Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Sr. GRC Analyst

$95k - $105k

Subsplash

Job Description

Job Description

Sr. GRC Analyst About Subsplash

Subsplash is an exciting award-winning team of 280+ mission-driven people who are committed to our core values of humility, innovation, and excellence. Founded in 2005, we've remained family owned and operated while pioneering the market with the first ever church mobile app. Since then, we've been working together to build The Ultimate Engagement Platform™ for churches, Christian ministries, non-profits, and businesses around the world. We find excitement in serving our 14,000+ clients, creating impactful products, and delighting the millions of people who use our platform every day. Subsplash has won awards for best mobile experience, been voted top 100 Washington's Best Workplaces by the Puget Sound Business Journal, created some of the most downloaded apps of all time, and built enterprise software for world-class brands like XBOX, Microsoft, Samsung, Expedia, and Cisco; yet, at the end of the day, we love making a lasting impact and a difference in our world.

Working at Subsplash is more than just a job; we are a team of people who are courageous, inventive, and passionate about doing meaningful work every day. Don't take our word for it—head to Glassdoor and see for yourself!

About the Team

The IT Team at Subsplash is the foundation that maintains all the activities and services that are required to support business functions as well as ensuring proper security across all IT systems. We are passionately focused on delivering delightful support to our internal customers. We achieve this by providing robust day-to-day technical support that empowers our fellow Subsplash employees to perform their best work most often. Beyond daily technical support, our team handles crucial functions such as access management, user provisioning and deprovisioning, new hardware and software setup, and diligently works to keep our dues and subscription spend under budget.

About the Role

The Senior GRC Analyst acts as a strategic lead to advance security and risk operations. In this role, you will integrate people, policy, and technology to drive operational excellence and framework maturity. You will be responsible for identifying security gaps, implementing best practices, and maturing our control environment to ensure we stay ahead of evolving regulatory and threat landscapes. We are building an AI-first compliance function, and this role is expected to lead from the front in identifying and deploying AI tools that scale our GRC program.

Compensation
  • The total compensation for this position is between $95,000-$105,000/yr depending on experience level.
Essential Functions of This Role: Compliance Program Management & Audit Leadership
  • Audit Execution: Act as the primary point of contact for external auditors; lead the end-to-end execution of PCI DSS audits and support internal audit on IT SOX controls.
  • Data Mapping Maintenance: Develop and maintain a comprehensive data inventory and data flow diagrams. Track how sensitive data (PII, PCI) moves through our systems to ensure compliance with privacy regulations and security boundaries.
  • Framework Maturation: Map and implement controls across multiple frameworks (PCI DSS, NIST CSF) to eliminate redundancies and improve the organization's security posture.
  • GRC Reporting: Track and report on GRC program health across compliance posture, risk register status, audit readiness, and control effectiveness. Present metrics and trends to leadership on a regular cadence.
2. Access Governance & Identity Management
  • User Access Reviews (UAR): Orchestrate and lead the quarterly and semi-annual user access review process across all critical systems (SaaS, Cloud Infrastructure, and Internal Tools).
  • Joiner/Mover/Leaver Oversight: Monitor and validate that provisioning and deprovisioning processes are executed accurately and on time across critical systems. Flag exceptions, track remediation, and maintain documentation to support access control audits.
3. Security Awareness & Phishing Program
  • Program Ownership: Execute and maintain a comprehensive, year-round Security Awareness Training (SAT) program that meets PCI DSS requirements while driving actual behavioral change.
  • Phishing Simulations: Execute monthly or quarterly phishing simulations; analyze "fail rates" and provide targeted follow-up training to high-risk groups.
  • Content Curation: Select and deploy engaging security content, newsletters, and "security moments" to keep cybersecurity top-of-mind for all employees.
  • Reporting: Present program health metrics (completion rates, simulation trends, and reporting speed) to the Leadership team.
4. Risk and Vendor Management
  • Vendor & Risk Execution: Execute the TPRM program—conducting vendor security reviews, tracking remediation to completion, and escalating high-risk findings to leadership.
  • Risk Register Ownership: Maintain and update the corporate risk register, ensuring remediation efforts are tracked, validated, and communicated to leadership.
Desired Qualifications:
  • Experience: 3–5 years of dedicated experience in GRC, Information Security, or Audit (FinTech or Financial Services industry experience is highly preferred).
  • Technical Mastery: Deep practical knowledge of PCI DSS requirements and controls.
  • Data Governance: Experience performing Data Mapping exercises and maintaining Records of Processing Activities (RoPA).
  • SAT Strategy: Proven experience managing phishing platforms (e.g., KnowBe4, Mimecast, or Vanta-integrated tools) and developing security training curricula.
  • IAM Expertise: Proven experience managing formal access review cycles and identity governance processes.
  • Systems: Proven experience administering a GRC platform, including automated evidence collection, control monitoring, and access review workflows. Direct experience with Vanta is a significant advantage.
  • SOX IT Controls: Experience with SOX IT General Controls (ITGCs), including change management, logical access, computer operations controls, and segregation of duties (SoD). This role will work directly with internal audit to support IT SOX control testing and evidence collection.
  • AI Tooling: Demonstrated experience using AI tools to improve GRC workflows, automate reporting, or accelerate evidence collection and analysis.
Core Competencies
  • Critical Thinker: You have a drive for distinguishing clear priorities and conclusions from ambiguous data.
  • Velocity: You bring urgency and momentum to compliance work—prioritizing ruthlessly, moving quickly through ambiguity, and consistently pushing the program further than the baseline requires.
  • Detail Oriented: You notice the small gaps in access logs, data maps, or training reports that others might miss.
  • AI-Forward: You treat AI as a force multiplier for GRC work—using it to compress audit prep cycles, automate evidence gathering, and free up capacity for higher-value risk analysis.
  • Collaborative: You work effectively across IT and Engineering to surface control gaps, translate technical risks into compliance language, and ensure cross-functional ownership of remediation.
Your First 90 Days
  • Own the PCI DSS evidence pipeline. Get fully oriented on the current ASV scanning cadence, open findings, and SAQ scoping in Vanta. By day 60, be actively supporting evidence collection. By day 90, have a clear understanding of the program state and a plan for taking it over fully.
  • Get oriented on the SOX SoD review cycle. The conflict detection framework and SoD procedure are built. Within 90 days, develop a working understanding of the quarterly review rhythm, the supporting Confluence documentation, and the compensating controls tracking process — with the goal of owning it independently shortly after.
  • Complete a full UAR cycle. Execute a complete user access review across all critical systems, coordinating with IT and system owners, documenting exceptions, and tracking remediation to closure. This is a tangible, auditable deliverable that demonstrates cross-functional coordination and Vanta proficiency.

