Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

GRC Analyst

Momentum

Momentum is a respected collection of independent companies, including PMG, Koddi, Further. We serve as a premier global business transformation partner for over 125 of the Fortune 500 brands. With 1,400 global employees and $5B in media spend under management, we foster a fast-growing, values-driven, people-first environment where you can thrive.

Our portfolio of companies partners with some of the world's most iconic and ambitious brands. We combine scalability with a solutions-oriented approach to deliver fast-paced, innovative results for our customers while creating meaningful growth opportunities for our teams.

If you are looking for opportunities to grow in your career and are passionate about being at the forefront of data and technology, and driving rapid innovation in the future of commerce, we would love to talk with you about joining Momentum.

We believe that a culture of belonging, inclusion, and diversity is key to empowering our team members to thrive both personally and professionally. Living out our values is not just a goal; it's a daily practice! For more information, please visit

The Opportunity


We are hiring a Security GRC & Risk Analyst to own the governance, risk, and compliance execution layer across a holding company and portfolio of businesses. This is a build-oriented role with a defined scope: you will be the internal anchor for our SOC 2 Type II audit, NIST CSF remediation roadmap, security policy library, vendor risk program, and client-facing security questionnaires.

You will work directly with the Cybersecurity Manager and a vCISO partner, collaborate with the Data Privacy legal team as a peer on overlapping policy areas, and engage regularly with portfolio company stakeholders. A dedicated internal Data Privacy legal team owns regulatory compliance - GDPR, CCPA, breach notification, and data subject rights. This role owns the technical controls layer: the evidence, the frameworks, the audit coordination, and the vendor risk program.

Join us in this full-time role, based in our Dallas Office at the Link: 2601 Olive Street, Dallas, TX. Be part of a vibrant community where amazing people, data & insights, and perpetual innovation converge to shape the future of digital commerce!

About This Role at Momentum

What You'll Do

SOC 2 & NIST CSF Program
  • Own the internal SOC 2 Type II evidence collection process, keeping controls audit-ready year-round. Manage the audit timeline, day-to-day liaison with the external auditor, and remediation finding closure between cycles.
  • Own the NIST CSF remediation roadmap: maintain the gap register, report progress to the VP and vCISO on a defined cadence, and coordinate with portfolio company IT teams to assess and close control gaps.
  • Build and maintain a unified controls library mapping SOC 2 Trust Services Criteria, NIST CSF subcategories, and applicable regulatory requirements.
  • Prepare the organization for bi-annual NIST CSF assessments, ensuring controls are documented and defensible.
Security Policy & AI Governance
  • Operationalize the enterprise-wide information security policy library across the corporate entity and portfolio companies. Inventory gaps against SOC 2, NIST CSF, and applicable regulations; draft, publish, and version-control policies in coordination with the vCISO.
  • Build and maintain annual policy attestation workflows across all employees. Bridge with the Data Privacy legal team on overlapping areas: data classification, retention, and incident notification.
  • Develop and maintain the AI governance framework: tool intake review, data handling risk assessment, and acceptable use policy. Evaluate AI tools proposed across the corporate entity and portfolio companies against security and compliance standards.
  • Own AI-related policy documentation and track emerging regulatory requirements including the EU AI Act and NIST AI RMF.
Risk Management & Vendor Risk
  • Build and maintain a risk register with risk-to-control mapping. Define and document formal risk tolerance and appetite in coordination with the vCISO and leadership.
  • Own the third-party risk management program. Define and implement a tiered due diligence model (critical, high, medium, low) and conduct recurring reviews of critical service providers.
  • Manage vendor risk assessments for tools under evaluation - SASE, CASB, DLP, AI governance tooling, and security platform consolidation. Coordinate with the Data Privacy legal team on vendors with material data processing obligations.
  • Lead operationalization of the GRC platform (OneTrust) for centralized vendor inventory, risk scoring, and lifecycle management.
Client Questionnaires & Audit Support
  • Manage and respond to inbound security questionnaires from portfolio company clients (SIG, CAIQ, and custom formats). Build and maintain a response library to improve turnaround time and accuracy.
  • Coordinate with the Cybersecurity Operations Engineer to validate technical control responses and keep answers current as the security stack evolves.
  • Own ITGC audit controls across identity, endpoint, cloud, and SaaS platforms. Support internal audit responses and evidence requests beyond the annual SOC 2 cycle.
BCP/DR & Security Awareness
  • Own BCP/DR formalization: develop a business continuity charter, coordinate Business Impact Analysis across the corporate entity and portfolio companies, define RTO/RPO for critical operations, and ensure crisis management is embedded in the IR framework.
  • Manage the KnowBe4 security awareness training program: campaign management, phishing simulations, completion tracking, and leadership reporting.
  • Manage the security testing program as the organization transitions from annual to continuous autonomous pentesting. Own vendor relationships, track findings to remediation, and produce executive-ready reporting.
Qualifications

Required
  • 5-7 years in GRC, security compliance, risk management, or a closely related security function.
  • Hands-on experience owning or supporting a SOC 2 Type II audit: evidence collection, control mapping, and auditor coordination.
  • Solid working knowledge of NIST CSF: gap assessments, control mapping, and remediation tracking.
  • Demonstrated experience building or formalizing a security policy library, not just updating existing documents.
  • Experience managing third-party and vendor risk assessments using a tiered risk model.
  • Experience responding to client security questionnaires: SIG, CAIQ, or similar formats.
  • Clear understanding of the boundary between GRC and legal/privacy functions. Proven ability to work alongside a legal team without blurring lanes.
  • Strong written communication: you can translate technical controls into clear, accurate language for clients, auditors, and executives.
  • Disciplined project management: you own timelines, follow up without being asked, and don't let things fall through.
  • Active daily use of AI and automation. We operate at 100% internal AI adoption. Non-negotiable.
Preferred Technical Experience
  • GRC platforms: OneTrust, Drata, Vanta, Whistic, or similar.
  • Security awareness platforms: KnowBe4 or equivalent.
  • ITGC working knowledge across identity (Okta), SaaS (Google Workspace), cloud (AWS, GCP, Azure), and endpoint (CrowdStrike).
  • BCP/DR frameworks: BIA methodology, RTO/RPO definition, and tabletop exercise facilitation.
  • AI governance frameworks: NIST AI RMF or EU AI Act.
  • Familiarity with CASB, DLP, or cloud security posture tooling from a compliance and documentation standpoint.
  • Private equity, holding company, or multi-entity compliance environment experience strongly preferred.

Commitment to Diversity and Inclusion at Momentum

At Momentum, our commitment to change for the better is reflected in our dedication to fostering a culture of belonging, inclusion, and diversity. We recognize diversity and inclusion as key components of our company's success and growth. Recognizing the ongoing journey ahead, we are determined to make lasting impacts through the collective efforts of our Leadership team, People & Culture team, and every employee.

Momentum is an equal opportunity employer, considering all qualified applicants regardless of characteristics protected by law. These include, but are not limited to, race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, genetic information, color, ancestry, and Veteran status. We actively seek qualified applicants from diverse backgrounds, with no consideration of criminal histories, in alignment with applicable legal requirements.

Should a reasonable accommodation be necessary for the application process and beyond, we are eager to review and provide reasonable accommodations as needed, in compliance with applicable laws.

Total Rewards

At Momentum, we prioritize the well-being of the whole individual. We are committed to supporting our people in every moment that matters on their journey with us! We are pleased to offer a comprehensive total rewards package designed to provide protection, peace of mind, and a focus on overall well-being while helping our people plan for the future.

