Senior GRC Analyst
Core
Lead day-to-day execution of the Governance, Risk, and Compliance (GRC) program, focusing on cybersecurity and AI risk assessments, exceptions management, and SDLC reviews.
Role type
Senior GRC Analyst (Cybersecurity & Risk)
Builds
Enterprise cyber risk registers, risk mitigation plans, executive risk reports, and dashboards for leadership visibility.
Domain
Cybersecurity, Enterprise Risk Management, AI Governance
Required skills
Cybersecurity risk assessment, IT risk management, Risk register maintenance, Security frameworks (NIST CSF, ISO 27001, PCI DSS), Regulatory compliance (GDPR, HIPAA), AI/ML risk evaluation, FAIR analysis, Technical-to-business translation
Preferred skills
Professional certifications (CRISC, CISSP, CISA, CGRC), AI governance frameworks (NIST AI RMF, ISO/IEC 42001)
Technologies
NIST CSF, ISO 27001, PCI DSS, GDPR, HIPAA, NIST AI RMF, ISO/IEC 42001, FAIR
Responsibilities
Lead cyber, AI, and technology risk assessments across systems and cloud environments; Maintain and operate the enterprise cyber risk register; Translate technical findings into clear business risk scenarios; Support quantitative cyber risk analysis approaches like FAIR; Prepare materials for the Cyber Risk Committee and executive reporting; Partner with Security Architecture to assess risk in system designs and cloud architecture; Collaborate with cross-functional teams to evaluate new initiatives and third-party integrations; Conduct risk assessments for emerging technologies including AI and ML systems; Develop dashboards for leadership visibility into cybersecurity risks.
Seniority
Senior, hands-on IC

