Company
Technology
GRCAnalyst,Operations&Risk
Neural analysis suggests this role is
optimal for Entry candidates.
“GRC Analyst, Operations & Risk. Skills: GRC program operations, Third-party risk management, Security compliance, Risk program management. Support GRC program operations. Manage GRC intakes”
Industry & Context.
Critical thinking; Assess complex issues
What They're Looking For.
Must Have
2+ years of experience, Bachelor's degree
Nice to Have
Computer science degree preferred, Cyber security degree preferred, Risk degree preferred, Technology degree preferred, CISA certification preferred, CRISC certification preferred
What You'll Do.
Support GRC program operations
Perform third-party risk management
Support third-party risk management
Conduct vendor reviews
Perform vendor reassessments
Follow-up with Security
Follow-up with Privacy
Follow-up with Procurement
Follow-up with Finance
Follow-up with business owners
Assist with risk program management
Support security compliance monitoring
Support audit readiness
Manage audit request lists
Gather security audit evidence
Coordinate security awareness training
Manage security awareness training
How You'll Work.
Team & Collaboration
Cross-functional follow-up; Work with management
Communication Scope
Verbal communication; Written communication
Full Job Description
RESPONSIBILITIES: - - Support day-to-day GRC program operations – manage and triage GRC intakes and accurate tracking through resolution - Perform and support third-party risk management activities, including vendor reviews, reassessments, partner coordination, remediation tracking, and cross-functional follow-up with Security, Legal, Privacy, Procurement, IT, Finance, and business owners - Assist with risk program management activities - Support security compliance monitoring and audit readiness activities, managing audit request lists and taking ownership of gathering security audit evidence to verify compliance with internal policies / regulations and industry best practices - Coordinate security awareness and training program management activities QUALIFICATIONS: - - 2+ years of experience in GRC, third-party risk management, security compliance, internal audit, risk management, or a related function - Deep understanding of Cybersecurity compliance frameworks and cybersecurity compliance controls – ISO 27001, NIST CSF, COSO, SOC 2, PDI-DSS - Possess a strong risk mindset, exceptional attention to detail, and the ability to apply critical thinking when assessing complex issues and control gaps - Highly organized and strong operational discipline ensuring clear and expedient escalations with informed recommendations to management - Superior interpersonal and communication skills – verbal and written - Being a team player and working to achieve common goal in a dynamic setting - Strong commitment to embracing and leveraging AI tools in day-to-day tasks, ensuring AI-assisted work aligns with the same high-quality standards as personal contributions. - A minimum bachelor’s degree in any discipline. Computer science, cyber security and risk or technology degrees preferred. CISA or CRISC certification preferred
Applying for this GRC Analyst, Operations & Risk role?
Most applicants get filtered before a human reads their resume. See if yours makes the cut.
How to Apply on Ashby
- Ashby is a fast modern ATS — most applications take under 3 minutes.
- The resume parser is strong; verify parsed experience dates and job titles.
- Custom screening questions are often scored algorithmically — answer completely.
- Location field affects geo-based screening; use your actual metro area.
ANONYMOUS · UNFILTERED
What do employees actually say about this company?
Real rants from real employees. Read before you apply.