GRC Analyst
$110k - $120kMacy's Backstage
GRC Analyst
At Cast & Crew, we've empowered creativity and supported the global entertainment industry for decades. Together with our family of brands, we operate as a combined entertainment technology and services provider offering industry standard screenwriting accounting software, digital payroll products, data & reporting, and a host of creative tools. The industry continues to move faster than ever, and the need for our expertise, our technology, and our people has never been greater. We are a production's best ally every step of the way. #OneCastOneCrew
Position Overview:
The GRC Analyst supports the Information Security Office by managing third-party vendor risk, processing security questionnaires, and assisting with audit and compliance activities across the enterprise. This role is well-suited for someone with a strong compliance background who is looking to grow within information security. The ideal candidate is detail-oriented, organized, and experienced working with compliance frameworks, audit processes, and GRC tools such as Drata or similar platforms. A willingness to learn security concepts and stay current on evolving practices is essential.
Essential Functions
- Managing the end-to-end third-party vendor risk management program, including onboarding assessments, periodic reviews, and ongoing monitoring of vendor security posture.
- Supporting an internal ISRM program focused on uncovering cybersecurity risk and adding it to a risk register for prioritization and acceptance and ownership or remediation
- Completing and responding to inbound security questionnaires (e.g., SIG, CAIQ, custom questionnaires) from clients and partners in a timely and accurate manner.
- Coordinating information gathering and interviewing of internal stakeholders to support third-party security questionnaire responses.
- Supporting and maintaining the organization's compliance automation platforms (e.g., Drata and Andromeda), including evidence collection, control mapping, and readiness tracking.
- Supporting SOC 1 Type 2 and SOC 2 Type 2 audits, including evidence collection, auditor coordination, and remediation of identified gaps.
- Developing, maintaining, and improving security documentation, policies, standards, procedures, and runbooks.
- Monitoring and reporting on internal control effectiveness and audit readiness posture.
- Advising internal lines of business, IT partners, and third parties on how to remediate security gaps identified through assessments or audits.
- Understanding applicable regulations, guidelines, and industry best practices to manage risk and ensure compliance.
- Drafting and presenting risk reports and proposals to executive leadership and senior staff.
- Performing other duties as directed.
Qualifications:
The following certifications are a plus, but are not expected at the time of hire:
- CISA or CISM (compliance/audit-focused; strongly relevant to this role)
- CRISC (risk and controls focus)
- CISSP, GIAC/GSEC, or vendor certifications (AWS/Azure)
Requirements:
5+ years of experience in compliance, audit, GRC, or a related field, with exposure to information security concepts. Equivalent experience in risk management, regulatory compliance, or internal audit will be considered. Candidates should have working knowledge of the following:
- Compliance frameworks, audit processes, or risk management programs
- SOC 1 or SOC 2 audit support or audit evidence collection (direct audit experience a plus)
- Development or maintenance of policies, procedures, and compliance documentation
- Third-party or vendor risk processes (experience with formal TPRM programs a plus)
- GRC or compliance automation tools (e.g., Drata, Andromeda, or similar platforms)
Communications:
- Excellent oral communication skills and comfortable in group or small team settings
- Excellent written communication skills
- Ability to take highly technical material and present/communicate it to a non-technical audience
Relationship Building:
- Builds excellent working relations with all IT colleagues and users, works effectively with department and executive management, and maintains a professional relationship with outside clients and vendors
Planning, Organizing, Prioritizing, Delivering:
- Exhibits mature organization and time management skills
- Excellent problem-solving skills
- Effectively planning and organizing daily work following priorities set by the Risk Manager
- Demonstrates strong follow-up and follow-through skills in ensuring timely completion of projects
- Self-starter who actively takes responsibility to resolve issues but also knows when to ask questions to avoid major delays in delivery of work product
Knowledge of:
- SOC 1 Type 2 and SOC 2 Type 2 audit processes and control frameworks
- GRC and compliance automation tools, with preference for Drata
- Security questionnaire frameworks (e.g., SIG, CAIQ, NIST) and third-party risk methodologies
- Evidence collection, reporting, and security documentation best practices
Skill In:
- Coordinating SOC audit activities, evidence collection, and auditor communication
- Working with compliance frameworks such as NIST CSF, NIST 800-53, or ISO/IEC 27001 (familiarity sufficient; deep expertise not required)
- Completing or supporting security questionnaire responses (SIG, CAIQ, or similar)
- Writing clear, well-organized compliance documentation and communicating requirements across teams
Physical Demands:
SEDENTARY - Exerts up to 30 lbs. of force occasionally and/or a negligible amount of force frequently or constantly to lift, carry, push, or pull. Involves sitting most of the time but may involve walking or standing for brief periods of time.
Benefits
Cast & Crew provides a comprehensive package of employee benefits including: Medical, Dental, Vision, PTO, health and wellness programs, employee discounts, and more! Note: Cast & Crew benefits are subject to eligibility requirements.
