IT GRC Lead Analyst

Westfield Insurance

Westfield Center (OH)

Hybrid

USD 130,000 - 170,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Westfield Insurance is seeking a GRC Lead Analyst to steer the design, implementation, and continuous improvement of the IT governance, risk, and compliance programs. This role partners with business and technology leaders to align with enterprise objectives and fosters a risk-aware culture.

The ideal candidate has deep expertise in governance frameworks, regulatory compliance, IT controls, and cybersecurity governance, with a track record of leading enterprise-wide initiatives and mentoring

Qualifications

  • 7+ years of experience in IT Governance, Risk, and Compliance or related fields.
  • Bachelor’s degree in Information Technology, Cybersecurity, Information Systems, Risk Management, Business, or related field.
  • Strong knowledge of regulatory requirements and industry standards.

Responsibilities

  • Lead the development, execution, and continuous improvement of the enterprise IT GRC program.
  • Serve as SME for IT governance, risk management, compliance, and control oversight.
  • Lead enterprise technology risk assessments and provide risk-based recommendations.
  • Drive maturity of risk management practices through governance enhancements.
  • Oversee regulatory compliance and internal policy implementation of controls.
  • Establish IT control frameworks including ITGCs and cybersecurity controls.
  • Lead audits, regulatory examinations, and remediation governance.
  • Champion GRC processes and technologies to improve efficiency.
  • Develop executive reporting and dashboards on risk, compliance, audit results, and remediation activities.

Skills

IT governance
Regulatory compliance
Risk management
Cybersecurity governance
Leadership

Education

Bachelor's degree in Information Technology, Cybersecurity, or related field

Tools

GRC platforms
Policy management tools
IT risk assessment tools
Audit management

Job description

Job Summary

The IT Governance, Risk, and Compliance (GRC) Lead Analyst serves as a subject matter expert responsible for leading the design, implementation, maturity, and continuous improvement of the organization’s IT governance, risk management, and compliance programs. This role provides strategic oversight of technology risk and control management, partners with business and technology leaders to ensure alignment with enterprise objectives and drives a proactive risk‑aware culture across the organization. The GRC Lead Analyst serves as a trusted advisor to senior leadership, influencing risk‑based decision‑making and ensuring compliance with regulatory requirements, industry standards, and internal policies.

The ideal candidate possesses deep expertise in governance frameworks, regulatory compliance, IT controls, risk management, audit practices, and cybersecurity governance, along with demonstrated leadership in driving enterprise‑wide initiatives and mentoring others.

Applicants must be currently authorized to work in the United States on a full-time basis without employer sponsorship.

Job Responsibilities
  • Lead the development, execution, and continuous improvement of the enterprise IT Governance, Risk, and Compliance (GRC) program, frameworks, and operating model.
  • Serve as the organization's subject matter expert for IT governance, risk management, compliance, and control oversight.
  • Lead enterprise technology risk assessments and provide risk‑based recommendations aligned with business objectives and risk appetite.
  • Drive the maturity of risk management practices through governance enhancements, process optimization, and industry best practices.
  • Oversee compliance with regulatory requirements, industry standards, and internal policies, ensuring effective implementation of controls and monitoring mechanisms.
  • Establish and maintain IT control frameworks, including ITGCs, cybersecurity controls, and key risk indicators (KRIs).
  • Lead control assessments, testing, continuous monitoring, and remediation efforts to strengthen the organization's control environment.
  • Serve as the primary liaison for internal and external audits, regulatory examinations, and issue remediation governance.
  • Lead third‑party technology risk management activities, including vendor assessments and ongoing risk oversight.
  • Champion the implementation, optimization, and automation of GRC processes and technologies to improve efficiency and effectiveness.
  • Develop and deliver executive‑level reporting, dashboards, and insights on risk, compliance, audit results, and remediation activities.
  • Lead cross‑functional GRC initiatives, influence strategic decision‑making, and mentor team members to foster a culture of risk awareness and continuous improvement.
Job Qualifications
  • 7+ years of experience in IT Governance, Risk, and Compliance, Information Security, IT Audit, or related disciplines.
  • Bachelor's degree in Information Technology, Cybersecurity, Information Systems, Risk Management, Business, or related field.
Location

Hybrid defined as three (3) or more days per week in the office.

Licenses And Certifications
  • CISSP
  • CISA
  • CRISC
  • CISM
  • CGEIT
Behavioral Competencies
  • Collaborates
  • Communicates Effectively
  • Customer Focus
  • Decision Quality
  • Nimble Learning
Technical Skills
  • Insurance Industry Knowledge
  • Regulatory Examinations
  • GRC Platforms
  • Policy Management
  • Compliance Automation Tools
  • IT Risk Assessment
  • Control Design
  • Security Testing

This job description describes the general nature and level of work performed in this role. It is not intended to be an exhaustive list of all duties, skills, responsibilities, knowledge, etc. These may be subject to change and additional functions may be assigned as needed by management.

Equal Opportunity Employer

United States: All applicants receive consideration for employment without regard to race, color, sex, religion, national origin, age, sexual orientation, gender identity, disability, or status as a protected veteran.

United Kingdom: Westfield is committed to equality of opportunity for all staff and applications from individuals are encouraged regardless of age, disability, sex, gender reassignment, sexual orientation, pregnancy and maternity, race, religion or belief and marriage and civil partnerships.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

IT GRC Lead Analyst
IT GRC Lead Analyst

Ohio Farmers Insurance Company • Westfield Center (OH)

Hybrid
USD 90,000 - 120,000
IT GRC Lead Analyst
IT GRC Lead Analyst

Jobtailor • Westfield Center (OH)

On-site
USD 120,000 - 190,000
Lead GRC Analyst (IT/Security)
Lead GRC Analyst (IT/Security)

Ultra Clean Technology • Manor (TX)

On-site
USD 90,000 - 120,000
Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

Delta-Denta • St. Louis (MO)

Hybrid
USD 75,000 - 110,000
Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

Delta Dental of Missouri • Missouri

Hybrid
USD 80,000 - 100,000
IT GRC Analyst
IT GRC Analyst

Radiant Systems Inc • Andover (MA)

On-site
USD 90,000 - 120,000
Lead GRC Analyst (IT/Security)
Lead GRC Analyst (IT/Security)

Ultra Clean Technology • Austin (TX)

On-site
USD 80,000 - 100,000
GRC Analyst
GRC Analyst

The Emery Company, LLC • Houston (TX)

On-site
USD 85,000 - 110,000
IT Governance Risk & Compliance (GRC) Analyst
IT Governance Risk & Compliance (GRC) Analyst

Trustmark • Ridgeland (MS)

Hybrid
USD 65,000 - 85,000
IT Governance Risk & Compliance (GRC) Analyst
IT Governance Risk & Compliance (GRC) Analyst

Trustmark Bank • Ridgeland (MS)

Hybrid
USD 60,000 - 80,000