Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

GRC Analyst

$110k - $120k

Macy's Backstage

GRC Analyst

At Cast & Crew, we've empowered creativity and supported the global entertainment industry for decades. Together with our family of brands, we operate as a combined entertainment technology and services provider offering industry standard screenwriting accounting software, digital payroll products, data & reporting, and a host of creative tools. The industry continues to move faster than ever, and the need for our expertise, our technology, and our people has never been greater. We are a production's best ally every step of the way. #OneCastOneCrew

Position Overview:

The GRC Analyst supports the Information Security Office by managing third-party vendor risk, processing security questionnaires, and assisting with audit and compliance activities across the enterprise. This role is well-suited for someone with a strong compliance background who is looking to grow within information security. The ideal candidate is detail-oriented, organized, and experienced working with compliance frameworks, audit processes, and GRC tools such as Drata or similar platforms. A willingness to learn security concepts and stay current on evolving practices is essential.

Essential Functions

  • Managing the end-to-end third-party vendor risk management program, including onboarding assessments, periodic reviews, and ongoing monitoring of vendor security posture.
  • Supporting an internal ISRM program focused on uncovering cybersecurity risk and adding it to a risk register for prioritization and acceptance and ownership or remediation
  • Completing and responding to inbound security questionnaires (e.g., SIG, CAIQ, custom questionnaires) from clients and partners in a timely and accurate manner.
  • Coordinating information gathering and interviewing of internal stakeholders to support third-party security questionnaire responses.
  • Supporting and maintaining the organization's compliance automation platforms (e.g., Drata and Andromeda), including evidence collection, control mapping, and readiness tracking.
  • Supporting SOC 1 Type 2 and SOC 2 Type 2 audits, including evidence collection, auditor coordination, and remediation of identified gaps.
  • Developing, maintaining, and improving security documentation, policies, standards, procedures, and runbooks.
  • Monitoring and reporting on internal control effectiveness and audit readiness posture.
  • Advising internal lines of business, IT partners, and third parties on how to remediate security gaps identified through assessments or audits.
  • Understanding applicable regulations, guidelines, and industry best practices to manage risk and ensure compliance.
  • Drafting and presenting risk reports and proposals to executive leadership and senior staff.
  • Performing other duties as directed.

Qualifications:

The following certifications are a plus, but are not expected at the time of hire:

  • CISA or CISM (compliance/audit-focused; strongly relevant to this role)
  • CRISC (risk and controls focus)
  • CISSP, GIAC/GSEC, or vendor certifications (AWS/Azure)

Requirements:

5+ years of experience in compliance, audit, GRC, or a related field, with exposure to information security concepts. Equivalent experience in risk management, regulatory compliance, or internal audit will be considered. Candidates should have working knowledge of the following:

  • Compliance frameworks, audit processes, or risk management programs
  • SOC 1 or SOC 2 audit support or audit evidence collection (direct audit experience a plus)
  • Development or maintenance of policies, procedures, and compliance documentation
  • Third-party or vendor risk processes (experience with formal TPRM programs a plus)
  • GRC or compliance automation tools (e.g., Drata, Andromeda, or similar platforms)

Communications:

  • Excellent oral communication skills and comfortable in group or small team settings
  • Excellent written communication skills
  • Ability to take highly technical material and present/communicate it to a non-technical audience

Relationship Building:

  • Builds excellent working relations with all IT colleagues and users, works effectively with department and executive management, and maintains a professional relationship with outside clients and vendors

Planning, Organizing, Prioritizing, Delivering:

  • Exhibits mature organization and time management skills
  • Excellent problem-solving skills
  • Effectively planning and organizing daily work following priorities set by the Risk Manager
  • Demonstrates strong follow-up and follow-through skills in ensuring timely completion of projects
  • Self-starter who actively takes responsibility to resolve issues but also knows when to ask questions to avoid major delays in delivery of work product

Knowledge of:

  • SOC 1 Type 2 and SOC 2 Type 2 audit processes and control frameworks
  • GRC and compliance automation tools, with preference for Drata
  • Security questionnaire frameworks (e.g., SIG, CAIQ, NIST) and third-party risk methodologies
  • Evidence collection, reporting, and security documentation best practices

Skill In:

  • Coordinating SOC audit activities, evidence collection, and auditor communication
  • Working with compliance frameworks such as NIST CSF, NIST 800-53, or ISO/IEC 27001 (familiarity sufficient; deep expertise not required)
  • Completing or supporting security questionnaire responses (SIG, CAIQ, or similar)
  • Writing clear, well-organized compliance documentation and communicating requirements across teams

Physical Demands:

SEDENTARY - Exerts up to 30 lbs. of force occasionally and/or a negligible amount of force frequently or constantly to lift, carry, push, or pull. Involves sitting most of the time but may involve walking or standing for brief periods of time.

