Black & Veatch

Senior Analyst, GRC

Black & Veatch$85K — $110K *
Finance & Insurance
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 7-10 years of experience in Governance, Risk, and Compliance (GRC) including auditing against standards and regulations
  • Experience supporting GRC functions in global companies
  • Proficiency in risk assessment methodologies and frameworks
  • Ability to assess the alignment of policies and processes with regulatory standards
  • Familiarity with industry standards (e.g., NIST CSF, ISO 27001)
  • Understanding of cyber and privacy laws and regulations
  • Professional certifications like CRISC or CISSP preferred

Responsibilities

  • Manage and assess contract risks related to data security and compliance
  • Support independent audits by collecting evidence from various departments
  • Monitor global regulatory and compliance landscape
  • Develop and enforce IT policies in line with contractual requirements
  • Establish metrics for measuring cyber risk effectiveness
  • Assess and mitigate third-party vendor risks
  • Assist in internal audits and develop risk treatment plans

Benefits

  • Hybrid or flexible work options after 90 days
  • Opportunities for professional development and certifications
  • Collaborative work environment
  • Engaging in a culture that promotes risk awareness
  • Access to tools and technology to drive efficiencies
Full Job Description
The Opportunity

The Sr. Analyst, Governance, Risk, and Compliance (GRC) plays an important role in the GRC delivery framework, ensuring Black & Veatch's compliance with contractual and regulatory requirements, assessing control design and operation against common standards and frameworks, and assisting with third-party/supply chain risk management. The candidate will also promote a culture of risk awareness across the enterprise among other responsibilities. With an emphasis on cyber, contract and regulatory compliance risk management, the ideal candidate should be able to contribute to measuring success and identifying improvement opportunities and capabilities development in these areas.

This role is ideal for a detail-oriented professional with a passion for cyber and compliance risk management who is comfortable operating independently. Independent and critical thinking is absolutely necessary to be successful in this role as is a desire to drive efficiencies in function delivery and day-to-day tasks.

Key Responsibilities

Contract Risk Management
  • Proven experience reviewing client contract provisions related to data security, breach reporting, cyber resilience, and compliance certifications and measuring compliance in IT and security architecture and operations.

Regulatory Compliance Risk Management
  • Support independent certification and audit by working with D&IT peer groups and lines of business to collect documentation and evidence of security policies and operations
  • Request and review documentation and evidence from control owners to certify and validate compliance to standards and industry-accepted best practice
  • Monitor regulatory and legal landscape at a global scale and across market sectors and maintain awareness of compliance requirements

IT Governance
  • Act as an informed voice in development of policy and ensure alignment with regulatory, legal, and contractual requirements
  • Assist establishment and enforcement of standards of practice documentation to be referenced by architecture and operations teams
  • Contribute process and subject matter expertise in governance forums and cross-functional committees

Cyber Risk Management
  • Support establishment, collection, and ongoing improvement of metrics to measure effectiveness of cyber risk management and provide data-driven insight to decision makers and control owners
  • Collaborate with peer D&IT groups to collect KPI's, KRI's and drive efficiency through automation and other means

Supplier/Third Party Risk Management
  • Contribute subject matter expertise through third party risk assessment process
  • Identify and communicate risk of vendor engagements and mitigation actions to business owners and D&IT stakeholders
  • Assist review of client security requirements in contracts and aggregate relevant clauses to inform contractual risk

Miscellaneous:
  • Assist development of user training aligned with cyber threat landscape, establish and implement metrics, and propose enhancements
  • Support internal audit
  • Assist with security certification/attestations/audits to demonstrate control effectiveness to independent service auditors/assessors and C3PAO's
  • Assist in development of risk treatment plans and monitoring progress of actions.
  • Collaborate with members of the GRC team to ensure timely and quality deliverables to internal and external customers
  • Contribute subject matter expertise in review and response to internal and external sourced GRC related requests


Management Responsibilities

Individual Contributor

Preferred Qualifications

  • 7-10 years of experience in GRC executing or auditing against standards, frameworks, and industry regulations
  • Demonstrated experience supporting GRC functions for global companies
  • Solid proficiency in risk assessment methodologies and frameworks
  • Proven ability to assess alignment of internal policy, process, control design and operations, and cyber risk management with regulatory standards and frameworks
  • Strong collaboration with IT teams
  • Familiarity with industry standards and frameworks (e.g., NIST CSF and supporting SP's, ISO 27001, AICPA SOC)
  • Working knowledge of cyber and privacy laws and regulations
  • Solid understanding of information security principles and concepts
  • Strong desire to create task and functional efficiencies through use of technology and tools, especially GenAI
  • Strong analytical, organizational, and communication skills
  • Professional certifications such as CRISC, CISSP or others
  • Experience with ServiceNow Risk Management platform
  • Knowledge of FAR, DFARS, CMMC
  • Experience with GRC platforms and risk management methodologies
  • Ability to work independently and collaboratively as required


Minimum Qualifications

  • Bachelor's degree in Information Systems, Computer Science or a related field, or relevant years of experience to substitute for a degree.
  • 2-3 years of experience in a GRC role


Work Environment/Physical Demands

Hybrid or flexible work options may be offered after the first 90 days of employment based upon manager discretion, job performance and work assignments.

Salary Plan

ITS: Information Technology Service

Job Grade

015

About Black & Veatch

Black & Veatch is a global engineering and construction company. The company was founded in 1915 and is headquartered in Overland Park, Kansas. Black & Veatch provides a range of services, including engineering, procurement, and construction (EPC) services, consulting, and environmental services. The company serves a variety of industries, including power, water, telecommunications, and oil and gas. Black & Veatch has operations in more than 100 countries around the world.
Learn more about Black & Veatch
Size
11,000 employees
Industry
Founded
1915

Similar Jobs

More Jobs at Black & Veatch

More Finance & Insurance Jobs

Find similar Senior Analyst, GRC jobs: