Senior GRC Analyst

Wolfe,-LLC-1

Pittsburgh (Allegheny County)

On-site

USD 114,000 - 163,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

RSUs
Profit Sharing
Medical Insurance
Dental Insurance
Vision Insurance
PTO
401(k)
Tuition Reimbursement

Job summary

Wolfe, a Pittsburgh-based FinTech, seeks a Senior GRC Analyst to own control and evidence work for PCI DSS Level 1, SOC 2 Type II readiness, IT general controls, and third‑party risk assessments. You will collaborate with QSA and auditors, guiding governance as AI integrates into products and processes.

This 5‑day onsite role requires senior contributor expertise. You will craft control narratives, lead evidence collection, and drive remediation with cross‑functional teams, reporting to

Qualifications

  • 7+ years in GRC, IT audit, or information security compliance.
  • Experience supporting PCI DSS in Level 1 env.
  • Experience with SOC 2 Type II examinations and ITGC controls.

Responsibilities

  • Lead PCI DSS Level 1 and SOC 2 Type II readiness end-to-end.
  • Own IT general controls: change mgmt, access, SDLC, backups.
  • Manage issues lifecycle and risk remediation tracking.
  • Execute third-party risk assessments and vendor reviews.
  • Administer GRC platform mappings and automated evidence collection.

Skills

GRC
IT Audit
PCI DSS
SOC 2
ITGC
Vendor Risk
Regulated FS
QSA coordination

Education

CISA Certification
CRISC Certification
CISSP Certification

Tools

Vanta
Drata
Secureframe
ServiceNow IRM
AuditBoard

Job description

Senior GRC Analyst

Department: Compliance & Fraud

Employment Type: Full Time

Location: Pittsburgh Onsite

Compensation: $114,000 - $163,000 / year

Description
Role Summary

Wolfe is a Pittsburgh-based FinTech company operating consumer gifting and payments brands, and we are actively embedding AI across our products, our internal processes, and the way our teams work day-to-day. As Senior GRC Analyst, you will be the hands-on owner of the control and evidence work behind our PCI DSS Level 1 service provider obligations, our SOC 2 Type II readiness, our IT general controls, our NIST CSF 2.0 maturity program, and our third-party risk assessments. This is a deliberately senior individual contributor role — you will operate with minimal oversight, work directly with our QSA and external auditors, and serve as the compliance advisor engineering, fraud, and product teams come to before they build. You will also help us define how governance keeps pace with AI adoption, including the controls and review process for AI use across the company. This is a 5-day onsite role in Pittsburgh, PA.

Responsibilities
  • Run our annual PCI DSS v4.0.1 Level 1 service provider assessment and SOC 2 Type II examination end to end — scope validation, evidence collection, QSA and auditor coordination, gap remediation tracking, and support for sponsor bank and processor due diligence requests.
  • Own IT general control readiness across change management, logical access, SDLC, and backup and job scheduling — documenting control narratives, walking auditors through the environment, and performing internal design and operating-effectiveness testing so that external testing produces no surprises.
  • Own the issues management lifecycle under our Issues Management Policy — intake, risk rating, remediation tracking, closure evidence, and recurring reporting to leadership and the Audit Committee.
  • Execute third-party risk assessments across our vendor portfolio, including security questionnaire review, contract security and PCI terms review, and ongoing monitoring of critical vendors.
  • Administer our GRC platform — control library and cross-framework mappings across PCI, SOC 2, and ITGC, automated evidence collection, control owner workflows, and compliance dashboards.
Impact Statement
  • Take over evidence collection for the current PCI DSS v4.0.1 assessment cycle and deliver a QSA‑accepted evidence package for your assigned requirement families, with an aging report showing zero overdue evidence requests at the 120‑day mark.
  • Deliver a SOC 2 Type II readiness assessment covering the full ITGC population — change management, logical access, SDLC, and backup and recovery — including written control narratives, identified design gaps, and a remediation plan sized to close before the audit period opens.
  • Complete a refreshed assessment of the governance function and deliver a prioritized remediation plan covering the lowest‑scoring subcategories, with owners, target dates, and a defined scoring path from current to target maturity.
  • Migrate all open compliance and audit findings into a single issues register in the GRC platform — each item risk‑rated, owner‑assigned, and due‑dated — and publish the first monthly issues report to the IT Steering Committee.
Qualifications
  • 7+ years in GRC, IT audit, or information security compliance, including at least 3 years directly supporting PCI DSS in a Level 1 service provider or equivalent payment card environment; CISA, CRISC, CISSP, PCIP, or ISA certification preferred but not required.
  • Demonstrated experience preparing for and supporting SOC 2 Type II examinations, including designing, documenting, and testing IT general controls across change management, logical access, and the software development lifecycle.
  • Working depth in IT governance, with proven ability to translate control requirements into testable evidence that an external assessor accepts without rework.
  • Hands‑on experience administering a GRC platform (Vanta, Drata, Secureframe, ServiceNow IRM, AuditBoard, or similar) — control mapping, automated evidence collection, and reporting.
  • Track record running third‑party risk assessments end to end, including reviewing security and compliance terms in vendor contracts.
  • Experience in a regulated financial services environment answering to external parties — sponsor banks, processors, regulators, or internal audit — and producing deliverables for executive and board audiences.
Compensation, Benefits, and Perks

