Senior GRC Analyst
Gilder Search Group
The Role We Want You For Under the direction of and in collaboration with the GRC Manager, the Sr. GRC Analyst, Third-Party & Human Risk Management (TPHRM) is a risk-focused, highly analytical role that ensures all Human and Third-Party risk to Clayco is identified, quantified, documented, and treated to an acceptable level across the Clayco organization. The role will assume ownership of the Third-Party Risk Management (TPRM) process to gather details on the security practices and compliance levels for each third party being considered or contracted for a solution or services to assess the potential for compromise due to a control gap or exploitable misconfiguration as well as non‑compliance with legal and regulatory requirements. Additional contribution will be expected for internal assessments and 3rd Party audits to gather and submit discovery and transactional responses and artifacts. The Sr. GRC Analyst will also assume ownership of Human Risk Management (HRM) including the delivery of comprehensive security awareness education, the end-to-end execution of phishing simulation programs, and the technical maintenance and life-cycle management of security awareness platforms. The position focuses on Human Risk Management using data-driven insights to identify high-risk user groups and implementing targeted interventions to proactively mitigate human-centric threats to cultivate a security-first culture internally through education and behavioral change. Additional responsibilities will be assigned as deemed necessary. Any travel is usually planned in advance, but issues may arise which warrant immediate travel to one or more satellite locations. The Specifics of the Role Assumes operational ownership of the 3rd Party Vendor Risk Management program identifying, assessing, and mitigating risks associated with external vendors, suppliers, and service providers Conducts due diligence on new and existing vendors by reviewing security questionnaires, SOC reports, compliance certifications, and other supporting attestations Captures, analyzes, and recommends treatment, assignment, and tracking of identified issues Collaborates with legal and stakeholder teams to ensure contracts include specific clauses for data protection, service-level agreements (SLAs), and AI governance Documents and communicates all relevant findings and recommendations to stakeholders Tracks, monitors, and reports on execution of remediation action plans and escalates inadequate responses or progress Assumes ownership of the Security Awareness program determining appropriate topics, themes, scopes, and timing of cyber awareness communications, events, and content delivery Conducts regular, simulated social engineering exercises to assess and improve employee recognition of real-world attacks Develops engaging, simple materials—such as infographics, newsletters, and videos—that translate complex technical risks into layman's terms Maintains Security Awareness training and simulation platforms to support content delivery and End User interaction, including support for any Client-side functionality (i.e., "Report Phish" button) Plans, coordinates, and executes activities for Cybersecurity month Partners with Employee Relations, Legal, and Marketing to ensure security messaging is integrated into the broader corporate culture Tracks Key Risk Indicators (KRI’s) such as actual phishing click-through rates, failed simulations, and missed training as well as Key Performance Indicators (KPIs) like suspicious email reporting, passed simulations, and successful training completion status to measure program effectiveness for leadership Requirements 6-8+ years’ experience in Risk & Compliance Assessment, Audit & Reporting, or similar functions, preferably within the Information Security or Technology fields 3-4+ years working specifically in Information Security roles involving Risk Analysis, Information System Security Assessment, and/or Security Awareness and Human Risk Management Bachelor's degree in Information Technology or related field, or equivalent experience Required Certifications: Certified in Risk & Information Systems Control (CRISC), SANS Security Awareness Professional (SSAP), and Certified Third-party Risk Professional Certification (CTPRP) (Current status, or obtained within 9 months of assuming role) Strong experience leveraging auditing principles and methods to evaluate policies, processes, systems, and vendors to identify business risks and control gaps Strong knowledge of Regulations, Frameworks, and Standards such as NIST 800-171/CSF/RMF, ISO27001, CIS Critical Security Controls, etc. Strong, technical knowledge of modern Systems, Services, Cloud Applications/Platforms, Identity Services, and Data Storage/Handling and their areas of Risk and Threat exposure Experience with administering, maintaining, and leveraging a Risk Register to track and communicate identified Risk and its required remediation Knowledge of statistics, reporting and analytical tools to analyze and solve complex problems Proficiency in necessary productivity tools (i.e., Microsoft Excel, PowerPoint, Word