Jobs · Information Technology · Georgia

Senior Analyst, IT Governance, Risk and Compliance (GRC)

Vestis Corporation · Roswell, GA · 1 mo ago
Information TechnologyFull-time

Responsibilities

  • Support administration and continuous improvement of the IT Governance, Risk, and Compliance (GRC) program.
  • Maintain the enterprise IT risk register, including documentation of risk owners, mitigation plans, due dates, and risk ratings.
  • Facilitate periodic IT risk assessments and control reviews across infrastructure, applications, data, cloud platforms, and vendor environments.
  • Aid business and technology teams in identifying emerging risks and developing risk mitigation plans.
  • Cook up governance committee meetings, risk reviews, and action item tracking.
  • Support policy management processes, including policy updates, exception tracking, and annual reviews.
  • Support compliance activities related to SOX, PCI DSS, privacy requirements, cybersecurity frameworks, and other regulatory obligations.
  • Aid in conducting technology vendor and third-party risk assessments.
  • Coordinate collection and review of security documentation, including SOC reports, security questionnaires, and attestations.
  • Monitor remediation activities associated with vendor risk findings.
  • Maintain vendor risk inventories and reporting.
  • Develop and maintain executive dashboards and reporting using Power BI and related tools.
  • Cook up materials for executive leadership, governance committees, and auditors.
  • Produce recurring risk and compliance reports to support management decision-making.
  • Partner with security operations vendor partner, infrastructure, application, and data teams to track risks identified through vulnerability management, incident response, and other security activities.
  • Aid in governance related to AI, cloud services, data privacy, and emerging technologies.
  • Support awareness initiatives that strengthen the organization's culture of governance and risk management.

Requirements

  • Build strong partnerships within and across IT, Internal Audit, Finance, Legal, Operations, and business functions.
  • Communicate risk findings and recommendations in clear business terms.
  • Influence stakeholders to address risks and compliance gaps through effective reporting and data-driven insights.
  • Promote consistent governance and risk management practices throughout the organization.
  • Working knowledge of risk management frameworks such as NIST, ISO 27001, COBIT, or similar frameworks.
  • Strong analytical and problem-solving skills.
  • Experience/Qualifications:
    • Bachelor's degree in Information Technology, Finance, Business, or related discipline.
    • 10+ years’ experience in IT governance, risk management, internal audit, security operations, or related disciplines.
    • Experience supporting audits, compliance programs, or control assessments.
    • Experience with Microsoft Excel, Power BI, and reporting tools.
    • Excellent written and verbal communication skills.
    • Experience supporting SOX, PCI DSS, privacy, or security programs.
    • Experience with GRC platforms such as ServiceNow GRC, Archer, AuditBoard, or similar tools.
    • Familiarity with cloud platforms (Azure, AWS, or Google Cloud).
    • Professional certifications such as: CRISC, CISA, CGRC, CDPSE, CISSP (Associate or progressing toward) desired.

Similar jobs