Cast & Crew is an equal opportunity employer committed to hiring a diverse workforce and sustaining an inclusive culture. It is our policy to provide equal employment opportunities to all individuals based on job-related qualifications and ability to perform a job, without regard to age, gender, gender identity, sexual orientation, race, color, religion, creed, national origin, disability, genetic information, veteran status, citizenship or marital status, and to maintain a non-discriminatory environment free from intimidation, harassment or bias based upon these grounds.
CA residents Your personal information may be collected in connection with certain services provided by Cast & Crew or its affiliated companies. A summary of your California privacy rights can be found at:
Compensation is commensurate with various factors including, but not limited to, relevant experience, qualifications, skills, training, licensure, certifications, geographic cost of labor, and other business and organizational needs. Compensation range for candidates in other locations may differ based on the cost of labor in that location. The compensation range for this position is: $110,000.00 - $120,000.00 per year.
$138k - $173k
THE POSITIONOur roster has an opening with your name on itFanDuel is seeking a Senior Technology Governance, Risk & Compliance (GRC) Analyst to join its Technology GRC team as a strategic specialist supporting our first line of defense (1LOD) function. This role offers...SuggestedTemporary workWork at officeLocal areaWorldwideShift work- ...customers get the high-quality gear they need to make the most of their adventures. We are BUILT FOR THE WILD.About the RoleThe SAP GRC Analyst will be responsible for GRC administration and segregation of duties (SoD) analysis. You will be responsible for evaluating risks...SuggestedFull timeLocal area
$80.05k - $165k
...end-to-end issue management activities, including intake, validation, prioritization, assignment, remediation tracking, and closure of GRC-related issues in ServiceNow, ensuring timely resolution, appropriate evidence, and alignment with audit, risk, and regulatory...SuggestedFull timeWork at office- ...Security Officer (CISO), to shape long-term cybersecurity strategy.Work in a greenfield environment where you'll help build foundational GRC processes rather than simply maintaining existing programs.Collaborate across Information Security, IT, Legal, Compliance, Privacy,...SuggestedContract workFlexible hours
- The TeamThe Analyst Governance, Risk, and Compliance, a member of the Information Security - Governance, Risk and Compliance (GRC) team, focuses on implementing and maintaining governance frameworks, managing risk remediation activities, and ensuring adherence to regulatory...SuggestedWork experience placementWork at officeLocal area
- ...ROLE, NOW OR IN THE FUTURE. (e.g., H-1B, STEM OPT, TN, etc.)About the RoleAs a member of the Information Security team, the IS GRC Senior Analyst - Risk & Compliance will be responsible for understanding the firm’s security risk and compliance requirements. You will...Full timeContract workWork experience placementH1bRemote workVisa sponsorshipRelocation packageMonday to Friday
- Job OverviewThe GRC Analyst I is responsible for supporting the organization's Governance, Risk, and Compliance (GRC) program through risk management, policy governance, compliance monitoring, reporting, and continuous improvement activities. This role assists with risk...Full time
- ...SoftwareClient: WiproContact: Meghana GorusuCompany: SRI Tech SolutionsTitle: GRC AnalystLocation: Portland,ORDuration: Full TimeWe are seeking a detail-oriented and technically proficient Principal GRC Analyst to join our Information Security team, with a focus on validating...Full time
- ...to its workforce, Kokosing is the winning team.Job Description:We are looking for a Security Governance, Risk, and Compliance (GRC) Analyst to support and mature our security and compliance programs across a large construction organization. This role focuses on maintaining...Full timeFor contractors
$130k - $170k
...performance and extend healthspan. The Governance, Risk, and Compliance (GRC) team helps ensure technology and cybersecurity risks are... ...an execution-oriented Senior Governance, Risk, and Compliance Analyst to lead the day-to-day execution and support the ongoing operation...Full timeWork at officeRelocation- ...Experience Experience in Financial Services domain expertise in one or more of the following areas - Governance, Risk & Compliance (GRC), Regulatory Reporting, Financial Risk. Experience in requirement gathering, process mapping, functional analysis, and Data validation...Full timeTemporary workRelocation
- ...TXEmployment Type: Full TimeIndustry: Computer SoftwareClient: WiproContact: Meghana GorusuCompany: SRI Tech SolutionsJob Title: Technical GRC Analyst with SQL DBDuration: Full timeLocation: Austin TX - Locals onlyJob Description:Skills: Technical GRC Analyst and SQL DBStrong...Local area
- Job Summary:The IT Governance, Risk, and Compliance (GRC) Lead Analyst serves as a subject matter expert responsible for leading the design, implementation, maturity, and continuous improvement of the organization’s IT governance, risk management, and compliance programs...Full timeWork at office3 days per week
- ...The GRC Cybersecurity Analyst III is a senior level contributor responsible for leading ICCU’s Governance, Risk, and Compliance (GRC) initiatives within the scope of the IT domain. This role provides strategic oversight of cyber and IT operational risk assessments, regulatory...Full timeWork experience placementWork at office
- ...GRC Analyst Join our team as a GRC Analyst and play a key role in regulatory compliance, IT risk management, security. You'll assess risks, support audits, and develop policies that align with industry standards. If you have a solid IT security background, experience...Casual workWork at officeWork from homeHome officeNight shiftWeekend work
- ...raised our Series B and have grown 800% over the last 12 months. The Opportunity Ivo is seeking a detail-oriented and proactive GRC Analyst to support the company's compliance, risk management, and security assurance initiatives. This role will play a key part in...Contract workWork at officeRemote workVisa sponsorshipRelocation packageFlexible hours
- ...Ruleset Security is offering an exciting internship opportunity for a Governance, Risk, and Compliance (GRC) Analyst. This role is perfect for students or recent graduates looking to gain hands-on experience in cybersecurity, compliance, and risk management. The internship...Full timeInternship
- ...GRC (3rd Party Risk) Analyst Duration: 12 – 24 Month Project Engagement The GRC Analyst is responsible for managing Client's governance, risk, and compliance functions, with a specific focus on third-party risk management. This role ensures Client operates in a compliant...
- ...Job Description Job Description Governance, Risk & Compliance (GRC) Analyst – State Agency – $40-46/hr W2 – Phoenix Hybrid – Contract-to-Hire SunSoftOnline is hiring a GRC / Information Security Analyst for an Arizona state agency's technology division, a 4-month...Permanent employmentFull timeContract workRemote workVisa sponsorshipMonday to Friday
- ...We are seeking a highly skilled and motivated Senior GRC Analyst to join our Security and Privacy team. In this role, you will own and grow RainFocus's governance, risk, and compliance program — maintaining our control framework, leading risk assessments, supporting...Full time
- ...landscape with groundbreaking technology. About the Role We are seeking an experienced Governance, Risk, and Compliance (GRC) Senior Analyst to join our InfoSec team. This role will be instrumental in maintaining and enhancing our organization's compliance posture...Full timeFlexible hours
- ...come to the office in Irvine, CA on in office days and as needed to carry out necessary functions of the role. The GRC Senior Regulatory Compliance Analyst, who has proficient knowledge in regulatory compliance rules and regulations will be responsible for assisting the...Contract workWork at office
$108k - $130k
...objectives. About the Opportunity Our Information Security team is growing, and we have an immediate opening for a GRC and IT Compliance Analyst to help support and execute Cleerly’s security and compliance objectives. Reporting to the Director of Information...Full timeImmediate startRemote work- ...Governance, Risk & Compliance (GrC) Analyst We're partnering with the world's leading AI research labs to build smarter, more trustworthy AI — and we need practitioners who know how GRC actually works in the real world. Your expertise in security policies, compliance...Hourly payOngoing contractContract workFreelanceRemote workFlexible hours
- ...Sr. GRC Analyst Sr. GRC Analyst Remote USC or GC only must be in the EST (highly preferred) or CST time zone. Brief Job Description ~6-8 years of experience as a GRC Analyst ~ Will be involved with assisting the clients internal GRC team to help with Third...Remote work
- ...the Role Hotman Group is a boutique cybersecurity and GRC consulting firm doing meaningful work for clients who need GRC... ...What You Will Do As an Experienced or Senior GRC Analyst at Hotman Group you will work directly with clients to help them...Permanent employmentFull timeContract workRemote work
- ...challenging and exciting scaling/optimization work to ensure that we can provide the most secure and performant service. As a GRC Analyst at Virtru, you will be the primary point of contact for compliance-related inquiries. You will lead and manage the organization's...Full timeFlexible hoursShift work
$95k - $105k
...Job Description Job Description Sr. GRC Analyst About Subsplash Subsplash is an exciting award-winning team of 280+ mission-driven people who are committed to our core values of humility, innovation, and excellence. Founded in 2005, we've remained family owned and...Temporary workCurrently hiringRemote workRelocation$134k - $202k
...GRC Analyst Remote - United States About Vercel: Vercel is the agentic infrastructure company. We free people and agents to ship what's next. For more than a decade, Vercel has shaped how the web is built. As the team behind Next.js, v0, and AI SDK, we create...Work at officeRemote workWork from homeWorldwideMonday to FridayFlexible hours- ...external audit activities • Develops, maintains, and reports on operational compliance metrics General Governance, Risk, and Compliance (GRC) Support • Leads process analysis, development, & improvement efforts • Assists in developing, testing, and delivering solutions,...Work experience placementWork at officeLocal areaRemote workRelocation
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to GRC Analyst. Be the first to apply!



