Senior GRC Analyst
Gilder Search Group
The Role We Want You For Under the direction of and in collaboration with the GRC Manager, the Sr. GRC Analyst, Third-Party & Human Risk Management (TPHRM) is a risk-focused, highly analytical role that ensures all Human and Third-Party risk to Clayco is identified, quantified, documented, and treated to an acceptable level across the Clayco organization. The role will assume ownership of the Third-Party Risk Management (TPRM) process to gather details on the security practices and compliance levels for each third party being considered or contracted for a solution or services to assess the potential for compromise due to a control gap or exploitable misconfiguration as well as non‑compliance with legal and regulatory requirements. Additional contribution will be expected for internal assessments and 3rd Party audits to gather and submit discovery and transactional responses and artifacts. The Sr. GRC Analyst will also assume ownership of Human Risk Management (HRM) including the delivery of comprehensive security awareness education, the end-to-end execution of phishing simulation programs, and the technical maintenance and life-cycle management of security awareness platforms. The position focuses on Human Risk Management using data-driven insights to identify high-risk user groups and implementing targeted interventions to proactively mitigate human-centric threats to cultivate a security-first culture internally through education and behavioral change. Additional responsibilities will be assigned as deemed necessary. Any travel is usually planned in advance, but issues may arise which warrant immediate travel to one or more satellite locations. The Specifics of the Role Assumes operational ownership of the 3rd Party Vendor Risk Management program identifying, assessing, and mitigating risks associated with external vendors, suppliers, and service providers Conducts due diligence on new and existing vendors by reviewing security questionnaires, SOC reports, compliance certifications, and other supporting attestations Captures, analyzes, and recommends treatment, assignment, and tracking of identified issues Collaborates with legal and stakeholder teams to ensure contracts include specific clauses for data protection, service-level agreements (SLAs), and AI governance Documents and communicates all relevant findings and recommendations to stakeholders Tracks, monitors, and reports on execution of remediation action plans and escalates inadequate responses or progress Assumes ownership of the Security Awareness program determining appropriate topics, themes, scopes, and timing of cyber awareness communications, events, and content delivery Conducts regular, simulated social engineering exercises to assess and improve employee recognition of real-world attacks Develops engaging, simple materials—such as infographics, newsletters, and videos—that translate complex technical risks into layman's terms Maintains Security Awareness training and simulation platforms to support content delivery and End User interaction, including support for any Client-side functionality (i.e., "Report Phish" button) Plans, coordinates, and executes activities for Cybersecurity month Partners with Employee Relations, Legal, and Marketing to ensure security messaging is integrated into the broader corporate culture Tracks Key Risk Indicators (KRI’s) such as actual phishing click-through rates, failed simulations, and missed training as well as Key Performance Indicators (KPIs) like suspicious email reporting, passed simulations, and successful training completion status to measure program effectiveness for leadership Requirements 6-8+ years’ experience in Risk & Compliance Assessment, Audit & Reporting, or similar functions, preferably within the Information Security or Technology fields 3-4+ years working specifically in Information Security roles involving Risk Analysis, Information System Security Assessment, and/or Security Awareness and Human Risk Management Bachelor's degree in Information Technology or related field, or equivalent experience Required Certifications: Certified in Risk & Information Systems Control (CRISC), SANS Security Awareness Professional (SSAP), and Certified Third-party Risk Professional Certification (CTPRP) (Current status, or obtained within 9 months of assuming role) Strong experience leveraging auditing principles and methods to evaluate policies, processes, systems, and vendors to identify business risks and control gaps Strong knowledge of Regulations, Frameworks, and Standards such as NIST 800-171/CSF/RMF, ISO27001, CIS Critical Security Controls, etc. Strong, technical knowledge of modern Systems, Services, Cloud Applications/Platforms, Identity Services, and Data Storage/Handling and their areas of Risk and Threat exposure Experience with administering, maintaining, and leveraging a Risk Register to track and communicate identified Risk and its required remediation Knowledge of statistics, reporting and analytical tools to analyze and solve complex problems Proficiency in necessary productivity tools (i.e., Microsoft Excel, PowerPoint, Word etc.) for analytics and presentations Operate with strong integrity