Senior GRC Analyst
Listed on 2026-09-17
-
IT/Tech
Cybersecurity, Information Security & Data Protection
Position Description
For more than 100 years, Modine has solved the toughest thermal management challenges for mission-critical applications. Our purpose of Engineering a Cleaner, Healthier World means we are always evolving our portfolio of technologies to provide the latest heating, cooling, and ventilation solutions. Through the hard work of more than 11,000 employees worldwide, our Climate Solutions and Performance Technologies segments advance our purpose with systems that improve air quality, reduce energy and water consumption, lower harmful emissions, enable cleaner running vehicles, and use environmentally friendly refrigerants.
Modine is a global company headquartered in Racine, Wisconsin (U.S.), with operations in North America, South America, Europe, and Asia. For more information about Modine, visit
We are seeking a highly structured, process-oriented, and proactive Senior GRC (Governance, Risk, and Compliance) Analyst to join our Information Security GRC team.
In this critical role, you will be the driving force behind the execution and continuous improvement of our IT General Controls (ITGC) framework, SOX compliance program, and overall risk management practices. You will serve as a key bridge between control owners, IT operational teams, internal/external audit, and corporate risk management. As a self-starter with deep compliance expertise, you will lead efforts to review, analyze, and update cybersecurity policies, manage GRC platform automation, and ensure that security risks are systematically identified, documented, and remediated.
Key Responsibilities- ITGC & SOX Compliance Management
- Control Lifecycle Ownership:
Track, monitor, and follow up with IT control owners to ensure all ITGC and SOX-related control tests and evidence collections are executed accurately, thoroughly, and on schedule. - Audit Readiness:
Act as the primary coordinator for internal and external auditors during security and compliance reviews, ensuring timely delivery of documentation and evidence. - Remediation & Correction:
Partner with IT and Security teams to design, document, and track effective remediation plans for any identified control gaps or deficiencies. - Policy, Standards & Procedures Governance
- Policy Lifecycle:
Lead the periodic review, analysis, and modernization of information security policies, standards, guidelines, and operating procedures to ensure alignment with evolving industry regulations and corporate risk tolerance. - Process Standardization:
Support the development ofclear, actionable technical standards and procedural documentation that simplify compliance for system administrators and business process owners. - Alignment:
Ensure corporate security documentation matches standard industry frameworks (e.g., NIST CSF, ISO 27001, COBIT, COSO). - Risk Assessment & GRC Tool Management
- GRC Tool Administration:
Manage and optimize our GRC platform (such asSimpleRiskor similar tools) to automate risk registers, compliance mappings, and control tracking. - Risk Assessments:
Conduct comprehensive IT and security risk assessments across applications, infrastructure, and third-party vendors. - Risk Register Maintenance:
Document risks, vulnerabilities, and policy exceptions systematically, tracking them from identification through to mitigation or formal acceptance. - Business Partnering & Stakeholder Collaboration
- Cross-Functional Liaison:
Build strong, collaborative relationships with stakeholders across IT, Information Security, Internal Audit, Corporate Risk Management, and External Auditors. - Control Owner Support:
Act as a subject matter expert and trusted advisor to control owners, offering ongoing guidance on compliance expectations, control design, and testing methodology. - Executive…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).