GRC Analyst I

Sub-Zero Group, Inc.

Madison (WI)

On-site

USD 60,000 - 80,000

Full time

14 days+
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Competitive compensation
Health, dental & vision plans
401(k) with profit sharing
Paid time off (PTO)
Parental leave
On-site health clinic
Education assistance
Employee discounts
Employee Assistance Program (EAP)

Job summary

The GRC Analyst I at Sub-Zero Group, Inc. supports the Governance, Risk, and Compliance program through risk assessments, risk register maintenance, control evaluations, and policy management.

This role collaborates with IT Security, Legal, Data Governance, and business stakeholders to promote responsible technology use and organizational resilience. Based at Sub-Zero Group's Fitchburg, Wisconsin headquarters, the position also supports emerging AI governance initiatives, risk reporting,

Qualifications

  • Strong analytical, organizational, and communication skills.
  • Experience in risk management, governance, compliance, auditing, or related disciplines is preferred.
  • Familiarity with NIST CSF, NIST AI RMF, ISO standards, or similar frameworks is a plus.

Responsibilities

  • Assist with risk assessment activities and document risks.
  • Maintain the risk register and track remediation actions.
  • Support policy governance and AI governance documentation and monitoring.
  • Develop dashboards, metrics, KPIs, and executive reporting of risk exposure.

Skills

Analytical skills
Organizational skills
Communication skills

Education

Bachelor’s or Associate’s degree in risk management

Job description

Job Overview

The GRC Analyst I is responsible for supporting the organization's Governance, Risk, and Compliance (GRC) program through risk management, policy governance, compliance monitoring, reporting, and continuous improvement activities. This role assists with risk assessments, maintenance of the risk register, control evaluations, mitigation tracking, policy management, and compliance-related activities that help protect the organization and enable business objectives.

Job Overview

The GRC Analyst I is responsible for supporting the organization's Governance, Risk, and Compliance (GRC) program through risk management, policy governance, compliance monitoring, reporting, and continuous improvement activities. This role assists with risk assessments, maintenance of the risk register, control evaluations, mitigation tracking, policy management, and compliance-related activities that help protect the organization and enable business objectives. The GRC Analyst I also supports emerging AI Governance initiatives by assisting with the identification, assessment, monitoring, and reporting of risks associated with artificial intelligence technologies. Working closely with IT Security, Legal, Business Continuity, Data Governance, and business stakeholders, this position helps promote responsible technology use, organizational resilience, and a risk-aware culture that enables the business to move faster with greater confidence. This is a full-time position based at Sub-Zero Group's headquarters in Fitchburg, Wisconsin, just outside Madison.

Job Responsibilities

Responsibilities include, but are not limited to:

Governance
  • Assist with policy governance activities, including the development, maintenance, review, and administration of policies, standards, procedures, and related governance documentation, while providing guidance to employees and business units on their application.
  • Support the organization's AI Governance program through documentation, inventories, risk assessments, stakeholder coordination, and monitoring activities that promote the responsible, secure, and compliant use of AI technologies.
  • Help maintain alignment with governance frameworks and industry standards, including NIST CSF, NIST AI RMF, and ISO standards, while assessing governance implications of new technologies, AI initiatives, business process changes, and emerging regulatory requirements.
Risk Management
  • Support risk assessment activities by gathering information, documenting risks, facilitating stakeholder discussions, evaluating inherent and residual risk, and tracking follow-up actions and remediation activities.
  • Maintain the risk register, including risk documentation, ownership assignments, risk scoring, review cadences, mitigation plans, control effectiveness evaluations, and reporting activities.
  • Partner with risk owners to evaluate risk events, root causes, business impacts, existing controls, and risk response strategies while developing dashboards, metrics, KPIs, and executive reporting that communicate organizational risk exposure and program maturity.
Compliance
  • Monitor compliance with internal policies, regulatory requirements, contractual obligations, and applicable industry standards while supporting assessments against relevant governance and compliance frameworks.
  • Assist with compliance reviews, internal audits, and audit readiness activities by collecting evidence, validating controls, documenting findings, maintaining records, and tracking remediation activities through resolution.
  • Track and report compliance metrics, audit findings, governance performance indicators, corrective actions, and overall program effectiveness and maturity.
Additional Opportunities
  • Business Continuity & Resilience: Participate in business continuity, IT disaster recovery, crisis management, resilience planning, business impact analyses, exercises, and improvement activities in support of organizational resilience efforts.
  • Third-Party Risk Management: Assist with vendor due diligence, third-party governance activities, and ongoing monitoring efforts as the organization's third-party risk management capabilities evolve and mature.
  • Awareness, Training & Risk Culture: Contribute to governance, risk, compliance, cybersecurity, and responsible AI awareness initiatives through the development of training materials, communications, workshops, and other educational opportunities that promote a culture of accountability and risk-informed decision‑making.
Required Qualifications
  • Associate’s or Bachelor's degree in enterprise risk management, information technology, cybersecurity, business administration, finance, accounting, or related field.
  • 0-3 years of relevant experience in risk management, governance, compliance, auditing, or related disciplines.
  • Strong analytical, organizational, and communication skills.
Preferred Qualifications
  • Experience supporting risk assessments, maintaining risk registers, or tracking remediation activities.
  • Experience supporting policy management, compliance reviews, control assessments, or audit activities.
  • Familiarity with NIST CSF, NIST AI RMF, ISO 27001, ISO 31000, ISO 22301, or similar frameworks.
  • Familiarity with regulations and standards such as CCPA/CPRA, GDPR, PCI DSS, or similar requirements.
  • Relevant certifications or progress toward certification, such as ISC2 CC, Security+, CISA, CRISC, CGRC, or similar credentials.
Why Join Sub-Zero Group?

Join a growing Governance, Risk, and Compliance program that is helping embed governance, risk management, compliance, and resilience into the fabric of the organization. This role offers a unique opportunity to help shape and mature a developing GRC program while gaining hands-on experience across technology risk management, cybersecurity governance, compliance, policy management, internal audit, and business continuity. Working closely with organizational leaders, you will have a direct impact on strengthening the company's ability to reliably achieve its objectives, address uncertainty, build resilience, and act with integrity.

We Value Our Employees By Providing
  • Competitive compensation based on skills
  • Industry leading health, dental, and vision plans
  • Generous 401(k) savings and profit sharing
  • 10 Paid Holidays
  • Paid Time Off (PTO)
  • Parental Leave
  • On-site UW Health clinic, fitness center, and walking paths
  • Education assistance and internal training programs
  • Employee discount program
  • Employee Assistance Program (EAP)
  • Electric vehicle charging
  • Department & Company-wide social events

This position requires a pre‑employment drug/alcohol test and background check, which will be administered after a conditional job offer is extended. A negative drug/alcohol test result is required for employment. Refusal to take the test or a positive result may disqualify a candidate from further consideration. All drug testing will be conducted in accordance with federal and state laws.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Analyst I
GRC Analyst I

Sub-Zero, Inc. • Madison (WI)

On-site
USD 55,000 - 85,000
Health insurance
401(k) plan
Paid time off
+2
GRC Analyst I: AI Governance & Risk Assurance
GRC Analyst I: AI Governance & Risk Assurance

Sub-Zero, Inc. • Madison (WI)

On-site
USD 55,000 - 85,000
Health insurance
401(k) plan
Paid time off
+2
Vice President, IT Governance, Risk & Compliance
Vice President, IT Governance, Risk & Compliance

Northwestern Mutual • Milwaukee (WI)

On-site
USD 220,000 - 330,000
Flexible work schedules
Concierge service
Comprehensive benefits
+1
GRC Security Administrator
GRC Security Administrator

ManpowerGroup Global, Inc. • Brownsville (WI)

On-site
USD 95,000 - 110,000
Manager, IT Security, Governance, Risk and Compliance
Manager, IT Security, Governance, Risk and Compliance

Burlington Stores, Inc. • Beverly (NJ)

Hybrid
USD 115,000 - 150,000
Medical, dental, and vision coverage
Paid time off and holidays
401(k) plan
GRC Manager
GRC Manager

Valence • United States

Hybrid
USD 130,000 - 190,000
WFH stipend
Phone stipend
Workspace support
Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

Delta Dental of Missouri • Missouri

Hybrid
USD 80,000 - 100,000
Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

Delta-Denta • St. Louis (MO)

Hybrid
USD 75,000 - 110,000
Manager - IT Governance, Risk and Compliance Neenah, WI IT Mgmt Posted 20 hours ago
Manager - IT Governance, Risk and Compliance Neenah, WI IT Mgmt Posted 20 hours ago

Plexus Corp. • Neenah (WI)

On-site
USD 130,000 - 194,000
Manager, Governance, Risk and Compliance
Manager, Governance, Risk and Compliance

Path Robotics • Columbus (OH)

On-site
USD 100,000 - 130,000
Daily free lunch
Flexible PTO
Comprehensive medical, dental, and vision coverage
+3