The base salary range for this position may vary based on location. Actual compensation will be determined by role, level, and location, considering additional factors such as job-related skills, experience, and relevant education or training. For roles eligible for remote work, the base salary is tailored to the designated work location. In addition to the base salary, candidates may be eligible to receive a discretionary annual bonus, determined based on both the company's business performance and individual contributions. The People & Culture team will provide specific details during the hiring process.

We take pride in offering a comprehensive benefits package for our full-time employees, encompassing healthcare benefits, a 401(k) plan with an employer match, short-term and long-term disability coverage, life insurance, paid time off, parental leave, and various paid holidays, among other perks.

Our workplace offers opportunities for involvement in a wide range of challenging and impactful projects, across diverse industries and business models, fostering career advancement and development within our growing organization. The culture is highly collaborative and supportive, contributing to a fulfilling professional journey.

Note on Confidentiality

Any personal data collected during the application process will be treated with the utmost confidentiality and privacy.
Vacancy posted 5 days ago
Similar jobs that could be interesting for youBased on the GRC Analyst in Dallas, TX vacancy
  •  ...Governance, Risk & Compliance (GRC) Analyst (AI Training) About the Role We're partnering with the world's leading AI research labs to build smarter, more trustworthy AI - and we need practitioners who know how GRC actually works in the real world. Your expertise... 
    Suggested
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work
    Flexible hours

    Alignerr

    Dallas, TX
    2 days ago
  • BERRY Appleman & Leiden (BAL) is seeking a GRC/Information Security professional to lead internal audits and manage ISO 27001/27701 programs from its Richardson, TX location. You’ll drive risk-based audits, support privacy operations, and help shape AI governance and vendor... 
    Suggested

    BAL

    Richardson, TX
    1 day ago
  •  ...simulations, analysis, and decision-making, accelerating discovery and driving faster innovation. THE POSITION NMC² is hiring a GRC Analyst to join the Information Security team, reporting to the GRC & Privacy Manager and based at our Dallas, TX offices at Victory Commons... 
    Suggested

    NMC2

    Dallas, TX
    3 days ago
  • Integrity, headquartered in Dallas, TX, seeks a Federal Exchange GRC Analyst to own compliance for federal Health Insurance Exchange and Enhanced Direct Enrollment, including Audit Readiness Certification and Privacy Evaluation obligations. This role requires disciplined... 
    Suggested

    Integrity Windows

    Dallas, TX
    3 days ago
  • UT Southwestern Medical Center seeks a Senior Governance Risk Compliance Analyst to lead information security governance, risk management, and compliance for the Texas Behavioral Health Center program. This role applies NIST, HIPAA, PCI standards and coordinates enterprise... 
    Suggested

    UT Southwestern Medical Center

    Dallas, TX
    5 days ago
  • UT Southwestern Medical Center in Dallas seeks a Senior Governance Risk Compliance Analyst to lead enterprise security governance, risk management and regulatory compliance initiatives at the Texas Behavioral Health Center project. This role partners with IT, clinical and... 

    University of Texas Southwestern Medical Center

    Dallas, TX
    1 day ago
  •  ...SAP GRC Analyst / SAP Security Analyst Location: Monday - Friday - Onsite in Richardson, TX Position Overview We are seeking an experienced SAP GRC Analyst to serve as the critical link between IT and business stakeholders, ensuring a secure... 
    Monday to Friday

    Anveta

    Dallas, TX
    5 days ago
  • $128.25k - $266.88k

    Paranoids Senior Security GRC Analyst (Finance) Yahoo serves as a trusted guide for hundreds of millions of people globally, helping them achieve their goals online through our portfolio of iconic products. For advertisers, Yahoo Advertising offers omnichannel solutions... 
    Work at office
    Flexible hours

    Yahoo Holdings Inc. in

    Richardson, TX
    5 days ago
  •  ...to predict risk issues, develop solutions, and partner with key owners and stakeholders.Designs, implements and supports modernized GRC process and tool capabilities.Participates in special projects and performs other duties as assigned.QualificationsFive years related... 
    Full time
    Work experience placement

