Senior GRC Analyst
Sky Mavis
About Us Clayco is a full-service, turnkey real estate development, master planning, architecture, engineering, and construction firm that safely delivers clients across North America the highest quality solutions on time, on budget, and above and beyond expectations. With $8.1 billion in revenue for 2025, Clayco specializes in the "art and science of building," providing fast track, efficient solutions for mission critical, industrial, life sciences, power & energy, aviation, commercial, institutional, residential and sports & entertainment related building projects. The Role We Want You For Under the direction of and in collaboration with the GRC Manager, the Sr. GRC Analyst, Third‑Party & Human Risk Management (TPHRM) is a risk‑focused, highly analytical role that ensures all human and third‑party risk to Clayco is identified, quantified, documented, and treated to an acceptable level across the Clayco organization. This role will assume ownership of the Third‑Party Risk Management (TPRM) process to gather details on the security practices and compliance levels for each third‑party being considered or contracted for a solution or services to assess the potential for compromise due to a control gap or exploitable misconfiguration as well as non‑compliance with legal and regulatory requirements. Additional contribution will be expected for internal assessments and 3rd Party audits to gather and submit discovery and transactional responses and artifacts. The Sr. GRC Analyst will also assume ownership of Human Risk Management (HRM) including the delivery of comprehensive security awareness education, the end‑to‑end execution of phishing simulation programs, and the technical maintenance and life‑cycle management of security awareness platforms. Beyond simple training, the position focuses on Human Risk Management (HRM), using data‑driven insights to identify high‑risk user groups and implementing targeted interventions to proactively mitigate human‑centric threats to cultivate a security‑first culture internally through education and behavioral change. Additional responsibilities will be assigned as deemed necessary. Any travel is usually planned in advance, but issues may arise which warrant immediate travel to one or more satellite locations. The Specifics of the Role Assumes operational ownership of the 3rd Party Vendor Risk Management program identifying, assessing, and mitigating risks associated with external vendors, suppliers, and service providers Conducts due diligence on new and existing vendors by reviewing security questionnaires, SOC reports, compliance certifications, and other supporting attestations Captures, analyzes, and recommends treatment, assignment, and tracking of identified issues Collaborates with legal and stakeholder teams to ensure contracts include specific clauses for data protection, service‑level agreements (SLAs), and AI governance Documents and communicates all relevant findings and recommendations to stakeholders Tracks, monitors, and reports on execution of remediation action plans and escalates inadequate responses or progress Assumes ownership of the Security Awareness program determining appropriate topics, themes, scopes, and timing of cyber awareness communications, events, and content delivery Conducts regular, simulated social engineering exercises to assess and improve employee recognition of real‑world attacks Develops engaging, simple materials—such as infographics, newsletters, and videos—that translate complex technical risks into lay'man's terms Maintains Security Awareness training and simulation platforms to support content delivery and End User interaction, including support for any Client‑side functionality (i.e., "Report Phish" button) Plans, coordinates, and executes activities for Cybersecurity month Partners with Employee Relations, Legal, and Marketing to ensure security messaging is integrated into the broader corporate culture Tracks Key Risk Indicators (KRI s) such as actual phishing click‑through rates, failed simulations, and missed training as well as Key Performance Indicators (KPIs) like suspicious email reporting, passed simulations, and successful training completion status to measure program effectiveness for leadership Requirements 6–8+ years’ experience in Risk & Compliance Assessment, Audit & Reporting, or similar functions, preferably within the Information Security or Technology fields 3–4+ years working specifically in Information Security roles involving Risk Analysis, Information System Security Assessment, and/or Security Awareness and Human Risk Management Bachelor's degree in Information Technology or related field, or equivalent experience Required Certifications: Certified in Risk & Information Systems Control (CRISC), SANS Security Awareness Professional (SSAP), and Certified Third‑party Risk Professional Certification (CTPRP) (Current status, or obtained within 9 months of assuming role) Strong experience leveraging auditing principles and methods to evaluate policies, processes, systems, and vendors to identify business risks and control gaps Strong knowledge of regulations, frameworks, and standards such as NIST 800‑171/CSF/RMF, ISO 27001, CIS Critical Security Controls, etc. Strong, technical knowledge of modern Systems, Services, Cloud Applications/Platforms, Identity Services, and Data Storage/Handling and their areas of Risk and