> Markdown version of [/jobs/ext/2462743-senior-grc-analyst](https://www.wearedevelopers.com/jobs/ext/2462743-senior-grc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior GRC Analyst - **Company:** Wolfe, Llc - **Location:** Pittsburgh, PA, United States - **Experience:** Expert - **Salary:** $114,000.0 - $163,000.0 - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Backup Devices, Information Technology Audit, IT Management, Job Scheduling, PCI Data Security Standards, Systems Development Life Cycle, Software Engineering, IT General Controls (ITGC), Servicenow - **Published:** August 10, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=ea5298e6cc4ce129 ## About the Role * 7+ years in GRC, IT audit, or information security compliance, including at least 3 years directly supporting PCI DSS in a Level 1 service provider or equivalent payment card environment; CISA, CRISC, CISSP, PCIP, or ISA certification preferred but not required. * Demonstrated experience preparing for and supporting SOC 2 Type II examinations, including designing, documenting, and testing IT general controls across change management, logical access, and the software development lifecycle. * Working depth in IT governance, with proven ability to translate control requirements into testable evidence that an external assessor accepts without rework. * Hands-on experience administering a GRC platform (Vanta, Drata, Secureframe, ServiceNow IRM, AuditBoard, or similar) - control mapping, automated evidence collection, and reporting. * Track record running third-party risk assessments end to end, including reviewing security and compliance terms in vendor contracts. * Experience in a regulated financial services environment answering to external parties - sponsor banks, processors, regulators, or internal audit - and producing deliverables for executive and board audiences. ## Description Wolfe is a Pittsburgh-based FinTech company operating consumer gifting and payments brands, and we are actively embedding AI across our products, our internal processes, and the way our teams work day-to-day. As Senior GRC Analyst, you will be the hands-on owner of the control and evidence work behind our PCI DSS Level 1 service provider obligations, our SOC 2 Type II readiness, our IT general controls, our NIST CSF 2.0 maturity program, and our third-party risk assessments. This is a deliberately senior individual contributor role - you will operate with minimal oversight, work directly with our QSA and external auditors, and serve as the compliance advisor engineering, fraud, and product teams come to before they build. You will also help us define how governance keeps pace with AI adoption, including the controls and review process for AI use across the company. This is a 5-day onsite role in Pittsburgh, PA., * Run our annual PCI DSS v4.0.1 Level 1 service provider assessment and SOC 2 Type II examination end to end - scope validation, evidence collection, QSA and auditor coordination, gap remediation tracking, and support for sponsor bank and processor due diligence requests. * Own IT general control readiness across change management, logical access, SDLC, and backup and job scheduling - documenting control narratives, walking auditors through the environment, and performing internal design and operating-effectiveness testing so that external testing produces no surprises. * Own the issues management lifecycle under our Issues Management Policy - intake, risk rating, remediation tracking, closure evidence, and recurring reporting to leadership and the Audit Committee. * Execute third-party risk assessments across our vendor portfolio, including security questionnaire review, contract security and PCI terms review, and ongoing monitoring of critical vendors. * Administer our GRC platform - control library and cross-framework mappings across PCI, SOC 2, and ITGC, automated evidence collection, control owner workflows, and compliance dashboards. Impact Statement For more clarity on the role, below are the success metrics and measurements for this role in the first 90 to 120 days.: * Take over evidence collection for the current PCI DSS v4.0.1 assessment cycle and deliver a QSA-accepted evidence package for your assigned requirement families, with an aging report showing zero overdue evidence requests at the 120-day mark. * Deliver a SOC 2 Type II readiness assessment covering the full ITGC population - change management, logical access, SDLC, and backup and recovery - including written control narratives, identified design gaps, and a remediation plan sized to close before the audit period opens. * Complete a refreshed assessment of the governance function and deliver a prioritized remediation plan covering the lowest-scoring subcategories, with owners, target dates, and a defined scoring path from current to target maturity. * Migrate all open compliance and audit findings into a single issues register in the GRC platform - each item risk-rated, owner-assigned, and due-dated - and publish the first monthly issues report to the IT Steering Committee. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Hate organising your photos? Try it with 5 Terabytes](https://www.wearedevelopers.com/videos/79-hate-organising-your-photos-try-it-with-5-terabytes) - [Your Manager Doesn’t Come with a User Manual (But You Can Totally Write One)](https://www.wearedevelopers.com/videos/1495-your-manager-doesn-t-come-with-a-user-manual-but-you-can-totally-write-one) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [Navigating the Corporate Jungle: Life as a Developer in a large Company](https://www.wearedevelopers.com/videos/621-navigating-the-corporate-jungle-life-as-a-developer-in-a-large-company) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [How We Built a Worry-Free System That Runs for 10+ Years – And What We’d Do Again](https://www.wearedevelopers.com/magazine/751-how-we-built-a-worry-free-system-that-runs-for-10-years-and-what-we-d-do-again) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [Data Analyst Salary in Switzerland](https://www.wearedevelopers.com/magazine/276-data-analyst-salary-in-switzerland) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer)