Sr. Analyst, GRC

Experis
Overland Park, KS, United States
7 days ago
Apply on www.experis.com
Prepare application

Role details

Contract type
Temporary contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Compensation
$195,000.0
Working hours
Regular working hours

Tech stack

Cyber Security Information Systems IT Management Cyber Threat Analysis

Job description

The Sr. Analyst, Governance, Risk, and Compliance (GRC) plays an important role in the GRC delivery framework, ensuring Black & Veatch’s compliance with contractual and regulatory requirements, assessing control design and operation against common standards and frameworks, and assisting with third-party/supply chain risk management. The candidate will also promote a culture of risk awareness across the enterprise among other responsibilities. With an emphasis on cyber, contract and regulatory compliance risk management, the ideal candidate should be able to contribute to measuring success and identifying improvement opportunities and capabilities development in these areas. This role is ideal for a detail-oriented professional with a passion for cyber and compliance risk management who is comfortable operating independently. Independent and critical thinking is absolutely necessary to be successful in this role as is a desire to drive efficiencies in function delivery and day-to-day tasks., Contract Risk Management · Proven experience reviewing client contract provisions related to data security, breach reporting, cyber resilience, and compliance certifications and measuring compliance in IT and security architecture and operations. Regulatory Compliance Risk Management · Support independent certification and audit by working with D&IT peer groups and lines of business to collect documentation and evidence of security policies and operations · Request and review documentation and evidence from control owners to certify and validate compliance to standards and industry-accepted best practice · Monitor regulatory and legal landscape at a global scale and across market sectors and maintain awareness of compliance requirements IT Governance · Act as an informed voice in development of policy and ensure alignment with regulatory, legal, and contractual requirements · Assist establishment and enforcement of standards of practice documentation to be referenced by architecture and operations teams · Contribute process and subject matter expertise in governance forums and cross-functional committees Cyber Risk Management · Support establishment, collection, and ongoing improvement of metrics to measure effectiveness of cyber risk management and provide data-driven insight to decision makers and control owners · Collaborate with peer D&IT groups to collect KPI’s, KRI’s and drive efficiency through automation and other means Supplier/Third Party Risk Management · Contribute subject matter expertise through third party risk assessment process · Identify and communicate risk of vendor engagements and mitigation actions to business owners and D&IT stakeholders · Assist review of client security requirements in contracts and aggregate relevant clauses to inform contractual risk

Requirements

· Bachelor’s degree in information systems, Information Security, or a related field · 7-10 years of experience in GRC executing or auditing against standards, frameworks, and industry regulations · Demonstrated experience supporting GRC functions for global companies · Solid proficiency in risk assessment methodologies and frameworks Attachments: Sr Analyst GRC- US.docx ,Sr Analyst GRC- US.docx

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.experis.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

59 sec

Proving regulatory compliance to auditors and chief officers

Mike Bursell Mike Bursell · World Congress 2026 Europe

1:53 min

Managing infrastructure limitations with managed Amazon Aurora databases

Dharin Shah Dharin Shah · World Congress 2025

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

3:24 min

Evaluating remote software roles and compensation structures

Nacho Iacovino · World Congress 2021

5:00 min

Managing complex state with scope-based resource management

Bjarne Stroustrup · World Congress 2022

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

Videos

See all

Related articles

See all