Benefits

Cast & Crew provides a comprehensive package of employee benefits including: Medical, Dental, Vision, PTO, health and wellness programs, employee discounts, and more! Note: Cast & Crew benefits are subject to eligibility requirements.

Cast & Crew is an equal opportunity employer committed to hiring a diverse workforce and sustaining an inclusive culture. It is our policy to provide equal employment opportunities to all individuals based on job-related qualifications and ability to perform a job, without regard to age, gender, gender identity, sexual orientation, race, color, religion, creed, national origin, disability, genetic information, veteran status, citizenship or marital status, and to maintain a non-discriminatory environment free from intimidation, harassment or bias based upon these grounds.

CA residents Your personal information may be collected in connection with certain services provided by Cast & Crew or its affiliated companies. A summary of your California privacy rights can be found at:

Compensation is commensurate with various factors including, but not limited to, relevant experience, qualifications, skills, training, licensure, certifications, geographic cost of labor, and other business and organizational needs. Compensation range for candidates in other locations may differ based on the cost of labor in that location. The compensation range for this position is: $110,000.00 - $120,000.00 per year.

Vacancy posted 2 days ago
Similar jobs that could be interesting for youBased on the GRC Analyst in United States vacancy
  • $138k - $173k

    THE POSITIONOur roster has an opening with your name on itFanDuel is seeking a Senior Technology Governance, Risk & Compliance (GRC) Analyst to join its Technology GRC team as a strategic specialist supporting our first line of defense (1LOD) function. This role offers... 
    Suggested
    Temporary work
    Work at office
    Local area
    Worldwide
    Shift work

    FanDuel

    Atlanta, GA
    15 hours ago
  •  ...customers get the high-quality gear they need to make the most of their adventures. We are BUILT FOR THE WILD.About the RoleThe SAP GRC Analyst will be responsible for GRC administration and segregation of duties (SoD) analysis. You will be responsible for evaluating risks... 
    Suggested
    Full time
    Local area

    YETI COOLERS

    Austin, TX
    15 hours ago
  • $80.05k - $165k

     ...end-to-end issue management activities, including intake, validation, prioritization, assignment, remediation tracking, and closure of GRC-related issues in ServiceNow, ensuring timely resolution, appropriate evidence, and alignment with audit, risk, and regulatory... 
    Suggested
    Full time
    Work at office

    Columbia Bank

    Hillsboro, OR
    3 days ago
  •  ...Security Officer (CISO), to shape long-term cybersecurity strategy.Work in a greenfield environment where you'll help build foundational GRC processes rather than simply maintaining existing programs.Collaborate across Information Security, IT, Legal, Compliance, Privacy,... 
    Suggested
    Contract work
    Flexible hours

    AccruePartners

    Charlotte, NC
    3 days ago
  • The TeamThe Analyst Governance, Risk, and Compliance, a member of the Information Security - Governance, Risk and Compliance (GRC) team, focuses on implementing and maintaining governance frameworks, managing risk remediation activities, and ensuring adherence to regulatory... 
    Suggested
    Work experience placement
    Work at office
    Local area

    American Tower

    Boston, MA
    4 days ago
  •  ...ROLE, NOW OR IN THE FUTURE. (e.g., H-1B, STEM OPT, TN, etc.)About the RoleAs a member of the Information Security team, the IS GRC Senior Analyst - Risk & Compliance will be responsible for understanding the firm’s security risk and compliance requirements. You will... 
    Full time
    Contract work
    Work experience placement
    H1b
    Remote work
    Visa sponsorship
    Relocation package
    Monday to Friday

    AlixPartners

    Detroit, MI
    3 days ago
  • Job OverviewThe GRC Analyst I is responsible for supporting the organization's Governance, Risk, and Compliance (GRC) program through risk management, policy governance, compliance monitoring, reporting, and continuous improvement activities. This role assists with risk... 
    Full time

    Sub-Zero and Wolf

    Madison, WI
    3 days ago
  •  ...SoftwareClient: WiproContact: Meghana GorusuCompany: SRI Tech SolutionsTitle: GRC AnalystLocation: Portland,ORDuration: Full TimeWe are seeking a detail-oriented and technically proficient Principal GRC Analyst to join our Information Security team, with a focus on validating... 
    Full time

    SRI Tech

    Portland, OR
    2 days ago
  •  ...to its workforce, Kokosing is the winning team.Job Description:We are looking for a Security Governance, Risk, and Compliance (GRC) Analyst to support and mature our security and compliance programs across a large construction organization. This role focuses on maintaining... 
    Full time
    For contractors

    Kokosing

    Westerville, OH
    1 day ago
  • $130k - $170k

     ...performance and extend healthspan. The Governance, Risk, and Compliance (GRC) team helps ensure technology and cybersecurity risks are...  ...an execution-oriented Senior Governance, Risk, and Compliance Analyst to lead the day-to-day execution and support the ongoing operation... 
    Full time
    Work at office
    Relocation

    WHOOP

    Boston, MA
    1 day ago
  •  ...Experience Experience in Financial Services domain expertise in one or more of the following areas - Governance, Risk & Compliance (GRC), Regulatory Reporting, Financial Risk. Experience in requirement gathering, process mapping, functional analysis, and Data validation... 
    Full time
    Temporary work
    Relocation

    Infosys Technologies

    Jersey City, NJ
    15 hours ago
  •  ...TXEmployment Type: Full TimeIndustry: Computer SoftwareClient: WiproContact: Meghana GorusuCompany: SRI Tech SolutionsJob Title: Technical GRC Analyst with SQL DBDuration: Full timeLocation: Austin TX - Locals onlyJob Description:Skills: Technical GRC Analyst and SQL DBStrong... 
    Local area

    SRI Tech

    Austin, TX
    3 days ago
  • Job Summary:The IT Governance, Risk, and Compliance (GRC) Lead Analyst serves as a subject matter expert responsible for leading the design, implementation, maturity, and continuous improvement of the organization’s IT governance, risk management, and compliance programs... 
    Full time
    Work at office
    3 days per week

    Westfield Insurance

    Westfield Center, OH
    3 days ago
  •  ...The GRC Cybersecurity Analyst III is a senior level contributor responsible for leading ICCU’s Governance, Risk, and Compliance (GRC) initiatives within the scope of the IT domain. This role provides strategic oversight of cyber and IT operational risk assessments, regulatory... 
    Full time
    Work experience placement
    Work at office

    Iccu

    Remote
    15 hours ago
  •  ...GRC Analyst Join our team as a GRC Analyst and play a key role in regulatory compliance, IT risk management, security. You'll assess risks, support audits, and develop policies that align with industry standards. If you have a solid IT security background, experience... 
    Casual work
    Work at office
    Work from home
    Home office
    Night shift
    Weekend work

    Delta Dental of Missouri

    Saint Louis, MO
    5 days ago
  •  ...raised our Series B and have grown 800% over the last 12 months. The Opportunity Ivo is seeking a detail-oriented and proactive GRC Analyst to support the company's compliance, risk management, and security assurance initiatives. This role will play a key part in... 
    Contract work
    Work at office
    Remote work
    Visa sponsorship
    Relocation package
    Flexible hours

    IVO Inc

    San Francisco, CA
    2 days ago
  •  ...Ruleset Security is offering an exciting internship opportunity for a Governance, Risk, and Compliance (GRC) Analyst. This role is perfect for students or recent graduates looking to gain hands-on experience in cybersecurity, compliance, and risk management. The internship... 
    Full time
    Internship

    Ruleset Security

    Arlington, VA
    5 days ago
  •  ...GRC (3rd Party Risk) Analyst Duration: 12 – 24 Month Project Engagement The GRC Analyst is responsible for managing Client's governance, risk, and compliance functions, with a specific focus on third-party risk management. This role ensures Client operates in a compliant... 

