Senior Risk and Compliance Analyst
This role is a key member of the IT Governance, Risk, and Compliance (GRC) team, responsible for supporting and advancing the organization’s IT risk, compliance, and third-party risk management (TPRM) programs. The Senior Risk and Compliance Analyst partners with stakeholders across IT, Information Security, Procurement, Legal, OT, and the business to assess technology and vendor-related risks, strengthen governance practices, and support risk-informed decision-making.
Responsibilities
- Act as an advisor for IT GRC, providing guidance to IT and business stakeholders while advancing strategic GRC initiatives.
- Lead and enhance the IT third-party risk management program, encompassing vendor risk assessments, onboarding procedures, ongoing monitoring, and remediation of identified risks.
- Collaborate with Information Security, IT, Procurement, Legal, and business teams to evaluate third-party vendors, applications, and services enterprise-wide.
- Review third-party security documentation, including SOC reports, ISO certifications, security questionnaires, policies, and other relevant evidence to assess control maturity and residual risk.
- Partner with the Security Operations Center (SOC) to monitor emerging threats, industry developments, and incident response insights, leveraging findings to assess and refine the risk profiles of critical vendors and technology supply chain partners.
- Support the end-to-end risk intake workflow, help to maintain the IT risk register process, and ensure timely escalation of technology risks.
- Collaborate with the IT Compliance Managers to support risk assessments for internal initiatives, third-party relationships, and critical business processes.
- Contribute to the development of security metrics and dashboards, leveraging automated and manual processes to produce relevant KRIs/KPIs that measure and communicate risk exposure and program effectiveness.
- Maintain current knowledge of industry best practices and monitor the legal and regulatory environment for developments that may require changes to policies and practices.
- Drive automation efforts within the GRC and third-party risk programs by identifying manual or repetitive tasks and implementing technology solutions or workflow tools to improve efficiency, consistency, and reporting.
- Continuously seek opportunities to optimize and modernize GRC operations through technical innovation and automation.
Requirements
- 4 or more years of experience in Information Security, Risk Management, Audit, IT Governance, IT Compliance, or related discipline.
- Proven ability to lead and mature an IT Third-Party Risk Management (TPRM) program, including governance, risk assessments, and continuous improvement initiatives.
- Strong understanding of third-party risk management practices across the vendor lifecycle, including due diligence, onboarding, ongoing monitoring, remediation, and offboarding.
- Broad, generalist understanding of information security risk and compliance—comfortable operating across risk, audit, policy, and third-party risk areas.
- Working knowledge of industry frameworks and regulatory requirements, including NIST, ISO, CIS, PCI-DSS, SOX, GDPR, CCPA, and HIPAA.
- High degree of ownership, self-direction, and demonstrated thought leadership.
- Ability to analyze manual processes and implement technical solutions to enhance efficiency and accuracy.
Qualifications
- Bachelor’s degree in business administration, compliance, information systems, privacy, or related field; equivalent work or education-related experience considered.
- One or more relevant certifications: CRISC, CISSP, CISA, CISM, CGEIT, GCCC, GSEC, GISP.
- Proven ability to interact with key stakeholders and align priorities based on risk.
- Familiarity with GRC platforms (e.g., LogicGate, Optro, OneTrust, Workiva).
- Strong written and verbal communication skills; able to present complex risk and compliance topics to both technical and non-technical audiences.
- Proficient in Microsoft Excel, Word, and PowerPoint.
Workplace Requirements
- Occasional lifting up to 25 lbs.
- Sitting, working at desk/personal computer for extended periods of time.
- Primary work environment is professional corporate office.
- Ability to travel commercially and internationally.
Schedule
Full time
Pay
The salary range for this role is $96,700.00 - $148,100.00. This is the lowest to highest salary we in good faith believe we would pay for this role at the time of this posting. Our compensation is based on cost of labor. For remote locations or positions open to multiple locations, the pay range may reflect several US geographic markets, including the lowest geographic market minimum to the highest geographic market maximum. We may ultimately pay more or less than the posted range, and the range may be modified in the future. An employee’s pay position within the salary range will be based on several factors including, but not limited to, the prevailing minimum wage for the location, relevant education, qualifications, certifications, experience, skills, seniority, geographic location, performance, shift, travel requirements, sales or revenue-based metrics, any collective bargaining agreements, and business or organizational needs.
Benefits
- Paid time off
- Medical, dental, and vision insurance
- 401(k) and other benefits for eligible employees
Locations
- Rochester, New York
- Chicago, Illinois
- San Antonio, Texas