Sr. GRC Analyst
$115k - $125kAddison Group
Type: Contract-to-HireCategory: Information TechnologyReference ID: 10081639Job record: a1qPL000008IyU9YAKValid through: 2027-09-15Senior GRC Analyst Industry: Professional Services / Information SecurityLocation: Chicago, ILWork Schedule: Hybrid – Onsite Monday, Wednesday & ThursdayAssignment Type: Contract-to-HireStart Date: ASAPPay: $115,000-$125,000About the OpportunityOur client, a national professional services organization, is seeking a Senior Governance, Risk & Compliance (GRC) Analyst to help build and mature its internal Information Security GRC program.This is a net-new position within an evolving security organization. The environment is still developing from a GRC process and tooling perspective, so this is an opportunity for someone who enjoys building—not simply maintaining an already mature compliance program.The Senior GRC Analyst will play a hands-on role across SOC 2, enterprise risk management, security risk assessments, policy management, NIST Cybersecurity Framework (CSF), audit readiness, remediation tracking, and executive reporting.The ideal candidate is a hands-on problem solver who can walk into an environment where every process or tool may not yet exist, identify what needs to improve, and develop practical solutions.This is a senior individual-contributor position with no direct reports. The Senior GRC Analyst will also provide guidance and mentorship to another GRC resource while working closely with senior Information Security leadership.Key ResponsibilitiesSOC 2, Compliance & AuditHelp strengthen and drive the organization's SOC 2 compliance and readiness program.Coordinate audit requests, evidence collection, and control-owner responses.Perform or coordinate control testing and validation.Identify control deficiencies and compliance gaps.Track audit findings and corrective actions through closure.Partner with control owners to develop practical remediation plans.Coordinate directly with auditors and internal stakeholders throughout compliance activities.Improve the overall structure and sustainability of the SOC 2 program.Enterprise Risk ManagementEstablish and maintain the enterprise information security risk register.Lead security risk assessments across the organization.Perform control-gap analyses and security maturity assessments.Identify, analyze, document, and prioritize security risks.Develop risk-treatment and remediation plans.Manage risk acceptance and security exceptions.Identify and document compensating controls.Track remediation activities through completion.Translate technical security risks into clear, business-focused recommendations for leadership.Governance & NIST CSFHelp operationalize the organization's information security governance program using NIST CSF 2.0.Apply NIST CSF to risk assessments, governance processes, controls, policies, and maturity evaluations.Maintain governance calendars, control assessments, risk reviews, and reporting cycles.Establish clear ownership and accountability for security controls.Identify systemic control gaps and opportunities to improve the overall security program.Help translate security frameworks into practical processes that can be consistently executed across the organization.Policy ManagementOwn and improve the information security policy lifecycle.Develop, review, update, and maintain security policies, standards, and procedures.Coordinate policy review and approval processes.Maintain policy publication, version control, and evidence retention.Map policies, standards, and procedures to NIST CSF 2.0 and applicable compliance requirements.Maintain policy exceptions and residual-risk documentation.Help ensure security policies are operationalized rather than simply documented.Reporting & Program ImprovementDevelop GRC dashboards, metrics, KRIs and KPIs.Provide leadership with clear reporting on: Enterprise security riskSOC 2 readinessCompliance statusPolicy governanceRemediation progressIdentify weaknesses in existing GRC processes and develop practical improvements.Help establish repeatable, scalable GRC processes where formal processes or tooling may not yet exist.Drive multiple GRC initiatives simultaneously using a strong project-management mindset.The position owns key activities spanning risk assessments and the risk register, policy lifecycle management, SOC 2, security exceptions, remediation, reporting, and NIST CSF governance.Required Qualifications5+ years of experience in Information Security, GRC, IT Risk, Security Compliance, Audit, or a related discipline.Strong hands-on experience with SOC 2 compliance and readiness.Experience taking meaningful ownership of SOC 2 activities—not solely collecting audit evidence.Experience coordinating controls, evidence, findings, remediation, and audit activities.Demonstrated experience leading security risk assessments.Experience identifying and evaluating control gaps.Hands-on experience developing and maintaining risk registers.Experience developing risk-treatment and remediation plans.Ability to drive identified risks and remediation items through closure.Strong experience developing, reviewing, and maintaining information security policies, standards, and procedures.Practical experience applying NIST Cybersecurity Framework (NIST CSF).Experience performing security maturity and/or gap assessments.Demonstrated ability to operate successfully within an evolving or immature GRC environment.Ability to create effective processes when mature tools or established workflows do not already exist.Strong project-management and organizational skills.Ability to manage multiple concurrent GRC initiatives.Strong analytical and problem-solving capabilities.Excellent written and verbal communication.Ability to communicate effectively with technical teams, non-technical business stakeholders, and senior leadership.Bachelor's degree in a relevant discipline or equivalent practical experience.The formal qualifications specifically call for hands-on SOC 2, risk assessment/risk-register ownership, policy management, practical NIST CSF application, and the ability to build solutions in an immature GRC environment.Preferred QualificationsCISACRISCCISMCISSPSecurity+ or comparable security/GRC certificationISO 27001 experienceIT General Controls (ITGC) experienceThird-party risk managementClient security questionnaires / assuranceAI governanceData protection / privacy-related security experienceSecurity awareness program experienceExperience with GRC and workflow technologies such as: AuditBoardServiceNow GRCOneTrustArcherJiraSharePointCertifications are valued, but practical GRC experience and demonstrated ownership are more important for this position.What We're Looking ForThis is not a role for someone who needs an established GRC program, mature tooling, or highly defined processes in order to be successful.The ideal candidate is comfortable hearing:"We know this needs to be better—help us figure out how to fix it."You should be able to assess the current state, identify gaps, prioritize what matters, develop a practical solution, gain stakeholder buy-in, and then drive the work through implementation.We're particularly interested in candidates who can provide specific examples of personally:Driving or significantly improving a SOC 2 programLeading a security risk assessmentBuilding or improving an enterprise risk registerIdentifying control gaps and developing remediation plansDriving remediation through closureDeveloping or restructuring security policiesApplying NIST CSF to a real-world security programBuilding GRC processes without sophisticated toolingWorking directly with auditorsCoordinating technical and business stakeholdersManaging several GRC initiatives simultaneouslyThe goal of the position is to help turn an immature GRC environment into a more structured and sustainable program across SOC 2, risk management, remediation, policy governance, and NIST CSF.Leadership & MentorshipThis is a senior individual-contributor position—not a people-management role.The Senior GRC Analyst will:Serve as a trusted GRC advisor to technical and business stakeholders.Provide guidance and mentorship to another GRC Analyst.Share GRC best practices and practical knowledge.Help improve the consistency and quality of GRC work.Partner closely with Information Security leadership.Help drive accountability across control owners and stakeholders.The position has no direct reports but is expected to provide mentorship and senior-level guidance.Core GRC Focus AreasSOC 2NIST CSF 2.0Enterprise Risk ManagementSecurity Risk AssessmentsRisk RegistersRisk TreatmentControl Gap AnalysisSecurity Maturity AssessmentsInformation Security Policy ManagementAudit ReadinessControl TestingEvidence ManagementFindings & RemediationSecurity ExceptionsCompensating ControlsKRIs / KPIsExecutive ReportingThird-Party RiskGRC Process ImprovementWork EnvironmentHybrid position based in downtown ChicagoOnsite Monday, Wednesday, and ThursdayContract-to-hireHighly visible position within the internal Information Security organizationSignificant interaction with IT, Legal, Privacy, HR, and business leadershipOpportunity to directly influence how the organization's GRC program is built and maturedAdditional DetailsNet-new positionASAP startSenior individual-contributor roleNo direct reportsTwo-step interview process: Initial video interview with Information Security leadershipFinal onsite interview with additional team stakeholdersStrong emphasis on practical experience, ownership, communication, and problem solvingBenefitsEligible consultants may receive:Medical and prescription drug coverageDental insuranceVision insuranceHealth Savings Account (HSA)Flexible Spending Accounts (FSA)Short-Term and Long-Term Disability InsuranceSupplemental Life Insurance401(k)Weekly payIf you're a hands-on Senior GRC Analyst who has personally driven SOC 2, risk assessments, policy management, remediation, and NIST CSF initiatives—and you enjoy building programs rather than simply maintaining them—apply today to learn more. Addison Group is an Equal Opportunity Employer. Addison Group provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, gender, sexual orientation, national origin, age, disability, genetic information, marital status, amnesty, or status as a covered veteran in accordance with applicable federal, state and local laws. Addison Group complies with applicable state and local laws governing non-discrimination in employment in every location in which the company has facilities. Reasonable accommodation is available for qualified individuals with disabilities, upon request.
