GRC Analyst
Job in
Boston, Suffolk County, Massachusetts, 02298, USA
Listed on 2026-09-20
Listing for:
Massachusetts-Bay-Transportation-Authority
Full Time
position Listed on 2026-09-20
Job specializations:
-
IT/Tech
Information Security & Data Protection, Cybersecurity, IT Business Analyst
Job Description & How to Apply Below
The Governance, Risk, and Compliance (GRC) Analyst is responsible for identifying, assessing, monitoring, and mitigating organizational risks while ensuring compliance with applicable regulatory requirements, industry standards, and internal policies. This role works closely with business units, Information Technology (IT), cybersecurity, audit, and leadership to strengthen the organization's governance, risk management, and compliance framework.
Enterprise & Information Security Risk Management- Conduct comprehensive enterprise and information security risk assessments to identify threats and vulnerabilities across IT, Operational Technology (OT), and business processes.
- Maintain and continuously update the MBTA's risk register, ensuring timely tracking of remediation actions and residual risk. Evaluate business processes, technical controls, and governance workflows to ensure they effectively mitigate identified risks and align with MBTA’s centralized compliance strategy.
- Support the maturation of risk methodologies, including development of risk scoring models, prioritization frameworks, and automated reporting feeds.
- Support the development, implementation, and continuous improvement of governance, risk, and compliance programs and procedures.
- Monitor and report compliance against regulatory requirements, industry standards, and internal policies, including International Organization for Standardization (ISO) 27001, National Institute of Standards and Technology Cybersecurity Framework (NIST CSF)/800-53, Service Organization Control (SOC) 2, Payment Card Industry Data Security Standard (PCI DSS), Transportation Security Administration (TSA) Surface Directives, United States Coast Guard (USCG) requirements, General Data Protection Regulation (GDPR), Health Insurance Portability and Accountability Act (HIPAA), Sarbanes‑Oxley Act (SOX), and other MBTA-applicable mandates.
- Assist with maintaining authoritative policy and standards documentation; participate in policy review cycles and support enterprise-wide enforcement.
- Perform detailed third-party/vendor security assessments covering onboarding, due-diligence, SOC 2/Federal Risk and Authorization Management Program (FedRAMP)/ISO attestation reviews, contractual security clauses, and ongoing monitoring.
- Track vendor remediation activities and partner with Procurement, Legal, and business owners to ensure sustained compliance.
- Assist with internal and external audits by gathering documentation, coordinating evidence collection, validating controls, and supporting remediation plans.
- Serve as a liaison between business units, auditors, and Information Security to ensure timely and accurate audit responses.
- Develop risk dashboards, status reports, metrics, and executive‑level summaries for leadership, including trends, Key Performance Indicators (KPIs), Key Risk Indicators (KRIs), and compliance performance indicators.
- Maintain high‑quality data integrity within GRC platforms (e.g., Service Now GRC, Archer) by ensuring accuracy of control catalogs, assessments, exceptions, and workflow automation.
- Partner with IT, Cybersecurity, Operations, Legal, Finance, and business teams to identify control gaps and recommend actionable mitigation strategies.
- Support enterprise roadmaps by providing risk insights that influence technology, process, and operational decisions.
- Assist team leaders and stakeholders in understanding risk exposure, obligations, and governance expectations.
- In collaboration with the GRC Policy Analyst, support…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×