> Markdown version of [/jobs/ext/2850310-grc-analyst](https://www.wearedevelopers.com/jobs/ext/2850310-grc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # GRC analyst - **Company:** Encore Capital Group - **Location:** San Diego, CA, United States - **Experience:** Expert - **Salary:** $93,800.0 - $121,800.0 - **Contract:** Permanent contract - **Skills:** Control Objectives for Information and Related Technology (COBIT), Cyber Security, Information Systems, Software Engineering, Information Technology - **Published:** September 11, 2026 - **Apply:** https://encore.wd1.myworkdayjobs.com/externalnew/job/CA---San-Diego/Senior-GRC-Analyst_HR-20683/apply ## About the Role Certification:Preferable Cobit, MOR (Management of Risk) and ITIL V3 Expert or ITIL Managing Professional Education: Education:Bachelor Field of Study:Computer Science,Information Systems,Information Technology,Software Engineering, Information Security Experience:Typically 5 years business experience; exhibit strong basic execution capabilities and begin to take on more responsibility Technical Skills:Working knowledge of the regulatory environment Encore operates in and associated requirements - e.g. SOX, PCI, GLBA, ISO Other Skills:Ability to follow guidelines and identify and resolve problems Languages:English PREFERRED SKILLSET Languages: English & Spanish; French a plus Education: Degree:Master or Advanced Field of Study:Computer Science,Information Systems,Information Technology,Software Engineering,Information Security Experience:Experience working for a publicly traded company in a similar role or with a reputable auditing /consulting firm ## Description Reporting to the Manager or Sr.Manager, IT Risk and Compliance, the Senior GRC analyst will be responsible for supporting the day to day IT compliance, data governance, and IT risk management functions.The role will include primary responsibility for the defining, creating, and managing IT policies and standards in support of legal and regulatory compliance needs as well as general IT and organizational information security practices., Audit and assess firm wide plan for IT Risk and Compliance policies and rules - log-in and passwords, etc.Participate in process and control documentation pertaining to controls implementation.Develop and implement operational and enterprise governance frameworks. Perform business impact analysis and assist with development of IT/InfoSec risk register. Operationalization of a metrics and reporting function to continually report on meaningful security, risk and compliance metrics for operational and executive management.Develop and manage the automation of KPIs & KRIs reporting that align with operational/business risk. Support internal and external audit process for relevant compliance concerns and risk management to re mediate new and outstanding issues including PCI, SOX, ISO,NIST,Issuers etc. Support vendor due-diligence process and help to lead and define overall third party risk management efforts including contracts ,performance etc. Perform periodic gap assessments across product lines to validate compliance on an ongoing basis.Driving remediation activities from identification,remediation plan and closure for various information systems and processes. Other data security projects as assigned. Liaise on with GPS counterparts for compliance reporting & continually enhancing the risk & compliance framework implemented for the project. ## Related Videos - [Microservices? Monoliths? An Annoying Discussion!](https://www.wearedevelopers.com/videos/970-microservices-monoliths-an-annoying-discussion) - [The Avengers Initiative (Practical Ethics for Software Engineers)](https://www.wearedevelopers.com/videos/2070-the-avengers-initiative-practical-ethics-for-software-engineers) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [You’re a great coder? That alone won’t get you far: The soft skills secret in IT success](https://www.wearedevelopers.com/videos/1076-you-re-a-great-coder-that-alone-won-t-get-you-far-the-soft-skills-secret-in-it-success) - [One Pipeline, Three Regulator - SBOM Compliance for the Developer](https://www.wearedevelopers.com/videos/100169-one-pipeline-three-regulator-sbom-compliance-for-the-developer) - [Great DevEx and Regulatory Compliance - Possible?](https://www.wearedevelopers.com/videos/1426-great-devex-and-regulatory-compliance-possible) ## Related Articles - [Résumé-Driven Development: How IT trends affect the job market for software developers](https://www.wearedevelopers.com/magazine/59-resume-driven-development-how-it-trends-affect-the-job-market-for-software-developers) - [What’s the Difference between a Junior, Mid, and Senior Developer?](https://www.wearedevelopers.com/magazine/238-what-s-the-difference-between-a-junior-mid-and-senior-developer) - [7 Important Tips That Every Software Developer Should Know](https://www.wearedevelopers.com/magazine/101-7-important-tips-that-every-software-developer-should-know) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Best Companies to work for in London: Top 25 Companies in 2023](https://www.wearedevelopers.com/magazine/187-best-companies-to-work-for-in-london-top-25-companies-in-2023)