Sr. IT Security Analyst

The Marzetti Company

Columbus (OH)

On-site

USD 90,000 - 120,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

The Marzetti Company is seeking a Senior IT GRC Analyst to advance governance, compliance, and security practices, focusing on IT SOX, third‑party risk management, and data protection.

You will partner with technology and business stakeholders to design and monitor controls, develop risk metrics, support audits, and help scale a risk‑based GRC program across the organization.

Qualifications

  • Bachelor’s Degree in related field or equivalent work experience.
  • 3-5 years’ experience in GRC, TPRM, SOX, Risk Management.
  • SAP, Azure, Industrial Control Systems (ICS) experience preferred.
  • Professional certification such as CISA, CRISC, CISSP, CISM, CGEIT, or CIA, or demonstrated progress toward a relevant certification preferred.
  • Experience in a publicly traded company or other environment subject to SOX, external audit, and formalized IT control requirements.

Responsibilities

  • Assist security leader in developing risk assessment and reporting tools that prioritize resources based on impact and risk.
  • Assist in development and generation of risk and compliance metrics and reporting for leadership visibility.
  • Assist in the performance of maturity assessments against frameworks such as NIST CSF.
  • Coordinate IT SOX lifecycle: risk assessments, scoping, testing readiness, evidence coordination, remediation tracking, and management reporting.
  • Support the design, documentation, monitoring, and improvement of IT General Controls (ITGCs).
  • Coordinate responses for audits, regulatory inquiries, and third‑party assurance activities.
  • Develop and maintain IT and information security policies and standards with stakeholders.
  • Provide advisory support translating requirements into practical controls for new systems and changes.
  • Identify opportunities to simplify, standardize, automate, and strengthen controls.

Skills

GRC
IT Risk Management
SOX
Risk Assessment
Stakeholder Communication

Education

Bachelor’s Degree in related field

Tools

SAP
Azure
Industrial Control Systems

Job description

Overview

The Senior IT GRC Analyst helps advance the organization’s approach to technology and data risk by connecting governance, compliance, and security practices with businessobjectives. The role leads key aspects of IT SOX and third-party risk management, advises stakeholders on effective control design, and supports security leadership in building scalable, risk-based GRC and data security programs focused on reducing key areas of data exposure and protecting sensitive information.

Responsibilities

Essential Functions/Primary Responsibilities:

  • IT Risk Management Program:
  • Assistthe security leader in developing risk assessment and reporting tools that help prioritize resources and initiatives based on business impact, threat exposure, regulatory requirements, and organizational risk appetite.
  • Assistin development and generation of meaningful risk and compliance metrics, and reporting that provides leadership with visibility into control effectiveness, risk exposure, remediation progress, third-party risk, and emerging trends.
  • Assistin the performance of maturity assessments against accepted frameworks such as NIST CSF.
  • SOX and Other Compliance Programs:
  • Partner with IT control owners, Internal Audit, External Audit, Finance, and business stakeholders to coordinate the annual IT SOX lifecycle. This includes risk assessments, control scoping, testing readiness,evidencecoordination, deficiency evaluation, remediation tracking, and management reporting.
  • Support the design, documentation, monitoring, and continuous improvement of IT General Controls (ITGCs) and other technology controls supporting financial reporting.
  • Support internal and external audits, regulatory inquiries, and customer or third-party assurance activities by coordinating responses,validatingevidence, and ensuring identified issues are appropriately addressed.
  • IT Governance and Controls:
  • Support the development, maintenance, and lifecycle management of IT and information security policies and standards, partnering with stakeholders to ensure requirements are clear, risk-aligned, appropriately governed, and periodically reviewed.
  • Provide control advisory support to technology teams, helping translate regulatory, audit, security, and risk requirements into practical, appropriately designed controls. This includesadvising oncontrol designfor new systems, significant system changes, implementations, integrations, and evolving business processes, promoting a controls-by-design approach.
  • Identifyopportunities to simplify, standardize, automate, and strengthen controls while balancing compliance requirements with operational efficiency and businessobjectives.
  • Cyber TPRM Program:
  • Execute the organization’s Cyber Third-Party Risk Management (TPRM) program, including vendor risk assessments, issue identification, and ongoing monitoring activities.
  • Partner with groups inside and outside of IT to ensure third-party technology and security risks are appropriatelyidentified, evaluated, accepted, mitigated, andmonitoredthroughout the vendor lifecycle.
  • Data Security Program:
  • Assist Information Security leadership to define risk-based requirements for a Critical Data Protection & Monitoring program, including capabilities required for tooling.
  • Deploy and tune monitoring capabilities to detect and respond to key data security risks, including data exfiltration, unauthorized or over-privileged access, inappropriate data sharing, sensitive data exposure, anomalous data movement, and privilege misuse,leveragingtargeted monitoring and guardrails whereappropriate.
Qualifications
  • Bachelor’s Degree in related field or equivalent work experience
  • 3-5 years’ experience in GRC, TPRM, SOX, Risk Management.
  • SAP, Azure, Industrial Control Systems (ICS) experience preferred
  • Professional certification such as CISA, CRISC, CISSP, CISM, CGEIT, or CIA, ordemonstratedprogress toward a relevant certification preferred.
  • Experience in a publicly traded company or other environment subject to SOX, external audit, and formalized IT control requirements.
Working Conditions/Environment

Working Conditions/Environment:

Works in a normal office environment where the employeeis regularly required tospeak, see, hear, sit, stand, talk, type,walkand bend while moving about the facility.The noise level in the office is quiet. Occasional travel to plants or meetings isrequired.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. Security Governance, Risk & Compliance Specialist
Sr. Security Governance, Risk & Compliance Specialist

clarioclinical • United States

On-site
USD 120,000 - 180,000
Lead GRC Analyst (IT/Security)
Lead GRC Analyst (IT/Security)

Ultra Clean Technology • Manor (TX)

On-site
USD 90,000 - 120,000
GRC Analyst
GRC Analyst

Golden Technology • North Carolina

Hybrid
USD 120,000 - 160,000
IT GRC Lead Analyst
IT GRC Lead Analyst

Westfield Insurance • Westfield Center (OH)

Hybrid
USD 90,000 - 120,000
Governance, Risk and Compliance Analyst Senior
Governance, Risk and Compliance Analyst Senior

Cone Health • Greensboro (NC)

On-site
USD 90,000 - 130,000
GRC Analyst
GRC Analyst

The Emery Company, LLC • Houston (TX)

On-site
USD 85,000 - 110,000
Governance Risk and Compliance Analyst Intermediate
Governance Risk and Compliance Analyst Intermediate

Cone Health • Greensboro (NC)

On-site
USD 110,000 - 140,000
Senior Cybersecurity Risk & Governance Analyst
Senior Cybersecurity Risk & Governance Analyst

Mortgage-Trade-Holding-Company,-LL • Oxford (MS)

On-site
USD 110,000 - 150,000
Senior Cybersecurity Risk & Governance Analyst
Senior Cybersecurity Risk & Governance Analyst

mTrade, LLC. • Oxford (MS)

On-site
USD 110,000 - 160,000
Governance, Risk & Compliance Analyst I
Governance, Risk & Compliance Analyst I

Geographic Solutions, Inc. • Dunedin (FL)

On-site
USD 60,000 - 100,000