Threat exposure Experience with administering, maintaining, and leveraging a Risk Register to track and communicate identified Risk and its required remediation Knowledge of statistics, reporting and analytical tools to analyze and solve complex problems Proficiency in necessary productivity tools (i.e., Microsoft Excel, PowerPoint, Word, etc.) for analytics and presentations Operate with strong integrity with ability to manage projects of a confidential nature Ability to translate technical or abstract concepts into a narrative that is easily understood Ability to thrive in fast‑paced environment Background check with mandatory drug testing (comprehensive background check included) Position is classified as a safety‑sensitive role in accordance with applicable state and federal laws Benefits Discretionary annual bonus: Subject to company and individual performance. Comprehensive benefits package including: Medical, dental and vision plans, 401k, generous PTO and paid company holidays, employee assistance program, flexible spending accounts, life insurance, disability coverage, learning & development programs and more! Compensation The salary range for this position considers a wide range of factors in making compensation decisions including but not limited to: education, qualifications, skills, training, experience, certifications, internal equity, and location. Compensation decisions are dependent on the facts and circumstances of each case. #J-18808-Ljbffr
- ...Sky Mavis is seeking a Sr. GRC Analyst for third-party and human risk management in Tulsa, Oklahoma. This role focuses on identifying and mitigating risks from external vendors while implementing a strong security awareness program to cultivate a security-first culture...Senior
- ...About the job This role will provide control design guidance and conduct independent control assessments within the Cybersecurity GRC function. The primary focus will be on the design, implementation, and testing of security controls, ensuring that technical systems...SeniorWork at officeLocal area
- BOK Financial Corporation is seeking an IW Plan Compliance Consultant in Tulsa, OK to enhance relationships and ensure compliance in Institutional Wealth Management. The role requires a Bachelor’s degree and 6-8 years of relevant experience or a combination of education...Senior
- ...Broughton Group in Tulsa, OK is seeking a Senior Compliance & Monitoring professional to analyze and process grant compliance documentation. This role requires strong analytical, communication, and problem-solving skills, as well as proficiency in data analysis tools....SeniorRemote work
- ...country. Your credit decisions directly enable the contracts and partnerships that make clean energy possible at scale. The Senior Credit Risk Analyst manages credit risk for a portfolio of counterparties by evaluating creditworthiness, establishing and approving credit...SeniorWork at officeWork from homeFlexible hours1 day per week
$80 - $90 per hour
...A leading staffing firm is seeking a skilled Sr. Epic Analyst to support healthcare application design and optimize systems. This fully remote role involves collaborative work with interdisciplinary teams to enhance patient care through technology. The ideal candidate...SeniorRemote work- Job Responsibilities: -Assists in the development and execution of the annual audit plan. -Conducts risk-based internal audits across the health system. -Assists with the creation of standardized audit procedures, templates, and risk assessment tools. -Evaluates...Senior
- HORNE LLP seeks an Experienced Senior Compliance & Monitoring professional to support timely analysis and compliance documentation for federal and state regulations. This role ensures audit-ready program records, resolves compliance issues, and communicates regulatory...SeniorWork at office
- A financial services company in Tulsa is seeking a Cash Manager to oversee accounting transactions and cash management for the Department of Housing and Urban Development. Candidates should have a bachelor's degree in Business, three years of mortgage servicing accounting...SeniorFull time
- BOK Financial Corporation in Tulsa, Oklahoma, is seeking an IT audit professional to join its ICFR team. The role emphasizes the execution and enhancement of the bank's SOX/ICFR program, supporting control monitoring and testing across teams. The ideal candidate should ...Senior
- BOK Financial in Tulsa seeks a quality control specialist for Loan Documentation and Post Booking Review. Responsibilities include analyzing loan worksheets, ensuring documentation compliance, and preparing necessary documents for loan closing. The role requires a Bachelor...Senior
- BOK Financial in Tulsa, Oklahoma is seeking a professional for their ICFR team, focusing on IT controls and SOX activities. This role involves collaborating with IT, Accounting, and Risk teams to ensure effective control design and integrity in financial reporting. Ideal...Senior
- ...System One is looking for a Business Analyst - SAP based in Tulsa, Oklahoma. The role involves owning IT business processes, engaging stakeholders, and recommending improvements in payment processes. Candidates should have a Bachelor’s degree, 6-8 years of experience,...Senior
- A leading SaaS provider is seeking a Senior Data Analyst to join their remote team. The role requires expertise in SQL and Python, alongside a strong background in data analysis with a minimum of five years' experience. You will lead complex analyses to inform business...SeniorRemote work
