GRC Analyst/Specialist

SK Select Staffing, Inc.

New York (NY)

Hybrid

USD 90,000 - 120,000

Full time

14 days+
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

A prominent staffing agency is seeking a GRC Analyst/Specialist in New York City (hybrid work). The ideal candidate will have 4–5+ years of experience in information security and GRC, and possess a Bachelor’s degree in a relevant field. Responsibilities include enhancing the governance framework for North America, collaborating with international teams, and conducting compliance assessments. Excellent stakeholder management and analytical skills are crucial for success in this role.

Qualifications

  • 4–5+ years of experience in GRC, information security, or cybersecurity.
  • Hands-on experience implementing GRC frameworks, policies, procedures, and regulatory requirements.
  • Excellent analytical, communication, and stakeholder management skills.

Responsibilities

  • Build, operate, and continuously improve the information security governance framework for North America.
  • Collaborate with global teams to maintain the 'Global One' security standard.
  • Define, refine, and implement security risk assessment standards and processes.

Skills

GRC framework implementation
Risk management
Stakeholder management
Information security
Analytical skills

Education

Bachelor’s degree in Information Systems, Engineering, Business, Risk Management, or a related field

Tools

Security+
CRISC
CISSP
CISA
GSEC

Job description

GRC Analyst / Specialist - New York City (Hybrid Based)

Candidates must be located in the NY Metropiltan area with the ability to be in a NYC office 3 days per week.

If sponsorship is required, only H1B transfers will be considered.

Our client is a global leader in apparel and retail, with a portfolio of internationally recognized brands. The organization is in the midst of a significant digital transformation aimed at optimizing operations worldwide. As part of this evolution, the company is strengthening its global security posture and establishing a unified, enterprise-wide framework for secure system development and operations.

To support this initiative, we are seeking a GRC Analyst / Specialist to join the New York City team. As the business continues to expand across regions, building and maintaining a globally consistent governance, risk management, and compliance (GRC) framework has become a strategic priority.

This role will assess business processes, data flows, operational practices, and third-party relationships; identify and evaluate risk; and drive the implementation of effective governance and risk management controls. The GRC Analyst will work closely with business and IT stakeholders to advance practical, scalable, and compliant security initiatives across North America.

Department Overview:

The Information Security Office is responsible for safeguarding customer personal data and confidential corporate information, while ensuring that governance, risk, and compliance standards are applied consistently across the enterprise.

Operating as a global organization with a diverse, multinational team, the office defines and maintains enterprise-wide security and GRC policies, delivers training and awareness programs, and continuously monitors compliance across regions. The team leads global risk assessment and mitigation initiatives, working closely with business units, IT, legal, privacy, and regional security teams to ensure alignment with global standards and local regulatory requirements.

Role Overview:

This is an execution-focused GRC role responsible for advancing information security governance, risk management, compliance, privacy, and third-party risk management (TPRM) initiatives across North America (U.S. and Canada).

Working in close collaboration with global headquarters, the GRC Analyst will execute security initiatives aligned with the organization’s “Global One” security standard, while tailoring implementation to North American regulatory requirements (including CCPA/CPRA and PIPEDA) and regional business needs.

The role requires hands-on ownership of designing, implementing, and continuously improving security and GRC practices, with a high degree of autonomy. For candidates on a leadership trajectory, this position offers the opportunity to assume broader responsibility for regional GRC strategy and cross-functional execution as the North American security landscape evolves.

Key Responsibilities:
  • Build, operate, and continuously improve the information security governance framework for North America
  • Collaborate with global GRC and ISO teams to apply and maintain the “Global One” security standard regionally
  • Drive cross-functional security initiatives and projects across North America
  • Define, refine, and implement security risk assessment standards and processes
  • Assess business processes and data handling practices for compliance with local regulations (CCPA/CPRA, PIPEDA)
  • Review security controls for projects from a governance and process perspective
  • Translate technical and operational risks into business-impact scenarios
  • Assess vendor and partner security postures and manage remediation efforts through completion
  • Oversee PCI DSS compliance activities, including non-technical audit coordination and remediation tracking
  • Plan and deliver security and compliance training programs tailored to North American stakeholders
Education & Qualifications:
  • Bachelor’s degree in Information Systems, Engineering, Business, Risk Management, or a related field
  • Relevant certifications preferred (e.g., CRISC, CISSP, CISM, CISA, Security+, GSEC)
  • 4–5+ years of experience in GRC, information security, or cybersecurity
  • Hands-on experience implementing GRC frameworks, policies, procedures, and regulatory requirements
  • Strong understanding of enterprise and retail risk landscapes, including how threats and vulnerabilities translate into business risk
  • Excellent analytical, communication, and stakeholder management skills, with the ability to present complex concepts to non-technical audiences and senior leadership
  • Experience working cross-functionally with security engineers, system administrators, developers, legal, and privacy teams
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

GRC Lead – NA (Hybrid NYC)
GRC Lead – NA (Hybrid NYC)

SK Select Staffing, Inc. • New York (NY)

Hybrid
USD 90,000 - 120,000
GRC Analyst
GRC Analyst

NMC2 • Dallas (TX), Northern (KY)

Hybrid
USD 81,000 - 99,000
GRC Analyst
GRC Analyst

The Emery Company, LLC • Houston (TX)

On-site
USD 85,000 - 110,000
IT GRC Lead Analyst
IT GRC Lead Analyst

Westfield Insurance • Westfield Center (OH)

Hybrid
USD 90,000 - 120,000
GOVERNANCE, RISK, AND COMPLIANCE ANALYST
GOVERNANCE, RISK, AND COMPLIANCE ANALYST

Access Data Consulting Corporation • Phoenix (AZ)

Hybrid
USD 80,000 - 100,000
Sr. Security Engineer/Analyst (GRC)
Sr. Security Engineer/Analyst (GRC)

Insight Global • United States

Hybrid
USD 120,000 - 160,000
GRC Specialist (Governance, Risk & Compliance)
GRC Specialist (Governance, Risk & Compliance)

360CyberX • United States

On-site
USD 70,000 - 90,000
Analyst, Information Security GRC
Analyst, Information Security GRC

ICE • Provo (UT)

On-site
USD 85,000 - 115,000
Analyst, Information Security GRC
Analyst, Information Security GRC

ICE • Atlanta (GA)

On-site
USD 90,000 - 120,000
Analyst, Information Security GRC
Analyst, Information Security GRC

ICE • Jacksonville (FL)

On-site
USD 90,000 - 130,000