Deliver a first GRC metrics report to leadership. Produce a polished metrics report covering compliance posture, risk register status, PCI standing, and SOX control health. This establishes the reporting cadence and introduces the role to leadership on their terms.

Location

Subsplash currently has operations in 27 states across the US! As much as we would love to have employees in as many states and countries as we have clients, we are currently limiting hiring to the states we already operate in. As a result of that, this role is only available as a 100% remote position if you reside in one of the following states:

AL, AR, AZ, CO, FL, GA, ID, IA, IN, KS, KY, MO, MI, MN, NC, NM, OK, OH, OR, SC, SD, TN, TX, UT, VA, WA, WY.

We are not sponsoring relocation for this role so unfortunately, if you do not currently reside in one of these states, we are unable to consider your application.

Benefits

Generous Paid Time Off, Medical Coverage, Dental Coverage, Vision Coverage, short and long term disability and life insurance all free of charge, Competitive Compensation, 401k Matching, Professional Development, Top of the Line Equipment, Referral Program, Parental Leave, Family-Friendly Culture, and the chance to work side-by-side with thought leaders in emerging tech

Note: Employment with Subsplash is contingent upon satisfactory proof of employee's right to work in the U.S., as required by law and upon completion of a basic background check and; employment with Subsplash is considered "at will," meaning that either the company or the employee may terminate the employment relationship at any time without cause or notice.

Subsplash is an Equal Opportunity Employer. We value all human life as all people are created with equal dignity, value, and worth. We do not discriminate on the ground of race, color, religion, sex, age, disability or national origin, or genetic information in the hiring, retention, or promotion of employees; nor in determining their rank, or the compensation or fringe benefits paid them.

#LI-Remote #BI-Remote

Vacancy posted 14 days ago
Similar jobs that could be interesting for youBased on the Sr. GRC Analyst in Louisville, KY vacancy
  • Brown-Forman is hiring an IT Governance/Risk/Compliance Analyst in Louisville, KY. This role involves developing and maintaining IT governance frameworks, supporting risk management programs, and ensuring compliance with internal policies and external regulations. The ideal... 
    Suggested

    Brown--forma

    Louisville, KY
    3 days ago
  • $140k - $170k

    Sr. Manager, International Tax Compliance Louisville, KY, United States and 1 more (Remote) Trending Job Description The Senior Manager, US International Tax - Quantitative will manage a US-based team responsible for the timely and accurate completion of all international... 
    Senior
    Full time
    Casual work
    Local area
    Remote work
    3 days per week

    KFC Corporation

    Louisville, KY
    4 days ago
  •  ...Sr. Analyst, COGS & Inventory The Sr. Analyst, COGS & Inventory will support Dan-O's product costing, inventory tracking, and gross margin visibility by ensuring cost data is accurate, timely, and consistently applied. This role partners closely with Operations/Supply... 
    Senior

