×
Register Here to Apply for Jobs or Post Jobs. X

Sr. Security GRC Analyst

Job in Lake Oswego, Clackamas County, Oregon, 97034, USA
Listing for: The Greenbrier Companies, Inc.
Full Time position
Listed on 2026-02-23
Job specializations:
  • IT/Tech
    Cybersecurity, IT Business Analyst, IT Consultant, Systems Analyst
Salary/Wage Range or Industry Benchmark: 85000 - 110000 USD Yearly USD 85000.00 110000.00 YEAR
Job Description & How to Apply Below

Summary

The Sr. Security GRC Analyst supports Greenbrier’s IT Compliance program and audit activities. This role serves as the first line of defense by monitoring, executing, and maintaining IT controls related to SOX, SOC 1, SOC 2, and ISO compliance. The analyst works closely with the Sr. Manager – GRC and the CISO to support compliance initiatives and audit readiness across the IT organization.

This position collaborates with cross‑functional, global teams and communicates with stakeholders at all organizational levels. The role requires strong knowledge of IT control frameworks or IT auditing, attention to detail, and the ability to develop and maintain effective processes and documentation.

Duties and Responsibilities
  • Audit Preparations and Auditor Access:
    Bulk upload SOX/SOC audit requests to centralized tool during interim and roll‑forward testing periods. Coordinate auditor access to Greenbrier systems, as needed.
  • Audit Evidence Request Monitoring:
    Monitor audit evidence request tickets in centralized tool to ensure responses to auditors meet agreed upon milestones. Facilitate evidence request issues and coordinate meetings between IT stakeholders and relevant auditors.
  • Compliance Liaison:
    Liaison between control owners and auditors/assessors for the evidence collection process and audit testing follow‑ups. Assist Control Owners with evidence requests from auditors. Schedule meetings as needed.
  • Control Automations:
    Facilitate and drive progress on control automation efforts, coordinating with subject matter experts, control owners, and automation teams.
  • Control Changes:
    Ensure control description and design changes and relevant procedure documentation get updated into the GRC tool master control list in a timely manner.
  • Control Failure Triage:
    Work with control owners/performers to perform root cause analyses on control issues and deficiencies, initiate risk‑based remediation plans, and follow escalation procedures. May facilitate control remediation execution.
  • Control Improvements:
    Support and implement control improvements, automation, and update relevant documentation, at the direction of management.
  • Control Monitoring:
    Using GRC Tool, monitor SOX/SOC controls for adequate completion by Control Owners and performers and secondary reviewers. Create dashboards for monitoring metrics by global region (U.S. vs. Europe).
  • Control Remediations:
    Design and track all assigned remediation plans through to timely completion. Provide status updates of remediation plans to key stakeholders within the organization. Document as needed.
  • Escalations:
    Proactively monitor audit follow‑ups to identify potential control issues or failures, and missing or unavailable evidence, and follow internal escalation protocols immediately so GRC can triage.
  • GRC Consultations:
    Provide audit, control, and evidence guidance to internal security and IT teams; partner with internal and external stakeholders to assist the IT organization during audits.
  • GRC Tool Enhancements:
    Enhance GRC tool usage for IT control monitoring at the direction of the Sr. Manager - GRC; onboard recurring and new controls to GRC Tool evidence request library and set recurring notifications. Work with vendor on system enhancements desired.
  • Meeting Attendance:
    Attending weekly meetings with external and internal auditors, all control walkthroughs and follow‑ups, as needed.
  • Procedure Documentation:
    Create SOX/SOC Control Procedures. Upload to GRC Tool.
  • Risk Management Support:
    Facilitate certain tasks that support our Risk Management and Third Party Risk Management Programs such as monitoring risk reviews due and risk assessments for completion, setting up meetings and coordinating with key stakeholders.
  • Auditor Interactions:
    Negotiation with auditors, issue management, productive and constructive communication with auditors.
  • Communicative:
    Highly responsive and collaborative. Skilled at conflict resolution.
  • Problem Solving:
    Think strategically and solve problems effectively, partner with specialists to design effective, reliable controls, as much as possible. Ability to ask the right questions and understand complex technical topics.
  • Trust Building:
    Excellent…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)

Job Posting Language
Employment Category
Education (minimum level)
Filters
Education Level
Experience Level (years)
Posted in last:
Salary