Quick Overview
Job Description
Summary:
The Governance, Risk and Compliance Senior Analyst helps protect the business by tracking cybersecurity risk, analyzing control-effectiveness information, and translating findings into prioritized actions aligned to business risk. This hands-on role conducts vendor security assessments within the OneTrust vendor review process, administers the policy and standards lifecycle, supports security awareness programs, and coordinates broader compliance evidence and documentation activities. You will join an evolving GRC program where resourcefulness, sound judgment, and follow-through matter. Working closely with the Senior Manager, Governance, Risk and Compliance and cross-functional partners, you will use OneTrust for third-party risk management, strengthen the policy and standards library, and run practical processes that scale with the business.
Requirements:
Success in this role depends on strong partnerships, clear communication, and dependable execution across Information Security and the broader business.
- Partner with the Senior Manager, Governance, Risk and Compliance, who owns enterprise risk governance, policy direction, control frameworks, compliance oversight, and formal assessment conclusions. Execute OneTrust vendor reviews and coordinate the tracking, reporting, evidence, and documentation that support broader GRC priorities.
- Document risk acceptance and exception decisions, maintain clear records, and drive required follow-through
- Translate technical findings, control gaps, and remediation status into clear, prioritized actions for business stakeholders, Information Security leadership, Internal Audit, and external auditors
- Coordinate work within the GRC program cadence and cross-functional delivery model
Required Skills:
- Three to five years of experience in information security, IT audit, IT risk, or compliance, including hands-on experience in third-party risk, policy administration, or security awareness
- Experience operating a third-party risk or GRC platform, including workflow execution, configuration, and ongoing maintenance
- Demonstrated ability to execute vendor security assessments within a OneTrust vendor review process from intake through findings closure
- Experience building practical processes, such as a policy library, review cycle, or intake workflow
- Working knowledge of recognized control and compliance frameworks, including CIS Controls v8 or NIST Cybersecurity Framework, PCI DSS, and SOX IT general controls
- Strong written communication and documentation skills with attention to accuracy and audit readiness
- Ability to prioritize work, manage competing deadlines, and deliver independently in a remote environment
Similar jobs
- AS
Risk Reporting & Governance Consultant
Apex Systems
Boston, MA🇺🇸Remote2 weeks agoSQLCompliancePower BI+3 - CS
Exposure Management Engineer / Exposure Risk Analyst - Remote / Telecommute
NewCynet Systems
Dallas, TX🇺🇸$95 - $100/hrRemoteYesterdayAgileEngineering - JM
Risk Management - Quantitative Research Senior Associate
NewJ.P. Morgan
Jersey City, New Jersey🇺🇸On-site5 hours agoComplianceDerivativesC+++3 - VE
Risk Analyst
NewVerisk
Boston, Massachusetts🇺🇸Hybrid8 hours agoSQLSQL ServerMicrosoft Office+1 - MM
Risk Manager
NewMitchell Martin, Inc.
Providence, RI🇺🇸$67 - $77/hrHybridYesterdayComplianceOnboardingRisk Management - ST
Strategy & Operations, Risk
NewStripe
US-SF🇺🇸YesterdaySQLPython