GRC Analyst I
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
Job description
The GRC Analyst I is responsible for supporting the organization’s Governance, Risk, and Compliance (GRC) program through risk management, policy governance, compliance monitoring, reporting, and continuous improvement activities. This role assists with risk assessments, maintenance of the risk register, control evaluations, mitigation tracking, policy management, and compliance-related activities that help protect the organization and enable business objectives.
The GRC Analyst I also supports emerging AI Governance initiatives by assisting with the identification, assessment, monitoring, and reporting of risks associated with artificial intelligence technologies. Working closely with IT Security, Legal, Business Continuity, Data Governance, and business stakeholders, this position helps promote responsible technology use, organizational resilience, and a risk-aware culture that enables the business to move faster with greater confidence.
This is a full-time position based at Sub-Zero Group’s headquarters in Fitchburg, Wisconsin, just outside Madison.
Job Responsibilities
Responsibilities include, but are not limited to:
Governance:
- Assist with policy governance activities, including the development, maintenance, review, and administration of policies, standards, procedures, and related governance documentation, while providing guidance to employees and business units on their application.
- Support the organization’s AI Governance program through documentation, inventories, risk assessments, stakeholder coordination, and monitoring activities that promote the responsible, secure, and compliant use of AI technologies.
- Help maintain alignment with governance frameworks and industry standards, including NIST CSF, NIST AI RMF, and ISO standards, while assessing governance implications of new technologies, AI initiatives, business process changes, and emerging regulatory requirements.
Risk Management:
- Support risk assessment activities by gathering information, documenting risks, facilitating stakeholder discussions, evaluating inherent and residual risk, and tracking follow-up actions and remediation activities.
- Maintain the risk register, including risk documentation, ownership assignments, risk scoring, review cadences, mitigation plans, control effectiveness evaluations, and reporting activities.
- Partner with risk owners to evaluate risk events, root causes, business impacts, existing controls, and risk response strategies while developing dashboards, metrics, KPIs, and executive reporting that communicate organizational risk exposure and program maturity.
Compliance:
- Monitor compliance with internal policies, regulatory requirements, contractual obligations, and applicable industry standards while supporting assessments against relevant governance and compliance frameworks.
- Assist with compliance reviews, internal audits, and audit readiness activities by collecting evidence, validating controls, documenting findings, maintaining records, and tracking remediation activities through resolution.
- Track and report compliance metrics, audit findings, governance performance indicators, corrective actions, and overall program effectiveness and maturity.
Additional Opportunities
The GRC Analyst I may have opportunities to contribute to additional initiatives based on business needs, program priorities, and individual career interests.
- Business Continuity & Resilience: Participate in business continuity, IT disaster recovery, crisis management, resilience planning, business impact analyses, exercises, and improvement activities in support of organizational resilience efforts.
- Third-Party Risk Management: Assist with vendor due diligence, third-party governance activities, and ongoing monitoring efforts as the organization’s third-party risk management capabilities evolve and mature.
- Awareness, Training & Risk Culture: Contribute to governance, risk, compliance, cybersecurity, and responsible AI awareness initiatives through the development of training materials, communications, workshops, and other educational opportunities that promote a culture of accountability and risk-informed decision-making.
Requirements
- Associate’s or Bachelor’s degree in enterprise risk management, information technology, cybersecurity, business administration, finance, accounting, or related field.
- 0-3 years of relevant experience in risk management, governance, compliance, auditing, or related disciplines.
- Strong analytical, organizational, and communication skills.
Preferred Qualifications
- Experience supporting risk assessments, maintaining risk registers, or tracking remediation activities.
- Experience supporting policy management, compliance reviews, control assessments, or audit activities.
- Familiarity with NIST CSF, NIST AI RMF, ISO 27001, ISO 31000, ISO 22301, or similar frameworks.
- Familiarity with regulations and standards such as CCPA/CPRA, GDPR, PCI DSS, or similar requirements.
- Relevant certifications or progress toward certification, such as ISC2 CC, Security+, CISA, CRISC, CGRC, or similar credentials.
Benefits & conditions
Pulled from the full job description
- Parental leave
- 401(k)
- Health insurance
- Paid time off
- Employee discount
- Vision insurance
- Dental insurance, * Competitive compensation based on skills
- Industry leading health, dental, and vision plans
- Generous 401(k) savings and profit sharing
- 10 Paid Holidays
- Paid Time Off (PTO)
- Parental Leave
- On-site UW Health clinic, fitness center, and walking paths
- Education assistance and internal training programs
- Employee discount program
- Employee Assistance Program (EAP)
- Electric vehicle charging
- Department & Company-wide social events
Interested in learning more about our robust benefits package? Click here (https://www.subzero-wolf.com/company/careers/benefits)!
This position requires a pre-employment drug/alcohol test and background check, which will be administered after a conditional job offer is extended. A negative drug/alcohol test result is required for employment. Refusal to take the test or a positive result may disqualify a candidate from further consideration. All drug testing will be conducted in accordance with federal and state laws.
Equal Opportunity Employer
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Software Developer Salary in Switzerland [2023]
Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud
Data Analyst Salary in the UK
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.