    Vanguard

    Dallas, TX
    3 days ago
  •  ...Responsibilities Kforce has a client that is seeking a Compliance and Risk Analyst in Dallas, TX.Summary:This position is responsible for assisting Company Compliance with end-to-end build and implementation of enhanced compliance program activities. Reporting to... 
    Hourly pay
    Contract work
    Work experience placement
    Flexible hours

    Kforce

    Dallas, TX
    4 days ago
  • $112.61k - $172.21k

     ...dedication and genuine care for our communities are what push us forward and make this a truly special place to be. Who You Are:The Senior Analyst, Insurance and Risk Management will serve as a key contributor responsible for executing development insurance and risk management... 

    Quality Technology Services

    Irving, TX
    4 days ago
  •  ...career opportunities. Come join our award winning 11,000 strong organization as we fuel the world and each other!Summary: The Risk Analyst supports various trade desks at Energy Transfer by performing business analytics and measuring exposure to commodity prices. There... 
    Long term contract
    Second job
    Work at office
    Night shift

    Energy Transfer Partners

    Dallas, TX
    2 days ago
  • How You Will Fulfill Your PotentialManage all aspects of issue identification, analysis, remediation and monitoring & reporting, including collaboration with issue owners, aggregation of issues across the business, and facilitation of executive reporting.Proactively identify...

    Goldman Sachs

    Irving, TX
    1 day ago
  • $55 - $60 per hour

     ...Meghana GorusuCompany: SRI Tech SolutionsTitle: Third Party Risk AnalystLocation: Dallas TXDuration: Contract / Full timeDescription:The Analyst/ Sr Analyst, Cybersecurity Risk is part of the Technology Division. This role plays a critical role in protecting digital ecosystem... 
    Hourly pay
    Full time
    Contract work

    SRI Tech

    Dallas, TX
    2 days ago
  •  ...is committed to your professional growth? Look no further! Join us at Gallagher Re and fast-track your career as a Catastrophe Risk Analyst through our REACH Program.This is a 24-month structured learning and development program that will equip upcoming and recent... 
    Full time
    Work experience placement
    Internship
    Work at office
    Local area
    Remote work
    Home office

    Arthur J. Gallagher & Co.

    Dallas, TX
    4 days ago
  • Asset & Wealth Management Divisional Overview A career with Goldman Sachs Asset & Wealth Management is an opportunity to help clients across the globe realize their potential, while you discover your own. As part of one of the world’s leading asset managers with over $3...
    Private practice
    Work at office

    Goldman Sachs

    Dallas, TX
    2 days ago
  • RISK Goldman Sachs’ Risk Division develops comprehensive programs and processes to identify, monitor, assess and manage financial and non-financial risks in support of the firm’s risk appetite statement and strategic business plans. Risk teams play a critical function for...
    Work experience placement

    Goldman Sachs

    Dallas, TX
    2 days ago
  • $77k - $143k

    Job DescriptionWhat is the opportunity?As a Senior Analyst, Client Risk Prevention in the Business Risk Oversight team, you will be responsible for the intake and case management of incidents of fraud, financial exploitation, and vulnerable client support, providing proactive... 
    Full time
    Work at office
    Flexible hours

    Royal Bank of Canada

    Dallas, TX
    4 days ago
  • OverviewWe are seeking a highly motivated and detail-oriented Operational Risk Associate to join our AM Private Operational Risk team. This position plays an integral role in supporting the risk management framework across multiple business segments within the Goldman Sachs...
    Work at office

    Goldman Sachs

    Dallas, TX
    3 days ago
  • $105.4k - $124k

     ...of your career. Try new things, learn new skills and discover what you excel at—all from Day One.Job DescriptionThe Fraud Business Analyst serves as a strategic partner across Fraud Strategy, business lines, digital teams, and enterprise risk functions. The role blends... 
    Full time
    Work experience placement
    Work at office
    Local area
    3 days per week

