أبلاي إيدج ابدأ البحث عن عمل

GRC Analyst

New York Technology Partners · Greater Chicago Area

قدّم وتابع مع أبلاي إيدج
We are looking for a highly organized and detail-oriented GRC Analyst with a primary focus on regulatory and organizational compliance. You will be responsible for ensuring the business remains aligned with applicable laws, regulations, and internal policies by building and maintaining scalable governance, risk, and compliance systems that support audit readiness without slowing business momentum. This role goes beyond checklists and audits—it is about building trust and accountability into the way we operate and grow.Your core responsibility will be to manage and continuously improve our compliance programs. You will develop scalable processes, manage certification and audit activities from start to finish, oversee remediation efforts, and align teams around a consistent compliance strategy. Your work will help ensure we meet the requirements of frameworks such as GDPR, HIPAA, ISO 27001, SOC 2, and other applicable standards as we grow.You bring a strong understanding of compliance frameworks, solid program management skills, and the ability to identify and address risks proactively. You will collaborate across Legal, IT, HR, Security, and Finance to align teams and keep compliance initiatives moving forward.You will also contribute to broader governance and risk initiatives, including policy development, risk registers, incident response, and organization-wide compliance awareness.This is a high-trust, high-impact role for someone who thrives in a fast-paced environment and enjoys creating structure, improving processes, and driving meaningful results. If this role aligns with your experience and strengths, we’d love to meet you.Key ResponsibilitiesPrimary: Compliance OwnershipLead the implementation, maintenance, and continuous improvement of compliance programs and controls across the organization.Monitor compliance with external regulatory requirements, including GDPR, HIPAA, ISO 27001, SOC 2, and PCI DSS, as well as internal policies.Serve as a subject matter expert (SME) for compliance initiatives, audits, and assessments.Partner with Legal, IT, HR, Finance, Security, and other internal stakeholders to support organization-wide compliance.Track and report on compliance metrics, findings, violations, and remediation efforts.Manage certification and audit processes from planning through completion.Supporting: Governance & Policy ManagementAssist with drafting, reviewing, updating, and communicating policies and procedures.Ensure policies reflect current regulatory requirements and align with business objectives.Support internal and external audits related to governance, risk, and compliance.Help maintain documentation and evidence required for ongoing compliance activities.Supporting: Risk ManagementConduct compliance risk assessments and identify potential control gaps.Maintain compliance risk registers and monitor emerging regulatory risks.Evaluate compliance risks and escalate key issues to the appropriate stakeholders.Partner with cross-functional teams to develop and track remediation plans.Supporting: Incident & Issue ManagementInvestigate potential compliance violations and data privacy incidents.Maintain incident and issue logs and coordinate with appropriate teams to support resolution.Support the development and continuous improvement of incident response plans from a compliance perspective.Lead compliance training and awareness initiatives across the organization.Promote a culture of accountability, risk awareness, and compliance.QualificationsRequired:1+ years of direct experience in compliance, regulatory affairs, governance, risk management, or internal controls.Working knowledge of compliance frameworks and regulatory requirements, including GDPR, HIPAA, SOC 2, and ISO 27001.Ability to interpret complex regulatory requirements and translate them into practical business processes and controls.Experience leading or supporting an organization through a certification or compliance audit, such as SOC 2, ISO 27001, HIPAA, or a similar framework.Experience working with GRC platforms such as Drata, Vanta, ServiceNow GRC, OneTrust, or similar tools.Key Competencies:Strong attention to detail and understanding of regulatory requirements.Excellent communication skills, with the ability to translate compliance concepts into clear, actionable guidance for cross-functional teams.Strong organizational and project management skills with the ability to manage multiple compliance initiatives simultaneously.Ability to adapt and prioritize in a fast-paced, evolving environment.Proactive, analytical, and solution-oriented approach to identifying and addressing risks.Strong collaboration skills and the ability to build relationships across departments.