    Dan-O's Seasoning

    Louisville, KY
    3 days ago
  •  ...Senior Data Analyst Byte Restaurant Coach is a best-in-class application that optimizes restaurant operations and creates the best jobs. We are proud to be part of Yum! Brands & Digital Technology, a company with over 55,000 restaurants across more than 150 countries... 
    Senior
    Full time
    Worldwide
    Trial period

    Yum! Brands

    Louisville, KY
    12 hours ago
  •  ...Interested in joining us on our journey? The Senior Business Systems Analyst - DT Physical Security partners closely with Legal and the...  ...decision-making and continuous improvement Position Sr. Business Systems Analyst - DT Physical Security Location... 
    Senior
    Work at office
    Immediate start
    Flexible hours

    GE Appliances, a Haier company

    Louisville, KY
    4 days ago
  •  ...Quality Assurance Analyst As a Quality Assurance Analyst, you will play a critical role in delivering high-quality software solutions to our clients by ensuring testing excellence across complex, data-driven initiatives. You will be aligned to a business-unit delivery... 
    Senior

    Baird Capital

    Louisville, KY
    2 days ago
  • At GE Appliances, a Haier company, we come together to make "good things, for life." As the fastest-growing appliance company in the U.S., we're powered by creators, thinkers and makers who believe that anything is possible and that there's always a better way. We believe...
    Senior
    Work at office
    Flexible hours

    GE Appliances, a Haier company

    Louisville, KY
    1 day ago
  • A leading financial services firm in Louisville, KY is looking for a Consumer Compliance Manager to manage regulatory compliance projects. The role involves interpreting regulatory changes, coordinating compliance audits, and providing guidance to clients and staff. Candidates...
    Senior

    PNC Investments LLC

    Louisville, KY
    2 days ago
  • $140k - $170k

    A leading fast-food chain based in Louisville, KY is seeking a Senior Manager for International Tax Compliance. This role involves overseeing a US-based team to ensure timely completion of international tax filings and providing strategic tax advice to business teams. Candidates...
    Senior
    Remote job

    KFC Corporation

    Louisville, KY
    4 days ago
  • $99.2k - $115k

     ...curiosity, high performance, and meaningful work—join us. Let’s build the future of Yum! together! About the Job: The Senior Analyst, Consolidations role is a key contributor to the overall periodic and quarterly consolidations of the operating results for the... 
    Senior
    Full time
    Work at office
    3 days per week

    Yum!

    Louisville, KY
    5 hours ago
  • $42k - $111.8k

    Job Title Job Description At PNC, our people are our greatest differentiator and competitive advantage in the markets we serve. We are all united in delivering the best experience for our customers. We work together each day to foster an inclusive workplace culture...
    Senior
    Full time
    Temporary work
    Part time
    Work experience placement
    Work at office

    PNC

    Louisville, KY
    1 day ago
  • $110k - $115k

    PPGNHAIK is seeking a Senior Philanthropy Officer for planned giving initiatives, based in Indianapolis or Louisville. This role will manage a portfolio of principal donors, develop strategies for securing major gifts, and collaborate across departments to achieve fundraising...
    Senior

    PPGNHAIK

    Louisville, KY
    2 days ago
  • $96.4k - $120.5k

     ...Want to work with highly motivated individuals on high-performance teams? Join WWT today! What will you be doing? IT Senior Analyst position will assist in requirement collection and refinement activities associated with the systematic exchange of critical data elements... 
    Senior
    Permanent employment
    Full time
    Work experience placement
    H1b
    Remote work
    Visa sponsorship
    Shift work

    World Wide Technology

    Louisville, KY
    3 days ago
  • A leading automotive dealership in Louisville, KY is seeking an experienced Finance & Insurance Manager (F&I) to oversee the complete finance and insurance process. The ideal candidate will have proven experience managing F&I operations, strong communication and organizational...
    Senior

    Germain Motor Co.

    Louisville, KY
    3 days ago
  • A leading automotive dealership in Louisville, KY, is seeking an experienced Finance & Insurance Manager (F&I). The successful candidate will oversee the complete finance and insurance process, ensuring compliance and delivering exceptional customer service. Key responsibilities...
    Senior

    Germain Chevrolet Buick GMC Of Sidney

    Louisville, KY
    2 days ago
  •  ...Role: Principal SAP Procure to Pay Business Analyst Location: Louisville, KY (Onsite) Job Type: Contract Principal SAP Procure to Pay (P2P) Business Analyst with 10-14 years of experience specializing in SAP MM, Inventory Management, and Production... 
    Contract work

    Lorven Technologies

    Louisville, KY
    4 days ago
  • A leading biotech pharmaceutical company is seeking a Sr Associate Supply Chain Compliance to manage temperature excursions and deviations. This hybrid role involves collaboration with quality and external partners to ensure compliance with Good Distribution Practice (... 
    Senior
    Hourly pay

    Advanced Bio-Logic Solutions Corp

    Louisville, KY
    4 days ago
  • Woodmont Health Campus is seeking an experienced construction manager in Indianapolis, Indiana. The role involves leading construction projects, managing budgets, and ensuring compliance with all regulations. Ideal candidates should have a Bachelor Degree and 5-8 years ...
    Senior

    Woodmont Health Campus

    Louisville, KY
    4 days ago
  • $107.33k - $137.86k

    A leading biotechnology company in Louisville, KY is seeking a Specialist in Supply Chain Compliance. In this role, you will manage deviations, support audits, and ensure supply chain compliance. Candidates should have a Doctorate or equivalent experience in Supply Chain...
    Senior

    BioSpace

    Louisville, KY
    3 days ago
  •  ...Oracle SCM purchase module Sr Architect role Louisville KY Onsite only Fulltime/ C2H for 3 Months Skill -:Oracle SCM techno functional • 15 Years Oracle EBS R12 SCM Techno Functional Architect with Strong Expertise in PO,INV, iSupplier, AP... 
    Senior
    Full time

    Yochana

    Louisville, KY
    2 days ago
  • SOC Service Delivery Lead Own end to end SOC service delivery including monitoring, detection, triage, investigation, and escalation, ensuring alignment with SLAs, KPIs, and client objectives. Act as onsite representative, managing escalations, clarifications, and priority...
    Senior

    Yantran LLC

    Louisville, KY
    3 days ago
  • $99.2k - $128.6k

     ...Sr. Business Intelligence Analyst 1 Taco Bell was born and raised in California and has been around since 1962. We went from selling everyone's favorite Crunchy Tacos on the West Coast to a global brand with 8,500+ restaurants, 350 franchise organizations, that serve... 
    Senior
    Immediate start
    Flexible hours

    Yum! Brands

    Louisville, KY
    1 day ago
  • A healthcare recruitment firm is urgently seeking a Medical Record Clerk to perform quality assurance of medical records with up to 75% travel to provider offices. The role requires strong communication and analytical skills, as well as proficiency in Microsoft Office ...
    Work at office
    Remote work

    Easy Recruiter

    Louisville, KY
    12 hours ago
  •  ...Sr. Salesforce Developer Visa status: U.S. Citizens and those authorized to work in the U.S. are encouraged to apply. Tax Terms: W2, 1099 Corp-Corp or 3rd Parties: Yes Location: Louisville, KY Term: 12 months Job Description ~4 -6 years of IT experience... 
    Senior

    Keylent Inc

    Louisville, KY
    2 days ago
  • $60k - $121.3k

    Senior Compliance Advisor Wealth/Trust Job Locations US-IL-Chicago | US-IN-Indianapolis | US-IN-Evansville | US-KY-Louisville | US-TN-Nashville | US-MN-Saint Paul | US-WI-Milwaukee Category/Function Risk/Security Position Type Regular...
    Senior
    Full time
    Work experience placement
    Work at office

    Old National Bank

    Louisville, KY
    2 days ago
  • Park Community Credit Union seeks a skilled Compliance Specialist I in Louisville, KY, to uphold enterprise-wide compliance with internal policies and regulations. This role involves monitoring business activities, identifying compliance risks, and providing actionable ...

    Park Community Credit Union

    Louisville, KY
    3 days ago
  •  ...Salesforce Sr.Developer Location: Hartford, CT / Louisville, KY / Chicago, IL / King Of Prussia, PA Yrs of Exp: 7+ Years Mode: Full Time Job Description: ~7+ years of experience in Salesforce configuration & customization ~4+ years of extensive hands... 
    Senior
    Full time
    Work experience placement

    Keylent Inc

    Louisville, KY
    12 hours ago
  • Clinical Laboratory Technologist Responsible for independently performing, interpreting, and correlating clinical laboratory tests to assist physician diagnosis and treatment. Performs testing according to policies and procedures. Provides clinical laboratory testing...
    Senior
    Relocation package

    Phenom People

    Louisville, KY
    2 days ago
  • Cornerstone OnDemand is looking for a strategic, analytical, and execution-oriented Principal, GTM Planning & Strategy to help own and evolve the planning engine that underpins our go-to-market execution. This role sits at the intersection of Sales, Finance, Marketing...
    Local area
    Shift work

    Cornerstone OnDemand

    Louisville, KY
    3 days ago
  • $212k - $318k

    NACBA is looking for a Partner, Senior Health Actuary in Louisville, Kentucky. This role involves leading client engagements, reviewing actuarial reports, and contributing to business development efforts. Candidates should have significant consulting experience with large...
    Senior
    Remote work

    NACBA

    Louisville, KY
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Sr. GRC Analyst. Be the first to apply!