GRC Analyst Consultant

Information Consulting Services
Philadelphia, PA, United States
9 days ago
Apply on www.indeed.com
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
4 years minimum
Working hours
Regular working hours
Job source

Tech stack

Cyber Security Information Systems Tisax Data Processing Information Technology SAP Ariba CIS Benchmarks Servicenow

Job description

The GRC Analyst - Third-Party Risk & Security Assurance supports the organization’s Governance, Risk, and Compliance (GRC) program with a primary focus on third-party risk management, customer security assurance activities, and compliance support. This role works closely with Information Security, Procurement, Legal, IT, and business stakeholders to assess vendor security risks, respond to customer security requests, support audits, and maintain compliance documentation and records.

This position is ideal for an early to mid-career cybersecurity or GRC professional looking to build experience across vendor risk management, security assurance, compliance, and governance activities., Third-Party Risk Management

· Conduct security assessments and periodic reassessments of vendors and service providers.

· Review vendor security documentation including SOC reports, ISO certifications, security questionnaires, policies, and related artifacts.

· Analyze and document identified risks and recommendations.

· Track vendor remediation activities and follow up on outstanding issues.

· Support vendor onboarding and offboarding reviews.

· Maintain assessment records and supporting documentation within GRC and vendor management platforms.

· Assist with ongoing vendor monitoring activities.

Customer Security Questionnaires & Assurance Activities

· Support completion of customer cybersecurity questionnaires and due diligence requests.

· Coordinate collection of responses and supporting evidence from technical and business teams.

· Support customer security assessments and audit requests.

· Maintain customer assurance documentation and evidence.

· Respond to customer requests for security policies, certifications, audit reports, and compliance documentation.

· Track customer findings, requests, and follow-up actions.

· Help maintain standard response content for common customer security inquiries.

Audit & Compliance Support

· Support internal and external audits through evidence collection and documentation management.

· Assist with control testing and validation activities.

· Maintain compliance records and supporting documentation.

· Track audit findings and remediation efforts.

· Support compliance initiatives and assessments as assigned.

Contract & Risk Review Support

· Assist with reviews of security and privacy requirements within vendor contracts, data processing agreements, and related documents.

· Document identified risks and required follow-up actions.

· Coordinate with Legal, Procurement, and Information Security teams during the review process, as needed.

General GRC Support

· Assist with risk assessments and risk documentation activities.

· Support maintenance of policies, standards, and procedures.

· Help manage security exceptions and related documentation.

· Support preparation of reports, metrics, and status updates for management.

· Support other governance, risk, compliance, and cybersecurity initiatives as needed., · Familiarity with organizational security requirements related to: o SOC 1 / SOC 2 reports o ISO 27001 o NIST Cybersecurity Framework o CIS Controls o GDPR and privacy requirements o SOX compliance o NIS2 Requirements o TISAX o Third-Party Risk Management practices

Requirements

· Bachelor’s degree in Cybersecurity, Information Technology, Information Systems, Risk Management, or related field.

· 4+ years of experience in cybersecurity, information security, GRC, compliance, audit, risk management, or related field.

· Basic understanding of cybersecurity concepts, security controls, and risk management principles.

· Strong written and verbal communication skills.

· Strong attention to detail and organizational skills.

· Ability to manage multiple tasks and deadlines in a fast-paced environment.

Preferred Qualifications

· Experience conducting vendor security assessments or third-party risk reviews.

· Experience responding to customer security questionnaires, due diligence requests, or security audits.

· Experience supporting audit or compliance programs.

· Experience with one or more of the following platforms, or comparable solutions: o SAP Ariba o OneTrust o ServiceNow o Vanta o Other GRC or third-party risk management solutions, · CISA (or working toward certification)

· CRISC (or working toward certification)

· Certified Third-Party Risk Professional (CTPRP)

· Other relevant cybersecurity, risk, or compliance certifications

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

56 sec

Integrating automated approval workflows into the portal

Markus Eisele Markus Eisele · World Congress 2025

2:15 min

Overcoming cultural resistance to achieve international security compliance standards

Ali Yazdani Ali Yazdani · World Congress 2023

2:27 min

Establishing a simulated technical environment for the workflow demo

Tobias Dunn-Krahn · LIVE

1:40 min

Addressing data sovereignty and compliance blind spots within AI

Sebastian Kister Sebastian Kister · World Congress 2026 Europe

2:07 min

Summarizing critical actions for organizational cybersecurity compliance readiness

Matthew Brady Matthew Brady · World Congress 2026 Europe

Videos

See all

Related articles

See all