Sr. GRC Analyst
$95k - $105kSubsplash
Sr. GRC Analyst
Remote
About Subsplash
Subsplash is an exciting award-winning team of 280+ mission-driven people who are committed to our core values of humility, innovation, and excellence. Founded in 2005, we've remained family owned and operated while pioneering the market with the first ever church mobile app. Since then, we've been working together to build The Ultimate Engagement Platform™ for churches, Christian ministries, non-profits, and businesses around the world. We find excitement in serving our 14,000+ clients, creating impactful products, and delighting the millions of people who use our platform every day. Subsplash has won awards for best mobile experience, been voted top 100 Washington's Best Workplaces by the Puget Sound Business Journal, created some of the most downloaded apps of all time, and built enterprise software for world-class brands like XBOX, Microsoft, Samsung, Expedia, and Cisco; yet, at the end of the day, we love making a lasting impact and a difference in our world.
Working at Subsplash is more than just a job; we are a team of people who are courageous, inventive, and passionate about doing meaningful work every day. Don't take our word for it—head to Glassdoor and see for yourself!
About the Team
The IT Team at Subsplash is the foundation that maintains all the activities and services that are required to support business functions as well as ensuring proper security across all IT systems. We are passionately focused on delivering delightful support to our internal customers. We achieve this by providing robust day-to-day technical support that empowers our fellow Subsplash employees to perform their best work most often. Beyond daily technical support, our team handles crucial functions such as access management, user provisioning and deprovisioning, new hardware and software setup, and diligently works to keep our dues and subscription spend under budget.
About the Role
The Senior GRC Analyst acts as a strategic lead to advance security and risk operations. In this role, you will integrate people, policy, and technology to drive operational excellence and framework maturity. You will be responsible for identifying security gaps, implementing best practices, and maturing our control environment to ensure we stay ahead of evolving regulatory and threat landscapes. We are building an AI-first compliance function, and this role is expected to lead from the front in identifying and deploying AI tools that scale our GRC program.
Compensation
The total compensation for this position is between $95,000-$105,000/yr depending on experience level.
Essential Functions of This Role
Compliance Program Management & Audit Leadership
- Audit Execution: Act as the primary point of contact for external auditors; lead the end-to-end execution of PCI DSS audits and support internal audit on IT SOX controls.
- Data Mapping Maintenance: Develop and maintain a comprehensive data inventory and data flow diagrams. Track how sensitive data (PII, PCI) moves through our systems to ensure compliance with privacy regulations and security boundaries.
- Framework Maturation: Map and implement controls across multiple frameworks (PCI DSS, NIST CSF) to eliminate redundancies and improve the organization's security posture.
- GRC Reporting: Track and report on GRC program health across compliance posture, risk register status, audit readiness, and control effectiveness. Present metrics and trends to leadership on a regular cadence.
Access Governance & Identity Management
- User Access Reviews (UAR): Orchestrate and lead the quarterly and semi-annual user access review process across all critical systems (SaaS, Cloud Infrastructure, and Internal Tools).
- Joiner/Mover/Leaver Oversight: Monitor and validate that provisioning and deprovisioning processes are executed accurately and on time across critical systems. Flag exceptions, track remediation, and maintain documentation to support access control audits.
Security Awareness & Phishing Program
- Program Ownership: Execute and maintain a comprehensive, year-round Security Awareness Training (SAT) program that meets PCI DSS requirements while driving actual behavioral change.
- Phishing Simulations: Execute monthly or quarterly phishing simulations; analyze "fail rates" and provide targeted follow-up training to high-risk groups.
- Content Curation: Select and deploy engaging security content, newsletters, and "security moments" to keep cybersecurity top-of-mind for all employees.
- Reporting: Present program health metrics (completion rates, simulation trends, and reporting speed) to the Leadership team.
Risk and Vendor Management
- Vendor & Risk Execution: Execute the TPRM program—conducting vendor security reviews, tracking remediation to completion, and escalating high-risk findings to leadership.
- Risk Register Ownership: Maintain and update the corporate risk register, ensuring remediation efforts are tracked, validated, and communicated to leadership.
Desired Qualifications
- Experience: 3–5 years of dedicated experience in GRC, Information Security, or Audit (FinTech or Financial Services industry experience is highly preferred).
- Technical Mastery: Deep practical knowledge of PCI DSS requirements and controls.
- Data Governance: Experience performing Data Mapping exercises and maintaining Records of Processing Activities (RoPA).
- SAT Strategy: Proven experience managing phishing platforms (e.g., KnowBe4, Mimecast, or Vanta-integrated tools) and developing security training curricula.
- IAM Expertise: Proven experience managing formal access review cycles and identity governance processes.
- Systems: Proven experience administering a GRC platform, including automated evidence collection, control monitoring, and access review workflows. Direct experience with Vanta is a significant advantage.
- SOX IT Controls: Experience with SOX IT General Controls (ITGCs), including change management, logical access, computer operations controls, and segregation of duties (SoD). This role will work directly with internal audit to support IT SOX control testing and evidence collection.
- AI Tooling: Demonstrated experience using AI tools to improve GRC workflows, automate reporting, or accelerate evidence collection and analysis.
Core Competencies
- Critical Thinker: You have a drive for distinguishing clear priorities and conclusions from ambiguous data.
- Velocity: You bring urgency and momentum to compliance work—prioritizing ruthlessly, moving quickly through ambiguity, and consistently pushing the program further than the baseline requires.
- Detail Oriented: You notice the small gaps in access logs, data maps, or training reports that others might miss.
- AI-Forward: You treat AI as a force multiplier for GRC work—using it to compress audit prep cycles, automate evidence gathering, and free up capacity for higher-value risk analysis.
- Collaborative: You work effectively across IT and Engineering to surface control gaps, translate technical risks into compliance language, and ensure cross-functional ownership of remediation.
Your First 90 Days
- Own the PCI DSS evidence pipeline. Get fully oriented on the current ASV scanning cadence, open findings, and SAQ scoping in Vanta. By day 60, be actively supporting evidence collection. By day 90, have a clear understanding of the program state and a plan for taking it over fully.
- Get oriented on the SOX SoD review cycle. The conflict detection framework and SoD procedure are built. Within 90 days, develop a working understanding of the quarterly review rhythm, the supporting Confluence documentation, and the compensating controls tracking process — with the goal of owning it independently shortly after.
- Complete a full UAR cycle. Execute a complete user access review across all critical systems, coordinating with IT and system owners, documenting exceptions, and tracking remediation to closure. This is a tangible, auditable deliverable that demonstrates cross-functional coordination and Vanta proficiency.
- Deliver a first GRC metrics report to leadership. Produce a polished metrics report covering compliance posture, risk register status, PCI standing, and SO
- ...# Sr GRC Analyst - $56 on w2 or 676 on c2c JD: Perform vendor risk assessments against all security domains Perform technical implementation assessments from a security perspective related to vendor integrations (i.e. API integrations, SFTP integrations...Senior
- ...Sr GRC Analyst Location: Frisco TX Hybrid: 2 days a week on site Duration: 6-12 + months Main Skills Communication, Automotive, ISO/SAE 21434, UN R155 Job Description Conduct compliance audits to ensure adherence to automotive cybersecurity standards and...Senior2 days per week
$80k - $100k
...First Entertainment Credit Union is looking for a Sr. GRC Analyst who will play a critical role in Continuous Improvement, Management Self‑Identification & Policies. The role supports the Director in executing enterprise‑wide programs that enhance risk ownership, facilitate...SeniorFull timeWork at office$100.8k - $168k
McKesson is an impact-driven, Fortune 10 company that touches virtually every aspect of healthcare. We are known for delivering insights, products, and services that make quality care more accessible and affordable. Here, we focus on the health, happiness, and well-being...Senior$116k - $157k
...mitigate loss, keep them safe, and restore their lives and businesses after an insured loss occurs. Overview The GRC, Third-Party Risk, Vulnerability Management Analyst performs established governance, risk, compliance, vendor risk, and vulnerability management activities...SeniorWork at office$130k - $170k
...performance and extend healthspan. The Governance, Risk, and Compliance (GRC) team helps ensure technology and cybersecurity risks are... ...an execution-oriented Senior Governance, Risk, and Compliance Analyst to lead the day-to-day execution and support the ongoing operation...SeniorFull timeWork at officeRelocation$80.05k - $165k
...end-to-end issue management activities, including intake, validation, prioritization, assignment, remediation tracking, and closure of GRC-related issues in ServiceNow, ensuring timely resolution, appropriate evidence, and alignment with audit, risk, and regulatory...SeniorFull timeWork at office$138k - $173k
THE POSITIONOur roster has an opening with your name on itFanDuel is seeking a Senior Technology Governance, Risk & Compliance (GRC) Analyst to join its Technology GRC team as a strategic specialist supporting our first line of defense (1LOD) function. This role offers...SeniorTemporary workWork at officeLocal areaWorldwideShift work- ...Senior GRC Analyst Location: Atlanta, GA Need local with availibilty of onsite interview in required Type: 5-Month Contract (Possibility of Extension) GC/USC GRC frameworks (ISO 27001, NIST, GDPR, CMMC), risk assessment, compliance audits,...SeniorContract workLocal area
- ...Insight Global is seeking a Senior Cybersecurity Governance Analyst to support their Cybersecurity Strategy & Governance team. This... ...Requirements • 5+ years of experience in Cybersecurity Governance, GRC, Cyber Risk, Security Compliance, or a related field • Experience...Senior
- ...the maintenance of our compliance policies, standards, and procedures Report on our compliance posture to senior leadership Scale our GRC function with AI and automation, building quick wins and scoping requirements for Engineering to fully automate the rest Requirements...Senior
- ...Description An R&D technology client is seeking a Senior Governance, Risk & Compliance Analyst for a contract role supporting the implementation and operationalization of an enterprise GRC platform. This role will focus on helping configure the GRC solution, establish risk...SeniorContract work
