JOBSEARCHER

Senior GRC Analyst

Senior GRC AnalystSalary: $120k-$140k + bonusLocation: Chicago, IL or Austin, TXHybrid: 3 days onsite, 2 days remote*We are unable to provide sponsorship for this role*QualificationsBachelor’s degree and 4+ years of Information Security experienceStrong working knowledge of security frameworks and standards such as ISO 27001, National Institute of Standards and Technology (NIST), System and Organization Controls (SOC), and Standardized Information Gathering (SIG)Experience leading risk assessments, vendor security reviews, and client-facing security discussions with professionalism and tact.Familiarity with GRC platforms, role-based access controls, and a broad range of security technologies and tools.Working knowledge of areas such as authentication, encryption, firewalls, SIEM, intrusion detection/prevention, vulnerability management, mobile security, and privileged access management.ResponsibilitiesLead responses to client security assessments, questionnaires, and audits, documenting evidence and performing risk assessments as needed.Create, maintain, and evolve security policies, standards, guidelines, and support documentation through strong technical writing.Manage and support processes that ensure Information Technology (IT) systems meet cybersecurity, risk, and compliance requirements.Serve as an Information Security subject matter expert, advising technical and non-technical stakeholders across the organization.Manage the third-party Security Vendor Risk Management program, including assessments, remediation tracking, and lifecycle oversight.Oversee the security exception request process and provide guidance on appropriate risk treatment decisions.Manage the full lifecycle of the Security Awareness program, including roadmap development, training evaluation, and effectiveness measurement.Support and optimize Governance, Risk, and Compliance (GRC) technology platforms and associated workflows.Conduct evaluations of IT programs and components to confirm alignment with published security standards and frameworks.