Senior GRC Analyst
About the Opportunity
Join a large, well-established financial services organization during a period of significant technology transformation. As the company invests heavily in AI and emerging technology, the Technology Risk team is helping build governance around these changes from the ground up – rather than simply maintaining an existing, mature program. This is a lean, high-visibility team within a large enterprise, offering meaningful ownership and the opportunity to directly shape how technology and AI risk are managed going forward.
The Role
This position sits within the organization’s Technology Risk function as a second-line risk role, focused on governance, risk management, controls, and cross-functional stakeholder engagement rather than hands-on technical cybersecurity work. You’ll work closely with Technology, Cybersecurity, Enterprise Risk, Legal, Compliance, and Internal Audit teams.
Key Responsibilities
- Lead technology and cyber risk assessments across the organization
- Manage and maintain the technology risk register
- Support internal and external audits, as well as regulatory exams
- Help build and mature governance frameworks around AI and other emerging technologies
- Contribute to continuous improvement of the broader GRC program and processes
- Partner cross-functionally with stakeholders across the business to influence and improve governance practices
What We’re Looking For
- Bachelor’s degree (or equivalent experience) and 5+ years of experience in IT risk management, cybersecurity governance, IT audit, GRC, compliance, consulting, or professional services
- Strong knowledge of regulatory and governance frameworks such as NIST, SOX, NYDFS, BMA, ISO 27001, and COBIT
- Experience with enterprise GRC platforms; ServiceNow GRC experience highly valued
- Background in Big Four consulting, IT audit, or compliance strongly preferred (candidates with experience limited to third-party risk management alone are unlikely to have the breadth needed)
- Strong communication skills and executive presence, with the ability to engage and influence stakeholders across the organization
- Self-starter who can work both independently and collaboratively in a fast-paced environment
What Sets This Role Apart
- Direct exposure to AI governance as the organization actively rolls out generative AI tools and invests in responsible adoption of emerging technology
- Roughly a 50/50 mix of ongoing risk/governance work and project-based initiatives
- Strong potential for growth into a technical lead position for high performers, with increasing responsibility and visibility over time
- Highly collaborative culture that emphasizes autonomy with accountability, continuous learning, and proactive communication
Schedule
Hybrid – 4 days in-office, 1 remote day per week after training