    US Bank

    Irving, TX
    3 days ago
  • Job Description - Senior Governance Risk Compliance Analyst - Texas Behavioral Health Center (968577) Job Description Senior Governance...  ...risk register. Ability to respond to and audits, and leverage GRC tools (e.g. Archer, Logic Manager, Optro). Experience creating... 
    Full time

    The University of Texas Southwestern Medical Center

    Dallas, TX
    2 days ago
  •  ...more about our services, industry experience and culture at weaver.com. Position Profile Weaver’s Governance, Risk, and Compliance (GRC) practice is seeking a motivated and detail-oriented experienced Associate or Senior Associate to join our growing Asset Management Consulting... 
    Work at office
    Flexible hours
    Shift work

    Weaver

    Dallas, TX
    4 days ago
  • About Us Heidelberg Materials is one of the world's largest suppliers of building materials. Heidelberg Materials North America operates over 450 locations across the U.S. and Canada with approximately 9,000 employees. What You'll Be Doing Manage the ISN Supplier...
    Temporary work
    Work at office
    Flexible hours

    Heidelberg Materials US, Inc.

    Irving, TX
    3 days ago
  •  ...and contribute to our core mission which is enhancing our customer's experience. Position Summary: The Senior Risk Analyst, Commercial Lending Analytics, will support the development, calibration, and ongoing performance monitoring of commercial lending... 
    Work at office
    Visa sponsorship
    Work visa
    Monday to Friday
    Weekend work

    Stellantis

    Dallas, TX
    2 days ago
  • $95k - $110k

     ...Risk Analyst – Dallas Who: A growing auto finance company building out its credit risk team. What: Analyze and forecast repossessions, origination risks, servicing exposure, and overall credit performance. When: Newly created position due to organizational expansion... 
    Work at office

    Staff Financial Group

    Dallas, TX
    2 days ago
  •  ...Risk Analyst We are seeking a Risk Analyst for a contract position in a hybrid setting within the Southeastern U.S. The role involves supporting a Risk Management and Analytics organization focused on portfolio analytics, forecasting, predictive modeling, and strategic... 
    Contract work

    Mitchell Martin

    Dallas, TX
    2 days ago
  • Job-ID28224324Reference24-01204 Responsibilities:This position leads project submissions for regulatory approvals and acts independently to identify and resolve problemsThis new team member will apply advanced regulatory expertise to guide cross-functional partners and ...
    For contractors

    Katalyst Healthcares & Life Sciences

    Dallas, TX
    2 days ago
  • Senior Credit Risk Specialist (Part-Time)TIB Consulting Solutions has provided sophisticated, independent credit risk services to community banks across the nation for more than 35 years. Our team of credit risk professionals leverages their extensive experience to communicate...
    Full time
    Part time
    Work at office
    Local area
    Remote work
    Work from home
    Flexible hours

    TIB, N.A.

    Farmers Branch, TX
    4 days ago
  • $40.35 per hour

    Job ID: 26001119Company: Baylor Scott & White HealthLocation: Dallas, Texas, United StatesJob Type: Full TimeHire Type: ProfessionalJob Level: Manager with Direct ReportsFLSA Status: ExemptShift: Day JobCategory: Shared ServicesIndustry: HealthcarePosted Date: 2026-08-1...
    Local area
    Immediate start
    Remote work

    Baylor Scott & White Health

    Dallas, TX
    2 days ago
  • We're seeking someone to join our team as a Governance & Oversight Specialist within the U.S. Banks Non-Financial Risk (NFR) to provide support across audit, exam, reporting and other core program execution processes.In the Legal & Compliance division, we assist the Firm...
    Temporary work
    Work at office

    Morgan Stanley

    Dallas, TX
    4 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to GRC Analyst. Be the first to apply!

Related searches