HYBRID IN CHARLOTTE, NORTH CAROLINA / HARTFORD, CONNECTICUT /or SHORT HILLS NEW JERSEYOptomi, in partnership with a leading provider in the insurance industry is seeking a Sr. GRC Analyst that will establish governance, risk, compliance, vendor risk, and vulnerability management activities with increasing independence. This role is designed for a developing risk professional who can execute risk assessments, analyze control evidence, support regulatory and audit requirements, coordinate remediation tracking, and produce clear reporting for stakeholders. The role applies working knowledge of cybersecurity controls, risk frameworks, third-party due diligence, vulnerability governance, and issue management to support consistent, defensible risk decisions.
Responsibilities: GRC Program Execution Execute assigned GRC activities, including risk documentation, control mapping, exception tracking, and assessment record maintenance. Support policy, standard, and procedure lifecycle activities by coordinating updates, collecting input, and validating evidence of approvals. Prepare materials for governance forums, risk reviews, audit discussions, and compliance reporting using established templates and data sources. Third-Party Risk Management Coordinate vendor assessment intake, due diligence requests, follow-ups, and stakeholder communications through closure. Review vendor questionnaires, SOC reports, ISO certifications, penetration test summaries, vulnerability information, business continuity documentation, and other due diligence artifacts for completeness and risk relevance. Document assessment conclusions, remediation items, missing evidence, and residual risk considerations in alignment with defined TPRM procedures. Vulnerability Management Governance Support vulnerability governance activities by tracking remediation status, exception requests, risk acceptance documentation, and aging issues. Partner with technology and risk stakeholders to validate ownership, required evidence, and remediation progress for identified vulnerabilities or control gaps. Contribute to recurring metrics and reporting related to vulnerability trends, overdue remediation, exception volume, and issue closure. Audit and Compliance Support Collect, organize, and validate audit evidence in accordance with defined control objectives and regulatory expectations. Assist with remediation tracking for audit findings, control gaps, risk acceptances, and compliance action items. Maintain documentation aligned to frameworks and requirements such as NIST CSF, NIST 800-53, NYDFS, GLBA, SOX, SOC reporting, and ISO 27001.Metrics and Continuous Improvement Maintain and enhance routine metrics for risk assessment volume, vendor status, vulnerability remediation, open issues, and documentation completeness. Identify opportunities to improve templates, procedures, evidence requests, stakeholder instructions, and process consistency. Support process improvement efforts by documenting pain points, recommending practical updates, and helping implement approved changes.

Also on the board Same function, level within a rung

Level

Manager

Location

Short Hills, NJ

Occupation

Information Security Analysts

Industry

Other Scientific and Technical Consulting Services

Posted

yesterday

Apply for this role →