GRC Analyst

Benesch Law

$99K — $120K *
Technical Services
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Information Security, Cybersecurity, Information Technology, Business, or related field or equivalent experience.
  • Minimum of 6 years experience in cybersecurity with a focus on GRC software platforms.
  • Foundational understanding of cybersecurity principles and risk management.
  • Knowledge of compliance frameworks such as ISO 27001, CIS, and NIST.
  • Strong analytical, documentation, and communication skills, especially with stakeholders.
  • Preferred certifications include CISA, CRISC, CGRC, Security+, ISO 27001 Internal Auditor, or CISM.

Responsibilities

  • Develop and maintain security and compliance policies, standards, and procedures.
  • Support internal governance processes, including document lifecycle management.
  • Track and report on compliance with internal control frameworks and policies.
  • Lead third-party risk management activities, including vendor assessments.
  • Conduct and document risk assessments across business units and processes.
  • Maintain the enterprise risk register and ensure risks are properly scored and remediated.
  • Assist with compliance efforts related to various regulatory frameworks.

Benefits

  • Hybrid work arrangement with flexibility for remote work.
  • Discretionary bonus eligibility for full-time positions.
  • Comprehensive benefits package including health and wellness offerings.
  • Professional development opportunities to enhance skills and certifications.
Full Job Description
Benesch is proud to announce the opening for a GRC Analyst in our Cleveland office! This position is hybrid and has work from home flexibility.

Position Summary

Are you an experience cybersecurity professional who has 6 or more years of working knowledge with GRC focused software platforms? Are you looking for a challenging opportunity to joining and cutting-edge, growing security division within a professional services organization? Then you may be interested in our GRC Analyst position. This role is perfect for the individual looking to be an essential part of a security team that focuses on supporting internal governance processes and developing policies and procedures. Join Benesch and play a pivotal role in shaping the success of our IT department.

The Governance, Risk, and Compliance (GRC) Analyst is responsible for supporting the implementation, execution, and continuous improvement of the organization's GRC program. This role ensures that risk management, policy governance, and compliance activities align with organizational objectives, regulatory requirements, and industry best practices.

POSITION RESPONSIBILITIES

Governance
  1. Develops, maintains, and updates security and compliance policies, standards, and procedures.
  2. Supports internal governance processes, including document lifecycle management, policy reviews, and approvals.
  3. Tracks and reports on compliance with internal control frameworks and policies.

Risk Management
  1. Leads third-party risk management activities, including vendor assessments, evidence review, and continuous monitoring.
  2. Conducts and documents risk assessments across business units, systems, and processes.
  3. Maintains the enterprise risk register and ensures risks are properly categorized, scored, and remediated.
  4. Partners with stakeholders to identify risk treatment options and tracks remediation activities.

Compliance
  1. Assists with compliance efforts related to client obligations, outside counsel guidelines, and frameworks such as ISO 27001, CIS, SOC 2, NIST CSF/800-53, GDPR, HIPAA, PCI, or others relevant to the organization.
  2. Collects, validates, and maintains evidence for internal/external audits.
  3. Supports regulatory and certification audits by coordinating with internal teams and external auditors.
  4. Monitors and reports on compliance gaps, exceptions, and corrective actions.

Security Awareness & Training
  1. Helps develop and administer security awareness programs.
  2. Supports phishing simulation campaigns and related analytics to track organizational improvement.

Monitoring & Reporting
  1. Produces regular and ad-hoc reports on risk, compliance posture, and control effectiveness.
  2. Utilizes GRC tools (e.g., SIG, Archer, OneTrust, LogicGate, ZenGRC) to manage workflows and dashboards.
  3. Tracks KPIs/KRIs to measure program maturity and effectiveness.

QUALIFICATIONS

The GRC Analyst requires a bachelor's degree in Information Security, Cybersecurity, Information Technology, Business, or a related field, or equivalent professional experience. A minimum of six years' experience is required for this position. The GRC Analyst has a foundational understanding of cybersecurity principles and risk management, knowledge of compliance frameworks such as ISO 27001, CIS, and NIST, strong analytical and documentation skills, and excellent communication and stakeholder management abilities. Preferred qualifications include experience with GRC software platforms; CISA, CRISC, CGRC, Security+, ISO 27001 Internal Auditor, or CISM certification, whether in progress or completed; and experience supporting audits or risk assessments in a regulated environment.

Key attributes for this role include being detail-oriented, organized, collaborative, and proactive, with the ability to manage multiple priorities. Able to work effectively with technical and non-technical teams, translate technical controls into business context, and take ownership of assigned tasks.ted and proactive, with a strong commitment to accuracy, follow-through and continuous improvement. The Specialist should also demonstrate professional presence, sound judgment and discretion in handling sensitive information, along with curiosity and strategic interest in legal market recognition, competitive positioning and process improvement.

The salary range for this position is $99K to $120K.

Please note that quoted salary ranges are based on Benesch's good faith belief at the time of the job posting and are not a guarantee of what final salary offers may be. Base pay is based on market location and may vary depending on job-related knowledge, skills, and experience. Base pay is only one part of the Total Rewards that Benesch provides to compensate and recognize our staff professionals for their work. Full-time positions are eligible for a discretionary bonus and a comprehensive benefits package.

Similar Jobs

More Jobs at Benesch Law

More Technical Services Jobs

Find similar GRC Analyst jobs: