Senior GRC Analyst

Greystar Worldwide, LLC$90K — $130K *
US-AnywhereRemote in Texas City, TX
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Information Security, Computer Science, Information Systems, or related field, or equivalent experience.
  • 5+ years in information security with 3+ years focused on GRC, risk, audit, or compliance.
  • Experience in building or operating risk management programs, including assessments and treatment planning.
  • Knowledge of third-party risk management and vendor assessments.
  • Familiar with security frameworks (ISO 27001, SOC 2, NIST 800-53) and GDPR.
  • Familiarity with cloud environments (AWS, GCP, Azure).
  • Knowledge of AI governance concepts or ability to quickly learn new frameworks.

Responsibilities

  • Execute GRC program activities including control assessments and policy reviews.
  • Monitor legal and regulatory changes affecting information security and translate them into requirements.
  • Conduct risk assessments across business units and document findings.
  • Perform third-party risk management and maintain vendor risk documentation.
  • Respond to audits and requests from clients and regulators, including evidence collection.
  • Partner with Legal and Privacy for ESI requests in legal holds or investigations.
  • Audit internal control systems and coordinate with Security management on findings.

Benefits

  • Competitive medical, dental, vision, and life insurance with low employee costs.
  • Generous paid time off starting at 15 vacation days, 4 personal days, and 10 sick days.
  • Onsite housing discounts for team members at Greystar-managed communities.
  • 6-week paid sabbatical after 10 years of service with recurring sabbaticals every 5 years.
  • 401(k) with company match after 6 months of service.
  • Paid parental leave and fertility assistance up to $10,000.
  • Employee assistance program and various insurance plans including pet insurance.
Full Job Description
JOB DESCRIPTION SUMMARY
The Senior GRC Analyst is responsible for executing the day-to-day activities of the Global Information Security Governance, Risk, and Compliance (GRC) program. This senior individual contributor performs security risk assessments, evaluates internal and third-party security controls, supports compliance and audit activities, and helps administer the enterprise GRC technology platform used to monitor, track, and report on security measures. Works closely with the Manager, Information Security and the broader Information Security team to preserve the availability, integrity, and confidentiality of Greystar and customer information in compliance with applicable information security laws, policies, and standards.

JOB DESCRIPTION

Responsibilities
  • Execute information security GRC program activities including control assessments, policy and procedure reviews, exception management, and documentation of security processes for global locations.
  • Monitor for changes in laws, regulations, and industry standards affecting information security requirements (e.g., NIST, ISO 27001, PCI DSS, SOX, GDPR, CCPA), perform periodic compliance assessments, and translate changes into actionable requirements for the business.
  • Conduct periodic risk assessments across business units, applications, infrastructure, and processes. Document findings, partner with control owners on remediation plans, and track issues through closure.
  • Perform third-party risk management activities, including pre-contract security due diligence, recurring vendor risk reviews, and remediation tracking. Maintain the vendor risk inventory and supporting documentation.
  • Respond to client, regulator, and internal audit requests, including security questionnaires (SIG, CAIQ), evidence collection, and findings remediation. Coordinate cross-functional input and maintain a library of standard responses.
  • Partner with Legal, Privacy, and other stakeholders to fulfill Electronically Stored Information (ESI) requests, including identification, preservation, collection, and chain-of-custody documentation in support of legal holds, investigations, and regulatory inquiries.
  • Audit internal control systems on a periodic basis to ensure that access levels, segregation of duties, and configuration baselines remain appropriate. Work closely with the Information Security Officer and Manager, Information Security to respond to audit findings that require action.
  • Run periodic user access reviews and privileged access reviews across in-scope systems and applications. Coordinate with system owners and managers to validate access, document results, and drive timely remediation of inappropriate or excessive access.
  • Maintain the enterprise security awareness program, including company-wide training curricula and ongoing awareness communications that promote secure behavior across the organization.
  • Operate the phishing simulation program, including campaign design, results analysis, and assignment of remediation training for users who require additional reinforcement.
  • Administer and enhance the enterprise GRC platform, including workflow configuration, control library maintenance, reporting, and user support.
  • Develop metrics, dashboards, and reporting on the health of the GRC program for the Information Security Officer and senior leadership.

Qualifications
  • Bachelor's degree in Information Security, Computer Science, Information Systems, or a related field, or equivalent work experience.
  • Five or more years of progressive experience in information security, with at least three years focused on GRC, risk, audit, or compliance.
  • Demonstrated experience building or operating an enterprise risk management program, including risk assessments, risk registers, and risk treatment planning.
  • Experience with third-party risk management, including vendor security assessments and due diligence.
  • Working knowledge of security frameworks and standards including ISO 27001, SOC 2, NIST 800-53, and GDPR.
  • Familiarity with cloud environments (AWS, GCP, Azure) and their risk and compliance implications.
  • Familiarity with AI governance concepts and emerging frameworks (ISO 42001, NIST AI RMF), or a demonstrated ability to learn and apply new frameworks quickly.
  • Strong analytical and problem-solving skills with the ability to translate technical risk into clear business language.
  • Demonstrated ability to manage multiple priorities, drive issues to closure, and work independently with minimal supervision.
  • Collaborative approach with the ability to influence partners across IT, Engineering, Legal, Privacy, Internal Audit, and the business.
  • Industry certifications such as CRISC, CISA, CISSP, or CCSK are a plus.
  • Experience with GRC platforms such as Hyperproof, OneTrust, Archer, or similar is a plus.
  • Experience with security awareness training platforms such as KnowBe4 or similar is a plus.


#LI-BB1

Additional Compensation:

Many factors go into determining employee pay within the posted range including business requirements, prior experience, current skills and geographical location.
  • Corporate Positions: In addition to the base salary, this role may be eligible to participate in a quarterly or annual bonus program based on individual and company performance.
  • Onsite Property Positions: In addition to the base salary, this role may be eligible to participate in weekly, monthly, and/or quarterly bonus programs.


Robust Benefits Offered*:
  • Competitive Medical, Dental, Vision, and Disability & Life insurance benefits. Low (free basic) employee Medical costs for employee-only coverage; costs discounted after 3 and 5 years of service.
  • Generous Paid Time off. All new hires start with 15 days of vacation, 4 personal days, 10 sick days, and 11 paid holidays. Plus your birthday off after 1 year of service! Additional vacation accrued with tenure.
  • For onsite team members, onsite housing discount at Greystar-managed communities are available subject to discount and unit availability.
  • 6-Week Paid Sabbatical after 10 years of service (and every 5 years thereafter).
  • 401(k) with Company Match up to 6% of pay after 6 months of service.
  • Paid Parental Leave and lifetime Fertility Benefit reimbursement up to $10,000 (includes adoption or surrogacy).
  • Employee Assistance Program.
  • Critical Illness, Accident, Hospital Indemnity, Pet Insurance and Legal Plans.
  • Charitable giving program and benefits.


*Benefits offered for full-time employees. For Union and Prevailing Wage roles, compensation and benefits may vary from the listed information above due to Collective Bargaining Agreements and/or local governing authority.

About Greystar Worldwide, LLC

Greystar Worldwide, LLC Careers

Joining Greystar Worldwide, LLC presents an unparalleled opportunity to become part of a leading team of professionals dedicated to pioneering innovations in the global marketplace. Greystar Worldwide, LLC stands as a beacon of career growth and professional development, offering a plethora of job opportunities across various sectors.

Explore Career Opportunities

Greystar Worldwide, LLC invites talented individuals to explore its diverse range of job opportunities. From internships that provide a solid foundation for future leaders to full-time positions that challenge and expand professional skills, Greystar Worldwide, LLC is a hub for career advancement.

Innovation and Leadership

At Greystar Worldwide, LLC, innovation intersects with leadership, driving the company to new heights in industry standards and operational excellence. Employees are encouraged to lead projects that set benchmarks in technology and service, fostering a culture of continuous improvement and creative problem-solving.

Diversity and Inclusion

With a commitment to diversity and inclusion, Greystar Worldwide, LLC ensures that all team members receive diversity training, promoting an environment where everyone’s contributions are valued. This approach not only enhances team dynamics but also contributes to the company’s robust problem-solving capabilities.

Professional Growth and Development

Career growth at Greystar Worldwide, LLC is not just a possibility—it is a priority. The company supports its employees with unmatched training programs, leadership development courses, and opportunities for networking and professional growth. This commitment ensures that every team member can reach their full potential.

Benefits and Culture

Greystar Worldwide, LLC is renowned for its vibrant culture and comprehensive benefits package designed to support the well-being and financial security of every team member. Employment at Greystar Worldwide, LLC means access to health benefits, retirement plans, and wellness programs that together create a supportive and positive workplace.

Join the Greystar Worldwide, LLC Team

Greystar Worldwide, LLC is actively hiring and looking for individuals who are passionate, curious, and driven to excel. Candidates interested in applying are encouraged to submit their resume and prepare for an interview process that values insight, experience, and a readiness to contribute to a dynamic team.

Stay Connected with Greystar Worldwide, LLC Careers

Stay informed about the latest in career opportunities and company news by subscribing to Greystar Worldwide, LLC job alerts and reading the careers blog. Personalize the subscription to receive updates that match specific career interests and skills.

SEARCH GREYSTAR WORLDWIDE, LLC JOBS

READ CAREERS BLOG

Greystar Worldwide, LLC is not just a company—it is a place where careers are made, skills are honed, and professional achievements are recognized and celebrated. Join Greystar Worldwide, LLC to be part of a team that is shaping the future through innovation, leadership, and a commitment to excellence.
Learn more about Greystar Worldwide, LLC

Similar Jobs

More Jobs at Greystar Worldwide, LLC

More Information Technology Jobs

Find similar Senior GRC Analyst jobs: