GRC Analyst
Momentum
Momentum is a respected collection of independent companies, including PMG, Koddi, Further. We serve as a premier global business transformation partner for over 125 of the Fortune 500 brands. With 1,400 global employees and $5B in media spend under management, we foster a fast-growing, values-driven, people-first environment where you can thrive. Our portfolio of companies partners with some of the world’s most iconic and ambitious brands. We combine scalability with a solutions-oriented approach to deliver fast-paced, innovative results for our customers while creating meaningful growth opportunities for our teams. If you are looking for opportunities to grow in your career and are passionate about being at the forefront of data and technology, and driving rapid innovation in the future of commerce, we would love to talk with you about joining Momentum. We believe that a culture of belonging, inclusion, and diversity is key to empowering our team members to thrive both personally and professionally. Living out our values is not just a goal; it’s a daily practice! For more information, please visit The Opportunity We are hiring a Security GRC & Risk Analyst to own the governance, risk, and compliance execution layer across a holding company and portfolio of businesses. This is a build-oriented role with a defined scope: you will be the internal anchor for our SOC 2 Type II audit, NIST CSF remediation roadmap, security policy library, vendor risk program, and client-facing security questionnaires. You will work directly with the Cybersecurity Manager and a vCISO partner, collaborate with the Data Privacy legal team as a peer on overlapping policy areas, and engage regularly with portfolio company stakeholders. A dedicated internal Data Privacy legal team owns regulatory compliance - GDPR, CCPA, breach notification, and data subject rights. This role owns the technical controls layer: the evidence, the frameworks, the audit coordination, and the vendor risk program. Join us in this full-time role, based in our Dallas Office at the Link: 2601 Olive Street, Dallas, TX. Be part of a vibrant community where amazing people, data & insights, and perpetual innovation converge to shape the future of digital commerce! About This Role at Momentum What You’ll Do SOC 2 & NIST CSF Program Own the internal SOC 2 Type II evidence collection process, keeping controls audit-ready year-round. Manage the audit timeline, day-to-day liaison with the external auditor, and remediation finding closure between cycles. Own the NIST CSF remediation roadmap: maintain the gap register, report progress to the VP and vCISO on a defined cadence, and coordinate with portfolio company IT teams to assess and close control gaps. Build and maintain a unified controls library mapping SOC 2 Trust Services Criteria, NIST CSF subcategories, and applicable regulatory requirements. Prepare the organization for bi-annual NIST CSF assessments, ensuring controls are documented and defensible. Security Policy & AI Governance Operationalize the enterprise-wide information security policy library across the corporate entity and portfolio companies. Inventory gaps against SOC 2, NIST CSF, and applicable regulations; draft, publish, and version-control policies in coordination with the vCISO. Build and maintain annual policy attestation workflows across all employees. Bridge with the Data Privacy legal team on overlapping areas: data classification, retention, and incident notification. Develop and maintain the AI governance framework: tool intake review, data handling risk assessment, and acceptable use policy. Evaluate AI tools proposed across the corporate entity and portfolio companies against security and compliance standards. Own AI-related policy documentation and track emerging regulatory requirements including the EU AI Act and NIST AI RMF. Risk Management & Vendor Risk Build and maintain a risk register with risk-to-control mapping. Define and document formal risk tolerance and appetite in coordination with the vCISO and leadership. Own the third-party risk management program. Define and implement a tiered due diligence model (critical, high, medium, low) and conduct recurring reviews of critical service providers. Manage vendor risk assessments for tools under evaluation - SASE, CASB, DLP, AI governance tooling, and security platform consolidation. Coordinate with the Data Privacy legal team on vendors with material data processing obligations. Lead operationalization of the GRC platform (OneTrust) for centralized vendor inventory, risk scoring, and lifecycle management. Client Questionnaires & Audit Support Manage and respond to inbound security questionnaires from portfolio company clients (SIG, CAIQ, and custom formats). Build and maintain a response library to improve turnaround time and accuracy. Coordinate with the Cybersecurity Operations Engineer to validate technical control responses and keep answers current as the security stack evolves. Own ITGC audit controls across identity, endpoint, cloud, and SaaS platforms. Support internal audit responses and evidence requests beyond the annual SOC 2 cycle. BCP/DR & Security Awareness Own BCP/DR formalization: develop a business continuity charter, coordinate Business Impact Analysis across the corporate entity and portfolio companies, define RTO/RPO for critical operations, and ensure crisis management is embedded in the IR framework. Manage the KnowBe4 security awareness training program: campaign management, phishing simulations, completion tracking, and leadership reporting. Manage the security testing program as the organization transitions from annual to continuous autonomous pentesting. Own vendor relationships, track findings to remediation, and produce executive-ready reporting. Qualifications Required 5-7 years in GRC, security compliance, risk management, or a closely related security function. Hands-on experience owning or supporting a SOC 2 Type II audit: evidence collection, control mapping, and auditor coordination. Solid working knowledge of NIST CSF: gap assessments, control mapping, and remediation tracking. Demonstrated experience building or formalizing a security policy library, not just updating existing documents. Experience managing third-party and vendor risk assessments using a tiered risk model. Experience responding to client security questionnaires: SIG, CAIQ, or similar formats. Clear understanding of the boundary between GRC and legal/privacy functions. Proven ability to work alongside a legal team without blurring lanes. Strong written communication: you can translate technical controls into clear, accurate language for clients, auditors, and executives. Disciplined project management: you own timelines, follow up without being asked, and don’t let things fall through. Active daily use of AI and automation. We operate at 100% internal AI adoption. Non-negotiable. Preferred Technical Experience GRC platforms: OneTrust, Drata, Vanta, Whistic, or similar. Security awareness platforms: KnowBe4 or equivalent. ITGC working knowledge across identity (Okta), SaaS (Google Workspace), cloud (AWS, GCP, Azure), and endpoint (CrowdStrike). BCP/DR frameworks: BIA methodology, RTO/RPO definition, and tabletop exercise facilitation. AI governance frameworks: NIST AI RMF or EU AI Act. Familiarity with CASB, DLP, or cloud security posture tooling from a compliance and documentation standpoint. Private equity, holding company, or multi-entity compliance environment experience strongly preferred. Commitment to Diversity and Inclusion at Momentum At Momentum, our commitment to change for the better is reflected in our dedication to fostering a culture of belonging, inclusion, and diversity. We recognize diversity and inclusion as key components of our company’s success and growth. Recognizing the ongoing journey ahead, we are determined to make lasting impacts through the collective efforts of our Leadership team, People & Culture team, and every employee. Momentum is an equal opportunity employer, considering all qualified applicants regardless of characteristics protected by law. These include, but are not limited to, race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, genetic information, color, ancestry, and Veteran status. We actively seek qualified applicants from diverse backgrounds, with no consideration of criminal histories, in alignment with applicable legal requirements. Should a reasonable accommodation be necessary for the application process and beyond, we are eager to review and provide reasonable accommodations as needed, in compliance with applicable laws. Total Rewards At Momentum, we prioritize the well-being of the whole individual. We are committed to supporting our people in every moment that matters on their journey with us! We are pleased to offer a comprehensive total rewards package designed to provide protection, peace of mind, and a focus on overall well-being while helping our people plan for the future. The base salary range for this position may vary based on location. Actual compensation will be determined by role, level, and location, considering additional factors such as job-related skills, experience, and relevant education or training. For roles eligible for remote work, the base salary is tailored to the designated work location. In addition to the base salary, candidates may be eligible to receive a discretionary annual bonus, determined based on both the company’s business performance and individual contributions. The People & Culture team will provide specific details during the hiring process. We take pride in offering a comprehensive benefits package for our full-time employees, encompassing healthcare benefits, a 401(k) plan with an employer match, short-term and long-term disability coverage, life insurance, paid time off, parental leave, and various paid holidays, among other perks. Our workplace offers opportunities for involvement in a wide range of challenging and impactful projects, across diverse industries and business models, fostering career advancement and development within our growing organization. The culture is highly collaborative and supportive, contributing to a fulfilling professional journey. Note on Confidentiality Any personal data collected during the application process will be treated with the utmost confidentiality and privacy. #J-18808-Ljbffr
$46.99k - $122.4k
The Hispanic Alliance for Career Enhancement is seeking a dedicated professional to handle investigations into healthcare fraud, waste, and abuse, focusing on complex cases and cooperation with law enforcement. This full-time position requires a bachelor's degree, with...SuggestedFull time- ...documentation and required research Conduct routine interviews with suspects and witnesses Completes a SAR when applicable The Sr. Fraud Analyst is directly responsible for the evaluation and decision to file suspicious activity reports on cases assigned to them Identify and...SuggestedLocal areaImmediate startFlexible hoursDay shift
- Centene Corporation is seeking an investigator to tackle healthcare fraud and abuse, essential for transforming health in communities. This remote role requires a bachelor's degree and at least one year of experience in medical claim investigations. You'll conduct thorough...SuggestedRemote workFlexible hours
$65 - $90 per hour
Crossing Hurdles is offering a remote position as a Permit Expeditor, focused on reviewing and labeling construction documents to ensure compliance with building codes. Ideal candidates should have strong familiarity with permitting workflows, experience coordinating with...SuggestedHourly payRemote work- A growing organization is seeking an experienced compliance professional to support regulatory documentation, adviser disclosures, and compliance program administration. This role will work closely with clients and internal stakeholders to help maintain compliant business...Suggested
- The City of Richardson Texas is seeking a Utility Compliance Manager for Public Services – Water Production to ensure adherence to federal, state, and local regulations. You will serve as liaison with TCEQ, EPA, TWDB, and other agencies, manage reporting lifecycles, inspections...Local area
- USCOR JAS Forwarding (USA), Inc. is seeking an experienced customs entry specialist to manage clearance processes and ensure data accuracy. You will interact with importers, prepare post-entry documentation, and collaborate with CBP and other agencies to resolve issues...
$80k - $100k
...ago Houston, TX $80,704.00-$120,000.00 6 days ago Texas, United States $18.00-$20.00 18 hours ago Remote Retirement Plan Compliance Analyst Remote Retirement Plan Compliance Analyst Fort Worth, TX $70,000.00-$100,000.00 1 week ago We’re unlocking community knowledge in a...Full timeRemote work- Salesforce.com, inc. is seeking a Force.com Developer to design, build, test, and deploy scalable internal solutions on the Salesforce platform. You will write Apex, Lightning, and Visualforce, integrate APIs, and enforce quality practices across the SDLC while collaborating...
- Neumo Group is seeking a Compliance Specialist to support the company’s compliance program remotely. Responsibilities include onboarding submerchants, due diligence, transaction monitoring, and vendor oversight. The role collaborates on regulatory requests, audits, ...Work at officeRemote work
- Compliance – Digital Asset Intelligence Operations Senior Investigator – Associate Bring your Expertise to JPMorgan Chase. As part of Risk Management and Compliance, you are at the center of keeping JPMorgan Chase strong and resilient. You help the firm grow its business...
- Who We Are At Academy Sports + Outdoors our vision is to be the best sports + outdoors retailer in the country — but what truly sets us apart is our people. We’re a passionate, purpose-driven team that’s as committed to each other as we are to our customers. We’ve spent...Work experience placementLocal area
- At HedgeServ, we're redefining what's possible in fund administration. With more than $700 billion in assets under administration, we partner with the world's most forward-thinking investment managers - across private equity, private credit, endowments, hedge funds and...InternshipWork at officeLocal areaRemote work
- ## Compliance Specialist IApplylocations: Godley, Texastime type: Full timeposted on: Posted Todayjob requisition id: R1235SUMMARYOwen Oil Tools is seeking a detail-oriented Compliance Specialist to manage, maintain, and audit regulatory compliance records and processes...Work at office
- ...IBC Bank is seeking a Prefunding Analyst to perform pre-funding and post-closing audits for loans, ensuring accuracy with bank policy. The role supports compliance with state and federal regulations and involves updating loan records in the system and assisting with exception...Work at office
- For nearly 20 years, TheKey has helped clients achieve successful long-term aging at home with comprehensive, concierge-based care. Ensuring the dignity, safety, and independence of its clients, TheKey is committed to changing how the world lives and ages at home. Employee...
- About the Role FloatMe runs a compliance management system spanning testing and monitoring, regulatory reporting, state licensing, complaint handling, and disciplined recordkeeping. As we grow across states and products, we are expanding the compliance team with Compliance...
- The City of Conroe is seeking a Code Enforcement Officer to ensure compliance with City and State codes. Under limited supervision, you will investigate complaints, identify violations, and draft citations. Strong independent thinking and knowledge of local laws are essential...Local area
- ...be expected to be curious, thorough, and proactive. This is an analyst-level position with meaningful ownership. Your work will matter:... ...partnership model Familiarity with compliance management systems or GRC tools CAMS certification or progress toward it College degree in...Work at office
- SpaceX was founded under the belief that a future where humanity is out exploring the stars is fundamentally more exciting than one where we are not. Today SpaceX is actively developing the technologies to make this possible, with the ultimate goal of enabling human life...Permanent employmentTemporary workFor contractorsLocal areaRelocationWeekend work
- A leading insurance firm is seeking an experienced Pricing Actuary to join their Pricing & Analytics team. This role supports CFC's US operations through effective pricing strategies. The ideal candidate will have deep expertise in pricing for admitted and E&S insurance...Remote work
$112.2k - $202.6k
Health Care Service Corporation is looking for a Sr Managing Actuary to manage and analyze actuarial models. This hybrid role requires in-office attendance for three days a week and offers a dynamic environment where actuarial principles are applied for pricing and underwriting...Work at office3 days per week$113k - $125k
...your skills and experience — talk with your recruiter to learn more. Base pay range $113,000.00/yr - $125,000.00/yr Senior Actuarial Analyst Senior Actuarial Analyst Come work for a stable organization with a solid plan for growth. Texas based client is seeking a talented...Full timeRemote work$110k - $135k
What You’ll Do As an Associate Actuary at Imagine Pediatrics, you will leverage your actuarial expertise to conduct and present analytics on several fronts. Key projects will include forecasting, budgeting, and analyzing the financial and clinical value proposition that...Temporary work$143.62k - $229.79k
Job Description As a Consulting Actuary - ACA Risk Adjustment, you will play a pivotal role in delivering a wide array of actuarial and analytical services for our organization. Responsibilities include leading pricing strategies and actuarial initiatives for business ...- ...Overall GPA 3.0 or higher; Math or Actuarial GPA 3.5 or higher Passing grade on at least three actuarial exams Prior experience as an analyst supporting pension plan valuations and/or actuarial consulting teams Demonstrated expertise with Microsoft, particularly Excel...
$119.1k - $172.6k
...further protect the payment ecosystem. Assist the Sr. Director of the Risk Operations Center (ROC) in establishing the roles of the analyst and what they should and should not be assisting with. Create training documentation for the Risk Operations Center. Communicate...Work experience placementInternshipWork at officeLocal areaRemote workWeekend work2 days per week3 days per week$10k
...collaborating with operational partners to drive value and improve outcomes for residents and stakeholders. The Asset Management Senior Analyst is responsible for providing support for a variety of asset management functions, including, but not limited to, assistance with...Local areaNight shift- Position Overview The Rebate Analyst is responsible for the accurate, timely, and complete collection of supplier rebate revenue by managing weekly and monthly rebate claims. This role supports the administration and analysis of supplier rebate programs through calculating...Weekly pay
- ...you can be proud of. 1st Shift, Monday-Friday, 7am-3pm As times change, processes need to change as well. As the Operations Support Analyst, you will track trends, consolidate data and update senior leadership on recommended improvements. Your advice and counsel will...Work at officeLocal areaMonday to FridayDay shift
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to GRC Analyst. Be the first to apply!

