise risk register, aligning policies with frameworks to protect...
$118k
...SAP GRC Analyst / SAP Security AnalystLocation: Monday - Friday - Onsite in Richardson, TX Employment Type: Direct Hire - Full-Time Employment Salary Range: $118K + BonusPosition OverviewWe are seeking an experienced SAP GRC Analyst to serve as the critical link between...Full timeMonday to Friday- Vanguard is seeking a Governance, Risk & Compliance Analyst, Specialist to lead enterprise‑wide information security policies and standards... ...within defined risk controls. You will assess the end‑to‑end GRC framework, monitor policy lifecycles, and use data‑driven methods...
- ...to predict risk issues, develop solutions, and partner with key owners and stakeholders.Designs, implements and supports modernized GRC process and tool capabilities.Participates in special projects and performs other duties as assigned.QualificationsSeven years related...Full timeWork experience placement
- Risk Division The Risk Division develops comprehensive processes to monitor, assess and manage the risk of expected and unexpected events that may have an adverse impact on the firm. Risk teams play a critical function for the firm, driving how the firm takes and manages...
- Asset & Wealth Management Divisional Overview A career with Goldman Sachs Asset & Wealth Management is an opportunity to help clients across the globe realize their potential, while you discover your own. As part of one of the world’s leading asset managers with over $3...Private practiceWork at office
$112.61k - $172.21k
Who You Are:The Senior Analyst, Insurance and Risk Management will serve as a key contributor responsible for executing development insurance and risk management activities supporting large-scale data center campuses. The role partners closely with cross-functional stakeholders...- ...Skill and ExperienceThe ideal candidate is a highly organized Risk Analyst with strong project management and documentation skills who can... .... Experience supporting Governance, Risk, and Controls (GRC) programs in financial services or other regulated environments....Full timeTemporary workWork at officeRelocation
- OverviewWe are seeking a highly motivated and detail-oriented Operational Risk Associate to join our AM Private Operational Risk team. This position plays an integral role in supporting the risk management framework across multiple business segments within the Goldman Sachs...Work at office
- JOB TITLE: Associate, Operational RiskENTITY: Goldman Sachs & Co. LLCDIVISION: Risk DivisionJOB LOCATION: 717 North Harwood Street, Dallas, TX 75201Number of direct reports: NoneJOB DUTIES:· Identify, monitor, and analyze operational risks arising from data management practices...
- ...team and culture and contribute to our core mission which is enhancing our customer's experience.Position Summary:The Senior Risk Analyst, Commercial Lending Analytics, will support the development, calibration, and ongoing performance monitoring of commercial lending...Work at officeVisa sponsorshipWork visaMonday to FridayWeekend work
- RISK Goldman Sachs’ Risk Division develops comprehensive programs and processes to identify, monitor, assess and manage financial and non-financial risks in support of the firm’s risk appetite statement and strategic business plans. Risk teams play a critical function for...Work experience placement
$114.72k - $172.08k
Compliance Risk Management OfficerServes as a compliance risk officer for Independent Compliance Risk Management (ICRM) responsible for establishing internal strategies, policies, procedures, processes, and programs to prevent violations of law, rule, or regulation and...Flexible hours- How You Will Fulfill Your PotentialManage all aspects of issue identification, analysis, remediation and monitoring & reporting, including collaboration with issue owners, aggregation of issues across the business, and facilitation of executive reporting.Proactively identify...
$109.6k - $191.7k
Senior Risk ConsultantRemote - USAProvides loss control support for Property & Casualty underwriters and insurance customers in AXA XL’s Americas - Environmental unit. What you’ll be doingWhat will your essential responsibilities include?Provides underwriting and loss control...For contractorsWork at officeFlexible hours$55 - $60 per hour
...Meghana GorusuCompany: SRI Tech SolutionsTitle: Third Party Risk AnalystLocation: Dallas TXDuration: Contract / Full timeDescription:The Analyst/ Sr Analyst, Cybersecurity Risk is part of the Technology Division. This role plays a critical role in protecting digital ecosystem...Hourly payFull timeContract work- Cetera Financial Group is seeking an AML Compliance Analyst to gather and analyze information ensuring adherence to AML policies and applicable laws. Responsibilities include CIP review documentation, discrepancy communication to the AML Manager, and addressing OFAC/FinCEN...
- Cetera Financial Group Inc. in Dallas, TX seeks a Compliance Associate to support regulatory compliance across field and home office teams. You will review inquiries, analyze transactions, and help ensure adherence to laws and firm policies. The role requires FINRA Series...Home office
- RSM US LLP is seeking a Technology Compliance & Emerging Risk Senior Associate to join the team in strengthening technology compliance, cybersecurity governance, and risk management, including AI and digital transformation initiatives. The role involves planning engagements...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to GRC Analyst. Be the first to apply!
Related searches


