Find Jobs
Find Jobs Near You – Available Work in Your Location
Skip to job details
IG
Insight Global
Senior GRC Analyst
Career Insights for Risk Manager
See where this job fits in the broader career landscape. Knowing your career path helps you see what's possible from here.
Scorecard
Based on Pennsylvania data
Review key factors to help you decide if this role fits your goals. How is this calculated?
What they do
A Risk Manager evaluates risk and recommends and manages strategies to mitigate or offset risks that could result in financial losses for a company or organization. Analyzes current risks and assesses potential new risks. Reviews contracts and insurance policies; prepares risk budgets. Communicates risk policies and procedures to staff at all levels of a company.
$102,842 / year median in Pennsylvania
Job Description
Insight Global
Keyword
Location
Search
view all jobs
Senior GRC Analyst
Whitemarsh, PA
Posted 2 days ago
Apply Now Job Description An R D technology client is seeking a Senior Governance, Risk & Compliance Analyst for a contract role supporting the implementation and operationalization of an enterprise GRC platform. This role will focus on helping configure the GRC solution, establish risk and control workflows, support policy and risk framework alignment, and enable repeatable reporting and risk analysis processes. The resource will partner with management, security, IT, compliance, and business stakeholders to translate governance requirements into practical GRC platform capabilities. Management will define overall policy direction, risk appetite, and risk tolerance levels; the Senior GRC Analyst will help operationalize those decisions within the platform. Key Responsibilities
To learn more about how we collect, keep, and process your private information, please review
- Support the implementation and configuration of the GRC platform, including risk registers, control libraries, assessment workflows, reporting, and dashboards.
- Help translate management-defined policies, risk appetite, and risk tolerance levels into measurable GRC workflows and platform rules.
- Align the GRC setup to a NIST SP 800-53-based risk and control framework.
- Configure risk scoring models, risk categories, ownership structures, assessment templates, and remediation workflows.
- Support setup of risk and control ownership assignments across business, IT, and security teams.
- Develop practical workflows for risk identification, assessment, treatment, acceptance, exception tracking, and remediation.
- Operationalize Level 1 risk analysis, including intake triage, initial risk categorization, evidence review, scoring support, and escalation criteria.
- Assist with AI-enabled automation for Level 1 risk analysis, including intake summarization, control mapping, risk classification, suggested scoring, and draft remediation recommendations.
- Support integration planning with identity management, ticketing, reporting, or other enterprise systems.
- Create documentation, playbooks, procedures, and training materials to support sustainable GRC operations.
- Prepare initial risk, control, and compliance reports for leadership and stakeholders.
- Support stakeholder engagement, go-live readiness, and post-launch stabilization.
To learn more about how we collect, keep, and process your private information, please review
Insight Global's Workforce Privacy Policy:
https://insightglobal.com/workforce-privacy-policy/. Skills and Requirements- Senior-level experience in governance, risk, compliance, or information security risk management.
- Hands-on experience implementing, configuring, or operationalizing a GRC platform.
- Strong understanding of risk registers, control frameworks, control testing, risk assessments, remediation tracking, and exception management.
- Experience with NIST SP 800-53 or similar control frameworks.
- Ability to translate governance and policy requirements into operational workflows, platform configuration, and reporting.
- Experience defining or supporting risk scoring models, risk categories, control mappings, and risk treatment processes.
- Ability to work with security, IT, compliance, audit, and business teams to drive ownership and adoption.
- Familiarity with AI-enabled workflow automation, risk intake automation, or analytics-driven risk triage.
- Experience with implementing GRC platforms.
- Experience integrating GRC platforms with ticketing, identity management, reporting, or workflow tools.
- Familiarity with AI use cases for GRC, including control mapping, risk summarization, evidence analysis, and automated risk triage.
- Experience supporting enterprise risk governance, security compliance, internal audit, or technology risk programs.
- Familiarity with regulatory, privacy, or cybersecurity frameworks such as
ISO 27001, SOC 2, CIS
Controls, orNIST CSF.
- Relevant certifications such as CRISC, CISA, CISM, CISSP, CGRC, or similar are a plus.