Wolfe is committed to providing a comprehensive benefits package to support your well‑being, along with competitive compensation. Our benefits and perks include but not limited to:

  • Restricted Stock Units (RSUs)
  • Profit Share
  • Medical, Prescription, Vision, and Dental insurance for employees and dependents (Wolfe pays 80% of premium)
  • Short‑Term Disability Insurance (Wolfe pays 100% of premium)
  • Voluntary Long‑Term Disability Insurance, Life Insurance, Critical Illness Insurance, Accident Insurance, and Hospital Indemnity coverage
  • PTO (vacation and sick time)
  • Corporate Holidays and Floating Holidays
  • 401(k)
  • Employee recognition program
  • Charitable Donation to a charity of your choice yearly
  • Employee Referral Bonus
  • Tuition Reimbursement
  • Internal Training and Information sessions
  • Family Picnic, Holiday Party, and other outings
  • Internal Culture Club
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior GRC Analyst
Senior GRC Analyst

Wolfe, LLC • Pittsburgh

On-site
USD 114,000 - 163,000
RSUs
Profit Sharing
Medical insurance (employee + depend.)
+8
Software Security Engineer
Software Security Engineer

Wolfe, LLC • Pittsburgh

On-site
USD 110,000 - 120,000
Restricted Stock Units (RSUs)
Profit Share and/or Incentive Bonus
Medical, Prescription, Vision, and Dental insurance
+3
Senior GRC Analyst: PCI/SOC 2 Lead (Pittsburgh Onsite)
Senior GRC Analyst: PCI/SOC 2 Lead (Pittsburgh Onsite)

Wolfe, LLC • Pittsburgh

On-site
USD 114,000 - 163,000
RSUs
Profit Sharing
Medical insurance (employee + depend.)
+8
Senior GRC Analyst: PCI & SOC 2 Compliance Lead – Onsite
Senior GRC Analyst: PCI & SOC 2 Compliance Lead – Onsite

Wolfe,-LLC-1 • Pittsburgh

On-site
USD 114,000 - 163,000
RSUs
Profit Sharing
Medical Insurance
+5
Senior Vice President, Product Management
Senior Vice President, Product Management

Telos Gifting LLC • Pittsburgh

On-site
USD 210,000 - 250,000
Restricted Stock Units (RSUs)
Profit Share
Management Incentive Plan
+7
VP, Data Platform and Knowledge
VP, Data Platform and Knowledge

Wolfe, LLC • Pittsburgh

On-site
USD 200,000 - 226,000
Restricted Stock Units (RSUs)
Incentive Bonus
Profit Share
+4
Senior Digital Marketing Manager
Senior Digital Marketing Manager

Wolfe, LLC • Pittsburgh

On-site
USD 100,000 - 140,000
RSUs
Profit sharing
Health insurance
+1
Senior GRC Analyst I, SOC 1 & SOC 2
Senior GRC Analyst I, SOC 1 & SOC 2

Sensiba LLP • California (MO)

On-site
USD 66,400 - 101,000
Comprehensive Health Coverage
Retirement & Financial Planning
Generous Paid Time Off
+5
Senior Security Assurance Analyst
Senior Security Assurance Analyst

United States Digital Space LLC • New York (NY)

On-site
USD 120,000 - 190,000
Medical, dental, and vision insurance
Mental health benefits
401(k) plan with company match
+2
GRC Analyst - Hybrid AZ
GRC Analyst - Hybrid AZ

Best Western Hotels & Resorts • Arizona

Hybrid
USD 110,000 - 160,000
Medical/Dental/Vision
Vacation/Sick accruals
401K matching
+3