Vestis logo

Senior Analyst, IT Governance, Risk And Compliance (Grc)

Automate your job search with Sonara.

Submit 10x as many applications with less effort than one manual application.1

Reclaim your time by letting our AI handle the grunt work of job searching.

We continuously scan millions of openings to find your top matches.

pay-wall

Overview

Schedule
Full-time
Career level
Senior-level
Remote
On-site
Benefits
Career Development

Job Description

Vestis is seeking a highly motivated Senior Analyst, IT Risk & Governance to support the organization's technology governance, risk management, compliance, and control programs. Reporting to the Sr. Director of IT Governance, Risk and Compliance, this role is responsible for coordinating IT risk assessments, maintaining governance processes, overseeing the security operations vendor partner relationship, developing risk reporting and dashboards, and partnering with technology and business teams to strengthen the company's overall risk posture.The Senior Analyst serves as a trusted partner to Internal Audit, Operations, and Finance by helping ensure technology risks are identified, assessed, monitored, and mitigated in a practical and business-aligned manner. This role provides analytical support for enterprise governance initiatives involving cybersecurity, cloud services, data protection, third-party risk, artificial intelligence, and regulatory compliance.Responsibilities/Essential Functions:

  • Support administration and continuous improvement of the IT Governance, Risk, and Compliance (GRC) program.
  • Maintain the enterprise IT risk register, including documentation of risk owners, mitigation plans, due dates, and risk ratings.
  • Facilitate periodic IT risk assessments and control reviews across infrastructure, applications, data, cloud platforms, and vendor environments.
  • Assist business and technology teams in identifying emerging risks and developing risk mitigation plans.
  • Coordinate governance committee meetings, risk reviews, and action item tracking.
  • Support policy management processes, including policy updates, exception tracking, and annual reviews.
  • Support compliance activities related to SOX, PCI DSS, privacy requirements, cybersecurity frameworks, and other regulatory obligations.
  • Assist in conducting technology vendor and third-party risk assessments.
  • Coordinate collection and review of security documentation, including SOC reports, security questionnaires, and attestations.
  • Monitor remediation activities associated with vendor risk findings.
  • Maintain vendor risk inventories and reporting.
  • Develop and maintain executive dashboards and reporting using Power BI and related tools.
  • Coordinate with security operations' vendor partner to gather analytics to assess trends associated with technology risks, vulnerabilities, audit findings, compliance activities, and remediation performance.
  • Prepare materials for executive leadership, governance committees, and auditors.
  • Produce recurring risk and compliance reports to support management decision-making.
  • Partner with security operations vendor partner, infrastructure, application, and data teams to track risks identified through vulnerability management, incident response, and other security activities.
  • Assist with governance related to AI, cloud services, data privacy, and emerging technologies.
  • Support awareness initiatives that strengthen the organization's culture of governance and risk management.

Knowledge/Skills/Abilities:

  • Build strong partnerships within and across IT, Internal Audit, Finance, Legal, Operations, and business functions.
  • Communicate risk findings and recommendations in clear business terms.
  • Influence stakeholders to address risks and compliance gaps through effective reporting and data-driven insights.
  • Promote consistent governance and risk management practices throughout the organization.
  • Working knowledge of risk management frameworks such as NIST, ISO 27001, COBIT, or similar frameworks.
  • Strong analytical and problem-solving skills.

Experience/Qualifications:

  • Bachelor's degree in Information Technology, Finance, Business, or related discipline.
  • 10+ years' experience in IT governance, risk management, internal audit, security operations, or related disciplines.
  • Experience supporting audits, compliance programs, or control assessments.
  • Strong analytical and problem-solving skills.
  • Experience with Microsoft Excel, Power BI, and reporting tools.
  • Excellent written and verbal communication skills.
  • Experience supporting SOX, PCI DSS, privacy, or security programs.
  • Experience with GRC platforms such as ServiceNow GRC, Archer, AuditBoard, or similar tools.
  • Familiarity with cloud platforms (Azure, AWS, or Google Cloud).
  • Professional certifications such as: CRISC, CISA, CGRC, CDPSE, CISSP (Associate or progressing toward) desired.

Automate your job search with Sonara.

Submit 10x as many applications with less effort than one manual application.

pay-wall

FAQs About Senior Analyst, IT Governance, Risk And Compliance (Grc) Jobs at Vestis

What is the work location for this position at Vestis?
This job at Vestis is located in Roswell, GA, according to the details provided by the employer. Some roles may also include multiple work locations depending on the requirement.
What pay range can candidates expect for this role at Vestis?
Employer has not shared pay details for this role.
What employment applies to this position at Vestis?
Vestis lists this role as a Full-time position.
What experience level is required for this role at Vestis?
Vestis is looking for a candidate with "Senior-level" experience level.
What benefits are offered by Vestis for this role?
Vestis offers Career Development for this position. Actual benefits may vary depending on the employer's policies and employment terms.
What is the process to apply for this position at Vestis?
You can apply for this role at Vestis either through Sonara's automated application system, which helps you submit applications 10X faster with minimal effort, or by applying manually using the direct link on the job page.