- ...Broughton Group is seeking a Project Controls Analyst to support engineering and construction project managers. This role involves performance tracking and analytical support for major projects. The ideal candidate will have a strong background in project controls, engineering...Senior
- ...A healthcare technology company in Tulsa is seeking a Software QA Analyst proficient in both automated and manual testing methods. The role involves testing deliverables from engineering teams and validating database functionality using SQL. Ideal candidates have 5+ years...Senior
- Traka (Assa Abloy) is looking for an IT Business Analyst in Tulsa, Oklahoma. The role involves acting as a liaison between IT and business operations, focusing on ERP processes such as quote-to-cash and procure-to-pay. Candidates should have over 5 years of experience with...Senior
$75k - $112k
...Job Description Job Description Job Title: Senior Internal Audit Analyst Location: Tulsa, OK Schedule: Monday–Friday | 8:00 AM – 5:00 PM Pay Range: $75,000 – $112,000 annually Job Summary: The Senior Internal Audit Analyst supports internal audit...SeniorMonday to Friday- A global professional services firm seeks an experienced tax professional to prepare and review complex individual tax returns. This role involves advising high-net-worth clients while collaborating with specialists to provide comprehensive tax planning solutions. Ideal...SeniorFlexible hours
- Bank of Texas is looking for a Sr. Analyst, Control Operations to ensure the integrity of internal controls within the finance department. The role involves administering SOX applications and managing reconciliation processes to maintain compliance. Candidates should have...Senior
- ...EMPLOYEES are our greatest asset in meeting our mission to be an Oklahoma Agency of Excellence.Position OverviewThe Compensation Analyst Senior plays a pivotal role in designing, implementing, and managing competitive compensation programs to attract, retain, and...SeniorWork at officeLocal area
$87.63k - $128.69k
...posting will close on the day before the posting end date. Job Summary ** No sponsorship will be offered for this role. The HRIS Analyst will assist in the maintenance and support of the Workday HRIS, including system updates and configurations. This role involves...SeniorWork experience placement- ...A leading professional services firm is seeking a Senior Analyst in tax reporting to join their team. This role involves preparing tax compliance filings and mentoring junior team members. Candidates should hold a Bachelor’s degree in Accounting or Finance and have 4-...SeniorFlexible hours
$122k - $184k
ONEOK, Inc is looking for a Lead Software Developer responsible for all aspects of the software development lifecycle. This includes software design, development, testing, deployment, and maintenance. The position offers flexibility with remote work eligibility in various...SeniorRemote job$91k - $321.5k
...code of conduct, and independence requirements. The Opportunity As a Risk Management - Contract Specialist - Managed Services - Senior Manager, you will lead initiatives in enterprise risk management, focusing on business continuity, risk model implementation, and...SeniorFull timeContract workH1b- Job Description The Sr. Analyst, Control Operations will use their knowledge of GAAP and bank operations, expertise in communication and organization, and skills in structural and analytical thinking to carry out a variety of functions in support of internal controls within...Senior
- ...Electrical Engineer (Senior - Principal - Advisor) Artificial Lift Date: May 24, 2026 Location: Tulsa, OK, US, 74104 We are looking for the right people — people who want to innovate, achieve, grow and lead. We attract and retain the best talent by investing...SeniorFull timePart timeSecond jobWork from homeWorldwideRelocation package
- System One is seeking a skilled Business Analyst in Tulsa or Oklahoma City with a focus on data visualization and analysis. The candidate will work directly with stakeholders to translate business needs into actionable insights. A strong background with SQL, Tableau, and...SeniorFull time
- ...Senior Data Analyst / Full-time / Remote About the job Senior Data Analyst / Full-time / Remote Our client is a Series B B2B SaaS software company that is profitable and experiencing triple digit, year over year growth and is looking to add a Senior Data Analyst...SeniorFull timeRemote workShift work
- ...Senior Health Data Analyst The Senior Health Data Analyst provides the analytical support for Executives and all departments including analysis, pricing, capitation, network, and provider specific reporting. Analytical support includes programming customer-based specifications...SeniorWork at officeImmediate start
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Senior GRC Analyst. Be the first to apply!
- senior program specialist Tulsa, OK
- senior manager quality engineering Tulsa, OK
- senior design technologist Tulsa, OK
- sr project engineer Tulsa, OK
- senior cloud solutions architect Tulsa, OK
- senior strategic account manager Tulsa, OK
- senior civil engineer project manager Tulsa, OK
- senior ai engineer Tulsa, OK
- sr operations manager Tulsa, OK
- senior account executive Tulsa, OK


