Haystack
← Back to Jobs
Technology
EV

GRC Analyst

Evolutyz CorpUnited States🇺🇸United StatesPosted 15 Sept 2026

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
United States
Posted
Yesterday
PCI DSS

Job Description

Summary:

The Governance, Risk and Compliance Senior Analyst helps protect the business by tracking cybersecurity risk, analyzing control-effectiveness information, and translating findings into prioritized actions aligned to business risk. This hands-on role conducts vendor security assessments within the OneTrust vendor review process, administers the policy and standards lifecycle, supports security awareness programs, and coordinates broader compliance evidence and documentation activities. You will join an evolving GRC program where resourcefulness, sound judgment, and follow-through matter. Working closely with the Senior Manager, Governance, Risk and Compliance and cross-functional partners, you will use OneTrust for third-party risk management, strengthen the policy and standards library, and run practical processes that scale with the business.

 

Requirements:

Success in this role depends on strong partnerships, clear communication, and dependable execution across Information Security and the broader business.

  • Partner with the Senior Manager, Governance, Risk and Compliance, who owns enterprise risk governance, policy direction, control frameworks, compliance oversight, and formal assessment conclusions. Execute OneTrust vendor reviews and coordinate the tracking, reporting, evidence, and documentation that support broader GRC priorities.
  • Document risk acceptance and exception decisions, maintain clear records, and drive required follow-through
  • Translate technical findings, control gaps, and remediation status into clear, prioritized actions for business stakeholders, Information Security leadership, Internal Audit, and external auditors
  • Coordinate work within the GRC program cadence and cross-functional delivery model

Required Skills:

  • Three to five years of experience in information security, IT audit, IT risk, or compliance, including hands-on experience in third-party risk, policy administration, or security awareness
  • Experience operating a third-party risk or GRC platform, including workflow execution, configuration, and ongoing maintenance
  • Demonstrated ability to execute vendor security assessments within a OneTrust vendor review process from intake through findings closure
  • Experience building practical processes, such as a policy library, review cycle, or intake workflow
  • Working knowledge of recognized control and compliance frameworks, including CIS Controls v8 or NIST Cybersecurity Framework, PCI DSS, and SOX IT general controls
  • Strong written communication and documentation skills with attention to accuracy and audit readiness
  • Ability to prioritize work, manage competing deadlines, and deliver independently in a remote environment

Similar jobs