This role is with a DeWinter Investment Management Partner
Boston, MA - Hybrid Role - We are targeting local candidates that can be in the Boston office 3 days per week.
12 Month + contract (or contract to hire, if desired)
Candidate Profile
We are looking for someone who can operate independently and execute effectively. The successful consultant will be comfortable gathering information from subject-matter experts, challenging incomplete responses, organizing evidence, interacting with auditors, managing competing deadlines, and driving issues through resolution.
The role requires strong attention to detail while maintaining a practical, risk-based approach appropriate for an enterprise financial services environment.
Position Overview
We are seeking an experienced GRC Analyst to support the Governance, Risk, and Compliance function for a leading financial services organization.
This is a hands-on consulting role focused on client and operational due diligence, audit and control support, risk management, policy governance, and third-party risk. The individual will work closely with Information Security, Technology, Legal and Compliance, Internal Audit, Operations, and client-facing teams.
The ideal candidate is a pragmatic, detail-oriented GRC professional who can independently manage multiple requests, work effectively with technical and business stakeholders, and translate security and technology controls into clear responses for clients, auditors, and external parties.
Key Responsibilities
- Coordinate and prepare responses to RFPs, RFIs, Due Diligence Questionnaires (DDQs), Operational Due Diligence (ODD) requests, and other client or prospect security and technology risk inquiries.
- Partner with subject‑matter experts to develop accurate responses and maintain reusable, approved security and technology due‑diligence content.
- Support third‑party assurance examinations (e.g., SOC 1, SOC 2, and internal/external audits), including evidence collection, auditor requests, control‑owner coordination, and remediation tracking.
- Support IT control frameworks and regulatory compliance activities, including control documentation, evidence collection, testing coordination, issue management, and remediation.
- Maintain and enhance GRC processes, including risk registers, control inventories, audit findings, remediation tracking, policies, standards, exceptions, and supporting evidence.
- Conduct and coordinate technology, cybersecurity, information‑security, and operational risk assessments and work with control owners to address identified gaps.
- Support third‑party risk management, including vendor security assessments, SOC report reviews, risk documentation, and ongoing monitoring.
- Support governance and oversight of data protection and information‑security controls, including control requirements, risk assessments, metrics, exceptions, and remediation.
- Develop clear risk, audit, control, and remediation reporting for management and key stakeholders.
- Identify opportunities to automate and streamline GRC, audit, evidence‑collection, and due‑diligence processes.
Qualifications
- 3–6 years of relevant experience in GRC, information security, technology risk, IT audit, operational risk, or a related discipline.
- Demonstrated experience responding to RFPs, DDQs, ODD requests, client security questionnaires, or similar due‑diligence requests.
- Experience supporting internal and external audits, control assurance activities, or regulatory compliance testing.
- Working knowledge of risk assessments, control design and testing, issue and remediation management, and policy governance.
- Familiarity with security and control frameworks such as NIST CSF, ISO 27001, SOC, COBIT, CIS Controls, or similar frameworks.
- Familiarity with third‑party security and technology risk assessments.
- Strong written and verbal communication skills, with the ability to work effectively with technical teams, business stakeholders, auditors, and client‑facing teams.
- Strong organizational skills and the ability to independently manage multiple concurrent questionnaires, audits, assessments, and remediation activities.
- Experience within financial services, asset management, or another highly regulated industry is required.
Preferred Qualifications
- Relevant certifications such as CISA, CRISC, CISM, CISSP, CIA, Security+, or ISO 27001.
- Experience with GRC platforms, questionnaire‑management tools, workflow/ticketing systems, or reporting and automation tools.
- Familiarity with information protection and data governance frameworks.
- Experience improving or automating manual GRC and due‑diligence processes.