- ...Senior IT GRC Analyst The Senior IT GRC Analyst leads policy development and audit execution within CMG's IT Governance, Risk, and Compliance program, with particular emphasis on CMG's upcoming SOC 2 readiness effort. This role works closely with the GRC team and the...SeniorWork at officeRemote work
- ...workforce, Kokosing is the winning team. Job Description: We are looking for a Security Governance, Risk, and Compliance (GRC) Analyst to support and mature our security and compliance programs across a large construction organization. This role focuses on...SeniorFor contractors
- ...Sr. GRC Analyst, Risk Management Under the direction of and in collaboration with the GRC Manager, the Sr. GRC Analyst, Risk Management is the primary owner and operational steward of the Enterprise Risk Register. This role is responsible for ensuring all identified...SeniorFor contractorsImmediate startFlexible hours
$183k - $205k
...Senior GRC Analyst San Francisco, CA - Hybrid At Gusto, we're on a mission to grow the small business economy. We handle the hard stuff — payroll, health insurance, 401(k)s, and HR — so owners can focus on their craft and their customers. With teams in Denver, San...SeniorFull timeWork at officeLocal area2 days per week3 days per week- Apply For This Job *indicates a required field FanDuelSenior
- ...Sr. GRC Analyst, Third-Party & Human Risk Management Clayco is a full-service, turnkey real estate development, master planning, architecture, engineering, and construction firm that safely delivers clients across North America the highest quality solutions on time,...SeniorFor contractorsImmediate startFlexible hours
- ...best company for remote workers Responsibilities Workato is seeking a detail-oriented, driven, and technically experienced Senior GRC Analyst to strengthen and advance its security governance, risk, and compliance (GRC) program - with a primary focus on FedRAMP...SeniorRemote workFlexible hours
$114k - $163k
...Senior GRC Analyst Department: Compliance & Fraud Employment Type: Full Time Location: Pittsburgh Onsite Compensation: $114,000 - $163,000 / year Description Role Summary Wolfe is a Pittsburgh-based FinTech company operating consumer gifting and payments...SeniorFull timeContract workTemporary work- ...audit activities Develops, maintains, and reports on operational compliance metrics General Governance, Risk, and Compliance (GRC) Support: Leads process analysis, development, & improvement efforts Assists in developing, testing, and delivering solutions,...SeniorWork experience placementWork at officeRemote work
- ...; equivalent relevant experience may be considered.5+ years of progressive experience in cybersecurity governance, risk, compliance (GRC), IT audit, risk management, control assurance, or related disciplines.Experience assessing control design, operating effectiveness,...SeniorPermanent employmentFor contractors
- ...Senior GRC Analyst job at Quantexa. New York, NY. What we’re all about. We find, when we come together in the pursuit of excellence, great things happen. And that’s how we do things at Quantexa – together. Our business is data, but our culture is collective. We’re about...SeniorContract workTemporary workWork experience placementImmediate start
- Crunchyroll is seeking an experienced Risk Analyst to support our Information Security GRC team. This role emphasizes governance, risk, and compliance, ensuring technology evolution aligns with employee needs and strategic goals. Successful candidates will have over 8 years...SeniorFlexible hours
- Ellenco Estágios e Treinamentos is seeking a Senior Information Security GRC Analyst to manage security audits and compliance efforts. The role requires over 10 years of experience in information security and a strong understanding of NIST standards. This position allows...SeniorRemote job
- Gilder Search Group is looking for a Sr. GRC Analyst focused on Third-Party & Human Risk Management in St. Louis, Missouri. The role ensures all human and third-party risks to Clayco are identified and treated appropriately. Key responsibilities include owning the TPRM...Senior
- Texas Health and Human Services Commission (HHSC) seeks a Cybersecurity Analyst III to lead Archer eGRC development and administer security controls across agency systems. Based in Austin, this role involves collaboration with executives and teams to design, implement,...Senior
- Berry Appleman & Leiden (BAL) is seeking an experienced GRC/Audit professional to help manage security, privacy, and AI governance across the firm. You will lead audits, shape ISMS/PIMS maintenance, and align controls with global standards. You will collaborate with cross...Senior
- Sky Mavis is seeking a Senior GRC Analyst focused on Third-Party and Human Risk Management in St. Louis, Missouri. This role requires 6-8+ years of experience in Risk Assessment and Information Security, with strong analytical skills. You will lead the Vendor Risk Management...Senior
- Gilder Search Group is looking for a Sr. GRC Analyst focusing on Third-Party & Human Risk Management in Atlanta, Georgia. This role involves risk analysis, compliance assessments, vendor management, and developing security awareness training. The ideal candidate has 6-8...Senior
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Sr. GRC Analyst. Be the first to apply!
- grc analyst United States
- senior human resources associate United States
- senior network engineer remote United States
- senior education consultant United States
- senior benefits manager United States
- senior app developer United States
- senior personal assistant United States
- senior manager legal United States
- senior geologist United States
- senior internal tool engineer United States

