Senior Analyst, IT Governance, Risk and Compliance (GRC)
Vestis Corporation · Roswell, GA · 1 mo ago
Information TechnologyFull-time
Responsibilities
- Support administration and continuous improvement of the IT Governance, Risk, and Compliance (GRC) program.
- Maintain the enterprise IT risk register, including documentation of risk owners, mitigation plans, due dates, and risk ratings.
- Facilitate periodic IT risk assessments and control reviews across infrastructure, applications, data, cloud platforms, and vendor environments.
- Aid business and technology teams in identifying emerging risks and developing risk mitigation plans.
- Cook up governance committee meetings, risk reviews, and action item tracking.
- Support policy management processes, including policy updates, exception tracking, and annual reviews.
- Support compliance activities related to SOX, PCI DSS, privacy requirements, cybersecurity frameworks, and other regulatory obligations.
- Aid in conducting technology vendor and third-party risk assessments.
- Coordinate collection and review of security documentation, including SOC reports, security questionnaires, and attestations.
- Monitor remediation activities associated with vendor risk findings.
- Maintain vendor risk inventories and reporting.
- Develop and maintain executive dashboards and reporting using Power BI and related tools.
- Cook up materials for executive leadership, governance committees, and auditors.
- Produce recurring risk and compliance reports to support management decision-making.
- Partner with security operations vendor partner, infrastructure, application, and data teams to track risks identified through vulnerability management, incident response, and other security activities.
- Aid in governance related to AI, cloud services, data privacy, and emerging technologies.
- Support awareness initiatives that strengthen the organization's culture of governance and risk management.
Requirements
- Build strong partnerships within and across IT, Internal Audit, Finance, Legal, Operations, and business functions.
- Communicate risk findings and recommendations in clear business terms.
- Influence stakeholders to address risks and compliance gaps through effective reporting and data-driven insights.
- Promote consistent governance and risk management practices throughout the organization.
- Working knowledge of risk management frameworks such as NIST, ISO 27001, COBIT, or similar frameworks.
- Strong analytical and problem-solving skills.
- Experience/Qualifications:
- Bachelor's degree in Information Technology, Finance, Business, or related discipline.
- 10+ years’ experience in IT governance, risk management, internal audit, security operations, or related disciplines.
- Experience supporting audits, compliance programs, or control assessments.
- Experience with Microsoft Excel, Power BI, and reporting tools.
- Excellent written and verbal communication skills.
- Experience supporting SOX, PCI DSS, privacy, or security programs.
- Experience with GRC platforms such as ServiceNow GRC, Archer, AuditBoard, or similar tools.
- Familiarity with cloud platforms (Azure, AWS, or Google Cloud).
- Professional certifications such as: CRISC, CISA, CGRC, CDPSE, CISSP (Associate or progressing toward) desired.