with ability to manage projects of a confidential nature Ability to translate technical or abstract concepts into a narrative that is easily understood Ability to thrive in fast-paced environment This position is classified as a safety-sensitive role in accordance with applicable state and federal laws. Candidates selected for this position will be subject to a comprehensive background check, which includes mandatory drug testing. Benefits Discretionary Annual Bonus: Subject to company and individual performance. Comprehensive Benefits Package Including: Medical, dental and vision plans, 401k, generous PTO and paid company holidays, employee assistance program, flexible spending accounts, life insurance, disability coverage, learning & development programs and more! Compensation The salary range for this position considers a wide range of factors in making compensation decisions including but not limited to: Education, qualifications, skills, training, experience, certifications, internal equity, and location. Compensation decisions are dependent on the facts and circumstances of each case. #J-18808-Ljbffr Gilder Search Group
- Sky Mavis seeks a Sr. GRC Analyst in Phoenix, AZ, to manage Third-Party and Human Risk Management. This analytical role involves vendor risk assessment, security awareness training, and compliance evaluation, ensuring holistic risk management. Candidates should have significant...Senior
- ...Governance, Risk, and Compliance (GRC) Analyst Schaumburg About Fulcrum We operate at the intersection of technology and law, in... ...seeking an experienced Governance, Risk, and Compliance (GRC) Senior Analyst to join our InfoSec team. This role will be instrumental...SuggestedFull timeFlexible hours
- BWH Hotels is seeking an information security compliance professional to support governance, risk, and compliance across the organization. You will coordinate evidence with stakeholders and auditors, maintain control documentation, and help ensure audit readiness for PCI...Suggested
- ...organizational privacy obligations. Familiarity with a broad range of IT and information security products and technologies such as GRC platforms, central logging systems, file integrity monitoring, vulnerability management, endpoint security, and cloud security tools....SuggestedFull timeWork at officeLocal areaRemote workMonday to Friday
$55 - $60 per hour
...Type: 1099, C2CIndustry: Computer SoftwareClient: WiproContact: Meghana GorusuCompany: SRI Tech SolutionsTitle: SaaS Engineer ( GRC Analyst with IAM )Location: Phoenix AZ onsite onlyDuration: ContractKey ResponsibilitiesPerform security assessments of SaaS and third‑party...SuggestedHourly pay$78k - $124.75k
Job ID: 26010895Posted: 2026-07-08Location: New York, NY, United States; Phoenix, AZ, United StatesSalary: $78000 - $124750 annually + bonus + benefitsJob Function: Risk ManagementSchedule: Full timeShift: DayWorkplace: HybridCareer Area: Analytics & Risk ManagementCompany...SeniorWork experience placement- City of Phoenix is seeking a Cybersecurity Risk and Compliance Analyst (Sr. BSA) to join the Information Security Office in a hybrid role. You will bridge security with business goals, manage risk assessments, audit prep, remediation tracking, and policy implementation...SeniorWork at office
$77.2k - $96.5k
...Time: Be the Linchpin of Security and Compliance at WWT As an Information Security (InfoSec) Governance, Risk, and Compliance (GRC) Analyst within Audit and Compliance, you will play a pivotal role in ensuring that WWT’s information security practices not only align...Full timeContract workPart timeRemote workFlexible hoursShift work- Bank of America in Phoenix, AZ is seeking an Enterprise Independent Tester to execute internal control discipline and quality assurance within a Line of Business. The role focuses on testing processes, documenting defects, and collaborating with process owners to drive ...Senior
- American Express seeks a driven risk professional to identify and assess operational risks across business processes and systems, partnering with process owners to evaluate risk scenarios and support risk assessments, testing, and quality assurance programs. You will maintain...Senior
- ...U.S. Bank in Arizona seeks a Senior Credit Analyst to assess credit risk, conduct thorough analyses of financial data, and support lending decisions for new, renewal, and extension credits. You will review portfolios, identify potential issues, prepare detailed reports...Senior
$77k - $143k
...Senior Analyst, Client Risk Prevention As a Senior Analyst, Client Risk Prevention in the Business Risk Oversight team, you will be responsible for the intake and case management of incidents of fraud, financial exploitation, and vulnerable client support, providing...SeniorWork at officeFlexible hours- RBC Wealth Management in the United States seeks a Senior Analyst, Client Risk Prevention, within the Business Risk Oversight team to oversee intake and case management of fraud, financial exploitation, and vulnerable client support. You will partner with legal, compliance...Senior
- ...Senior Director, IT Compliance & Governance (Contractor) About the Company Innovative company designing & developing gene therapeutic products Industry Biotechnology Type Public Company Founded 2013 Employees 51-200 Categories Biotechnology...SeniorFor contractors
- • Identify risks throughout business processes and systems with business process owners • Assess operational risk implications for new and existing products, features, and services within new product approval and change management governance frameworks • Facilitate US Consumer...Senior
$92.45k - $114.2k
Job Title:Senior Compliance OfficerLocation:CA - Westlake VillageWhat you'll do:As a Senior Compliance Officer in the Second Line of Defense, you'll review and analyze information, reports or data to determine if the applicable process is in compliance with internal policy...SeniorFull time- City National Bank is seeking a senior KYC Review Analyst in Operations to conduct Enhanced Due Diligence for commercial loan borrowers and periodic client reviews. You will assess compliance risks, verify KYC completion, and escalate activities per policy while leveraging...Senior
- SOLV Energy is seeking a Senior Labor Compliance Specialist to lead the labor compliance program for nationwide solar, storage, and substation projects. You will oversee audits, coordinate investigations, and implement training across Operations and SI Departments. This...SeniorRemote jobWork at office
- Turo Inc. is seeking a Claims Specialist to handle high-complexity claims, requiring analysis of policies and customer communication. This role involves investigating claims, negotiating resolutions, and providing recommendations on processes. The ideal candidate will demonstrate...Senior
- Job Title:Senior Servicing Compliance Manager - Residential Mortgage PortfolioLocation:BiltmoreWhat you'll do:As a Senior Compliance Manager, you'll be responsible for developing, leading, and overseeing the Company’s mortgage servicing regulatory compliance program, thereby...SeniorFull time
- ...Senior Director, Principal Gifts About the Company Philanthropic organization supporting Indigenous culture & individuals Industry Non-Profit Organization Management Type Non Profit Founded 2017 Employees 11-50 Categories ~ Non-Profit &...Senior
- Chubb seeks a Sr. Auto Examiner (Commercial) to manage complex Auto Claims, including property damage and related coverages. The role demands excellent time management, precise analysis, and clear communication with insureds and claimants. The position requires 2-4 years...SeniorRemote work
- Job Title:Senior Financial Risk AnalystLocation:CityScapeWhat you'll do:The Financial Risk Management Group (FRM) oversees risk-taking... ..., and overall process improvement. As a Financial Risk Senior Analyst, you will support the oversight of the company’s investment portfolio...SeniorFull time
- ...Senior Compliance SpecialistInspired by faith. Driven by innovation. Powered by humankindness. CommonSpirit Health is building a healthier future for all through its integrated health services. As one of the nation's largest nonprofit Catholic healthcare organizations...Senior
- Humana is seeking a Senior Professional for Risk and Compliance in Phoenix, AZ to oversee risks associated with Medicaid programs and ensure adherence to MHPAEA regulations. Responsibilities include risk management strategy development, conducting assessments, and collaborating...SeniorRemote job
- ...If you want to be part of an inclusive, adaptable, and forward-thinking organization, apply now.We are currently seeking a ERP Senior Analyst to join our team in Phoenix, Arizona (US-AZ), United States (US).Sound knowledge of Procurement and Inventory Management.Should...Senior
- Cambridge is seeking an Advocacy and Supervision Principal to join the Advocacy and Supervision department. This role reviews, analyzes, and approves daily transactions and account activity while helping ensure adherence to firm policies, clearing firm requirements, and...Senior
- Mercer is seeking a Sr. Government Health Actuary to join our Government Human Services Consulting team. You will participate in client engagements, manage delivery, and design strategies while leveraging AI and technology-enabled tools. The role requires extensive health...Senior
- Mercer, part of Marsh McLennan, is seeking a Sr. Government Health Actuary to join the Government Human Services Consulting team in Phoenix. You will lead health actuarial engagements, perform complex Medicaid analyses, and guide junior staff while interacting with clients...Senior
- Gather and analyze disparate Tech Investment/Platform Health data sets to identify patters, trends, and outliers - Ideate and design visuals to represent data findings to support leadership communications and meetings - Create on-demand PowerPoint tables/charts/visuals...Senior
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior GRC Analyst. Be the first to apply!
- senior technical analyst Phoenix, AZ
- senior associate attorney Phoenix, AZ
- senior developer Phoenix, AZ
- senior aws cloud engineer Phoenix, AZ
- senior manager business development Phoenix, AZ
- remote senior salesforce administrator Phoenix, AZ
- senior marketing operations manager Phoenix, AZ
- senior manager tax Phoenix, AZ
- senior property accountant Phoenix, AZ
- senior tax director Phoenix, AZ


