GRC Analyst

AccruePartners, Inc.

$95K — $115K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years in GRC, Information Security, IT Risk, Audit, or Compliance.
  • Proven experience in developing or enhancing GRC programs.
  • In-depth knowledge of frameworks like NIST, SOC 2, ISO 27001.
  • Expertise in managing risk registers and facilitating governance meetings.
  • Skilled in creating executive-level reports and dashboards.
  • Hands-on experience with GRC tools like ServiceNow GRC or Archer.
  • Relevant certifications such as CRISC, CISA, or CISSP are preferred.

Responsibilities

  • Build and implement the enterprise GRC program from scratch.
  • Manage the enterprise risk register, focusing on identification and tracking.
  • Lead Security Steering Committee meetings and coordinate governance forums.
  • Create executive dashboards and reports to enhance visibility into risks.
  • Support compliance with security frameworks and prepare for maturity improvements.
  • Collaborate with internal teams and auditors for effective compliance and audits.
  • Develop documentation and templates to ensure governance sustainability.

Benefits

  • Comprehensive health coverage, including medical, dental, and vision insurance.
  • Generous paid time off policy and flexible work arrangements.
  • Retirement savings plan with company match options.
  • Professional development opportunities and continuing education support.
Full Job Description
WHAT YOU WILL DO
  • Build and operationalize the enterprise Governance, Risk & Compliance (GRC) program from the ground up.
  • Establish, maintain, and manage the enterprise risk register, including risk identification, assessments, remediation tracking, and reporting.
  • Coordinate governance forums and lead operational execution of monthly Security Steering Committee meetings.
  • Develop executive dashboards, KPIs, KRIs, and reporting that provide leadership with meaningful visibility into enterprise risk.
  • Support compliance initiatives aligned with SOC 2, ISO 27001, NIST, and other security frameworks while preparing for future maturity.
  • Partner with internal stakeholders and external auditors to support audits, evidence collection, control mapping, and compliance activities.
  • Create repeatable documentation, governance templates, and operational playbooks that enable long-term sustainability and knowledge transfer.

THE BACKGROUND THAT FITS
  • 5+ years of experience in Governance, Risk & Compliance (GRC), Information Security, IT Risk, Audit, or Compliance.
  • Demonstrated success building or maturing enterprise GRC, risk management, or governance programs.
  • Strong knowledge of security frameworks including NIST, SOC 2, ISO 27001, and enterprise risk management methodologies.
  • Experience managing enterprise risk registers, facilitating governance committees, and driving risk remediation activities.
  • Ability to develop executive-level reporting, dashboards, metrics, and presentations for both technical and business leadership.
  • Hands-on experience with GRC platforms such as ServiceNow GRC, Archer, AuditBoard, LogicGate, OneTrust, or similar solutions.
  • Professional certifications such as CRISC, CISA, CISSP, or ISO 27001 Lead Implementer are highly valued, along with exceptional communication and stakeholder management skills.

Similar Jobs

More Jobs at AccruePartners, Inc.

More Information Technology Jobs

Find similar GRC Analyst jobs: