Senior GRC Analyst Wolfe LLC
Overview
Lead compliance evidence ownership for PCI DSS Level 1 SOC 2 Type II IT GRC Kubernetes AWS React certifications. Stack with QSA and external auditors. Define AI governance controls and review process.
What You'll Do11
- 1Run annual PCI DSS v4.0.1 Level 1 assessment and SOC 2 Type II end to end — scope validation evidence collection QSA coordination gap remediation tracking sponsor bank due diligence support
- 2Own IT general control readiness across change management logical access SDLC backup scheduling documenting control narratives walking auditors performing internal design effectiveness testing
- 3Execute third party risk assessments including security questionnaires contract security PCI terms review ongoing vendor monitoring
- 4Administer GRC platform control library cross framework mapping PCI SOC 2 ITGC automated evidence collection control owner workflows compliance dashboards
- 5Take over evidence collection for current PCI DSS v4.0.1 cycle deliver QSA accepted evidence package aging report zero overdue requests at 120 days
- 6Deliver SOC 2 Type II readiness assessment covering change management logical access SDLC backup recovery written control narratives design gaps remediation plan
- 7Migrate open compliance findings into issues register single platform owners due dated publish first monthly issues report to IT steering committee
- 8Support governance pacing with AI adoption controls review process for AI use across organization
- 9Define how governance keeps pace with AI adoption including controls and review process
- 10Operate with minimal oversight direct engagement QSA external auditors compliance advisor engineering fraud product teams
- 11Analyze and communicate success metrics for first 90 to 120 days
Requirements9
- 15+ years building ETL pipelines with Spark and Airflow
- 23-5 seasons experience in regulated financial services environment
- 3CISA CRISC CISSP PCIP ISA certification preferred
- 45+ years supporting PCI DSS in Level 1 service provider or equivalent payment card environment
- 53-5 years directly supporting SOC 2 Type II examinations designing documenting testing IT general controls
- 6Hands-on experience administering GRC platform Vanta Drata Secureframe ServiceNow IRM AuditBoard or similar
- 7Track record running third party risk assessments end to end including security contract compliance terms review
- 8Experience answering to external parties producing deliverables for executive board audiences
- 9Competitive compensation benefits package includes RSUs profit share medical prescription vision dental insurance employee referral bonus tuition reimbursement internal training cultural club
Salary Insight
$114 - $163k per year
Location
Required Skills
Similar open positions
Explore active roles that match your skills and interests.

Javen Technologies, Inc
VerifiedSenior IT Risk and Compliance Analyst - GRC Framework Expertise
Lead ownership of IT governance alignment supporting Bank's GRC framework Enterprise Risk Management and Sarbanes-Oxley compliance. Drive improvements through collaboration with IT staff. Analyze technology risks and develop appropriate controls. Stand out by delivering measurable risk reduction outcomes within first 90 days.

Mergen IT LLC
VerifiedCybersecurity GRC Consultant NIST CSF 2.0
Lead end to end engagement governance project planning milestones risks oversee Cybersecurity GRC Consultant NIST CSF 2.0 San Francisco CA (Onsite) drive practical improvement roadmap deliver results within 90 days
Scigon Solutions
VerifiedGRC Specialist II Scigon Solutions Chicago Illinois Onsite Payroll
Senior Information Governance Specialist II leads and executes critical Information Governance Compliance services protecting firm and client data throughout its lifecycle. Serves as subject matter expert and escalation point partnering with attorneys IT and senior Risk Management leaders to ensure policies client requirements and applicable laws are applied consistently and defensibly.
LPL Financial Corp
VerifiedAnalyst II Tech Governance & Assurance
We seek a skilled IT Risk & Controls professional to lead our first line of defense in IT compliance. You will own daily readiness testing and audit facilitation for critical programs like SOX SOC 1 SOC 2 CCPA/CPRA cybersecurity audits and NYDFS attestation. This hands-on role embeds within control owners to perform self-testing and drive automation reducing manual effort. Expect collaboration with IT Engineering Security and external auditors to maintain audit readiness year-round.

Shiro Technologies
VerifiedSenior ServiceNow GRC Solution Architect
Design and implement enterprise-wide Cyber Risk Register in ServiceNow leading translation of complex cyber risk requirements into scalable automated solutions. Lead development of workflows reporting dashboards risk scoring and remediation tracking. High visibility role collaborating with business and IT leadership risk committees and cross functional stakeholders.
Robert Half
VerifiedGRC Security Manager Robert Half Salt Lake City Utah Onsite Payroll
Lead cybersecurity governance risk and compliance for a health focused organization in West Valley City Utah shaping security policies evaluating enterprise risk and strengthening compliance practices. Collaborate with audit legal privacy procurement and technical teams to improve resilience managing third party exposure supporting informed security decisions.