GRC Analyst Consultant
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
The GRC Analyst - Third-Party Risk & Security Assurance supports the organization’s Governance, Risk, and Compliance (GRC) program with a primary focus on third-party risk management, customer security assurance activities, and compliance support. This role works closely with Information Security, Procurement, Legal, IT, and business stakeholders to assess vendor security risks, respond to customer security requests, support audits, and maintain compliance documentation and records.
This position is ideal for an early to mid-career cybersecurity or GRC professional looking to build experience across vendor risk management, security assurance, compliance, and governance activities., Third-Party Risk Management
· Conduct security assessments and periodic reassessments of vendors and service providers.
· Review vendor security documentation including SOC reports, ISO certifications, security questionnaires, policies, and related artifacts.
· Analyze and document identified risks and recommendations.
· Track vendor remediation activities and follow up on outstanding issues.
· Support vendor onboarding and offboarding reviews.
· Maintain assessment records and supporting documentation within GRC and vendor management platforms.
· Assist with ongoing vendor monitoring activities.
Customer Security Questionnaires & Assurance Activities
· Support completion of customer cybersecurity questionnaires and due diligence requests.
· Coordinate collection of responses and supporting evidence from technical and business teams.
· Support customer security assessments and audit requests.
· Maintain customer assurance documentation and evidence.
· Respond to customer requests for security policies, certifications, audit reports, and compliance documentation.
· Track customer findings, requests, and follow-up actions.
· Help maintain standard response content for common customer security inquiries.
Audit & Compliance Support
· Support internal and external audits through evidence collection and documentation management.
· Assist with control testing and validation activities.
· Maintain compliance records and supporting documentation.
· Track audit findings and remediation efforts.
· Support compliance initiatives and assessments as assigned.
Contract & Risk Review Support
· Assist with reviews of security and privacy requirements within vendor contracts, data processing agreements, and related documents.
· Document identified risks and required follow-up actions.
· Coordinate with Legal, Procurement, and Information Security teams during the review process, as needed.
General GRC Support
· Assist with risk assessments and risk documentation activities.
· Support maintenance of policies, standards, and procedures.
· Help manage security exceptions and related documentation.
· Support preparation of reports, metrics, and status updates for management.
· Support other governance, risk, compliance, and cybersecurity initiatives as needed., · Familiarity with organizational security requirements related to: o SOC 1 / SOC 2 reports o ISO 27001 o NIST Cybersecurity Framework o CIS Controls o GDPR and privacy requirements o SOX compliance o NIS2 Requirements o TISAX o Third-Party Risk Management practices
Requirements
· Bachelor’s degree in Cybersecurity, Information Technology, Information Systems, Risk Management, or related field.
· 4+ years of experience in cybersecurity, information security, GRC, compliance, audit, risk management, or related field.
· Basic understanding of cybersecurity concepts, security controls, and risk management principles.
· Strong written and verbal communication skills.
· Strong attention to detail and organizational skills.
· Ability to manage multiple tasks and deadlines in a fast-paced environment.
Preferred Qualifications
· Experience conducting vendor security assessments or third-party risk reviews.
· Experience responding to customer security questionnaires, due diligence requests, or security audits.
· Experience supporting audit or compliance programs.
· Experience with one or more of the following platforms, or comparable solutions: o SAP Ariba o OneTrust o ServiceNow o Vanta o Other GRC or third-party risk management solutions, · CISA (or working toward certification)
· CRISC (or working toward certification)
· Certified Third-Party Risk Professional (CTPRP)
· Other relevant cybersecurity, risk, or compliance certifications
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
9 Ways to Make Money Hacking
Data Analyst Salary in Switzerland
Fully Remote Software Engineer Jobs
Résumé-Driven Development: How IT trends affect the job market for software developers