etc.) for analytics and presentations Operate with strong integrity with ability to manage projects of a confidential nature Ability to translate technical or abstract concepts into a narrative that is easily understood Ability to thrive in fast-paced environment This position is classified as a safety-sensitive role in accordance with applicable state and federal laws. Candidates selected for this position will be subject to a comprehensive background check, which includes mandatory drug testing. Benefits Discretionary Annual Bonus: Subject to company and individual performance. Comprehensive Benefits Package Including: Medical, dental and vision plans, 401k, generous PTO and paid company holidays, employee assistance program, flexible spending accounts, life insurance, disability coverage, learning & development programs and more! Compensation The salary range for this position considers a wide range of factors in making compensation decisions including but not limited to: Education, qualifications, skills, training, experience, certifications, internal equity, and location. Compensation decisions are dependent on the facts and circumstances of each case. #J-18808-Ljbffr Gilder Search Group
- Sky Mavis seeks a Sr. GRC Analyst in Phoenix, AZ, to manage Third-Party and Human Risk Management. This analytical role involves vendor risk assessment, security awareness training, and compliance evaluation, ensuring holistic risk management. Candidates should have significant...Senior
- Gilder Search Group is looking for a Sr. GRC Analyst to manage Third-Party & Human Risk while ensuring risks are identified and treated satisfactorily. The role requires 6-8 years in risk assessment, with a bachelor's degree and required certifications expected. You'll...SeniorFlexible hours
- ...Governance, Risk, and Compliance (GRC) Analyst We operate at the intersection of technology and law, in an industry that demands agility... ...seeking an experienced Governance, Risk, and Compliance (GRC) Senior Analyst to join our InfoSec team. This role will be...SuggestedFull timeFlexible hours
- ...Job Description Job Description Governance, Risk & Compliance (GRC) Analyst – State Agency – $40-46/hr W2 – Phoenix Hybrid – Contract-to-Hire SunSoftOnline is hiring a GRC / Information Security Analyst for an Arizona state agency's technology division, a 4-month...SuggestedPermanent employmentFull timeContract workRemote workVisa sponsorshipMonday to Friday
$55 - $60 per hour
...Type: 1099, C2CIndustry: Computer SoftwareClient: WiproContact: Meghana GorusuCompany: SRI Tech SolutionsTitle: SaaS Engineer ( GRC Analyst with IAM )Location: Phoenix AZ onsite onlyDuration: ContractKey ResponsibilitiesPerform security assessments of SaaS and third‑party...SuggestedHourly pay- A large enterprise organization is seeking a GRC Analyst to support a high-visibility security initiative in an onsite role based in downtown Phoenix, AZ. This is a contract position focused on governance, risk, and compliance activities across technology projects, with...Contract workWork at office
- ...organizational privacy obligations. Familiarity with a broad range of IT and information security products and technologies such as GRC platforms, central logging systems, file integrity monitoring, vulnerability management, endpoint security, and cloud security tools....Full timeWork at officeLocal areaRemote workMonday to Friday
- Idealforce LLC is seeking an Information Security Analyst contractor to join our Governance, Risk, and Compliance team in Phoenix, AZ. The role is hybrid with flexible work options and requires collaboration across business units to define requirements, manage data flows...For contractorsFlexible hours
- BWH Hotels is seeking a Security Compliance professional to support governance, risk, and regulatory compliance across PCI DSS, SOX, GDPR/CCPA. The role collaborates with stakeholders and auditors to maintain control documentation, evidence collection, and remediation tracking...
- BWH Hotels is seeking an information security compliance professional to support governance, risk, and compliance across the organization. You will coordinate evidence with stakeholders and auditors, maintain control documentation, and help ensure audit readiness for PCI...
- Jobtailor is seeking a Security Risk Analyst in the Phoenix area to perform risk assessments, audit reviews, and manage security plans. You will generate findings reports, track remediation, and ensure compliance with NIST RMF controls. The role requires hands-on experience...Local areaVisa sponsorship
$78k - $124.75k
Job ID: 26010895Posted: 2026-07-08Location: New York, NY, United States; Phoenix, AZ, United StatesSalary: $78000 - $124750 annually + bonus + benefitsJob Function: Risk ManagementSchedule: Full timeShift: DayWorkplace: HybridCareer Area: Analytics & Risk ManagementCompany...SeniorWork experience placement- Jobtailor is seeking a Security Compliance Analyst to perform risk assessments, manage security documentation, and produce compliance reports. The role collaborates with multiple business units to ensure adherence to standards and regulations, including NIST 800-53 R5 and...
