×
Register Here to Apply for Jobs or Post Jobs. X

Senior Governance, Risk & Compliance (GRC) Analyst

Job in North Stonington, Connecticut, 06359, USA
Listing for: Cianbro
Full Time position
Listed on 2026-08-01
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, IT Business Analyst
Salary/Wage Range or Industry Benchmark: 90000 - 110000 USD Yearly USD 90000.00 110000.00 YEAR
Job Description & How to Apply Below
Location: North Stonington

Senior Governance, Risk & Compliance (GRC) Analyst (SNE~CT~0685~~EXT~CORP3~PROF2~CBO1)

We are seeking a Senior Governance, Risk & Compliance (GRC) Analyst to support and mature the organization's governance, risk management, compliance, and business continuity programs.

Reporting to the Director of IT Risk Management, this role focuses on CMMC Level 1 and Level 2 compliance, enterprise risk management, audit readiness, third-party risk, and administration of the Onspring GRC platform.

The successful candidate will work collaboratively across business and technology teams and with external partners, auditors, assessors, and service providers to drive compliance, accountability, and continuous improvement.

The ideal candidate brings strong CMMC and NIST SP 800-171 expertise, exceptional written and verbal communication skills, and the ability to translate complex regulatory requirements into practical business processes and technical controls.

Job Responsibilities CMMC Compliance & Regulatory Governance
  • Support and enhance the organization's CMMC Level 1 and Level 2 compliance program in alignment with NIST SP 800-171 requirements.
  • Maintain compliance documentation, including System Security Plans (SSPs), policies, procedures, Plans of Action and Milestones (POA&Ms), and supporting assessment artifacts.
  • Coordinate with our Enclave hosting provider to ensure shared responsibility controls are clearly defined, documented, and monitored.
  • Partner with control owners, business stakeholders, technology teams, and external assessors to evaluate compliance and track remediation activities.
  • Support CMMC assessments, audits, and readiness activities through evidence collection, documentation management, and control validation.
  • Monitor regulatory, contractual, and customer compliance requirements and help translate them into actionable business and technical processes.
  • Communicate compliance obligations, risks, and program status clearly to both technical and non-technical audiences.
Enterprise Governance, Risk Management & Audit Readiness
  • Support the development and maturation of enterprise governance, risk management, and compliance processes.
  • Conduct risk assessments, maintain risk registers, and track remediation activities to improve risk visibility, accountability, and decision-making.
  • Coordinate internal audits, external audits, customer assessments, and regulatory reviews, maintaining appropriate evidence and documentation to support audit readiness.
  • Partner with stakeholders across the organization to identify risks, address compliance gaps, and strengthen governance practices.
  • Support the development, maintenance, and continuous improvement of the organization's Business Continuity and Operational Resilience program.
  • Conduct Business Impact Analyses (BIAs) and partner with business stakeholders to identify critical processes, dependencies, recovery requirements, and operational risks.
  • Develop, maintain, and test Business Continuity and Disaster Recovery plans, incorporating lessons learned and remediation activities from exercises and testing.
  • Manage Business Continuity documentation, workflows, reporting, and program administration within the Onspring GRC platform.
Third-Party Risk Management
  • Support the third-party risk management lifecycle, including vendor onboarding, due diligence reviews, periodic assessments, and ongoing monitoring.
  • Assess supplier security, compliance, operational, and business continuity risks.
  • Coordinate with Procurement, Legal, Information Technology, and business stakeholders to ensure vendor risk requirements are addressed appropriately.
  • Track assessment findings, remediation activities, and risk acceptance decisions.
  • Maintain visibility into third-party risk exposure through effective reporting and dashboarding.
Security Risk Analysis
  • Review vulnerability assessment results, security findings, and remediation recommendations provided by internal teams and service providers.
  • Assess technical findings to determine business impact, likelihood, and overall organizational risk.
  • Work collaboratively with technical teams to prioritize remediation efforts using a risk-based approach.
  • Translate technical security issues into clear business risk statements and recommendations for leadership.
  • Assist with evaluating the effectiveness of security controls and identifying opportunities for improvement.
Qualifications/Requirements Required
  • Bachelor's degree in Information Systems, Cybersecurity, Information Technology, Business, Risk Management, or a related field, or equivalent professional experience.
  • 5+ years of experience in governance, risk management, cybersecurity, compliance, audit, or related disciplines.
  • Demonstrated experience supporting CMMC and NIST SP 800-171 compliance programs.
  • Experience developing and maintaining SSPs, POA&Ms, policies, procedures, risk assessments, and audit evidence repositories.
  • Experience administering or supporting a GRC platform, preferably Onspring.
  • Strong understanding of risk management,…
Position Requirements
10+ Years work experience
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary