Company

Technology

GRCAnalyst,Operations&Risk

$75–95k ~AI est. Boston, Massachusetts, United States FULL TIME
Market Sentiment
HIGH DEMAND

Neural analysis suggests this role is
optimal for Entry candidates.

The Brief

“GRC Analyst, Operations & Risk. Skills: GRC program operations, Third-party risk management, Security compliance, Risk program management. Support GRC program operations. Manage GRC intakes”

Industry & Context.

Technology
Problems you'll solve

Critical thinking; Assess complex issues

What They're Looking For.

Must Have

2+ years of experience, Bachelor's degree

Nice to Have

Computer science degree preferred, Cyber security degree preferred, Risk degree preferred, Technology degree preferred, CISA certification preferred, CRISC certification preferred

What You'll Do.

Support GRC program operations

Perform third-party risk management

Support third-party risk management

Conduct vendor reviews

Perform vendor reassessments

Follow-up with Security

Follow-up with Privacy

Follow-up with Procurement

Follow-up with Finance

Follow-up with business owners

Assist with risk program management

Support security compliance monitoring

Support audit readiness

Manage audit request lists

Gather security audit evidence

Coordinate security awareness training

Manage security awareness training

How You'll Work.

Team & Collaboration

Cross-functional follow-up; Work with management

Communication Scope

Verbal communication; Written communication

Full Job Description

RESPONSIBILITIES: - - Support day-to-day GRC program operations – manage and triage GRC intakes and accurate tracking through resolution - Perform and support third-party risk management activities, including vendor reviews, reassessments, partner coordination, remediation tracking, and cross-functional follow-up with Security, Legal, Privacy, Procurement, IT, Finance, and business owners - Assist with risk program management activities - Support security compliance monitoring and audit readiness activities, managing audit request lists and taking ownership of gathering security audit evidence to verify compliance with internal policies / regulations and industry best practices - Coordinate security awareness and training program management activities QUALIFICATIONS: - - 2+ years of experience in GRC, third-party risk management, security compliance, internal audit, risk management, or a related function - Deep understanding of Cybersecurity compliance frameworks and cybersecurity compliance controls – ISO 27001, NIST CSF, COSO, SOC 2, PDI-DSS - Possess a strong risk mindset, exceptional attention to detail, and the ability to apply critical thinking when assessing complex issues and control gaps - Highly organized and strong operational discipline ensuring clear and expedient escalations with informed recommendations to management - Superior interpersonal and communication skills – verbal and written - Being a team player and working to achieve common goal in a dynamic setting - Strong commitment to embracing and leveraging AI tools in day-to-day tasks, ensuring AI-assisted work aligns with the same high-quality standards as personal contributions. - A minimum bachelor’s degree in any discipline. Computer science, cyber security and risk or technology degrees preferred. CISA or CRISC certification preferred

Free ATS check

Applying for this GRC Analyst, Operations & Risk role?

Most applicants get filtered before a human reads their resume. See if yours makes the cut.

How to Apply on Ashby

  • Ashby is a fast modern ATS — most applications take under 3 minutes.
  • The resume parser is strong; verify parsed experience dates and job titles.
  • Custom screening questions are often scored algorithmically — answer completely.
  • Location field affects geo-based screening; use your actual metro area.

ANONYMOUS · UNFILTERED

What do employees actually say about this company?

Real rants from real employees. Read before you apply.

Read Company Rants →