> Markdown version of [/jobs/ext/2618673-grc-analyst-i](https://www.wearedevelopers.com/jobs/ext/2618673-grc-analyst-i). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # GRC Analyst I - **Company:** Sub-Zero Group, Inc - **Location:** Madison, WI, United States - **Experience:** Starter - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Cyber Security, Data Governance, Disaster Recovery, PCI Data Security Standards, Information Technology - **Published:** August 6, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=25888204a24b0444 ## About the Role * Associate's or Bachelor's degree in enterprise risk management, information technology, cybersecurity, business administration, finance, accounting, or related field. * 0-3 years of relevant experience in risk management, governance, compliance, auditing, or related disciplines. * Strong analytical, organizational, and communication skills. Preferred Qualifications * Experience supporting risk assessments, maintaining risk registers, or tracking remediation activities. * Experience supporting policy management, compliance reviews, control assessments, or audit activities. * Familiarity with NIST CSF, NIST AI RMF, ISO 27001, ISO 31000, ISO 22301, or similar frameworks. * Familiarity with regulations and standards such as CCPA/CPRA, GDPR, PCI DSS, or similar requirements. * Relevant certifications or progress toward certification, such as ISC2 CC, Security+, CISA, CRISC, CGRC, or similar credentials. ## Description The GRC Analyst I is responsible for supporting the organization's Governance, Risk, and Compliance (GRC) program through risk management, policy governance, compliance monitoring, reporting, and continuous improvement activities. This role assists with risk assessments, maintenance of the risk register, control evaluations, mitigation tracking, policy management, and compliance-related activities that help protect the organization and enable business objectives. The GRC Analyst I also supports emerging AI Governance initiatives by assisting with the identification, assessment, monitoring, and reporting of risks associated with artificial intelligence technologies. Working closely with IT Security, Legal, Business Continuity, Data Governance, and business stakeholders, this position helps promote responsible technology use, organizational resilience, and a risk-aware culture that enables the business to move faster with greater confidence. This is a full-time position based at Sub-Zero Group's headquarters in Fitchburg, Wisconsin, just outside Madison. Job Responsibilities Responsibilities include, but are not limited to: Governance: * Assist with policy governance activities, including the development, maintenance, review, and administration of policies, standards, procedures, and related governance documentation, while providing guidance to employees and business units on their application. * Support the organization's AI Governance program through documentation, inventories, risk assessments, stakeholder coordination, and monitoring activities that promote the responsible, secure, and compliant use of AI technologies. * Help maintain alignment with governance frameworks and industry standards, including NIST CSF, NIST AI RMF, and ISO standards, while assessing governance implications of new technologies, AI initiatives, business process changes, and emerging regulatory requirements. Risk Management: * Support risk assessment activities by gathering information, documenting risks, facilitating stakeholder discussions, evaluating inherent and residual risk, and tracking follow-up actions and remediation activities. * Maintain the risk register, including risk documentation, ownership assignments, risk scoring, review cadences, mitigation plans, control effectiveness evaluations, and reporting activities. * Partner with risk owners to evaluate risk events, root causes, business impacts, existing controls, and risk response strategies while developing dashboards, metrics, KPIs, and executive reporting that communicate organizational risk exposure and program maturity. Compliance: * Monitor compliance with internal policies, regulatory requirements, contractual obligations, and applicable industry standards while supporting assessments against relevant governance and compliance frameworks. * Assist with compliance reviews, internal audits, and audit readiness activities by collecting evidence, validating controls, documenting findings, maintaining records, and tracking remediation activities through resolution. * Track and report compliance metrics, audit findings, governance performance indicators, corrective actions, and overall program effectiveness and maturity. Additional Opportunities The GRC Analyst I may have opportunities to contribute to additional initiatives based on business needs, program priorities, and individual career interests. * Business Continuity & Resilience: Participate in business continuity, IT disaster recovery, crisis management, resilience planning, business impact analyses, exercises, and improvement activities in support of organizational resilience efforts. * Third-Party Risk Management: Assist with vendor due diligence, third-party governance activities, and ongoing monitoring efforts as the organization's third-party risk management capabilities evolve and mature. * Awareness, Training & Risk Culture: Contribute to governance, risk, compliance, cybersecurity, and responsible AI awareness initiatives through the development of training materials, communications, workshops, and other educational opportunities that promote a culture of accountability and risk-informed decision-making. ## Related Videos - [Reporting Active Exploits in 24 Hours: Are You Ready for the CRA?](https://www.wearedevelopers.com/videos/100248-reporting-active-exploits-in-24-hours-are-you-ready-for-the-cra) - [Data Governance in the Era of AI](https://www.wearedevelopers.com/videos/1622-data-governance-in-the-era-of-ai) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Convincing Product teams to Adopt Gitops in a Large Org](https://www.wearedevelopers.com/videos/1936-convincing-product-teams-to-adopt-gitops-in-a-large-org) - [GenAI Security: Navigating the Unseen Iceberg](https://www.wearedevelopers.com/videos/1744-genai-security-navigating-the-unseen-iceberg) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) ## Related Articles - [Data Analyst Salary in Switzerland](https://www.wearedevelopers.com/magazine/276-data-analyst-salary-in-switzerland) - [Software Developer Salary in Switzerland [2023]](https://www.wearedevelopers.com/magazine/215-software-developer-salary-in-switzerland-2023) - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud) - [Data Analyst Salary in the UK](https://www.wearedevelopers.com/magazine/278-data-analyst-salary-in-the-uk) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Data Analyst Salary Germany](https://www.wearedevelopers.com/magazine/277-data-analyst-salary-germany)