H

GRC Analyst - Third-Party Risk

Hampton North • United State
Relocation
Apply
AI Summary

Support Governance, Risk, and Compliance program with third-party vendor risk focus. Manage vendor assessment requests, perform risk reviews, and drive cross-functional follow-up. Analyze intake and ticketing data to identify workflow trends.

Key Highlights
Manage and triage third-party vendor risk assessment intakes
Perform vendor risk reviews, reassessments, and remediation tracking
Analyze intake and ticketing data to identify workflow trends
Key Responsibilities
Manage and triage third-party vendor risk assessment intakes, tracking each request accurately from submission through resolution
Prioritize, route, and track vendor assessments so requests are reviewed and completed on time
Perform vendor risk reviews, reassessments, and remediation tracking
Coordinate with vendors and partners on assessment findings and follow-up items
Drive cross-functional follow-up with Security, Legal, Privacy, Procurement, IT, Finance, and business owners
Analyze intake and ticketing data to identify workflow trends and improvement opportunities across guidance, templates, reporting, and automation
Technical Skills Required
Cybersecurity compliance frameworks and controls ISO 27001 NIST CSF
Benefits & Perks
$90,000 to $130,000 + bonus
Hybrid in Boston
Relocation assistance available

Job Description


GRC Analyst, Third-Party Risk


We are hiring a GRC Analyst to support the Governance, Risk, and Compliance program with a focus on third-party vendor risk. You will own the intake, triage, and completion of vendor assessment requests, keeping them moving through review across a fast-paced, cross-functional environment. This is an operational role where responsiveness, accountability, and follow-through determine success. You will also use intake and ticketing data to surface workflow trends, recurring questions, handoff gaps, and opportunities to sharpen guidance, templates, reporting, and automation.


Compensation: $90,000 to $130,000 + bonus, some flexibility on leveling

Logistics: hybrid in Boston, relocation assistance available


Here's what you'll be doing:

  • Manage and triage third-party vendor risk assessment intakes, tracking each request accurately from submission through resolution
  • Prioritize, route, and track vendor assessments so requests are reviewed and completed on time
  • Perform vendor risk reviews, reassessments, and remediation tracking
  • Coordinate with vendors and partners on assessment findings and follow-up items
  • Drive cross-functional follow-up with Security, Legal, Privacy, Procurement, IT, Finance, and business owners
  • Support broader third-party risk program management activities
  • Analyze intake and ticketing data to identify workflow trends and improvement opportunities across guidance, templates, reporting, and automation

And what you need to have:

  • 2+ years in GRC, with third-party risk management experience preferred
  • Working knowledge of cybersecurity compliance frameworks and controls: ISO 27001, NIST CSF, COSO, SOC 2, PCI-DSS
  • Strong organizational and operational discipline, with the ability to escalate clearly and quickly and bring informed recommendations to management
  • A collaborative approach in a dynamic, fast-moving setting
  • A bachelor's degree in any discipline, with computer science, cybersecurity, risk, or technology degrees preferred

No CTC or sponsorship at this time.


Similar Jobs

Explore other opportunities that match your interests

Cyber Analyst Level 2 (JTAGS Program Support)

Networking
•
8h ago

Premium Job

Sign up is free! Login or Sign up to view full details.

•••••• •••••• ••••••
Job Type ••••••
Experience Level ••••••

Northrop Grumman

United State
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Entry level

Lawrence Livermore National La...

United State
Visa Sponsorship Relocation Remote
Job Type Full-time
Experience Level Not Applicable

Montana Department of Transpor...

United State

Subscribe our newsletter

New Things Will Always Update Regularly