Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Sr. GRC Analyst

$95k - $105k
Full-time

Subsplash

Job Description

Job Description

Sr. GRC Analyst About Subsplash

Subsplash is an exciting award-winning team of 280+ mission-driven people who are committed to our core values of humility, innovation, and excellence. Founded in 2005, we've remained family owned and operated while pioneering the market with the first ever church mobile app. Since then, we've been working together to build The Ultimate Engagement Platform™ for churches, Christian ministries, non-profits, and businesses around the world. We find excitement in serving our 14,000+ clients, creating impactful products, and delighting the millions of people who use our platform every day. Subsplash has won awards for best mobile experience, been voted top 100 Washington's Best Workplaces by the Puget Sound Business Journal, created some of the most downloaded apps of all time, and built enterprise software for world-class brands like XBOX, Microsoft, Samsung, Expedia, and Cisco; yet, at the end of the day, we love making a lasting impact and a difference in our world.

Working at Subsplash is more than just a job; we are a team of people who are courageous, inventive, and passionate about doing meaningful work every day. Don't take our word for it—head to Glassdoor and see for yourself!

About the Team

The IT Team at Subsplash is the foundation that maintains all the activities and services that are required to support business functions as well as ensuring proper security across all IT systems. We are passionately focused on delivering delightful support to our internal customers. We achieve this by providing robust day-to-day technical support that empowers our fellow Subsplash employees to perform their best work most often. Beyond daily technical support, our team handles crucial functions such as access management, user provisioning and deprovisioning, new hardware and software setup, and diligently works to keep our dues and subscription spend under budget.

About the Role

The Senior GRC Analyst acts as a strategic lead to advance security and risk operations. In this role, you will integrate people, policy, and technology to drive operational excellence and framework maturity. You will be responsible for identifying security gaps, implementing best practices, and maturing our control environment to ensure we stay ahead of evolving regulatory and threat landscapes. We are building an AI-first compliance function, and this role is expected to lead from the front in identifying and deploying AI tools that scale our GRC program.

Compensation
  • The total compensation for this position is between $95,000-$105,000/yr depending on experience level.
Essential Functions of This Role: Compliance Program Management & Audit Leadership
  • Audit Execution: Act as the primary point of contact for external auditors; lead the end-to-end execution of PCI DSS audits and support internal audit on IT SOX controls.
  • Data Mapping Maintenance: Develop and maintain a comprehensive data inventory and data flow diagrams. Track how sensitive data (PII, PCI) moves through our systems to ensure compliance with privacy regulations and security boundaries.
  • Framework Maturation: Map and implement controls across multiple frameworks (PCI DSS, NIST CSF) to eliminate redundancies and improve the organization's security posture.
  • GRC Reporting: Track and report on GRC program health across compliance posture, risk register status, audit readiness, and control effectiveness. Present metrics and trends to leadership on a regular cadence.
2. Access Governance & Identity Management
  • User Access Reviews (UAR): Orchestrate and lead the quarterly and semi-annual user access review process across all critical systems (SaaS, Cloud Infrastructure, and Internal Tools).
  • Joiner/Mover/Leaver Oversight: Monitor and validate that provisioning and deprovisioning processes are executed accurately and on time across critical systems. Flag exceptions, track remediation, and maintain documentation to support access control audits.
3. Security Awareness & Phishing Program
  • Program Ownership: Execute and maintain a comprehensive, year-round Security Awareness Training (SAT) program that meets PCI DSS requirements while driving actual behavioral change.
  • Phishing Simulations: Execute monthly or quarterly phishing simulations; analyze "fail rates" and provide targeted follow-up training to high-risk groups.
  • Content Curation: Select and deploy engaging security content, newsletters, and "security moments" to keep cybersecurity top-of-mind for all employees.
  • Reporting: Present program health metrics (completion rates, simulation trends, and reporting speed) to the Leadership team.
4. Risk and Vendor Management
  • Vendor & Risk Execution: Execute the TPRM program—conducting vendor security reviews, tracking remediation to completion, and escalating high-risk findings to leadership.
  • Risk Register Ownership: Maintain and update the corporate risk register, ensuring remediation efforts are tracked, validated, and communicated to leadership.
Desired Qualifications:
  • Experience: 3–5 years of dedicated experience in GRC, Information Security, or Audit (FinTech or Financial Services industry experience is highly preferred).
  • Technical Mastery: Deep practical knowledge of PCI DSS requirements and controls.
  • Data Governance: Experience performing Data Mapping exercises and maintaining Records of Processing Activities (RoPA).
  • SAT Strategy: Proven experience managing phishing platforms (e.g., KnowBe4, Mimecast, or Vanta-integrated tools) and developing security training curricula.
  • IAM Expertise: Proven experience managing formal access review cycles and identity governance processes.
  • Systems: Proven experience administering a GRC platform, including automated evidence collection, control monitoring, and access review workflows. Direct experience with Vanta is a significant advantage.
  • SOX IT Controls: Experience with SOX IT General Controls (ITGCs), including change management, logical access, computer operations controls, and segregation of duties (SoD). This role will work directly with internal audit to support IT SOX control testing and evidence collection.
  • AI Tooling: Demonstrated experience using AI tools to improve GRC workflows, automate reporting, or accelerate evidence collection and analysis.
Core Competencies
  • Critical Thinker: You have a drive for distinguishing clear priorities and conclusions from ambiguous data.
  • Velocity: You bring urgency and momentum to compliance work—prioritizing ruthlessly, moving quickly through ambiguity, and consistently pushing the program further than the baseline requires.
  • Detail Oriented: You notice the small gaps in access logs, data maps, or training reports that others might miss.
  • AI-Forward: You treat AI as a force multiplier for GRC work—using it to compress audit prep cycles, automate evidence gathering, and free up capacity for higher-value risk analysis.
  • Collaborative: You work effectively across IT and Engineering to surface control gaps, translate technical risks into compliance language, and ensure cross-functional ownership of remediation.
Your First 90 Days
  • Own the PCI DSS evidence pipeline. Get fully oriented on the current ASV scanning cadence, open findings, and SAQ scoping in Vanta. By day 60, be actively supporting evidence collection. By day 90, have a clear understanding of the program state and a plan for taking it over fully.
  • Get oriented on the SOX SoD review cycle. The conflict detection framework and SoD procedure are built. Within 90 days, develop a working understanding of the quarterly review rhythm, the supporting Confluence documentation, and the compensating controls tracking process — with the goal of owning it independently shortly after.
  • Complete a full UAR cycle. Execute a complete user access review across all critical systems, coordinating with IT and system owners, documenting exceptions, and tracking remediation to closure. This is a tangible, auditable deliverable that demonstrates cross-functional coordination and Vanta proficiency.

Deliver a first GRC metrics report to leadership. Produce a polished metrics report covering compliance posture, risk register status, PCI standing, and SOX control health. This establishes the reporting cadence and introduces the role to leadership on their terms.

Location

Subsplash currently has operations in 27 states across the US! As much as we would love to have employees in as many states and countries as we have clients, we are currently limiting hiring to the states we already operate in. As a result of that, this role is only available as a 100% remote position if you reside in one of the following states:

AL, AR, AZ, CO, FL, GA, ID, IA, IN, KS, KY, MO, MI, MN, NC, NM, OK, OH, OR, SC, SD, TN, TX, UT, VA, WA, WY.

We are not sponsoring relocation for this role so unfortunately, if you do not currently reside in one of these states, we are unable to consider your application.

Benefits

Generous Paid Time Off, Medical Coverage, Dental Coverage, Vision Coverage, short and long term disability and life insurance all free of charge, Competitive Compensation, 401k Matching, Professional Development, Top of the Line Equipment, Referral Program, Parental Leave, Family-Friendly Culture, and the chance to work side-by-side with thought leaders in emerging tech

Note: Employment with Subsplash is contingent upon satisfactory proof of employee's right to work in the U.S., as required by law and upon completion of a basic background check and; employment with Subsplash is considered "at will," meaning that either the company or the employee may terminate the employment relationship at any time without cause or notice.

Subsplash is an Equal Opportunity Employer. We value all human life as all people are created with equal dignity, value, and worth. We do not discriminate on the ground of race, color, religion, sex, age, disability or national origin, or genetic information in the hiring, retention, or promotion of employees; nor in determining their rank, or the compensation or fringe benefits paid them.

#LI-Remote #BI-Remote

Vacancy posted 20 days ago
Similar jobs that could be interesting for youBased on the Sr. GRC Analyst in Indianapolis, IN vacancy
  •  ...Secuirty Analyst Sr. (Sr. Third Party Cybersecurity GRC Analyst ) Information Security Risk Management Hybrid 1: This role requires associates to be in-office 1 - 2 days per week in the Indianaplis, IN or Atlanta, GA office, fostering collaboration and connectivity... 
    Senior
    Temporary work
    Work at office
    Local area
    2 days per week
    1 day per week

    Elevance Health

    Indianapolis, IN
    2 days ago
  • $40 - $45 per hour

     ...Job Title: GRC Analyst (AI Risk & Governance Focus) Location: Indianapolis, IN (Hybrid) Duration: 12-month contract (potential for extension or conversion) Compensation: $40-45/hr (W-2) Overview Our client is seeking a GRC Analyst with exposure to AI risk... 
    Suggested
    Contract work
    Local area

    Brooksource

    Indianapolis, IN
    2 days ago
  • $90k

    Senior Risk Placement Specialist NFP, an Aon company, is a multiple Best Places to Work award winner in Business Insurance. We are an organization of consultative advisors and problem solvers. We help companies and individuals around the globe address their most significant...
    Senior
    Work at office
    Remote work

    NFP

    Indianapolis, IN
    6 hours ago
  • $100 per hour

     ...Job Summary The Sr Director of Regulatory Reporting is responsible for overseeing and managing the end-to-end regulatory reporting process including preparing and reviewing filings such as the FR Y-9C, FR Y-9LP, Call Report, FR Y-15, FR Y-14M/Q series, FR 2052a, FR... 
    Senior

    Synovus

    Indianapolis, IN
    4 days ago
  • $135k - $190k

     ...human health for tomorrow. Learn about the Danaher Business Syste m which makes everything possible. We are currently seeking a Sr Manager of Global Commercial Contract & Deal Enablement who will be responsible to lead and evolve a global team responsible for... 
    Senior
    Contract work
    Part time
    Remote work
    Work from home
    Flexible hours

    Danaher Corporation

    Indianapolis, IN
    1 day ago
  • $169.5k - $248.6k

    At Lilly, we unite caring with discovery to make life better for people around the world. We are a global healthcare leader headquartered in Indianapolis, Indiana. Our employees around the world work to discover and bring life-changing medicines to those who need them,...
    Senior
    Full time
    Local area
    Relocation
    Flexible hours

    Eli Lilly

    Indianapolis, IN
    4 days ago
  • $143k - $243k

    A healthcare benefit management company seeks a Senior Principal Actuary to provide actuarial direction and innovative modeling concepts. This remote role requires strong strategic pricing expertise and leadership skills with a minimum of 10 years in actuarial work. The...
    Senior
    Remote work

    Prime Therapeutics

    Indianapolis, IN
    5 days ago
  •  ...Job Description Insight Global is looking for a Senior Interconnection Contracts Analyst to support one of our largest clients in Carmel, IN. The Senior Interconnection Contracts Analyst is responsible for the drafting and processing of agreements required to support... 
    Senior
    Contract work

    Insight Global

    Carmel, IN
    3 days ago
  • $104k - $156k

    Public Consulting Group LLC (PCG) is a leading public sector solutions implementation and operations improvement firm that partners with health, education, and human services agencies to improve lives. Founded in 1986, PCG employs approximately 2,000 professionals throughout...
    Senior
    For contractors
    H1b
    Work at office
    Local area
    Remote work

