Governance, Risk & Compliance Senior Analyst
Atlanta, GA
IT Governance, Risk & Compliance (GRC) Analyst
We are seeking an IT Governance, Risk & Compliance (GRC) Analyst to support technology compliance, risk, and data governance programs.
This hands-on role will help maintain year-round SOC 2 readiness, coordinate IT controls and access reviews, support Microsoft Purview and data retention initiatives, administer security awareness activities, and ensure compliance documentation remains organized and audit-ready.
The ideal candidate has experience in IT audit, GRC, cybersecurity compliance, or technology risk and is looking to continue developing their expertise in a collaborative environment.
What Youll Do
- Maintain the SOC 2 control calendar and coordinate recurring control activities.
- Collect, review, and maintain audit evidence and documentation.
- Track control gaps, exceptions, remediation plans, and outstanding items.
- Coordinate SOC 2 readiness activities and external auditor requests.
- Perform and document recurring user and privileged access reviews.
- Support Microsoft Purview initiatives, including data classification, DLP, sensitivity labeling, and retention.
- Assist with the development and implementation of data retention programs.
- Administer security awareness campaigns, phishing simulations, and reporting.
- Maintain IT compliance and security policies and coordinate periodic reviews.
- Review change requests for compliance, risk, data protection, and audit requirements, ensuring proper approvals and documentation.
- Assist with technology risk assessments, vendor security reviews, and client security questionnaires.
- Maintain risk and remediation registers and follow up with control owners.
- Prepare compliance reporting for IT leadership.
- Identify opportunities to automate compliance monitoring and evidence collection.
- Escalate significant control failures, risks, and policy exceptions.
What Were Looking For
- 4+ years of experience in IT GRC, IT audit, cybersecurity compliance, technology risk, SOC/SOX controls, or information security.
- Understanding of IT controls, audit evidence, and risk management concepts.
- Experience working within Microsoft 365 or similar enterprise technology environments.
- Strong organization, documentation, communication, and follow-through skills.
- Ability to work independently while coordinating across multiple teams.
Preferred Qualifications
- SOC 2 audit or readiness experience.
- Experience with Microsoft Purview, Entra ID, DLP, or data retention.
- Experience with access reviews or GRC/compliance platforms.
- Vendor or third-party risk experience.
- Security awareness program administration experience.
- Experience in accounting, financial services, professional services, or another environment handling sensitive client information.
- Security+, CISA, CRISC, CGRC, Microsoft security/compliance, or a similar certification, or an interest in pursuing one.