> Markdown version of [/jobs/ext/1854389-senior-grc-analyst](https://www.wearedevelopers.com/jobs/ext/1854389-senior-grc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior GRC Analyst - **Company:** Modine Manufacturing Company - **Location:** Racine, WI, United States (Remote available) - **Experience:** Expert - **Salary:** $120,000.0 - $190,000.0 - **Contract:** Permanent contract - **Skills:** Control Objectives for Information and Related Technology (COBIT), Cyber Security, Information Systems, Information Technology Audit, Information Systems Security Architecture Professional, Smartsuite, IT General Controls (ITGC), Information Technology - **Published:** July 14, 2026 - **Apply:** https://www.milwaukeejobs.com/apply/add/87719121/1 ## About the Role * Experience:5+ years of dedicated experience in Information Security GRC, IT Audit, or IT Compliance, with a proven track record of managing and auditingIT General Controls (ITGCs)andSOX compliance. * Process Mindset:Extremely process-oriented with exceptional organizational and project management skills; ability to track dozens of moving compliance targets simultaneously without losing details. * Work Style:Proven self-starter who can take initiative, work independently, meet strict regulatory deadlines, and proactively drive results. * Tooling:Practical experience configuring and utilizing modern GRC tools (e.g.,SimpleRisk,AuditBoard, LogicGate, or similar). * Framework Knowledge:Deep familiarity with leading risk and control frameworks (e.g., NIST CSF, COBIT, COSO, ISO 27001/27002). * Communications:Outstanding written and verbal communication skills, with the ability to translate complex technical control concepts into plain language for diverse audit, security, and business stakeholders. * Company Alignment:Ability to apply core corporate values and support operational efficiency initiatives (including 80/20 principles) to optimize GRC workflows. Education & Certifications * Education:Bachelor's degree in Information Technology, Management Information Systems (MIS), Cybersecurity, Accounting, Finance, Business Administration, or equivalent professional experience. * Preferred Certifications:Highly desirable professional credentials such as: * Certified Information Systems Auditor (CISA) * Certified in Risk and Information Systems Control (CRISC) * Certified Information Security Manager (CISM) * Certified Information Systems Security Professional (CISSP) Travel Requirements * This position may require up to 15% travel depending on project needs and compliance audits. ## Description We are seeking a highly structured, process-oriented, and proactive Senior GRC (Governance, Risk, and Compliance) Analyst to join our Information Security GRC team. In this critical role, you will be the driving force behind the execution and continuous improvement of our IT General Controls (ITGC) framework, SOX compliance program, and overall risk management practices. You will serve as a key bridge between control owners, IT operational teams, internal/external audit, and corporate risk management. As a self-starter with deep compliance expertise, you will lead efforts to review, analyze, and update cybersecurity policies, manage GRC platform automation, and ensure that security risks are systematically identified, documented, and remediated., 1. ITGC & SOX Compliance Management * Control Lifecycle Ownership:Track, monitor, and follow up with IT control owners to ensure all ITGC and SOX-related control tests and evidence collections are executed accurately, thoroughly, and on schedule. * Audit Readiness:Act as the primary coordinator for internal and external auditors during security and compliance reviews, ensuring timely delivery of documentation and evidence. * Remediation & Correction:Partner with IT and Security teams to design, document, and track effective remediation plans for any identified control gaps or deficiencies. 2. Policy, Standards & Procedures Governance * Policy Lifecycle:Lead the periodic review, analysis, and modernization of information security policies, standards, guidelines, and operating procedures to ensure alignment with evolving industry regulations and corporate risk tolerance. * Process Standardization:Support the development ofclear, actionable technical standards and procedural documentation that simplify compliance for system administrators and business process owners. * Alignment:Ensure corporate security documentation matches standard industry frameworks (e.g., NIST CSF, ISO 27001, COBIT, COSO). 3. Risk Assessment & GRC Tool Management * GRC Tool Administration:Manage and optimize our GRC platform (such asSimpleRiskor similar tools) to automate risk registers, compliance mappings, and control tracking. * Risk Assessments:Conduct comprehensive IT and security risk assessments across applications, infrastructure, and third-party vendors. * Risk Register Maintenance:Document risks, vulnerabilities, and policy exceptions systematically, tracking them from identification through to mitigation or formal acceptance. 4. Business Partnering & Stakeholder Collaboration * Cross-Functional Liaison:Build strong, collaborative relationships with stakeholders across IT, Information Security, Internal Audit, Corporate Risk Management, and External Auditors. * Control Owner Support:Act as a subject matter expert and trusted advisor to control owners, offering ongoing guidance on compliance expectations, control design, and testing methodology. * Executive Reporting:Prepare clear, metrics-driven status updates, compliance dashboards, and risk posture reports for leadership. 5. Awareness & Continuous Improvement * Process Orientation:Constantly evaluate current GRC workflows to eliminate friction, automate manual checks, and introduce best practices. * Training & Enablement:Facilitate training sessions and develop educational resources for control owners to enhance organizational compliance awareness and accountability. ## Related Videos - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [Now is the time for industrialized software development](https://www.wearedevelopers.com/magazine/601-now-is-the-time-for-industrialized-software-development) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [Should senior developers refuse interview coding challenges?](https://www.wearedevelopers.com/magazine/29-should-senior-developers-refuse-interview-coding-challenges) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Résumé-Driven Development: How IT trends affect the job market for software developers](https://www.wearedevelopers.com/magazine/59-resume-driven-development-how-it-trends-affect-the-job-market-for-software-developers)