Technical GRC Senior Analyst
Location: Cleveland, OH | Company: Major Professional Services Firm
3-4 days a week on-site
Role Overview:
The Technical GRC Senior Analyst supports the company’s Governance, Risk, and Compliance (GRC) program, ensuring adherence to regulatory requirements and strengthening the organization’s security posture. This role collaborates across business functions to maintain compliance, manage third-party risks, and mature GRC operations within a dynamic, fast-paced environment.
Key Responsibilities:
- Support compliance with SOX, SOC 2, HIPAA, CCPA, and other regulatory standards.
- Conduct risk assessments, audits, and control testing; maintain and update the enterprise risk register.
- Assist in third-party risk management, onboarding, and monitoring processes.
- Map and maintain security controls across frameworks to streamline compliance efforts.
- Enhance GRC platforms for reporting, automation, and control management.
- Deliver security awareness and training initiatives to promote a culture of compliance.
- Collaborate with cross-functional teams to integrate risk management into operations and recommend process improvements.
- Stay informed on regulatory changes, industry standards, and emerging security trends.
Qualifications:
- Bachelor’s degree or equivalent experience; 5–6+ years in GRC, risk, or information security (public company experience preferred).
- Strong knowledge of SOX, SOC 2, HIPAA, CCPA, and related frameworks.
- Experience with GRC and third-party risk tools.
- Excellent communication and stakeholder management skills.
- Certifications such as CISA, CISM, CISSP, or CRISC preferred.