    Datamtx LLC

    Peachtree City, GA
    3 days ago
  •  ...Job Description Job Description Governance, Risk & Compliance (GRC) Analyst – State Agency – $40-46/hr W2 – Phoenix Hybrid – Contract-to-Hire SunSoftOnline is hiring a GRC / Information Security Analyst for an Arizona state agency's technology division, a 4-month... 
    Permanent employment
    Full time
    Contract work
    Remote work
    Visa sponsorship
    Monday to Friday

    SunSoft Online

    Phoenix, AZ
    2 days ago
  •  ...We are seeking a highly skilled and motivated Senior GRC Analyst to join our Security and Privacy team. In this role, you will own and grow RainFocus's governance, risk, and compliance program — maintaining our control framework, leading risk assessments, supporting... 
    Full time

    Rainfocus

    Remote
    4 days ago
  •  ...landscape with groundbreaking technology. About the Role We are seeking an experienced Governance, Risk, and Compliance (GRC) Senior Analyst to join our InfoSec team. This role will be instrumental in maintaining and enhancing our organization's compliance posture... 
    Full time
    Flexible hours

    Fulcrum Global Technologies

    Schaumburg, IL
    more than 2 months ago
  •  ...come to the office in Irvine, CA on in office days and as needed to carry out necessary functions of the role. The GRC Senior Regulatory Compliance Analyst, who has proficient knowledge in regulatory compliance rules and regulations will be responsible for assisting the... 
    Contract work
    Work at office

    Kura Sushi Corporate Support Center

    Irvine, CA
    2 days ago
  • $108k - $130k

     ...objectives. About the Opportunity Our Information Security team is growing, and we have an immediate opening for a GRC and IT Compliance Analyst to help support and execute Cleerly’s security and compliance objectives. Reporting to the Director of Information... 
    Full time
    Immediate start
    Remote work

    Cleerly

    Remote
    3 days ago
  •  ...Governance, Risk & Compliance (GrC) Analyst We're partnering with the world's leading AI research labs to build smarter, more trustworthy AI — and we need practitioners who know how GRC actually works in the real world. Your expertise in security policies, compliance... 
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work
    Flexible hours

    Alignerr

    United States
    2 days ago
  •  ...Sr. GRC Analyst Sr. GRC Analyst Remote USC or GC only must be in the EST (highly preferred) or CST time zone. Brief Job Description ~6-8 years of experience as a GRC Analyst ~ Will be involved with assisting the clients internal GRC team to help with Third... 
    Remote work

    ShiftCode Analytics

    United States
    2 days ago
  •  ...the Role Hotman Group is a boutique cybersecurity and GRC consulting firm doing meaningful work for clients who need GRC...  ...What You Will Do As an Experienced or Senior GRC Analyst at Hotman Group you will work directly with clients to help them... 
    Permanent employment
    Full time
    Contract work
    Remote work

    Hotman Group LLC

    United States
    5 days ago
  •  ...challenging and exciting scaling/optimization work to ensure that we can provide the most secure and performant service. As a GRC Analyst at Virtru, you will be the primary point of contact for compliance-related inquiries. You will lead and manage the organization's... 
    Full time
    Flexible hours
    Shift work

    Virtru

    Remote
    12 days ago
  • $95k - $105k

     ...Job Description Job Description Sr. GRC Analyst About Subsplash Subsplash is an exciting award-winning team of 280+ mission-driven people who are committed to our core values of humility, innovation, and excellence. Founded in 2005, we've remained family owned and... 
    Temporary work
    Currently hiring
    Remote work
    Relocation

    Subsplash

    Indianapolis, IN
    more than 2 months ago
  • $134k - $202k

     ...GRC Analyst Remote - United States About Vercel: Vercel is the agentic infrastructure company. We free people and agents to ship what's next. For more than a decade, Vercel has shaped how the web is built. As the team behind Next.js, v0, and AI SDK, we create... 
    Work at office
    Remote work
    Work from home
    Worldwide
    Monday to Friday
    Flexible hours

    c e r e m o n y

    United States
    5 days ago
  •  ...external audit activities • Develops, maintains, and reports on operational compliance metrics General Governance, Risk, and Compliance (GRC) Support • Leads process analysis, development, & improvement efforts • Assists in developing, testing, and delivering solutions,... 
    Work experience placement
    Work at office
    Local area
    Remote work
    Relocation

    Blue Cross and Blue Shield of Louisiana

    United States
    15 hours ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to GRC Analyst. Be the first to apply!