Strategic Vendor Risk & IT GRC Analyst

Core Specialty

Cincinnati (OH)

Hybrid

USD 85,000 - 115,000

Full time

3 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Medical insurance
Dental & Vision
401(k) match
Employee Assistance Plan
Wellness program

Job summary

Core Specialty in Cincinnati seeks an IT GRC Risk Analyst to support evaluating and monitoring technology and cybersecurity risks from third parties. You will review vendor questionnaires, SOC reports, and security documentation to identify control gaps and risk factors.

You will collaborate with IT, procurement, legal, compliance, and business owners to collect evidence, track remediation, and prepare risk summaries for leadership review.

Qualifications

  • Bachelor’s degree or equivalent work experience in a related field.
  • 3+ years of experience in IT GRC, risk management, compliance, or related technology risk function.
  • Experience supporting technology and cybersecurity risk assessments and governance activities.
  • Knowledge of IT risk management principles and control frameworks.

Responsibilities

  • Conduct third-party risk assessments by reviewing vendor questionnaires and security documents.
  • Identify and document third-party risks and remediation priorities.
  • Track findings, remediation plans, and exceptions to completion.
  • Prepare risk summaries, dashboards, and escalation materials for leadership.

Skills

GRC
Risk Assessments
Regulatory Frameworks
Vendor Risk
SOC 2
NIST CSF
ISO 27001
CISA/CRISC/CISM

Education

Bachelor's degree in Information Systems/Cybersecurity/Risk Management

Tools

Jira
Confluence
SharePoint
Power BI

Job description

Core Specialty in Cincinnati seeks an IT GRC Risk Analyst to support evaluating and monitoring technology and cybersecurity risks from third parties. You will review vendor questionnaires, SOC reports, and security documentation to identify control gaps and risk factors.

You will collaborate with IT, procurement, legal, compliance, and business owners to collect evidence, track remediation, and prepare risk summaries for leadership review.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Vendor Risk & IT GRC Analyst
Vendor Risk & IT GRC Analyst

Kalepa • Cincinnati (OH)

Hybrid
USD 100,000 - 140,000
Health benefits
IT GRC - Risk Analyst
IT GRC - Risk Analyst

Kalepa • Cincinnati (OH)

Hybrid
USD 100,000 - 140,000
Health benefits
IT GRC - Risk Analyst
IT GRC - Risk Analyst

Core Specialty • Cincinnati (OH)

Hybrid
USD 85,000 - 115,000
Medical insurance
Dental & Vision
401(k) match
+2
Hybrid IT GRC Lead Analyst | Risk & Compliance
Hybrid IT GRC Lead Analyst | Risk & Compliance

Kalepa • Cincinnati (OH)

Hybrid
USD 110,000 - 150,000
Medical Insurance
Dental Insurance
401(k) Plan
+1
IT Security & Vendor Risk Analyst
IT Security & Vendor Risk Analyst

Judge Group, Inc. • Columbus (OH)

On-site
USD 48,000 - 52,000
Medical, dental, and vision insurance
Vendor Risk & Cybersecurity Analyst
Vendor Risk & Cybersecurity Analyst

TEKsystems • Chicago (IL)

Hybrid
USD 90,000 - 100,000
Medical, dental & vision
401(k) Retirement Plan
Life Insurance
+2
IT GRC Lead Analyst
IT GRC Lead Analyst

Kalepa • Cincinnati (OH)

Hybrid
USD 110,000 - 150,000
Medical Insurance
Dental Insurance
401(k) Plan
+1
Strategic IT Vendor Relations Leader
Strategic IT Vendor Relations Leader

Procter & Gamble • Cincinnati (OH)

Hybrid
USD 110,000 - 165,000
Third Party Cyber Risk Analyst
Third Party Cyber Risk Analyst

Selby Jennings • New York (NY)

On-site
USD 90,000 - 140,000
Sr. IT Security Analyst
Sr. IT Security Analyst

The Marzetti Company • Columbus (OH)

On-site
USD 90,000 - 120,000