Senior GRC Analyst
EDZ Systems · Raleigh-Durham-Chapel Hill Area
Apply & track with Apply EdgeSenior GRC Analyst OverviewThe Senior Analyst, Governance, Risk, and Compliance (GRC) plays an important role in the GRC delivery framework, ensuring compliance with contractual and regulatory requirements, assessing control design and operation against common standards and frameworks, and assisting with third-party/supply chain risk management. The candidate will also promote a culture of risk awareness across the enterprise among other responsibilities. With an emphasis on cyber, contract and regulatory compliance risk management, the ideal candidate should be able to contribute to measuring success and identifying improvement opportunities and capabilities development in these areas.This role is ideal for a detail-oriented professional with a passion for cyber and compliance risk management who is comfortable operating independently. Independent and critical thinking is absolutely necessary to be successful in this role as is a desire to drive efficiencies in function delivery and day-to-day tasks.Key ResponsibilitiesContract Risk ManagementProven experience reviewing client contract provisions related to data security, breach reporting, cyber resilience, and compliance certifications and measuring compliance in IT and security architecture and operations.Regulatory Compliance Risk ManagementSupport independent certification and audit by working with D&IT peer groups and lines of business to collect documentation and evidence of security policies and operationsRequest and review documentation and evidence from control owners to certify and validate compliance to standards and industry-accepted best practiceMonitor regulatory and legal landscape at a global scale and across market sectors and maintain awareness of compliance requirementsIT GovernanceAct as an informed voice in development of policy and ensure alignment with regulatory, legal, and contractual requirementsAssist establishment and enforcement of standards of practice documentation to be referenced by architecture and operations teamsContribute process and subject matter expertise in governance forums and cross-functional committeesCyber Risk ManagementSupport establishment, collection, and ongoing improvement of metrics to measure effectiveness of cyber risk management and provide data-driven insight to decision makers and control ownersCollaborate with peer D&IT groups to collect KPI’s, KRI’s and drive efficiency through automation and other meansSupplier/Third Party Risk ManagementContribute subject matter expertise through third party risk assessment process Identify and communicate risk of vendor engagements and mitigation actions to business owners and D&IT stakeholdersAssist review of client security requirements in contracts and aggregate relevant clauses to inform contractual riskQualificationsMinimum RequirementsBachelor’s degree in information systems, Information Security, or a related field7–10 years of experience in GRC executing or auditing against standards, frameworks, and industry regulationsStrong NIST expertise, including NIST SP 800-53, NIST RMF, and NIST Cybersecurity FrameworkProficient with CIS Controls, ISO/IEC 27001, and AICPA SOC 2 / Trust Services CriteriaHands-on risk assessments, control testing, audits, policy/standards development, and remediationStrong technical/IT operations background with the ability to translate security controls and frameworks into practical operational processesDemonstrated experience supporting GRC functions for global companiesSolid proficiency in risk assessment methodologies and frameworks