US Jobs US Jobs     UK Jobs UK Jobs     EU Jobs EU Jobs


IT GRC - Risk Analyst

-

The IT GRC - Risk Analyst supports the IT Governance, Risk, Compliance (GRC) team by helping assess, monitor, and manage technology and cybersecurity risks associated with vendors, suppliers, service providers, and other third parties.

This role helps ensure third-party relationships are reviewed in alignment with internal policies, regulatory expectations, contractual requirements, and recognized frameworks such as NIST, COBIT, SOC 2, and applicable cybersecurity and privacy requirements.

The IT GRC - Risk Analyst works closely with IT, cybersecurity, procurement, legal, compliance, business owners, and vendors to support vendor risk assessments, evidence collection, questionnaire reviews, issue tracking, remediation follow-up, and ongoing monitoring activities.

The role helps strengthen the organization’s third-party risk management program by identifying risks, documenting findings, and supporting timely, risk-based decisions.

Key Accountabilities/Deliverables:


* Support the execution of the third-party risk management process as part of the IT GRC team, including initial assessments, reassessments, ongoing monitoring, and remediation tracking.


* Conduct third-party risk assessments by reviewing vendor questionnaires, security documentation, SOC reports, certifications, policies, penetration test summaries, business continuity information, and other relevant evidence.


* Identify and document third-party technology, cybersecurity, privacy, operational, and compliance risks based on vendor responses and supporting documentation.


* Work with business owners, IT teams, cybersecurity, legal, procurement, compliance, and vendors to collect required information and resolve assessment gaps.


* Review vendor control environments against internal requirements, regulatory expectations, and applicable frameworks.


* Support risk rating activities by evaluating vendor criticality, data sensitivity, service type, system access, control maturity, and potential business impact.


* Track third-party risk findings, remediation plans, risk acceptances, exceptions, and outstanding vendor information requests through completion.


* Maintain accurate and organized assessment records, evidence, risk summaries, vendor profiles, decision documentation, and approval artifacts.


* Support ongoing vendor monitoring activities, including security rating changes, alerts, performance indicators, contract or service changes, and emerging third-party risks.


* Prepare clear assessment summaries, risk reports, dashboards, status updates, and escalation materials for management review.


* Escalate significant vendor risks, overdue remediation items, missing information, control concerns, and high-risk third-party relationships to IT GRC leadership.


* Assist with improving third-party risk processes, assessment templates, questionnaires, workflows, reporting, evidence standards, and monitoring practices.


* Suppo...




Share Job