GRC Analyst
Job in
Southfield, Oakland County, Michigan, 48076, USA
Listed on 2026-08-06
Listing for:
Saanvi Technologies
Full Time
position Listed on 2026-08-06
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Consultant, IT Business Analyst
Job Description & How to Apply Below
About The Role
As a member of the Information Security team, the IS GRC Risk & Compliance Senior Analyst will support the firm's Governance, Risk, and Compliance (GRC) program by managing security risks, maintaining the risk register, conducting risk assessments, coordinating control testing, and supporting audit activities. The role partners closely with IT leadership, business stakeholders, and third-party vendors to ensure security and compliance objectives are achieved.
Key Responsibilities Security Risk Management- Support the CISO with annual and periodic security risk assessments.
- Manage and maintain the enterprise risk register.
- Conduct security risk assessments and evaluate risk and control effectiveness.
- Track remediation activities through closure and report status to leadership.
- Interview SMEs and gather information for risk assessments.
- Develop and support risk mitigation strategies with cross-functional teams.
- Conduct third-party security risk assessments, including review of:
- Security questionnaires
- Supporting documentation
- Independent audit reports
- Identify vendor security gaps, assign risk ratings, and recommend mitigations.
- Design, execute, and monitor security control testing.
- Ensure compliance with contractual, regulatory, and internal security requirements.
- Partner with IT and business control owners.
- Prepare audit evidence and documentation for internal and external audits.
- Report metrics and compliance status to the IS GRC Manager, Director, and CISO.
- Improve and automate GRC processes where possible.
- Perform additional responsibilities as assigned.
- Bachelor's degree in Information Technology or a related field (or equivalent experience).
- 3+ years of professional experience.
- Experience in one or more of the following:
- Information Security
- Governance, Risk & Compliance (GRC)
- IT Risk
- Information Technology
- Audit
- Experience with security frameworks or regulations such as:
- ISO 27001
- SOC 2
- PCI DSS
- HIPAA
- Other global security/compliance standards
- Strong experience in:
- Risk assessments
- Risk registers
- Control testing
- Security compliance
- Third-party/vendor risk management
- Excellent analytical, communication, and documentation skills.
- Experience with Microsoft Office Suite.
- Service Now experience is preferred.
- CISSP (Preferred)
- CISA (Preferred)
- CRISC (Nice to have)
- Willingness to pursue security certifications is highly valued.
- Core business hours: 8:30 AM 5:30 PM (Monday Friday).
- Occasional work outside standard business hours may be required.
- Hybrid work schedule:
- Onsite:
Tuesday, Wednesday & Thursday - Remote:
Monday & Friday - No relocation assistance or benefits are provided for this contract position.
Thanking you Jeevan
#J-18808-LjbffrTo View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×