IT GRC - Risk Analyst

Core Specialty InsuranceCincinnati, OhioOn-siteFull-timeMid level, 2–5 yearsListed 4 hours ago

Apply now

About this role

-

The IT GRC - Risk Analyst supports the IT Governance, Risk, Compliance (GRC) team by helping assess, monitor, and manage technology and cybersecurity risks associated with vendors, suppliers, service providers, and other third parties. This role helps ensure third-party relationships are reviewed in alignment with internal policies, regulatory expectations, contractual requirements, and recognized frameworks such as NIST, COBIT, SOC 2, and applicable cybersecurity and privacy requirements.

The IT GRC - Risk Analyst works closely with IT, cybersecurity, procurement, legal, compliance, business owners, and vendors to support vendor risk assessments, evidence collection, questionnaire reviews, issue tracking, remediation follow-up, and ongoing monitoring activities. The role helps strengthen the organization’s third-party risk management program by identifying risks, documenting findings, and supporting timely, risk-based decisions.

Key Accountabilities/Deliverables:

- Support the execution of the third-party risk management process as part of the IT GRC team, including initial assessments, reassessments, ongoing monitoring, and remediation tracking.
- Conduct third-party risk assessments by reviewing vendor questionnaires, security documentation, SOC reports, certifications, policies, penetration test summaries, business continuity information, and other relevant evidence.
- Identify and document third-party technology, cybersecurity, privacy, operational, and compliance risks based on vendor responses and supporting documentation.
- Work with business owners, IT teams, cybersecurity, legal, procurement, compliance, and vendors to collect required information and resolve assessment gaps.
- Review vendor control environments against internal requirements, regulatory expectations, and applicable frameworks.
- Support risk rating activities by evaluating vendor criticality, data sensitivity, service type, system access, control maturity, and potential business impact.
- Track third-party risk findings, remediation plans, risk acceptances, exceptions, and outstanding vendor information requests through completion.
- Maintain accurate and organized assessment records, evidence, risk summaries, vendor profiles, decision documentation, and approval artifacts.
- Support ongoing vendor monitoring activities, including security rating changes, alerts, performance indicators, contract or service changes, and emerging third-party risks.
- Prepare clear assessment summaries, risk reports, dashboards, status updates, and escalation materials for management review.
- Escalate significant vendor risks, overdue remediation items, missing information, control concerns, and high-risk third-party relationships to IT GRC leadership.
- Assist with improving third-party risk processes, assessment templates, questionnaires, workflows, reporting, evidence standards, and monitoring practices.
- Support audit and regulatory readiness by maintaining third-party risk documentation and responding to requests related to vendor risk management activities.

Technical Knowledge and Understanding:

- Understanding of third-party risk management principles, including vendor due diligence, risk assessments, ongoing monitoring, issue tracking, and risk-based decision-making.
- Working knowledge of cybersecurity, IT risk, privacy, and compliance concepts relevant to third-party service providers.
- Familiarity with frameworks, standards, and reports such as NIST CSF, ISO 27001, COBIT, SOC 1, SOC 2, PCI DSS, HIPAA, NYDFS, and other applicable requirements.
- Understanding of common vendor risk areas, including access management, data protection, encryption, vulnerability management, incident response, logging and monitoring, business continuity, disaster recovery, subcontractor risk, and cloud/SaaS security.
- Ability to review vendor questionnaires, SOC reports, certifications, policies, security summaries, and other evidence to identify control gaps and risk concerns.
- Knowledge of third-party risk rating concepts, including vendor criticality, inherent risk, residual risk, data sensitivity, control maturity, and remediation priority.
- Strong analytical, documentation, communication, and follow-up skills, with the ability to summarize risks clearly for technical and non-technical stakeholders.
- Ability to manage multiple vendor assessments, track deadlines, follow up on open items, and maintain audit-ready assessment documentation.
- Professional certifications such as Security+, CISA, CRISC, CTPRP, ISO 27001 Foundation, or similar certifications are a plus.

Requirements:

Applicants must be authorized to work for any employer in the U.S.  We are unable to sponsor or take over work authorization sponsorship now or in the future for this position.

- Bachelor’s degree in Information Systems, Cybersecurity, Risk Management, Information Assurance, Business Administration, or related field; or equivalent work experience.
- 3+ years of experience in IT Governance, Risk Management, Compliance (GRC), IT Audit, Cybersecurity, Internal Controls, or a related technology risk function.
- Experience supporting technology and cybersecurity risk assessments, risk analysis, control evaluations, compliance reviews, or governance activities.
- Knowledge of IT risk management principles, control frameworks, risk treatment strategies, remediation tracking, and issue management practices.
- Experience documenting and maintaining risk registers, findings, remediation plans, exceptions, and governance artifacts.
- Experience supporting compliance with regulatory and industry frameworks such as NIST CSF, ISO 27001, COBIT, NYDFS, HIPAA, SOX, or similar standards.
- Experience supporting internal audits, external audits, regulatory examinations, customer due diligence reviews, or compliance assessments.
- Experience collaborating with Information Security, IT Operations, Application Owners, Compliance, Legal, Internal Audit, and business stakeholders to manage risk and remediation activities.
- Experience developing risk metrics, dashboards, reports, and management summaries for governance and risk reporting.
- Experience using GRC, workflow, reporting, and collaboration tools such as Jira, Confluence, SharePoint, Microsoft 365, Power BI, or similar platforms.
- Strong analytical, organizational, communication, and problem-solving skills with the ability to assess risks and communicate recommendations effectively.
- Professional certifications such as CRISC, CISA, CISM, CGRC, CISSP, or similar certifications preferred.
- Experience within insurance, financial services, healthcare, or other regulated industries preferred.

#LI-Hybrid

-

At Core Specialty, you will receive a competitive salary and opportunities for professional development and advancement.  We offer medical, dental, vision, and life insurances; short and long-term disability; a Company-match of 100% of a 6% contribution 401(k) plan; an Employee Assistance Plan; Health Savings Account, Flexible Spending Account, Health Reimbursement Account, and a wellness program