Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Sr. GRC Analyst

$95k - $105k

Subsplash

Sr. GRC Analyst

Remote

About Subsplash

Subsplash is an exciting award-winning team of 280+ mission-driven people who are committed to our core values of humility, innovation, and excellence. Founded in 2005, we've remained family owned and operated while pioneering the market with the first ever church mobile app. Since then, we've been working together to build The Ultimate Engagement Platform™ for churches, Christian ministries, non-profits, and businesses around the world. We find excitement in serving our 14,000+ clients, creating impactful products, and delighting the millions of people who use our platform every day. Subsplash has won awards for best mobile experience, been voted top 100 Washington's Best Workplaces by the Puget Sound Business Journal, created some of the most downloaded apps of all time, and built enterprise software for world-class brands like XBOX, Microsoft, Samsung, Expedia, and Cisco; yet, at the end of the day, we love making a lasting impact and a difference in our world.

Working at Subsplash is more than just a job; we are a team of people who are courageous, inventive, and passionate about doing meaningful work every day. Don't take our word for it—head to Glassdoor and see for yourself!

About the Team

The IT Team at Subsplash is the foundation that maintains all the activities and services that are required to support business functions as well as ensuring proper security across all IT systems. We are passionately focused on delivering delightful support to our internal customers. We achieve this by providing robust day-to-day technical support that empowers our fellow Subsplash employees to perform their best work most often. Beyond daily technical support, our team handles crucial functions such as access management, user provisioning and deprovisioning, new hardware and software setup, and diligently works to keep our dues and subscription spend under budget.

About the Role

The Senior GRC Analyst acts as a strategic lead to advance security and risk operations. In this role, you will integrate people, policy, and technology to drive operational excellence and framework maturity. You will be responsible for identifying security gaps, implementing best practices, and maturing our control environment to ensure we stay ahead of evolving regulatory and threat landscapes. We are building an AI-first compliance function, and this role is expected to lead from the front in identifying and deploying AI tools that scale our GRC program.

Compensation

The total compensation for this position is between $95,000-$105,000/yr depending on experience level.

Essential Functions of This Role
Compliance Program Management & Audit Leadership
  • Audit Execution: Act as the primary point of contact for external auditors; lead the end-to-end execution of PCI DSS audits and support internal audit on IT SOX controls.
  • Data Mapping Maintenance: Develop and maintain a comprehensive data inventory and data flow diagrams. Track how sensitive data (PII, PCI) moves through our systems to ensure compliance with privacy regulations and security boundaries.
  • Framework Maturation: Map and implement controls across multiple frameworks (PCI DSS, NIST CSF) to eliminate redundancies and improve the organization's security posture.
  • GRC Reporting: Track and report on GRC program health across compliance posture, risk register status, audit readiness, and control effectiveness. Present metrics and trends to leadership on a regular cadence.
Access Governance & Identity Management
  • User Access Reviews (UAR): Orchestrate and lead the quarterly and semi-annual user access review process across all critical systems (SaaS, Cloud Infrastructure, and Internal Tools).
  • Joiner/Mover/Leaver Oversight: Monitor and validate that provisioning and deprovisioning processes are executed accurately and on time across critical systems. Flag exceptions, track remediation, and maintain documentation to support access control audits.
Security Awareness & Phishing Program
  • Program Ownership: Execute and maintain a comprehensive, year-round Security Awareness Training (SAT) program that meets PCI DSS requirements while driving actual behavioral change.
  • Phishing Simulations: Execute monthly or quarterly phishing simulations; analyze "fail rates" and provide targeted follow-up training to high-risk groups.
  • Content Curation: Select and deploy engaging security content, newsletters, and "security moments" to keep cybersecurity top-of-mind for all employees.
  • Reporting: Present program health metrics (completion rates, simulation trends, and reporting speed) to the Leadership team.
Risk and Vendor Management
  • Vendor & Risk Execution: Execute the TPRM program—conducting vendor security reviews, tracking remediation to completion, and escalating high-risk findings to leadership.
  • Risk Register Ownership: Maintain and update the corporate risk register, ensuring remediation efforts are tracked, validated, and communicated to leadership.
Desired Qualifications
  • Experience: 3–5 years of dedicated experience in GRC, Information Security, or Audit (FinTech or Financial Services industry experience is highly preferred).
  • Technical Mastery: Deep practical knowledge of PCI DSS requirements and controls.
  • Data Governance: Experience performing Data Mapping exercises and maintaining Records of Processing Activities (RoPA).
  • SAT Strategy: Proven experience managing phishing platforms (e.g., KnowBe4, Mimecast, or Vanta-integrated tools) and developing security training curricula.
  • IAM Expertise: Proven experience managing formal access review cycles and identity governance processes.
  • Systems: Proven experience administering a GRC platform, including automated evidence collection, control monitoring, and access review workflows. Direct experience with Vanta is a significant advantage.
  • SOX IT Controls: Experience with SOX IT General Controls (ITGCs), including change management, logical access, computer operations controls, and segregation of duties (SoD). This role will work directly with internal audit to support IT SOX control testing and evidence collection.
  • AI Tooling: Demonstrated experience using AI tools to improve GRC workflows, automate reporting, or accelerate evidence collection and analysis.
Core Competencies
  • Critical Thinker: You have a drive for distinguishing clear priorities and conclusions from ambiguous data.
  • Velocity: You bring urgency and momentum to compliance work—prioritizing ruthlessly, moving quickly through ambiguity, and consistently pushing the program further than the baseline requires.
  • Detail Oriented: You notice the small gaps in access logs, data maps, or training reports that others might miss.
  • AI-Forward: You treat AI as a force multiplier for GRC work—using it to compress audit prep cycles, automate evidence gathering, and free up capacity for higher-value risk analysis.
  • Collaborative: You work effectively across IT and Engineering to surface control gaps, translate technical risks into compliance language, and ensure cross-functional ownership of remediation.
Your First 90 Days
  • Own the PCI DSS evidence pipeline. Get fully oriented on the current ASV scanning cadence, open findings, and SAQ scoping in Vanta. By day 60, be actively supporting evidence collection. By day 90, have a clear understanding of the program state and a plan for taking it over fully.
  • Get oriented on the SOX SoD review cycle. The conflict detection framework and SoD procedure are built. Within 90 days, develop a working understanding of the quarterly review rhythm, the supporting Confluence documentation, and the compensating controls tracking process — with the goal of owning it independently shortly after.
  • Complete a full UAR cycle. Execute a complete user access review across all critical systems, coordinating with IT and system owners, documenting exceptions, and tracking remediation to closure. This is a tangible, auditable deliverable that demonstrates cross-functional coordination and Vanta proficiency.
  • Deliver a first GRC metrics report to leadership. Produce a polished metrics report covering compliance posture, risk register status, PCI standing, and SO
Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the Sr. GRC Analyst in United States vacancy
  •  ...# Sr GRC Analyst - $56 on w2 or 676 on c2c JD: Perform vendor risk assessments against all security domains Perform technical implementation assessments from a security perspective related to vendor integrations (i.e. API integrations, SFTP integrations... 
    Senior

    Sparktek

    San Jose, CA
    3 days ago
  •  ...Sr GRC Analyst Location: Frisco TX Hybrid: 2 days a week on site Duration: 6-12 + months Main Skills Communication, Automotive, ISO/SAE 21434, UN R155 Job Description Conduct compliance audits to ensure adherence to automotive cybersecurity standards and... 
    Senior
    2 days per week

    InterSources

    Frisco, TX
    4 days ago
  • $80k - $100k

     ...First Entertainment Credit Union is looking for a Sr. GRC Analyst who will play a critical role in Continuous Improvement, Management Self‑Identification & Policies. The role supports the Director in executing enterprise‑wide programs that enhance risk ownership, facilitate... 
    Senior
    Full time
    Work at office

    Firstent

    Los Angeles, CA
    2 days ago
  • $100.8k - $168k

    McKesson is an impact-driven, Fortune 10 company that touches virtually every aspect of healthcare. We are known for delivering insights, products, and services that make quality care more accessible and affordable. Here, we focus on the health, happiness, and well-being...
    Senior

    McKesson

    Irving, TX
    3 days ago
  • $116k - $157k

     ...mitigate loss, keep them safe, and restore their lives and businesses after an insured loss occurs. Overview The GRC, Third-Party Risk, Vulnerability Management Analyst performs established governance, risk, compliance, vendor risk, and vulnerability management activities... 
    Senior
    Work at office

