×
Register Here to Apply for Jobs or Post Jobs. X

GRC Analyst I

Job in Madison, Dane County, Wisconsin, 53774, USA
Listing for: Sub-Zero, Inc.
Full Time position
Listed on 2026-08-10
Job specializations:
  • IT/Tech
    Information Security & Data Protection, Cybersecurity, IT Business Analyst
  • Business
Salary/Wage Range or Industry Benchmark: 55000 - 85000 USD Yearly USD 55000.00 85000.00 YEAR
Job Description & How to Apply Below

The GRC Analyst I is responsible for supporting the organization's Governance, Risk, and Compliance (GRC) program through risk management, policy governance, compliance monitoring, reporting, and continuous improvement activities. This role assists with risk assessments, maintenance of the risk register, control evaluations, mitigation tracking, policy management, and compliance-related activities that help protect the organization and enable business objectives.

The GRC Analyst I also supports emerging AI Governance initiatives by assisting with the identification, assessment, monitoring, and reporting of risks associated with artificial intelligence technologies. Working closely with IT Security, Legal, Business Continuity, Data Governance, and business stakeholders, this position helps promote responsible technology use, organizational resilience, and a risk-aware culture that enables the business to move faster with greater confidence.

This is a full-time position based at Sub-Zero Group's headquarters in Fitchburg, Wisconsin, just outside Madison.

Job Responsibilities

Responsibilities include, but are not limited to:

Governance:

  • Assist with policy governance activities, including the development, maintenance, review, and administration of policies, standards, procedures, and related governance documentation, while providing guidance to employees and business units on their application.
  • Support the organization's AI Governance program through documentation, inventories, risk assessments, stakeholder coordination, and monitoring activities that promote the responsible, secure, and compliant use of AI technologies.
  • Help maintain alignment with governance frameworks and industry standards, including NIST CSF, NIST AI RMF, and ISO standards, while assessing governance implications of new technologies, AI initiatives, business process changes, and emerging regulatory requirements.
  • Support risk assessment activities by gathering information, documenting risks, facilitating stakeholder discussions, evaluating inherent and residual risk, and tracking follow-up actions and remediation activities.
  • Maintain the risk register, including risk documentation, ownership assignments, risk scoring, review cadences, mitigation plans, control effectiveness evaluations, and reporting activities.
  • Partner with risk owners to evaluate risk events, root causes, business impacts, existing controls, and risk response strategies while developing dashboards, metrics, KPIs, and executive reporting that communicate organizational risk exposure and program maturity.

Compliance:

  • Monitor compliance with internal policies, regulatory requirements, contractual obligations, and applicable industry standards while supporting assessments against relevant governance and compliance frameworks.
  • Assist with compliance reviews, internal audits, and audit readiness activities by collecting evidence, validating controls, documenting findings, maintaining records, and tracking remediation activities through resolution.
  • Track and report compliance metrics, audit findings, governance performance indicators, corrective actions, and overall program effectiveness and maturity.

Additional Opportunities

The GRC Analyst I may have opportunities to contribute to additional initiatives based on business needs, program priorities, and individual career interests.

  • Business Continuity & Resilience: Participate in business continuity, IT disaster recovery, crisis management, resilience planning, business impact analyses, exercises, and improvement activities in support of organizational resilience efforts.
  • Third-Party

    Risk Management:

    Assist with vendor due diligence, third-party governance activities, and ongoing monitoring efforts as the organization's third-party risk management capabilities evolve and mature.
  • Awareness, Training & Risk Culture: Contribute to governance, risk, compliance, cybersecurity, and responsible AI awareness initiatives through the development of training materials, communications, workshops, and other educational opportunities that promote a culture of accountability and risk-informed decision-making.

Required Qualifications

  • Associate’s or…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary