Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.
GRC Analyst / Specialist - New York City (Hybrid Based)
Candidates must be located in the NY Metropiltan area with the ability to be in a NYC office 3 days per week.
If sponsorship is required, only H1B transfers will be considered.
Our client is a global leader in apparel and retail, with a portfolio of internationally recognized brands. The organization is in the midst of a significant digital transformation aimed at optimizing operations worldwide. As part of this evolution, the company is strengthening its global security posture and establishing a unified, enterprise-wide framework for secure system development and operations.
To support this initiative, we are seeking a GRC Analyst / Specialist to join the New York City team. As the business continues to expand across regions, building and maintaining a globally consistent governance, risk management, and compliance (GRC) framework has become a strategic priority.
This role will assess business processes, data flows, operational practices, and third-party relationships; identify and evaluate risk; and drive the implementation of effective governance and risk management controls. The GRC Analyst will work closely with business and IT stakeholders to advance practical, scalable, and compliant security initiatives across North America.
The Information Security Office is responsible for safeguarding customer personal data and confidential corporate information, while ensuring that governance, risk, and compliance standards are applied consistently across the enterprise.
Operating as a global organization with a diverse, multinational team, the office defines and maintains enterprise-wide security and GRC policies, delivers training and awareness programs, and continuously monitors compliance across regions. The team leads global risk assessment and mitigation initiatives, working closely with business units, IT, legal, privacy, and regional security teams to ensure alignment with global standards and local regulatory requirements.
This is an execution-focused GRC role responsible for advancing information security governance, risk management, compliance, privacy, and third-party risk management (TPRM) initiatives across North America (U.S. and Canada).
Working in close collaboration with global headquarters, the GRC Analyst will execute security initiatives aligned with the organization’s “Global One” security standard, while tailoring implementation to North American regulatory requirements (including CCPA/CPRA and PIPEDA) and regional business needs.
The role requires hands-on ownership of designing, implementing, and continuously improving security and GRC practices, with a high degree of autonomy. For candidates on a leadership trajectory, this position offers the opportunity to assume broader responsibility for regional GRC strategy and cross-functional execution as the North American security landscape evolves.