$132.6k - $195k
..., merchants, and drivers.About the RoleThe Global Governance, Risk, and Compliance (GRC) team is looking for a technical, security-focused Third-Party Risk Management (TPRM) Sr. Analyst. If you are comfortable and have experience working in a fast-paced environment, taking...SeniorHourly payContract workWork at officeLocal areaRemote workFlexible hours$172.5k - $222.5k
...work environment where new ideas are encouraged and everyone is a stakeholder.What you’ll be responsible for: Circle is looking for a Senior Manager to join the Regulatory Assurance team who will help to create a central global function focused on developing a best in...SeniorFlexible hours- Motion Recruitment Partners LLC is seeking a GRC Analyst for a contract position in downtown Phoenix, AZ. This role involves ownership of governance, risk, and compliance activities on technology projects, ensuring comprehensive tracking and audit readiness. The ideal candidate...Contract work
- Kelly Services is looking for a GRC Analyst to enhance governance and compliance initiatives for a key security project based in downtown Phoenix, AZ. The contract role involves overseeing a project risk register, ensuring all documentation is audit-ready, and collaborating...Contract work
- Jobtailor in the United States (Arizona) seeks a seasoned Risk/Compliance professional to partner with the Line of Business, RCA teams, and management to build and maintain an effective risk management framework. You will drive initiatives to ensure compliance with federal...SeniorLocal area
- ...Support the Senior Director of Enterprise Risk Management in executing, monitoring, and maintaining the enterprise risk management program... ...Support coordination of risk assessments, including RCSAs and GRC application updates Create and distribute risk-based reports to...SeniorVisa sponsorshipWork visa
- Job Title:Senior Financial Crimes Compliance (FCC) Data analystLocation:CityScapeWhat you'll do:As a Senior FCC Data Analyst you'll assist in maintaining and improving FCC’s analytics and technological capabilities. You'll support the development of processes and technological...SeniorFull time
- Job Title:Regulatory Relations Senior AnalystLocation:CityScapeWhat you'll do:As a Regulatory Relations Senior Analyst you'll maintain the bank's open, cooperative, and constructive relations with its regulators, assisting the Regulatory Relations Manager as the central...SeniorFull timeWork at office
$130k - $160k
...Danaher Business System which makes everything possible.The Senior Cybersecurity Risk Analyst is responsible for executing third-party and supplier risk... ...including country-of-origin scrutiny.Familiarity with GRC platforms (e.g., OneTrust, ServiceNow IRM, RSA Archer) and...SeniorFull timeRemote workWork from homeFlexible hours$127.31k - $243.34k
...duty military spouses consistent with applicable policy and business needs. The Opportunity As a dedicated Bank Credit Risk Analyst Senior, you will have a strong background in credit risk strategy development for card, consumer and deposits credit portfolios to...SeniorH1bWork at officeRemote work- Jobtailor in Arizona is seeking a first-line defense risk professional to support and execute various risk programs and business unit risk activities. You will engage with business units to manage risks and controls across all risk types, monitor policy execution, and serve...Senior
- ...Senior Director, IT Compliance & Governance (Contractor) About the Company Innovative company designing & developing gene therapeutic products Industry Biotechnology Type Public Company Founded 2013 Employees 51-200 Categories Biotechnology...SeniorFor contractors
- Western Alliance Bancorporation is seeking a First Line Risk & Control Senior Analyst in CityScape, Phoenix, to support and/or execute risk programs in line with risk appetite and corporate strategy. You will work with business units to manage risk across all types, monitor...Senior
- ConsultNet Technology Services and Solutions is seeking a Manager, Third Party Payment Partner Due Diligence Operations to support partner onboarding, compliance reviews, and ongoing due diligence efforts in a regulated financial services environment. The role involves ...Senior
- Western Alliance Bank in CityScape seeks a First Line Risk & Control Senior Analyst to support and execute risk programs across all risk types, aligning with risk appetite and corporate strategy. You will engage with business units to monitor risks and controls and ensure...Senior
- Our client, a leading organization in the financial services industry, seeks a Senior AML Analyst to join the Global Merchant & Network Services (GMNS) team in Phoenix. The role centers on supporting payment facilitation and compliance operations in a dynamic, inclusive...Senior
- SWCA Environmental Consultants is seeking a Senior Contracts Analyst to review, draft, and manage client agreements, ensuring compliance with internal policies and regulatory requirements. This role supports internal stakeholders, mitigates risk, and optimizes terms in...SeniorPermanent employmentFull time
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior GRC Analyst. Be the first to apply!
- grc analyst Phoenix, AZ
- senior maintenance supervisor Phoenix, AZ
- senior lead project manager Phoenix, AZ
- senior robotics software engineer Phoenix, AZ
- senior devops engineer remote Phoenix, AZ
- senior sas administrator Phoenix, AZ
- senior IT manager Phoenix, AZ
- senior director of client services Phoenix, AZ
- senior contracts analyst Phoenix, AZ
- senior implementation consultant Phoenix, AZ


