Senior GRC Analyst
CRG
Sr. GRC Analyst, Risk Management
Under the direction of and in collaboration with the GRC Manager, the Sr. GRC Analyst, Risk Management is the primary owner and operational steward of the Enterprise Risk Register. This role is responsible for ensuring all identified risk is accurately captured, properly rated, assigned to an accountable owner, actively worked, and driven to resolution across the Clayco organization. The analyst functions as the operational hub of the risk lifecycle from initial intake and classification through remediation coordination, escalation, stakeholder accountability, and reporting. This is a high-accountability, process-driven role that demands both technical depth and organizational influence. The analyst transforms the risk register from a static document into a dynamic governance instrument one that delivers a clear, current, and quantified view of organizational risk exposure to leadership. Additional responsibilities will be assigned as deemed necessary. Any travel is usually planned in advance, but issues may arise which warrant immediate travel to one or more satellite locations.
The Specifics of the Role:
- Assumes the ownership and maintenance of the Enterprise Risk Register as the authoritative system of record for all identified risks across the Clayco organization.
- Enforces rigorous data integrity standards: no missing owners, undefined due dates, stale entries, or incomplete risk descriptions.
- Establishes and maintains a consistent process for risk creation, categorization, severity rating, and treatment classification to ensure comparability and defensibility of the data set.
- Applies qualitative risk analysis methodologies, including likelihood/impact matrices to produce accurate, prioritized risk ratings.
- Conducts regular audits of the risk register to surface stale, incomplete, or improperly rated entries and drive timely corrections with risk owners.
- Maintains comprehensive documentation for each risk, including: risk description, affected assets and systems, threat source, inherent risk rating, current controls, residual risk, treatment decision, assigned owner, and target remediation date.
- Manages the full risk lifecycle from intake through closure, including periodic re-evaluation of accepted risks to confirm continued acceptability.
- Serve as the primary coordinator and driver of risk remediation and mitigation activities, ensuring every open risk has an actionable, time-bound treatment plan with a clearly accountable owner.
- Collaborates with risk owners and technical teams to develop realistic remediation plans that define specific tasks, milestones, resource requirements, and completion criteria.
- Coordinates corrective and preventive actions (CAPA) arising from audit findings, control failures, and policy exceptions, tracking each to verified closure.
- Tracks and monitors remediation progress across all open items; proactively identify blockers, resource gaps, and at-risk milestones before they result in missed deadlines.
- Escalates risks with insufficient remediation progress, missed SLAs, or unacceptable residual risk levels to the GRC Manager and relevant leadership with supporting data and recommended courses of action.
- Assumes operational ownership of Vulnerability Management and External Attack Surface Management (EASM) processes:
- In collaboration with SOC, ensures that Vulnerability Scanning output ingested into Workflow platform has high fidelity with accurate association with CI's
- In collaboration with SOC, ensures that EASM output ingested into Workflow Platform has high fidelity with accurate association with CI's
- Ensures effective tuning and appropriate scoring of Risk Rating algorithm
- Ensures effective execution of assignment Rules and track remediation activity
- Remediates Unknown/Unclassed CI's from scanning output and tune assignment Rules
- Ensures timely and accurate reporting of active Risk and Vulnerability by severity as well as performance against Remediation targets process.
- Collaborates cross-functionally with other Information Technology teams and Business Stakeholders across the Organization
- Engages as necessary in all GRC functions to maintain an understanding of process and procedures
- Provides leadership with comprehensive reports of compliance-focused activities and outcomes, as requested.
Requirements:
- 5-7+ years' experience in Risk & Compliance Assessment, Audit & Reporting, or similar functions, preferably within the Information Security or Technology fields
- 3-4+ years working specifically in Information Security roles involving Risk Analysis, Information System Security Assessment, Compliance Audit with Regulations, Frameworks, & Standards
- Bachelor's degree in Information Technology or related field, or equivalent experience
- Required Certifications: Certified in Risk & Information Systems Control (CRISC), Certified Information Systems Auditor (CISA), or Certified Information Systems Security Professional (CISSP) (Current status, or obtained within 9 months of assuming role)
- Strong experience leveraging auditing principles and methods to evaluate policies, processes, systems, and vendors to identify business risks and control gaps
- Experience in administering Risk management programs for technology and information security
- Strong, technical knowledge of modern Systems, Services, Cloud Applications/Platforms, Identity Services, and Data Storage/Handling and their areas of Risk and Threat exposure
- Experience with administering, maintaining, and leveraging a Risk Register to track and communicate identified Risk and its required remediation
- Knowledge of statistics, reporting and analytical tools to analyze and solve complex problems
- Proficiency in necessary productivity tools (i.e. Microsoft Excel, PowerPoint, Word etc.) for analytics and presentations
- Operate with strong integrity with ability to handle projects of a sensitive & confidential nature
- Excellent written and verbal communication skills with a proven ability to translate technical or abstract concepts into a narrative that is easily understood by clients.
