> Markdown version of [/jobs/ext/613670-senior-grc-analyst](https://www.wearedevelopers.com/jobs/ext/613670-senior-grc-analyst). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior GRC Analyst - **Company:** Greystar Real Estate Partners, LLC - **Location:** Southlake, TX, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Artificial Intelligence, Amazon Web Services, Microsoft Azure, Cyber Security, Information Systems, Information Security Management, PCI Data Security Standards, Phishing, Simulation Software, Google Cloud, Cloud Platform System, Information Technology, RSA Archer Platform - **Published:** June 19, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=94c4a16be99a1170 ## About the Role Do you have experience in Vendor risk management?, Do you have a Bachelor's degree?, * Bachelor's degree in Information Security, Computer Science, Information Systems, or a related field, or equivalent work experience. * Five or more years of progressive experience in information security, with at least three years focused on GRC, risk, audit, or compliance. * Demonstrated experience building or operating an enterprise risk management program, including risk assessments, risk registers, and risk treatment planning. * Experience with third-party risk management, including vendor security assessments and due diligence. * Working knowledge of security frameworks and standards including ISO 27001, SOC 2, NIST 800-53, and GDPR. * Familiarity with cloud environments (AWS, GCP, Azure) and their risk and compliance implications. * Familiarity with AI governance concepts and emerging frameworks (ISO 42001, NIST AI RMF), or a demonstrated ability to learn and apply new frameworks quickly. * Strong analytical and problem-solving skills with the ability to translate technical risk into clear business language. * Demonstrated ability to manage multiple priorities, drive issues to closure, and work independently with minimal supervision. * Collaborative approach with the ability to influence partners across IT, Engineering, Legal, Privacy, Internal Audit, and the business. * Industry certifications such as CRISC, CISA, CISSP, or CCSK are a plus. * Experience with GRC platforms such as Hyperproof, OneTrust, Archer, or similar is a plus. * Experience with security awareness training platforms such as KnowBe4 or similar is a plus. ## Description The Senior GRC Analyst is responsible for executing the day-to-day activities of the Global Information Security Governance, Risk, and Compliance (GRC) program. This senior individual contributor performs security risk assessments, evaluates internal and third-party security controls, supports compliance and audit activities, and helps administer the enterprise GRC technology platform used to monitor, track, and report on security measures. Works closely with the Manager, Information Security and the broader Information Security team to preserve the availability, integrity, and confidentiality of Greystar and customer information in compliance with applicable information security laws, policies, and standards., * Execute information security GRC program activities including control assessments, policy and procedure reviews, exception management, and documentation of security processes for global locations. * Monitor for changes in laws, regulations, and industry standards affecting information security requirements (e.g., NIST, ISO 27001, PCI DSS, SOX, GDPR, CCPA), perform periodic compliance assessments, and translate changes into actionable requirements for the business. * Conduct periodic risk assessments across business units, applications, infrastructure, and processes. Document findings, partner with control owners on remediation plans, and track issues through closure. * Perform third-party risk management activities, including pre-contract security due diligence, recurring vendor risk reviews, and remediation tracking. Maintain the vendor risk inventory and supporting documentation. * Respond to client, regulator, and internal audit requests, including security questionnaires (SIG, CAIQ), evidence collection, and findings remediation. Coordinate cross-functional input and maintain a library of standard responses. * Partner with Legal, Privacy, and other stakeholders to fulfill Electronically Stored Information (ESI) requests, including identification, preservation, collection, and chain-of-custody documentation in support of legal holds, investigations, and regulatory inquiries. * Audit internal control systems on a periodic basis to ensure that access levels, segregation of duties, and configuration baselines remain appropriate. Work closely with the Information Security Officer and Manager, Information Security to respond to audit findings that require action. * Run periodic user access reviews and privileged access reviews across in-scope systems and applications. Coordinate with system owners and managers to validate access, document results, and drive timely remediation of inappropriate or excessive access. * Maintain the enterprise security awareness program, including company-wide training curricula and ongoing awareness communications that promote secure behavior across the organization. * Operate the phishing simulation program, including campaign design, results analysis, and assignment of remediation training for users who require additional reinforcement. * Administer and enhance the enterprise GRC platform, including workflow configuration, control library maintenance, reporting, and user support. * Develop metrics, dashboards, and reporting on the health of the GRC program for the Information Security Officer and senior leadership., Many factors go into determining employee pay within the posted range including business requirements, prior experience, current skills and geographical location. * Corporate Positions: In addition to the base salary, this role may be eligible to participate in a quarterly or annual bonus program based on individual and company performance. * Onsite Property Positions: In addition to the base salary, this role may be eligible to participate in weekly, monthly, and/or quarterly bonus programs. ## Related Videos - [Forecasting Cyber Attacks with Glassdoor Reviews - Lianne Potter](https://www.wearedevelopers.com/videos/2143-forecasting-cyber-attacks-with-glassdoor-reviews-lianne-potter) - [The Cloud is Calling: Answer with In-Demand Skills](https://www.wearedevelopers.com/videos/945-the-cloud-is-calling-answer-with-in-demand-skills) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Tackling the Risks of AI - With AI](https://www.wearedevelopers.com/videos/1690-tackling-the-risks-of-ai-with-ai) - [Skynet wants your Passwords! The Role of AI in Automating Social Engineering](https://www.wearedevelopers.com/videos/770-skynet-wants-your-passwords-the-role-of-ai-in-automating-social-engineering) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Got AI ideas but no money? Here are 10 free ways to level up your AI skills with Google Cloud](https://www.wearedevelopers.com/magazine/600-got-ai-ideas-but-no-money-here-are-10-free-ways-to-level-up-your-ai-skills-with-google-cloud) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Highest Paying Tech Companies for Developers](https://www.wearedevelopers.com/magazine/220-highest-paying-tech-companies-for-developers) - [The Biggest German Tech Companies](https://www.wearedevelopers.com/magazine/424-the-biggest-german-tech-companies) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)