Governance Risk & Compliance; GRC Analyst
Job in
Lakewood, Jefferson County, Colorado, USA
Listed on 2026-06-19
Listing for:
Judge Group, Inc.
Full Time
position Listed on 2026-06-19
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Job Description & How to Apply Below
Location: Lakewood, CO Salary: $50.00 USD Hourly - $70.00 USD Hourly Description: Title:
Governance Risk & Compliance (GRC) Analyst
Location:
Lakewood, CO
Remote:
No, Hybrid OK
Convert to Perm:
Yes
Full Time Salary After Conversion: 120-130K
Contact:
Brian Merin; ;
Main focus for this position is Security Audits to prepare for ISO 27001 Certification
Remote candidate are good if in Denver need to be onsite Tuesday through Thursday
Current Software being used is Bit Site
Soft Skills:
Strong Communication skills as they will be interacting with PP from around the globe
ability to take after hours meeting again due to Global team
Team make up
1 in Belgum
1 in Japan
2 in US ( looking to add two more this year
1 Europe
Governance Risk & Compliance (GRC) Analyst
JOB DESCRIPTION:
The GRC Analyst is a member of the Governance, Risk & Compliance function within the Global Information Security Office and supports the implementation of company-wide security governance, risk management, and compliance programs. Under the direction of the GRC Functional Leader, the analyst contributes to policy development, risk oversight, and continuous improvement of the organization's security posture. The role also works closely with regional Information Security Officers (ISOs) and cross-functional teams to support the deployment of global standards and local regulatory requirements.
ESSENTIAL DUTIES:
Company-wide risk assessment and audit response:
Support information security risk assessments for new projects, systems, and business processes. Assist in conducting internal control reviews (e.g., J-SOX), preparing audit materials, and coordinating responses to internal and external auditors. Track and follow up on remediation actions to ensure timely closure of identified risks.
Policy Development and Management:
Contribute to drafting, updating, and maintaining global information security policies, standards, and procedures. Review relevant laws, regulations, and industry frameworks (e.g., ISO 27001, NIS2) and incorporate stakeholder feedback into documentation. Support the rollout and implementation of policies across regions.
Maintain compliance and certification:
Monitor adherence to security and regulatory requirements, including ISO 27001, NIS2, and GDPR. Collect and organize compliance evidence, track corrective actions, and support certification and regulatory readiness efforts such as ISO 27001/42001 and NIS2 programs.
Supplier
Risk Management:
Conduct third-party security risk assessments by distributing questionnaires, analyzing responses, verifying controls, and documenting results in the GRC tracking systems. Identify and escalate high-risk findings to the GRC Functional Leader and support follow-up mitigation activities.
Security Awareness and Training:
Participate in the planning and implementation of security awareness programs for all Terumo associates. Specifically, help to improve the security literacy of associates by creating e-learning materials and training materials, conducting phishing email exercises, and distributing disseminated content on internal portals. The GRC Analyst will help foster a culture in line with the company-wide security strategy promoted by the GRC functional leader.
Cybersecurity Regulatory Monitoring (Industrial Systems, IT Systems, and Critical Infrastructure):
Monitor and analyze global regulatory developments related to cybersecurity with a focus on industrial control systems (ICS), IT environments, and critical infrastructure. Assist in evaluating how new or updated regulations (e.g., NIS2, FDA cybersecurity expectations, industrial cybersecurity standards, or country-specific critical infrastructure laws) impact company operations. Track emerging obligations, document requirements, and support gap assessments to ensure timely compliance.
CISO Dashboard:
Assist in the preparation, maintenance, and continuous improvement of the CISO Dashboard by collecting, validating, and analyzing security metrics across the Global GRC function. Compile key performance indicators (KPIs) and key risk indicators (KRIs) related to compliance status, audit findings, supplier risk, incident trends, training…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×