- Ability to thrive in fast-paced environment.
Some Things You Should Know:
- No other builder can offer the collaborative design-build approach that Clayco does.
- We work on creative, complex, award-winning, high-profile jobs.
- The pace is fast!
- This position is classified as a safety-sensitive role in accordance with applicable state and federal laws. Candidates selected for this position will be subject to a comprehensive background check, which includes mandatory drug testing.
Why Clayco?
- 2025 Best Places to Work St. Louis Business Journal, Los Angeles Business Journal, and Phoenix Business Journal.
- 2025 ENR Top 400 Top Data Center Contractor (Top 3).
- 2025 ENR Top 100 Design-Build Firms Design-Build Contractor (Top 5).
- 2025 ENR Top 100 Green Contractors Green Contractor (Top 3).
Benefits:
- Discretionary Annual Bonus: Subject to company and individual performance.
- Comprehensive Benefits Package Including: Medical, dental and vision plans, 401k, generous PTO and paid company holidays, employee assistance program, flexible spending accounts, life insurance, disability coverage, learning & development programs and more!
Compensation:
- The salary range for this position considers a wide range of factors in making compensation decisions including but not limited to: Education, qualifications, skills, training, experience, certifications, internal equity, and location. Compensation decisions are dependent on the facts and circumstances of each case.
- Sky Mavis seeks a Sr. GRC Analyst in Phoenix, AZ, to manage Third-Party and Human Risk Management. This analytical role involves vendor risk assessment, security awareness training, and compliance evaluation, ensuring holistic risk management. Candidates should have significant...Senior
- ...entertainment related building projects. The Role We Want You For Under the direction of and in collaboration with the GRC Manager, the Sr. GRC Analyst, Third‑Party & Human Risk Management (TPHRM) is a risk focused, highly analytical role that ensures all Human and...SeniorImmediate startFlexible hours
- Join Dorsey's Information Security team as a Senior GRC Information Security Systems Analyst to help safeguard our firm and clients by driving high-impact security initiatives across audits, risk, governance, and compliance. Reporting directly to the Information Security...SeniorContract workTemporary workCurrently hiringWork at officeWorldwideFlexible hours
- BWH Hotels is seeking an information security compliance professional to support governance, risk, and compliance across the organization. You will coordinate evidence with stakeholders and auditors, maintain control documentation, and help ensure audit readiness for PCI...Suggested
- ...organizational privacy obligations. Familiarity with a broad range of IT and information security products and technologies such as GRC platforms, central logging systems, file integrity monitoring, vulnerability management, endpoint security, and cloud security tools....SuggestedFull timeWork at officeLocal areaRemote workMonday to Friday
$55 - $60 per hour
...Type: 1099, C2CIndustry: Computer SoftwareClient: WiproContact: Meghana GorusuCompany: SRI Tech SolutionsTitle: SaaS Engineer ( GRC Analyst with IAM )Location: Phoenix AZ onsite onlyDuration: ContractKey ResponsibilitiesPerform security assessments of SaaS and third‑party...Hourly pay- Western Alliance Bank is seeking a Compliance Consultant on a contract-to-hire basis. You will review information to ensure compliance with internal policies and regulations, support the Compliance Management System, and advise on policies, risk assessments, and controls...SeniorContract work
$77k - $143k
...Senior Analyst, Client Risk Prevention What is the opportunity? As a Senior Analyst, Client Risk Prevention in the Business Risk Oversight team, you will be responsible for the intake and case management of incidents of fraud, financial exploitation, and vulnerable...SeniorFull timeWork at officeFlexible hours- ...U.S. Bank in Arizona seeks a Senior Credit Analyst to assess credit risk, conduct thorough analyses of financial data, and support lending decisions for new, renewal, and extension credits. You will review portfolios, identify potential issues, prepare detailed reports...Senior
- City of Phoenix is seeking a Cybersecurity Risk and Compliance Analyst (Sr. BSA) to join the Information Security Office in a hybrid role. You will bridge security with business goals, manage risk assessments, audit prep, remediation tracking, and policy implementation...SeniorWork at office
- Terros Health is seeking a Senior Risk Analyst to safeguard the organization by identifying, evaluating, and mitigating risks across clinical, operational, financial, and technical domains. The role supports strategic decision-making and drives enterprise risk management...Senior
$127.31k - $243.34k
...duty military spouses consistent with applicable policy and business needs. The Opportunity As a dedicated Bank Credit Risk Analyst Senior, you will have a strong background in credit risk strategy development for card, consumer and deposits credit portfolios to...SeniorFull timeH1bWork at officeRemote workHome office- RBC US Wealth Management is seeking a Risk Advice Senior Manager, Business Risk Oversight to guide product managers and business owners on credit, lending and cash management risks. The role emphasizes applying professional judgment, cross-functional collaboration, and...Senior
- American Express seeks a driven risk professional to identify and assess operational risks across business processes and systems, partnering with process owners to evaluate risk scenarios and support risk assessments, testing, and quality assurance programs. You will maintain...Senior
- RBC Wealth Management in the United States seeks a Senior Analyst, Client Risk Prevention, within the Business Risk Oversight team to oversee intake and case management of fraud, financial exploitation, and vulnerable client support. You will partner with legal, compliance...Senior
- SWCA Environmental Consultants' Legal team is seeking a Senior Contracts Analyst to review client terms, draft agreements, and ensure compliance with internal policies and regulatory requirements in a fast-paced environment. This permanent, full-time role offers a hybrid...SeniorPermanent employmentFull timeContract work
- • Identify risks throughout business processes and systems with business process owners • Assess operational risk implications for new and existing products, features, and services within new product approval and change management governance frameworks • Facilitate US Consumer...Senior
- ...Senior Director, IT Compliance & Governance (Contractor) About the Company Innovative company designing & developing gene therapeutic products Industry Biotechnology Type Public Company Founded 2013 Employees 51-200 Categories Biotechnology...SeniorFor contractors
- Western Alliance Bank, a Western Alliance Bancorporation subsidiary, seeks a Compliance Manager to oversee compliance risk management for residential mortgage lending. You will guide the 2LOD function, advise the business on federal and state mortgage rules, and support...Senior
- Responsibilities Lead high-priority, long-term strategic initiatives supporting claims modernization, platform transformation, policy changes, customer experience improvements, and other complex business priorities Develop initiative objectives, success measures, business...SeniorWork experience placementVisa sponsorship3 days per week
- City National Bank is seeking a senior KYC Review Analyst in Operations to conduct Enhanced Due Diligence for commercial loan borrowers and periodic client reviews. You will assess compliance risks, verify KYC completion, and escalate activities per policy while leveraging...Senior
$92.45k - $114.2k
Job Title:Senior Compliance OfficerLocation:CA - Westlake VillageWhat you'll do:As a Senior Compliance Officer in the Second Line of Defense, you'll review and analyze information, reports or data to determine if the applicable process is in compliance with internal policy...SeniorFull time- ...We are seeking a highly organized and collaborative Regulatory Affairs Generalist / Senior Associate to support a strategic pharmaceutical partnership and its associated development and commercial programs. This role is dedicated to providing end-to-end regulatory affairs...SeniorLocal areaRemote work
- NBT Bank seeks a Compliance Specialist III to prepare complex compliance and government filings in line with company standards. The role includes mentoring peers and reviewing filings for accuracy. Education includes an Associate's degree with 5+ years of related experience...Senior
- Turo Inc. is seeking a Claims Specialist to handle high-complexity claims, requiring analysis of policies and customer communication. This role involves investigating claims, negotiating resolutions, and providing recommendations on processes. The ideal candidate will demonstrate...Senior
- Chubb seeks a Sr. Auto Examiner (Commercial) to manage complex Auto Claims, including property damage and related coverages. The role demands excellent time management, precise analysis, and clear communication with insureds and claimants. The position requires 2-4 years...SeniorRemote work
- Job Title:Senior Financial Risk AnalystLocation:CityScapeWhat you'll do:The Financial Risk Management Group (FRM) oversees risk-taking... ..., and overall process improvement. As a Financial Risk Senior Analyst, you will support the oversight of the company’s investment portfolio...SeniorFull time
- Gore Medical is seeking a Senior Principal Engineer - Technical Program Leader to steer the technical direction and delivery of a new product development (NPD) program for a complex medical device. This role combines hands-on engineering leadership with end-to-end technical...Senior
- Humana is seeking a Senior Professional for Risk and Compliance in Phoenix, AZ to oversee risks associated with Medicaid programs and ensure adherence to MHPAEA regulations. Responsibilities include risk management strategy development, conducting assessments, and collaborating...SeniorRemote job
- ...Senior Director, Principal Gifts About the Company Philanthropic organization supporting Indigenous culture & individuals Industry Non-Profit Organization Management Type Non Profit Founded 2017 Employees 11-50 Categories ~ Non-Profit &...Senior
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior GRC Analyst. Be the first to apply!
- senior operations technician Phoenix, AZ
- senior cloud service delivery manager Phoenix, AZ
- senior it service manager Phoenix, AZ
- senior project engineer Phoenix, AZ
- senior chief engineer Phoenix, AZ
- sr operations manager Phoenix, AZ
- senior physical design engineer Phoenix, AZ
- senior account director Phoenix, AZ
- senior director clinical development Phoenix, AZ
- senior customer service representative Phoenix, AZ