$76k - $134k
...driven decisions, mitigate risks & deliver projects on time & within budget. Position Responsibilities Responsibilities: As a Senior GRC Analyst, you will support assessment, audit readiness, cloud security compliance, risk management, & security tooling across SaaS/cloud...SeniorContract workTemporary workFor contractors$59.3k - $98.8k
...grown to over $1 billion in annual revenue and we’re just getting started! Job Summary: The Governance, Risk & Compliance (GRC) Analyst supports the development, execution, and continuous improvement of Zoro's Governance, Risk & Compliance program with a primary...SuggestedFull timeWork at officeLocal area2 days per week$109k - $131k
...geographic footprint and value the talent that comprises each of our locations. Benesch is proud to announce the opening for a GRC Analyst in our Chicago office! This position is hybrid and has work from home flexibility. Position Summary Are you an experience cybersecurity...SuggestedFull timeWork at officeLocal areaWork from home$110k - $130k
Akkodis, Inc. is seeking a GRC Analyst for a full-time direct hire and hybrid role with an industry leader located in Chicago IL. The GRC Analyst will be responsible for supporting the implementation, execution, and continuous improvement of the organization's GRC program...SuggestedFull timeLocal area- ...GRC Analyst The GRC Analyst is a member of the IT Security team and works closely with other IT teams and business stakeholders in the development and automation of core functions supporting the Information Security program. The GRC Analyst will work to support the...Suggested
$158.8k - $261.3k
...requirement of working at least three days a week in the office. As a Sr. Principal Lead Health Actuary Consultant , you'll manage... ...negotiations. You’ll create deliverables, provide direction to analysts and associates, and serve as one of the primary financial client...SeniorMinimum wageWork at officeLocal areaRemote workFlexible hours3 days per week1 day per week$102.85k - $133.1k
...Paralegal Certificate preferred.Five or more years of legal and/or financial markets experience in a professional, administrative or analyst role.The ability to:Interact in a professional manner with internal and external contacts; use tact and diplomacy; maintain...SeniorFull timeContract workWork at officeImmediate start$82.4k - $123.6k
...Job Description Position Summary The Process Sr. Analyst, Internal Controls supports the Logistics & Fulfillment Team by executing daily/weekly operational routines, maintaining process documentation, compiling performance and controls reporting, and coordinating...SeniorMinimum wageFull timeRemote workShift work$58.8k - $102.1k
...Job Description Position Summary The Logistics Trade Compliance Sr Analyst is responsible for executing and coordinating key operational trade compliance activities while providing guidance to cross-functional partners on import/export compliance requirements, documentation...SeniorMinimum wageFull timeRemote workShift work$112.2k - $202.6k
At HCSC, our employees are the cornerstone of our business and the foundation to our success. We empower employees with curated development plans that foster growth and promote rewarding, fulfilling careers. Join HCSC and be part of a purpose-driven company that will...SeniorWork at officeVisa sponsorship3 days per week$112.2k - $202.6k
Job SummaryThis position is responsible for managing the implementation, maintenance and critical review and analysis of models, studies and systems which use actuarial principles for the purposes of pricing, underwriting, statistics, reserving, forecasting and other actuarial...SeniorWork at officeVisa sponsorship3 days per week- Sales Support supports Avanade's sales teams in successfully and efficiently closing new business and leveraging specific skills depending on the area of focus. Will support administrative functions, and complete analytics to report accurate, efficient, and timely processes...Senior
$61k - $136k
...valued so your life can be as rewarding as your career. One of the largest Health insurers in the country is in search of a Sr Actuarial Analyst. This individual will run complicated models, perform detailed analysis of the results, and present findings for decision making...SeniorRemote work$110.87k - $153.58k
...DLA Piper is a place you can engage in meaningful work and grow your career. Let’s see what we can achieve. Together.SummaryAs the Sr Analyst - Restructuring, working in collaboration with and in support of the firm’s strategic initiatives, you will support the Firm by...SeniorFull timeWork at officeRemote workRelocationVisa sponsorshipRelocation package- Job DescriptionSr. Analyst, Data and Reporting Job Description The primary responsibility of the Senior Analyst is to enable Kraft Heinz and their customers to grow category sales, to provide objective category expertise, and deliver the best possible product assortment...SeniorFull timeSeasonal workFlexible hours
$149.7k - $256.7k
