GRC Analyst

Benesch Law

Cleveland (OH)

Hybrid

USD 99,000 - 120,000

Full time

17 hours ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

Discretionary bonus
Comprehensive benefits package

Job summary

Benesch in Cleveland is seeking a GRC Analyst to join its expanding security team. You will drive governance, risk, and compliance activities across the firm, working with stakeholders to implement controls and ensure regulatory alignment.

The role requires 6+ years of information security experience, familiarity with ISO 27001, CIS, NIST CSF/800-53, and proficiency with GRC tools; a strong communicator who can translate technical controls into business context.

Qualifications

  • Six+ years in information security with governance, risk, and compliance experience.
  • Familiarity with ISO 27001, CIS, NIST CSF/800-53, GDPR, and HIPAA is preferred.
  • Experience supporting audits and regulatory examinations is a plus.

Responsibilities

  • Develops and maintains security and compliance policies and procedures.
  • Leads third-party risk management activities and vendor assessments.
  • Supports internal/external audits by coordinating evidence collection.
  • Produces risk and compliance reports and dashboards.

Skills

Analytical thinking
Documentation skills
Stakeholder management
Communication

Education

Bachelor's degree in Information Security, IT, or related field
CISA
CRISC
CGRC
Security+
ISO 27001 Internal Auditor
CISM

Tools

SIG
Archer
OneTrust
LogicGate
ZenGRC

Job description

Who We Are

At Benesch we pride ourselves on exceeding expectations and building trust not only with our clients but with our employees - Benesch's #1 asset. Committed to providing not only the highest level of legal service to our clients, Benesch also aspires to create a positive work environment for our employees. Our Firm continues to earn placement on Chicago and Cleveland's Top Workplaces list, along with Cleveland's NorthCoast 99 Top Workplaces rankings. We also continue to advance on the AmLaw 125 list, placing us among the top 125 law firms in the country.

Benesch is proud to be recognized for being a Firm that attracts and retains top talent - making Benesch a great place to work. We offer a hybrid schedule, career development and growth, transparent and visible leadership teams, and a place where diversity, equity and inclusion is celebrated. In addition, the Firm offers a full array of benefits which can be viewed at www.mybeneschbenefits.com.

Working with Us - Come and "Be Benesch!"

We are one of the fastest growing firms in the nation, and have offices in Chicago, Cleveland, Columbus, Miami, New York City, San Francisco, and Wilmington. We continue to expand our geographic footprint and value the talent that comprises each of our locations. If you are someone who champions a First in Service approach and are ready to be part of an exciting and growing Firm, we would invite you to apply to join our team.

Benesch is proud to announce the opening for a GRC Analyst in our Cleveland office! This position is hybrid and has work from home flexibility.

Position Summary

Are you an experience cybersecurity professional who has 6 or more years of working knowledge with GRC focused software platforms? Are you looking for a challenging opportunity to joining and cutting-edge, growing security division within a professional services organization? Then you may be interested in our GRC Analyst position. This role is perfect for the individual looking to be an essential part of a security team that focuses on supporting internal governance processes and developing policies and procedures. Join Benesch and play a pivotal role in shaping the success of our IT department.

Position Responsibilities
Governance
  • Develops, maintains, and updates security and compliance policies, standards, and procedures.
  • Supports internal governance processes, including document lifecycle management, policy reviews, and approvals.
  • Tracks and reports on compliance with internal control frameworks and policies.
Risk Management
  • Leads third-party risk management activities, including vendor assessments, evidence review, and continuous monitoring.
  • Conducts and documents risk assessments across business units, systems, and processes.
  • Maintains the enterprise risk register and ensures risks are properly categorized, scored, and remediated.
  • Partners with stakeholders to identify risk treatment options and tracks remediation activities.
Compliance
  • Assists with compliance efforts related to client obligations, outside counsel guidelines, and frameworks such as ISO 27001, CIS, SOC 2, NIST CSF/800-53, GDPR, HIPAA, PCI, or others relevant to the organization.
  • Collects, validates, and maintains evidence for internal/external audits.
  • Supports regulatory and certification audits by coordinating with internal teams and external auditors.
  • Monitors and reports on compliance gaps, exceptions, and corrective actions.
Security Awareness & Training
  • Helps develop and administer security awareness programs.
  • Supports phishing simulation campaigns and related analytics to track organizational improvement.
Monitoring & Reporting
  • Produces regular and ad-hoc reports on risk, compliance posture, and control effectiveness.
  • Utilizes GRC tools (e.g., SIG, Archer, OneTrust, LogicGate, ZenGRC) to manage workflows and dashboards.
  • Tracks KPIs/KRIs to measure program maturity and effectiveness.
Qualifications

The GRC Analyst requires a bachelor's degree in Information Security, Cybersecurity, Information Technology, Business, or a related field, or equivalent professional experience. A minimum of six years' experience is required for this position. The GRC Analyst has a foundational understanding of cybersecurity principles and risk management, knowledge of compliance frameworks such as ISO 27001, CIS, and NIST, strong analytical and documentation skills, and excellent communication and stakeholder management abilities. Preferred qualifications include experience with GRC software platforms; CISA, CRISC, CGRC, Security+, ISO 27001 Internal Auditor, or CISM certification, whether in progress or completed; and experience supporting audits or risk assessments in a regulated environment.

Key attributes for this role include being detail-oriented, organized, collaborative, and proactive, with the ability to manage multiple priorities. Able to work effectively with technical and non-technical teams, translate technical controls into business context, and take ownership of assigned tasks.ted and proactive, with a strong commitment to accuracy, follow-through and continuous improvement. The Specialist should also demonstrate professional presence, sound judgment and discretion in handling sensitive information, along with curiosity and strategic interest in legal market recognition, competitive positioning and process improvement.

The salary range for this position is $99K to $120K.

Please note that quoted salary ranges are based on Benesch's good faith belief at the time of the job posting and are not a guarantee of what final salary offers may be. Base pay is based on market location and may vary depending on job-related knowledge, skills, and experience. Base pay is only one part of the Total Rewards that Benesch provides to compensate and recognize our staff professionals for their work. Full-time positions are eligible for a discretionary bonus and a comprehensive benefits package.

Benesch is an equal opportunity employer. We strongly value and encourage diversity and solicit applications from all qualified applicants without regard to race, color, gender, sex, age, religion, creed, national origin, ancestry, citizenship, marital status, sexual orientation, physical or mental disability (where applicant is qualified to perform the essential functions of the job with or without reasonable accommodations), medical condition, protected veteran status, gender identity, genetic information, or any other characteristic protected by federal, state, or local law.

Applicants who are interested in applying for a position and require special assistance or an accommodation during the process due to a disability should contact the Benesch Human Resources Department by phone at 216-363-4578 or email at cwatson@beneschlaw.com.

Salary: $99000 - $120000 per year

Job Posted by ApplicantPro

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Analyst
GRC Analyst

Benesch, Friedlander, Coplan & Aronoff • Chicago (IL)

On-site
USD 109,000 - 131,000
Hybrid schedule
Comprehensive benefits
GRC Analyst
GRC Analyst

beneschlaw • Chicago (IL)

Hybrid
USD 109,000 - 131,000
Discretionary bonus
Comprehensive benefits package
GRC Analyst
GRC Analyst

beneschlaw • Cleveland (OH)

Hybrid
USD 99,000 - 120,000
Hybrid schedule
GRC Analyst
GRC Analyst

Benesch, Friedlander, Coplan & Aronoff • Cleveland (OH)

On-site
USD 99,000 - 120,000
Hybrid schedule
Benefits package
SOC/Incident Response Engineer
SOC/Incident Response Engineer

beneschlaw • Chicago (IL)

Hybrid
USD 112,000 - 139,000
GRC Analyst - Hybrid: Risk, Compliance & Security
GRC Analyst - Hybrid: Risk, Compliance & Security

Benesch Law • Cleveland (OH)

Hybrid
USD 99,000 - 120,000
Discretionary bonus
Comprehensive benefits package
Human Resources Generalist
Human Resources Generalist

Benesch, Friedlander, Coplan & Aronoff • Cleveland (OH)

Hybrid
USD 77,000 - 95,000
Comprehensive benefits package
Discretionary bonus
IT Sr. Systems Engineer
IT Sr. Systems Engineer

Benesch, Friedlander, Coplan & Aronoff • Cleveland (OH)

On-site
USD 89,000 - 107,000
Comprehensive benefits package
Discretionary bonus
Hybrid GRC Analyst: Risk, Compliance & Security Strategy
Hybrid GRC Analyst: Risk, Compliance & Security Strategy

beneschlaw • Cleveland (OH)

Hybrid
USD 99,000 - 120,000
Hybrid schedule
Client Operations & LPM Analyst
Client Operations & LPM Analyst

Benesch, Friedlander, Coplan & Aronoff • Cleveland (OH)

Hybrid
USD 94,000 - 120,000
Comprehensive benefits package
Discretionary bonus
Career development opportunities