    Public Consulting Group

    Indianapolis, IN
    5 days ago
  • $90k - $115k

     ...Opportunity Employer This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights ( notice from the Department of Labor. Job Category: Analyst Full-Time... 
    Senior
    Full time
    Contract work
    Local area

    MISO Energy

    Carmel, IN
    3 days ago
  •  ...patients. And above all, it means exceptional care, simply delivered - and we couldn't do it without you. Make a Difference The Epic Analyst will be responsible for planning, system analysis, application building, testing, maintenance, upgrades, configuration, and support... 
    Senior
    Live in
    Work at office
    Remote work
    Relocation
    Weekend work

    Community Health Network

    Indianapolis, IN
    5 days ago
  •  ...Sr. Business Analyst Location: 2 N. Meridian St. Indianapolis IN 46204 – (HYBRID/ onsite 3 days per week and 2 days REMOTE) This position will provide senior level business system analysis, support, and quality assurance for the Office of Technology and Compliance... 
    Senior
    Work at office
    Remote work
    3 days per week

    My3Tech Inc

    Indianapolis, IN
    5 days ago
  • Title: IT Senior Business Analyst Location: Indianapolis, IN Duration: 24 Months Type: Contract - Hybrid Job Description: Candidate will be a detailed planner, expert communicator, top‑notch analyst, and have a deep understanding of business operations and IT systems. The... 
    Senior
    Contract work

    Creative Solutions Services, LLC

    Indianapolis, IN
    5 days ago
  •  ...package. Come grow with us! This opportunity, it is on-site at our Manufacturing Plant in Indianapolis, Indiana. SCOPE: The Sr. Principal Engineer is the principal technical point of reference for processing operations across the company with a focus on Stevia... 
    Senior
    Full time

    Heartland FPG

    Indianapolis, IN
    22 days ago
  •  ...Sr. Business Objects Analyst We are seeking an experienced Sr. Data Warehouse / Business Analyst on a full-time, permanent basis for our client, a worldwide leader in the technology and media space. The Sr. Data Warehouse /Business Analyst will serve as a leader for... 
    Senior
    Permanent employment
    Full time
    Remote work
    Worldwide

    Bluestone Solutions Group

    Indianapolis, IN
    5 days ago
  •  ...Sr. Quality Analyst We are seeking a Sr. Quality Analyst for our client, a $350M+ recognized and viable leader in the business services industry on a full-time, permanent basis. The Sr. Quality Analyst will play an integral role in ensuring the accuracy and quality... 
    Senior
    Permanent employment
    Full time

    Bluestone Solutions Group

    Indianapolis, IN
    4 days ago
  • $90k - $110k

     ...Ownership.** We deliver what we promise and learn along the way.****We’re Looking For:****We are seeking an analytical and hands-on Senior Analyst, Revenue Management to evaluate, develop, and optimize the transportation pricing structure for the US Marketplace. This role... 
    Senior
    Temporary work
    Seasonal work
    Immediate start
    Remote work
    Shift work

    KAR Auction Services

    Carmel, IN
    3 days ago
  • $77.95k - $91.7k

     ...Job Title Sr. Compensation Analyst Job Description Summary The Senior Compensation Analyst is a key member of C&W’s Global Compensation team, supporting the Americas Human Resources organization. This role is responsible for analyzing, designing, and administering... 
    Senior
    Hourly pay
    Minimum wage
    Local area
    Flexible hours

    Cushman & Wakefield

    Indianapolis, IN
    5 days ago
  • $163.9k - $235.55k

     ...that succeeds together. Because at UKG, your work matters—and so do you. Role Overview We are seeking a Senior Principal, CMI analyst to serve as a cornerstone of this transformation, someone who can operationalize market intelligence, shape executive narratives,... 
    Senior
    Local area
    Shift work

    UKG

    Indianapolis, IN
    3 days ago
  • $27.4 - $39.3 per hour

     ...Title: Sr Transportation Analyst - Freight Pay & Audit Job Code: P29417 - Sr Analyst, Transportation Job Summary The Global Supply Chain Center of Excellence provides technology solutions to facilitate transportation and product distribution, creating a differentiated... 
    Senior
    Hourly pay
    Temporary work
    Local area
    Immediate start
    Remote work
    Flexible hours

    Cardinal Health

    Indianapolis, IN
    3 days ago
  •  ...subcontractor flow-down concepts, and prohibited/covered telecommunications considerations (e.g., Section 889). - Experience using GRC/TPRM tooling to manage supplier inventories, risk assessments, evidence collection, issues/remediation, and reporting (tool... 
    Senior
    Minimum wage
    Contract work
    Temporary work
    Work experience placement
    For subcontractor
    Work at office

    MAXIMUS

    Indianapolis, IN
    2 days ago
  •  ...Sr. Data Science Analyst Our team members advance our mission and exemplify excellence, compassion, teamwork, and purpose in all that they do. Indiana University Health is seeking individuals who embody these values to join our System Strategy Team in the role of Sr... 
    Senior
    Full time
    Local area
    Shift work

    IU Health

    Indianapolis, IN
    3 days ago
  • $110.7k

     ...Business Sys Analyst Sr - req1597 OVERVIEW Responsible for optimization and streamlining the organization's Quote 2 Cash workstream, focusing on analyzing existing process, identifying areas for improvement, and implementing effective changes, by working with Business... 
    Senior
    Remote work

    Canon USA & Affiliates

    Indianapolis, IN
    4 days ago
  •  ...Remote Business Analyst Apex Systems, a leader in IT Solutions, is looking for a REMOTE Business Analyst! This role is for a long term contract opportunity for a fast growing, dynamic Healthcare organization. The Business Analyst will represent the business community... 
    Senior
    Remote job
    Long term contract
    Work experience placement

    Software Technology, Inc.

    Indianapolis, IN
    1 day ago
  • $115.3k - $264.1k

    Job Description Manage the development and implementation process of a specific company product. Responsibilities Manage the development and implementation process of a specific company product involving departmental or cross-functional teams focused on the delivery...
    Senior
    Temporary work
    Flexible hours

    Oracle

    Indianapolis, IN
    6 hours ago
  • $112.7k - $140.9k

     ...LinkedIn. Job Overview We are currently seeking a dynamic, highly motivated, and experienced individual for the position of Senior Analyst, Market Access Applications. This individual will serve as a liaison between Market Access Commercial Business and IT, responsible... 
    Senior
    Work experience placement
    Worldwide
    Flexible hours

    Sumitomo Pharma

    Indianapolis, IN
    4 days ago
  • $98.4k - $199k

     ...that is firmly rooted in its core values. Responsibilities Position Summary We are seeking an experienced Technical Business Analyst to support and enhance our Commercial Digital Banking technology. This role sits within the Commercial Digital Banking IT team and... 
    Senior

    Old National Bank

    Indianapolis, IN
    5 days ago
  • $67.7k - $90.27k

     ...in building the future. The Role As the Senior Business Analyst within the GCO Front Door Team , this role is accountable for leading...  ...risk management across presales operational engagements. The Sr. Business Analyst serves as a central point of coordination to... 
    Senior
    Contract work
    Temporary work
    Remote work

    Lumen Inc

    Indianapolis, IN
    2 days ago
  • Senior Director, Regulatory Affairs About the Company International labelling organization based in Los Angeles Industry Retail Type Privately Held About the Role The Senior Director, Regulatory Affairs will be responsible for developing and managing...
    Senior
    Worldwide

    Confidential

    Indianapolis, IN
    3 days ago
  • $100k - $130k

     ...Fearless Ownership. We deliver what we promise and learn along the way. We're Looking For: We are seeking a Senior HRIS Analyst with experience in HR systems configuration, business process design, and data/reporting. You will be part of an HR Technology team... 
    Senior
    Temporary work
    Immediate start
    Remote work

    OPENLANE

    Carmel, IN
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Sr. GRC Analyst. Be the first to apply!