The Senior Principal Solutions Architect - AI & Data will lead the architecture, design, and adoption of enterprise AI, RPA, advanced analytics, data platforms, and intelligent automation solutions. This role serves as the senior technical authority responsible for translating...SeniorFull timeTemporary workPart time- ...leaders, and zone leadership — translating strategic priorities into structured plans and disciplined execution. Job Purpose The Senior Analyst, Business Development - Annual Business Cycle and Strategy will support, enable, and help govern the 1-3 Year Plans processes for...SeniorFull timeFlexible hours
$80.9k - $150.3k
..., and Telecom (TMT) Sales Strategy & Operations team is the analytical engine behind Salesforce's TMT sales organization: and this analyst role sits at the center of it. You'll partner directly with the CMRCL SVP-level sales leadership team as a trusted advisor, translating...SeniorFull timeWork experience placementSeasonal work$109.04k - $163.56k
Sr Risk Analyst - KR07DEWe’re determined to make a difference and are proud to be an insurance company that goes well beyond coverages and policies. Working here means having every opportunity to achieve your goals - and to help others accomplish theirs, too. Join our team...SeniorFull timeTemporary workWork at office3 days per week- ...we strengthen our focus on technology-enabled risk management, governance, and assurance. We are seeking a Senior Technology Risk Analyst to play a critical role in helping the organization proactively manage technology risks while supporting Stryker’s strategic objectives...SeniorFull timeFor contractorsRemote work
- ...Sr Business Analyst Chicago, IL Onsite Required: ~ Ability to understand, communicate and engage effectively with multiple stakeholders and interactions ~ Strong problem-solving, listening, written and verbal communication, and decision-making skills ~1 2 years...Senior
$38.02 - $55.18 per hour
...qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, and other legally protected characteristics. Position Sr Compensation Analyst Location US:IL:Chicago Req ID 29615...SeniorHourly payFull time- ...provide excellent benefits such as Medical, Dental, Vision ++ a fun company to work!!! Job description: Position Title: Sr. Business Analyst Location: Oak Brook, IL (Onsite Wednesdays and Thursdays) | Hybrid Position Type: Contract-for-Hire Duration:...SeniorFull timeContract workLocal area2 days per week
- Job Title: Sr. Business Analyst Job ID: 2023-12430 Job Location: Chicago, IL Job Travel Location(s): # Positions: 1 Employment Type: W2 Candidate Constraints: Duration: Long term # of Layers: Work Eligibility: Key Technology: PBM, Analysis, workflows Job Responsibilities...Senior
- ...Job Description Job Description The Senior Data Analyst serves as a trusted partner to business and executive leadership by transforming complex mortgage, financial, and operational data into actionable insights. This role supports strategic decision-making through...Senior
$164.6k - $288k
## Sr Principal Software Engineer, AI Security PlatformApply: Chicago, IL: Full time: Posted Today: R161850**About Northern Trust** As a global leader in innovative wealth management, asset servicing, asset management and banking services, Northern Trust (Nasdaq: NTRS)...SeniorFull timeH1bWorldwideFlexible hours$94k - $115k
...Sr. Ecommerce Analyst Chicago, Illinois, United States What Is Box? Box (NYSE:BOX) is the leader in Intelligent Content Management. Our platform enables organizations to fuel collaboration, manage the entire content lifecycle, secure critical content, and transform...SeniorLive inWork at officeShift work3 days per week$149.7k - $256.7k
Posting Details ~ Posted on September 28, 2026 Locations Showing 1 location Chicago, IL 60666, USA Hybrid Information Technology Full-Time Requisition #: SENIO002041 Description The Senior Principal Solutions Architect – AI & Data ...SeniorFull timeTemporary workPart timeWork from home3 days per week- ...Sr. Business Analyst Location: Chicago, IL (Onsite/Hybrid). 12+ months Rate: $58/hr W2 or $65 on C2C Exp.: 9-10+ Yrs. Business Analyst with Data Exposure & Airline Exposure. Airline domain knowledge 1-2 years experience working with exposure in back office...SeniorContract work
- Sr Data Analyst Chicago, IL - Hybrid 6 + months REQUIRED 1. Highly analytical and excel at ambiguity. Must have worked in large company environment in past. 2. Have experience with large and complex datasets - we have 400-500K of customers a day and our operation is...Senior
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Sr. GRC Analyst. Be the first to apply!
- senior living director Chicago, IL
- heritage senior living Chicago, IL
- senior manager customer operations Chicago, IL
- senior support engineer Chicago, IL
- senior product manager mobile Chicago, IL
- senior c++ developer Chicago, IL
- senior java developer Chicago, IL
- senior software engineer ruby on rails Chicago, IL
- sr finance manager Chicago, IL
- sr marketing manager Chicago, IL





