Similar Jobs
See allCyber GRC Analyst
Warner Music Group
Canada
GRC
Security Operations
KPI
Governance, Risk and Compliance (GRC) Analyst
CapIntel
North America
Security
Compliance
Risk Management
GRC Analyst
Radicle Health
US
GRC
Risk Management
Compliance
Director, GRC, Engineering
Smartsheet
US
Leadership
Management
GRC
Senior Manager, Security Risk Management
Affirm
Canada
NIST
ISO
GRC
Position Responsibilities:
- Execute end-to-end third-party and vendor risk assessments, including inherent risk scoring, due diligence reviews, and residual risk evaluation
- Review and analyze third-party artifacts such as SOC reports, ISO certifications, policies, procedures, and security questionnaires
- Identify control gaps, document risk issues, and track remediation activities with vendors and internal stakeholders
Reporting, Metrics & Executive Support:
- Develop, maintain, and enhance risk metrics, dashboards, and reporting for third-party risk
- Track key performance indicators (KPIs) and key risk indicators (KRIs) related to vendor risk, assessment cycle times, remediation status, and risk trends
- Prepare materials for leadership and executive-level reporting, translating risk data into clear, actionable insights
Broader GRC Support:
- Assist with additional GRC activities as needed, including policy management, risk assessments, control testing, and compliance initiatives
- Support alignment with recognized frameworks and standards (e.g., NIST CSF, ISO 27001, SOC, FFIEC, or similar)
- Participate in continuous improvement of GRC processes, templates, and methodologies
Aprio
Aprio is a Top 20 CPA and advisory firm that accounts for anything. With over 3,200 team members and 40 U.S. office locations, plus international offices, they bring proven expertise and strategic foresight to fast-growing industries.