Overview
The Senior IT GRC Analyst helps advance the organization’s approach to technology and data risk by connecting governance, compliance, and security practices with businessobjectives. The role leads key aspects of IT SOX and third-party risk management, advises stakeholders on effective control design, and supports security leadership in building scalable, risk-based GRC and data security programs focused on reducing key areas of data exposure and protecting sensitive information.
Responsibilities
Essential Functions/Primary Responsibilities:
- IT Risk Management Program:
- Assistthe security leader in developing risk assessment and reporting tools that help prioritize resources and initiatives based on business impact, threat exposure, regulatory requirements, and organizational risk appetite.
- Assistin development and generation of meaningful risk and compliance metrics, and reporting that provides leadership with visibility into control effectiveness, risk exposure, remediation progress, third-party risk, and emerging trends.
- Assistin the performance of maturity assessments against accepted frameworks such as NIST CSF.
- SOX and Other Compliance Programs:
- Partner with IT control owners, Internal Audit, External Audit, Finance, and business stakeholders to coordinate the annual IT SOX lifecycle. This includes risk assessments, control scoping, testing readiness,evidencecoordination, deficiency evaluation, remediation tracking, and management reporting.
- Support the design, documentation, monitoring, and continuous improvement of IT General Controls (ITGCs) and other technology controls supporting financial reporting.
- Support internal and external audits, regulatory inquiries, and customer or third-party assurance activities by coordinating responses,validatingevidence, and ensuring identified issues are appropriately addressed.
- IT Governance and Controls:
- Support the development, maintenance, and lifecycle management of IT and information security policies and standards, partnering with stakeholders to ensure requirements are clear, risk-aligned, appropriately governed, and periodically reviewed.
- Provide control advisory support to technology teams, helping translate regulatory, audit, security, and risk requirements into practical, appropriately designed controls. This includesadvising oncontrol designfor new systems, significant system changes, implementations, integrations, and evolving business processes, promoting a controls-by-design approach.
- Identifyopportunities to simplify, standardize, automate, and strengthen controls while balancing compliance requirements with operational efficiency and businessobjectives.
- Execute the organization’s Cyber Third-Party Risk Management (TPRM) program, including vendor risk assessments, issue identification, and ongoing monitoring activities.
- Partner with groups inside and outside of IT to ensure third-party technology and security risks are appropriatelyidentified, evaluated, accepted, mitigated, andmonitoredthroughout the vendor lifecycle.
- Assist Information Security leadership to define risk-based requirements for a Critical Data Protection & Monitoring program, including capabilities required for tooling.
- Deploy and tune monitoring capabilities to detect and respond to key data security risks, including data exfiltration, unauthorized or over-privileged access, inappropriate data sharing, sensitive data exposure, anomalous data movement, and privilege misuse,leveragingtargeted monitoring and guardrails whereappropriate.
Qualifications
- Bachelor’s Degree in related field or equivalent work experience
- 3-5 years’ experience in GRC, TPRM, SOX, Risk Management.
- SAP, Azure, Industrial Control Systems (ICS) experience preferred
- Professional certification such as CISA, CRISC, CISSP, CISM, CGEIT, or CIA, ordemonstratedprogress toward a relevant certification preferred.
- Experience in a publicly traded company or other environment subject to SOX, external audit, and formalized IT control requirements.
Working Conditions/Environment
Working Conditions/Environment:
Works in a normal office environment where the employeeis regularly required tospeak, see, hear, sit, stand, talk, type,walkand bend while moving about the facility.The noise level in the office is quiet. Occasional travel to plants or meetings isrequired.