Senior GRC Analyst: Build SOC 2 & CSF (Hybrid)

Gosnaphop

Chicago (IL)

Hybrid

USD 115,000 - 125,000

Part time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Medical and prescription drug coverage
Dental insurance
Vision insurance
Health Savings Account (HSA)
Flexible Spending Accounts (FSA)
Short-Term Disability Insurance
Long-Term Disability Insurance
Supplemental Life Insurance
401(k)
Weekly pay

Job summary

Addison Group is seeking a Senior GRC Analyst in a hybrid Chicago setting to build and mature its information security GRC program. You will drive SOC 2 readiness, lead risk assessments, manage policy lifecycle, and apply NIST CSF 2.0 across governance, risk, and compliance.

The role is contract-to-hire, with an ASAP start, reporting to Information Security leadership in downtown Chicago. You will collaborate with stakeholders across IT, Legal, Privacy, and HR, mentoring another GRC resource

Qualifications

  • 5+ years of experience in Information Security, GRC, IT Risk, Security Compliance, Audit, or a related discipline.
  • Strong hands-on experience with SOC 2 compliance and readiness.
  • Experience taking meaningful ownership of SOC 2 activities—not solely collecting audit evidence.
  • Experience coordinating controls, evidence, findings, remediation, and audit activities.
  • Demonstrated experience leading security risk assessments.
  • Experience identifying and evaluating control gaps.
  • Hands-on experience developing and maintaining risk registers.
  • Experience developing risk-treatment and remediation plans.
  • Ability to drive identified risks and remediation items through closure.
  • Strong experience developing, reviewing, and maintaining information security policies, standards, and procedures.
  • Practical experience applying NIST CSF.
  • Experience performing security maturity and/or gap assessments.
  • Demonstrated ability to operate successfully within an evolving or immature GRC environment.
  • Ability to create effective processes when mature tools or established workflows do not already exist.
  • Strong project-management and organizational skills.
  • Ability to manage multiple concurrent GRC initiatives.
  • Strong analytical and problem-solving capabilities.
  • Excellent written and verbal communication.
  • Ability to communicate effectively with technical teams, non-technical business stakeholders, and senior leadership.
  • Bachelor's degree in a relevant discipline or equivalent practical experience.

Responsibilities

  • SOC 2, Compliance & Audit: Strengthen and drive SOC 2 readiness program; coordinate audit requests and evidence; perform control testing and validation; track findings and remediation; work with auditors and stakeholders.
  • Enterprise Risk Management: Maintain enterprise information security risk register; lead risk assessments; perform control-gap analyses and maturity assessments; translate risks for leadership.
  • Governance & NIST CSF: Operationalize governance using NIST CSF 2.0; apply CSF to risk assessments, governance, controls, policies; maintain governance calendars and reporting cycles.
  • Policy Management: Own information security policy lifecycle; update policies, standards, procedures; map to NIST CSF 2.0; manage policy exceptions.
  • Reporting & Program Improvement: Develop GRC dashboards, KRIs and KPIs; report on risk, SOC 2 readiness, compliance, policy governance, remediation; drive process improvements.

Skills

SOC 2 compliance
Security risk assessments
Risk registers
NIST CSF
Policy management
Project management
Stakeholder communication
Mentorship

Education

Bachelor's degree or equivalent practical experience

Tools

AuditBoard
ServiceNow GRC
OneTrust
Archer
Jira
SharePoint

Job description

Addison Group is seeking a Senior GRC Analyst in a hybrid Chicago setting to build and mature its information security GRC program. You will drive SOC 2 readiness, lead risk assessments, manage policy lifecycle, and apply NIST CSF 2.0 across governance, risk, and compliance.

The role is contract-to-hire, with an ASAP start, reporting to Information Security leadership in downtown Chicago. You will collaborate with stakeholders across IT, Legal, Privacy, and HR, mentoring another GRC resource

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior GRC Analyst, SOC 1 & 2 — Remote/Hybrid & Growth
Senior GRC Analyst, SOC 1 & 2 — Remote/Hybrid & Growth

Sensiba LLP • California (MO)

On-site
USD 66,400 - 101,000
Comprehensive Health Coverage
Retirement & Financial Planning
Generous Paid Time Off
+5
Sr. GRC Analyst
Sr. GRC Analyst

Gosnaphop • Chicago (IL)

Hybrid
USD 115,000 - 125,000
Medical and prescription drug coverage
Dental insurance
Vision insurance
+7
GRC Analyst: Elevate Policy, Risk & Compliance
GRC Analyst: Elevate Policy, Risk & Compliance

Benesch Law • Chicago (IL)

Hybrid
USD 109,000 - 131,000
Senior GRC Manager — Security & Compliance Lead
Senior GRC Manager — Security & Compliance Lead

G2 Crowd, Inc. • Chicago (IL)

On-site
USD 120,000 - 131,000
Flexible work
Parental leave
Unlimited PTO
Hybrid GRC Analyst - HIPAA & SOC 2 Readiness
Hybrid GRC Analyst - HIPAA & SOC 2 Readiness

Frontier Cybersecurity Consulting • Miami (FL)

Hybrid
USD 70,000 - 100,000
Hybrid GRC Analyst | Risk & Compliance
Hybrid GRC Analyst | Risk & Compliance

Benesch • Chicago (IL)

Hybrid
USD 109,000 - 131,000
Hybrid work schedule
Benefits package
GRC Analyst - Hybrid: Risk, Compliance & Security
GRC Analyst - Hybrid: Risk, Compliance & Security

Benesch Law • Cleveland (OH)

Hybrid
USD 99,000 - 120,000
Discretionary bonus
Comprehensive benefits package
Senior Governance Risk & Compliance Analyst
Senior Governance Risk & Compliance Analyst

Oliver James • Farmington Hills (MI)

On-site
USD 89,544 - 96,432
Senior GRC & InfoSec Systems Analyst
Senior GRC & InfoSec Systems Analyst

Dorsey & Whitney LLP • Wilmington (DE)

On-site
USD 114,000 - 150,000
Senior GRC Analyst: AI Security & Compliance Leader
Senior GRC Analyst: AI Security & Compliance Leader

Shift Technology • New York (NY)

Hybrid
USD 120,000 - 150,000
Remote and hybrid options
Learning & development opportunities
Generous PTO & holidays
+2