    Selective Insurance

    Short Hills, NJ
    2 days ago
  • $130k - $170k

     ...performance and extend healthspan. The Governance, Risk, and Compliance (GRC) team helps ensure technology and cybersecurity risks are...  ...an execution-oriented Senior Governance, Risk, and Compliance Analyst to lead the day-to-day execution and support the ongoing operation... 
    Senior
    Full time
    Work at office
    Relocation

    WHOOP

    Boston, MA
    1 day ago
  • $80.05k - $165k

     ...end-to-end issue management activities, including intake, validation, prioritization, assignment, remediation tracking, and closure of GRC-related issues in ServiceNow, ensuring timely resolution, appropriate evidence, and alignment with audit, risk, and regulatory... 
    Senior
    Full time
    Work at office

    Columbia Bank

    Hillsboro, OR
    3 days ago
  • $138k - $173k

    THE POSITIONOur roster has an opening with your name on itFanDuel is seeking a Senior Technology Governance, Risk & Compliance (GRC) Analyst to join its Technology GRC team as a strategic specialist supporting our first line of defense (1LOD) function. This role offers... 
    Senior
    Temporary work
    Work at office
    Local area
    Worldwide
    Shift work

    FanDuel

    Atlanta, GA
    15 hours ago
  •  ...Senior GRC Analyst Location: Atlanta, GA Need local with availibilty of onsite interview in required Type: 5-Month Contract (Possibility of Extension) GC/USC GRC frameworks (ISO 27001, NIST, GDPR, CMMC), risk assessment, compliance audits,... 
    Senior
    Contract work
    Local area

    3B Staffing LLC

    Atlanta, GA
    2 days ago
  •  ...Insight Global is seeking a Senior Cybersecurity Governance Analyst to support their Cybersecurity Strategy & Governance team. This...  ...Requirements • 5+ years of experience in Cybersecurity Governance, GRC, Cyber Risk, Security Compliance, or a related field • Experience... 
    Senior

    Insight Global

    Davie, FL
    1 day ago
  •  ...the maintenance of our compliance policies, standards, and procedures Report on our compliance posture to senior leadership Scale our GRC function with AI and automation, building quick wins and scoping requirements for Engineering to fully automate the rest Requirements... 
    Senior

    Jobtailor

    New York, NY
    15 hours ago
  •  ...Description An R&D technology client is seeking a Senior Governance, Risk & Compliance Analyst for a contract role supporting the implementation and operationalization of an enterprise GRC platform. This role will focus on helping configure the GRC solution, establish risk... 
    Senior
    Contract work

    Insight Global

    Conshohocken, PA
    2 days ago
  •  ...Senior IT GRC Analyst The Senior IT GRC Analyst leads policy development and audit execution within CMG's IT Governance, Risk, and Compliance program, with particular emphasis on CMG's upcoming SOC 2 readiness effort. This role works closely with the GRC team and the... 
    Senior
    Work at office
    Remote work

    CMG Financial

    United States
    5 days ago
  •  ...workforce, Kokosing is the winning team. Job Description: We are looking for a Security Governance, Risk, and Compliance (GRC) Analyst to support and mature our security and compliance programs across a large construction organization. This role focuses on... 
    Senior
    For contractors

    Kokosing

    Westerville, OH
    4 days ago
  •  ...Sr. GRC Analyst, Risk Management Under the direction of and in collaboration with the GRC Manager, the Sr. GRC Analyst, Risk Management is the primary owner and operational steward of the Enterprise Risk Register. This role is responsible for ensuring all identified... 
    Senior
    For contractors
    Immediate start
    Flexible hours

    Clayco

    Phoenix, AZ
    5 days ago
  • $183k - $205k

     ...Senior GRC Analyst San Francisco, CA - Hybrid At Gusto, we're on a mission to grow the small business economy. We handle the hard stuff — payroll, health insurance, 401(k)s, and HR — so owners can focus on their craft and their customers. With teams in Denver, San... 
    Senior
    Full time
    Work at office
    Local area
    2 days per week
    3 days per week

    Gusto

    San Francisco, CA
    4 days ago
  • Apply For This Job *indicates a required field FanDuel
    Senior

    FanDuel

    Atlanta, GA
    4 days ago
  •  ...Sr. GRC Analyst, Third-Party & Human Risk Management Clayco is a full-service, turnkey real estate development, master planning, architecture, engineering, and construction firm that safely delivers clients across North America the highest quality solutions on time,... 
    Senior
    For contractors
    Immediate start
    Flexible hours

    Clayco

    Atlanta, GA
    5 days ago
  •  ...best company for remote workers Responsibilities Workato is seeking a detail-oriented, driven, and technically experienced Senior GRC Analyst to strengthen and advance its security governance, risk, and compliance (GRC) program - with a primary focus on FedRAMP... 
    Senior
    Remote work
    Flexible hours

    Workato

    Palo Alto, CA
    4 days ago
  • $114k - $163k

     ...Senior GRC Analyst Department: Compliance & Fraud Employment Type: Full Time Location: Pittsburgh Onsite Compensation: $114,000 - $163,000 / year Description Role Summary Wolfe is a Pittsburgh-based FinTech company operating consumer gifting and payments... 
    Senior
    Full time
    Contract work
    Temporary work

    Wolfe

    Pittsburgh, PA
    4 days ago
  •  ...audit activities Develops, maintains, and reports on operational compliance metrics General Governance, Risk, and Compliance (GRC) Support: Leads process analysis, development, & improvement efforts Assists in developing, testing, and delivering solutions,... 
    Senior
    Work experience placement
    Work at office
    Remote work

    Louisiana Blue

    United States
    2 days ago
  •  ...; equivalent relevant experience may be considered.5+ years of progressive experience in cybersecurity governance, risk, compliance (GRC), IT audit, risk management, control assurance, or related disciplines.Experience assessing control design, operating effectiveness,... 
    Senior
    Permanent employment
    For contractors

    Karman Space & Defense

    Huntington Beach, CA
    3 days ago
  •  ...Senior GRC Analyst job at Quantexa. New York, NY. What we’re all about. We find, when we come together in the pursuit of excellence, great things happen. And that’s how we do things at Quantexa – together. Our business is data, but our culture is collective. We’re about... 
    Senior
    Contract work
    Temporary work
    Work experience placement
    Immediate start

    Quantexa

    New York, NY
    2 days ago
  • Crunchyroll is seeking an experienced Risk Analyst to support our Information Security GRC team. This role emphasizes governance, risk, and compliance, ensuring technology evolution aligns with employee needs and strategic goals. Successful candidates will have over 8 years... 
    Senior
    Flexible hours

    Crunchyroll

    Dallas, TX
    2 days ago
  • Ellenco Estágios e Treinamentos is seeking a Senior Information Security GRC Analyst to manage security audits and compliance efforts. The role requires over 10 years of experience in information security and a strong understanding of NIST standards. This position allows... 
    Senior
    Remote job

    Ellenco Estágios e Treinamentos

    New York, NY
    3 days ago
  • Gilder Search Group is looking for a Sr. GRC Analyst focused on Third-Party & Human Risk Management in St. Louis, Missouri. The role ensures all human and third-party risks to Clayco are identified and treated appropriately. Key responsibilities include owning the TPRM... 
    Senior

    Gilder Search Group

    Saint Louis, MO
    3 days ago
  • Texas Health and Human Services Commission (HHSC) seeks a Cybersecurity Analyst III to lead Archer eGRC development and administer security controls across agency systems. Based in Austin, this role involves collaboration with executives and teams to design, implement,... 
    Senior

    Texas Health and Human Services

    Austin, TX
    2 days ago
  • Berry Appleman & Leiden (BAL) is seeking an experienced GRC/Audit professional to help manage security, privacy, and AI governance across the firm. You will lead audits, shape ISMS/PIMS maintenance, and align controls with global standards. You will collaborate with cross... 
    Senior

    Berry Appleman & Leiden

    Richardson, TX
    4 days ago
  • Sky Mavis is seeking a Senior GRC Analyst focused on Third-Party and Human Risk Management in St. Louis, Missouri. This role requires 6-8+ years of experience in Risk Assessment and Information Security, with strong analytical skills. You will lead the Vendor Risk Management... 
    Senior

    Sky Mavis

    Saint Louis, MO
    15 hours ago
  • Gilder Search Group is looking for a Sr. GRC Analyst focusing on Third-Party & Human Risk Management in Atlanta, Georgia. This role involves risk analysis, compliance assessments, vendor management, and developing security awareness training. The ideal candidate has 6-8... 
    Senior

    Gilder Search Group

    Atlanta, GA
    3 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Sr. GRC Analyst. Be the first to apply!