About this role
-
IT GRC Lead Analyst reports to the AVP of IT Compliance and is responsible for leading governance, risk, and compliance activities across the IT organization. This role supports the design, execution, and ongoing maturity of the IT Governance, Risk, and Compliance (GRC) program by helping ensure IT policies, standards, controls, risks, and compliance activities align with regulatory requirements, audit expectations, enterprise risk objectives, and recognized frameworks such as SOX, NYDFS, COBIT, NIST, and ISO 27001.
The IT GRC Lead Analyst serves as a key partner to IT leadership, control owners, cybersecurity, internal audit, external auditors, compliance, and enterprise risk teams. This role leads activities across IT governance, IT risk management, and IT compliance, including control monitoring, risk assessments, audit readiness, issue remediation, policy governance, framework alignment, reporting, and continuous improvement.
Key Accountabilities/Deliverables:
- Lead and directly execute day-to-day IT GRC activities across IT governance, IT risk, and IT compliance under the direction of the AVP of IT Compliance.
- Support the execution and maturity of the IT GRC program by both coordinating team activities and personally performing key deliverables, including risk assessments, control reviews, evidence validation, audit support, and remediation tracking.
- Lead and perform IT governance activities, including policy, standard, and procedure reviews; control ownership documentation; framework mapping; exception tracking; approval evidence; and governance reporting.
- Conduct IT risk assessments, including identifying risks, evaluating control design and operating effectiveness, documenting findings, assigning risk ratings, recommending remediation actions, and tracking issues through closure.
- Perform IT compliance monitoring activities, including control testing, evidence review, issue identification, remediation tracking, and validation of corrective actions.
- Coordinate and actively support audit readiness efforts by managing evidence requests, preparing control owners, reviewing documentation, tracking audit deliverables, and responding to internal and external auditor requests.
- Prepare and maintain IT GRC artifacts, including risk registers, control matrices, control narratives, testing records, audit artifacts, remediation trackers, policy inventories, issue logs, and governance dashboards.
- Monitor, analyze, and report on IT GRC KPIs, KRIs, audit issues, control gaps, policy exceptions, remediation progress, overdue items, and emerging areas of concern.
- Partner directly with IT control owners to strengthen control design, improve process documentation, resolve control gaps, and support sustainable remediation of findings.
- Serve as a key working liaison between IT, cybersecurity, internal audit, external audit, enterprise risk, compliance, legal, control owners, and business stakeholders on GRC-related activities.
- Provide hands-on guidance, coaching, task coordination, and quality review for IT GRC analysts, including reviewing evidence, workpapers, risk assessments, status updates, and remediation documentation.
- Identify and implement improvements to IT GRC processes, reporting, evidence collection, governance workflows, control monitoring, and audit readiness practices.
- Escalate significant risks, control gaps, overdue remediation items, audit concerns, and governance issues to the AVP of IT Compliance in a timely manner.
- Support IT compliance and governance awareness by helping communicate policy expectations, control responsibilities, risk obligations, and audit readiness requirements across IT.
Technical Knowledge and Understanding:
- Strong understanding of IT governance, IT risk management, and IT compliance principles, including how policies, standards, risks, controls, and evidence support regulatory, audit, and business requirements.
- Working knowledge of key frameworks, standards, and regulations such as SOX, NYDFS Cybersecurity Regulation, COBIT, NIST CSF, ISO 27001, COSO, HIPAA, and other applicable requirements.
- Strong understanding of IT General Controls, including access management, privileged access, change management, computer operations, backup and recovery, incident management, system development lifecycle, and third-party technology controls.
- Hands-on knowledge of IT control testing practices, including test planning, evidence review, control performance validation, issue documentation, remediation tracking, and management reporting.
- Knowledge of IT governance practices, including policy and standard lifecycle management, control ownership, approval workflows, exceptions, framework mapping, document repositories, and governance dashboards.
- Ability to interpret regulatory, framework, and control requirements and translate them into practical testing procedures, evidence requests, governance activities, risk assessments, and remediation actions.
- Understanding of cybersecurity and technology risk areas, including identity and access management, vulnerability management, endpoint security, data protection, logging and monitoring, cloud controls, business continuity, disaster recovery, and third-party risk.
- Strong analytical, documentation, communication, stakeholder management, and leadership skills, with the ability to explain risk, control, and compliance matters to both technical and non-technical stakeholders.
- Ability to lead workstreams while also performing hands-on execution, including reviewing evidence, preparing work papers, documenting findings, tracking remediation, and preparing status reporting.
Requirements:
Applicants must be authorized to work for any employer in the U.S. We are unable to sponsor or take over work authorization sponsorship now or in the future for this position.
- Bachelor's degree in Information Systems, Cybersecurity, Risk Management, Information Assurance, Business Administration, or related field; or equivalent experience.
- 5+ years of experience in IT Governance, Risk Management, Compliance, IT Audit, Cybersecurity Governance, Internal Controls, or a related technology risk discipline.
- Demonstrated experience leading or coordinating IT compliance programs, control monitoring activities, risk assessments, governance initiatives, audit engagements, and remediation efforts.
- Strong understanding of governance frameworks, risk management methodologies, internal control concepts, compliance monitoring practices, and issue management processes.
- Experience supporting compliance with regulatory and industry requirements including SOX, NYDFS, HIPAA, ISO 27001, NIST CSF, COBIT, COSO, privacy regulations, or similar frameworks.
- Experience developing, maintaining, and interpreting IT policies, standards, procedures, control documentation, and governance artifacts.
- Experience performing or overseeing risk assessments, compliance reviews, control evaluations, certification activities, and control attestation processes.
- Experience supporting external audits, internal audits, regulatory examinations, customer due diligence activities, and management responses.
- Experience preparing executive reporting, dashboards, metrics, KPIs, KRIs, committee materials, and compliance status updates.
- Experience managing risk registers, corrective action plans, compliance exceptions, findings, and remediation tracking activities.
- Experience collaborating with technology, security, legal, privacy, audit, business, and executive stakeholders in a highly regulated environment.
- Experience using GRC, reporting, workflow, and evidence management tools such as Jira, Confluence, SharePoint, Microsoft 365, Power BI, or similar platforms.
- Strong analytical, organizational, project coordination, and communication skills, including the ability to lead initiatives with minimal supervision.
- Professional certifications such as CISA, CRISC, CISSP, CISM, CGEIT, ISO 27001 Lead Auditor, ISO 27001 Lead Implementer, or equivalent certifications preferred.
- Experience within insurance, financial services, healthcare, or other regulated industries preferred.
#LI-Hybrid
-
At Core Specialty, you will receive a competitive salary and opportunities for professional development and advancement. We offer medical, dental, vision, and life insurances; short and long-term disability; a Company-match of 100% of a 6% contribution 401(k) plan; an Employee Assistance Plan; Health Savings Account, Flexible Spending Account, Health Reimbursement Account, and a wellness program