The Senior GRC Analyst is an experienced individual contributor within the IT Security function responsible for advancing Amynta’s governance, risk management, and compliance (GRC) program. This role independently executes information security risk assessments, control oversight, and support for regulatory, audit, and customer assurance requirements.
Hybrid schedule with 3 days in Fort Worth, TX office on a set schedule.
What You Will Do
- Independently assess, analyze, and document information security risks across systems, applications, and technology‑enabled processes using a risk‑based approach.
- Support and maintain the information security governance framework, including policies, standards, procedures, and control documentation.
- Assess the design and operating effectiveness of security controls and provide risk‑based recommendations to Information Security leadership.
- Monitor and report on adherence to internal security policies and applicable regulatory and contractual requirements.
- Identify, track, and report control deficiencies and policy violations; partner with stakeholders to drive corrective actions.
- Support internal and external audits, regulatory examinations, and customer assurance activities, including evidence coordination, audit responses, and remediation tracking.
- Provide governance and coordination support for SOC 2 Type 2 assurance activities, including control readiness, internal testing, and auditor engagement.
- Develop and maintain a centralized security knowledge base to streamline customer, partner, and due‑diligence responses.
- Execute security awareness and training activities, including platform administration and phishing simulations.
- Partner with IT, Legal, and business stakeholders to ensure security requirements are understood and incorporated into relevant processes.
- Support the development and implementation of the IT vendor risk management program, including third‑party risk assessments and vendor risk tracking.
- Contribute to continuous improvement of GRC processes, tooling, and reporting.
- Perform other duties consistent with the scope of the role.
About You