Senior Analyst-GRC

Berry Appleman and Leiden

$90K — $110K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 3-5 years in information security, GRC, compliance, or related field.
  • 2+ years in internal audit, GRC, or compliance/risk role.
  • Experience with risk management methodologies and audit processes.
  • Familiarity with ISO 27001, ISO 27701, and data protection regulations.
  • Strong interpersonal and communication skills for diverse audiences.
  • Knowledge of AI governance and emerging regulatory frameworks preferred.

Responsibilities

  • Lead internal audits and develop risk-based audit plans.
  • Manage and improve Information Security and Privacy Management Systems.
  • Support privacy program operations and compliance with data protection laws.
  • Expand AI governance framework and perform risk assessments for AI tools.
  • Conduct Third-Party Risk Management assessments and due diligence reviews.
  • Oversee data loss prevention tools and incident response functions.
  • Maintain Business Continuity and Disaster Recovery program and documentation.

Benefits

  • Professional development opportunities in evolving GRC and AI governance areas.
  • Exposure to complex organizational environments and regulatory frameworks.
  • Collaborative team environment with autonomy in decision-making.
  • Engagement with diverse stakeholders across the organization.
Full Job Description


PRIMARY RESPONSIBILITIES:

  • Leads and performs internal audits using a risk-based methodology; assess IT, InfoSec, Privacy, and AI-related controls and processes; develops and executes audit plans, manages and prioritizes findings based on risk ratings, and tracks corrective action plans to closure.
  • Supports the ongoing management and improvement of BAL's Information Security Management System (ISMS) and Privacy Information Management System (PIMS) to maintain compliance and certification with ISO standards 27001 and 27701.
  • Supports privacy program operations including Records of Processing Activities maintenance, Data Protection Impact Assessments (DPIAs), and Data Subject Access Request (DSAR).
  • Supports the expansion and ongoing management of BAL's AI governance framework, including leading risk assessments of AI tools and use cases against applicable regulatory frameworks (e.g., EU AI Act), development and maintenance of AI acceptable use policies, creation and maintenance of an AI system inventory, and the development of AI specific vendor due diligence criteria.
  • Supports the Third-Party Risk Management (TPRM) program by performing risk-tiered vendor assessments, security and privacy due diligence reviews, maintaining the vendor risk register, and escalating findings to appropriate stakeholders.
  • Serves as the primary operator of BAL's data loss prevention (DLP) tools, managing alert queues, refining detection policies and works with the SecOps team to review and escalate security operations alerts and vulnerabilities to ensure timely remediation.
  • Supports review and response for Security Operations, and Privacy exposure events (incident response).
  • Owns and maintains BAL's Business Continuity and Disaster Recovery (BC/DR) program, including plan documentation, scheduled testing and tabletop exercises, gap identification and remediation tracking, and periodic reporting to firm leadership on program status and maturity.
  • Development and management of BAL's GRC metrics and reporting, including defining Key Performance Indicators (KPIs) and Key Risk Indicators (KRIs) across Information Security, Privacy, and AI governance domains.
  • Supports the development and ongoing management of BAL's data governance program, including data classification, data inventory and mapping, records retention policy enforcement, and coordination with practice groups on data lifecycle management.


QUALIFICATIONS:

Skills and Abilities:

  • Experience applying risk management methodologies to assess, prioritize, and remediate security, privacy, and compliance risks across complex organizational environments
  • Demonstrated knowledge of information security and privacy frameworks including ISO 27001, ISO 27701, NIST CSF, and applicable data protection regulations (GDPR, U.S. state privacy laws)
  • Familiarity with AI governance frameworks and emerging regulatory requirements (EU AI Act, NIST AI RMF) with the ability to translate regulatory obligations into operational controls
  • Experience conducting and supporting internal audits, including audit planning, control testing, findings documentation, and remediation tracking
  • Working knowledge of Third-Party Risk Management (TPRM) methodologies and vendor due diligence processes and best practices
  • Familiarity with Data Loss Prevention (DLP) tooling, security operations alert management, and vulnerability triage processes
  • Experience developing and maintaining KPIs and KRIs for GRC programs, with the ability to translate metrics into executive level reporting
  • Strong interpersonal skills including the ability to achieve goals through genuine influence, collaboration, and cooperation
  • Exceptional written and verbal communication skills with demonstrated ability to convey complex security, privacy, and compliance concepts clearly to both technical and non-technical audiences, including firm leadership, attorneys, and clients
  • Ability to quickly adapt to new concepts / processes while maintaining performance levels within a dynamic and challenging environment
  • Ability to maintain professionalism while interacting with customers and colleagues at all levels and to foster positive business relationships
  • Ability to work independently and in a collaborative team environment
  • Genuine interest in the evolving GRC and AI governance landscape, with a commitment to continuous learning and professional development
  • Comfortable operating with autonomy in ambiguous situations; takes initiative to identify gaps and drive solutions forward


Experience:

  • Minimum of 3-5 years' experience in information security, GRC, compliance, or a related field, with demonstrated exposure to GRC, risk management, audit, and/or privacy programs.
  • 2+ years' direct experience in internal audit, GRC, or a compliance/risk role, with familiarity with audit methodologies, control testing, and findings documentation
  • Experience with TPRM programs, AI governance frameworks, or assessing risk of third-party and AI/ML vendors a plus; familiarity with emerging regulatory standards (e.g., NIST AI RMF, EU AI Act) preferred
  • Knowledge of ISO standards 27001 and 27701
  • CISA, CRISC, CGRC (formerly CAP), or other relevant GRC or audit certification a plus


Minimum Education Level:

  • Bachelor's degree in related field or equivalent experience.


Note: To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed are representative of the knowledge, skill, and/or ability required and are not intended to be an exhaustive list of all duties, responsibilities or qualifications associated with this job.

Similar Jobs

More Jobs at Berry Appleman and Leiden

More Information Technology Jobs

Find similar Senior Analyst-GRC jobs: