Suzy Logo

Suzy

GRC Analyst

Reposted 3 Days Ago
Remote or Hybrid
Hiring Remotely in United States
125K-135K Annually
Mid level
Remote or Hybrid
Hiring Remotely in United States
125K-135K Annually
Mid level
The GRC Analyst will manage risk management, regulatory compliance, audit processes, and IT asset management while collaborating across teams.
The summary above was generated by AI

Suzy puts the voice of the consumer at your fingertips. Whether you’re a novice or an expert researcher, our platform brings advanced tools together with the highest quality audience to deliver insights in minutes. Some of the biggest brands in the world use Suzy to deliver breakthrough products and experiences backed by data-driven decisions. Learn more at www.suzy.com.

The Governance, Risk, Compliance (GRC) Analyst will manage policies, procedures, and standards to govern the protection of corporate information systems, networks, data, and 3rd party services. The analyst will stay up to date on the latest cybersecurity intelligence while managing privacy workflows to ensure the company meets regulatory compliance.

Responsibilities

  • Third Party Risk Management

    • Provide oversight, coordination, and deliver the activities supporting successful risk management activities around third parties

    • Perform risk analysis for systems, processes, third-party tools/applications, and configurations

    • Perform Third Party Risk Management (TPRM) functions and analyze SOC-2 and other reporting from vendors

    • Respond to initial and annual security questionnaires from customers

  • Controls and Risk Management

    • Manage company’s Risk Register

    • Perform periodic risk assessments

    • Document the results and develop a plan of action and milestones for mitigating identified risk

    • Gather data for metric reporting for company’s Information Security and Privacy Council

  • Audits

    • Coordinate multiple large-scale audit projects and programs simultaneously

    • Help implement Governance, Risk and Control tool

    • Document business ownership and responsibilities of security controls using the company’s GRC tool

    • Schedule and perform regular assessments (internal and external) to test the effectiveness of controls

    • Manage remediation efforts for the identified gaps including assessment of new or enhanced implemented controls

    • Coordinate, track, and verify remediation of audit findings

  • Asset Management

    • Maintain Suzy’s information asset inventory with accurate and updated information

    • Identify and rank the value, sensitivity, and criticality of the operations and assets that could be affected should a threat materialize

Basic Qualifications

  • Creative problem solver and desire to learn

  • Willing to #getyourhandsdirty and work across cross-functional teams

  • Bachelor’s degree or equivalent work experience (Information Technology, Engineering, Cybersecurity, Audit, Risk, Compliance, or a related technical field)

  • Familiarity with industry security frameworks, including SCF, ISO, SOC, and NIST

  • Audit, compliance, and/or risk management experience

  • Experience in Project Management Methodologies

  • Experience testing or auditing technical controls

Preferred Qualifications

  • Certified Information Security Auditor/Manager (CISA/M) designation or CISSP, CRISC, CISA, CIPT, CIPP

  • Direct participation in ISO/SOC audits

  • Understanding of Enterprise Risk Management and Strategy frameworks

  • Providing consultative information security or risk management services to a broad range of companies

  • Experience proposing enterprise level solutions to mitigate risk

  • Experience creating and managing corporate security policies

  • Microsoft cloud technical certifications

Benefits:

  • We take care of our employees and their families. We have generous health dental and vision benefits, and our 401K plan vests immediately

  • A friendly, fun, and collaborative work environment that allows for frequent exposure to executives

  • The opportunity to make an immediate impact as a part of a fast-growing company

  • The target base compensation for this role is $125,000 - $135,000.

Suzy is an equal opportunity employer. We are a welcoming place for everyone, and we do our best to ensure all people feel supported and connected at work.

Suzy is committed to protecting its customers, employees, partners, and the company as a whole, from damaging acts that are intentional or unintentional. Effective security is a team effort involving the participation and support of every user who interacts with company information/data and systems. It is the responsibility of each individual to help protect company information assets.

#LI-Remote #LI-LH1

Click Here to view our Applicant Privacy Notice

Top Skills

Iso
Microsoft Cloud Certifications
Nist
Scf
Soc

Suzy New York, New York, USA Office

Just north of Times Square, this location is in the Brill Building, known for launching the careers of many musicians and artists. This combination of art and science is at the core of Suzy.

Similar Jobs

8 Days Ago
Remote or Hybrid
New York, NY, USA
110K-140K Annually
Mid level
110K-140K Annually
Mid level
AdTech • Cloud • Digital Media • Information Technology • News + Entertainment • App development
The Lead IT GRC Analyst will manage the security governance framework, develop governance processes, and ensure compliance with industry standards, while collaborating with various stakeholders.
Top Skills: Active DirectoryArcherAzure AdCisIso 27001M365Microsoft Defender For CloudNistOnetrustServicenow GrcSlack
Yesterday
In-Office or Remote
3 Locations
106K-243K Annually
Senior level
106K-243K Annually
Senior level
Artificial Intelligence • Cloud • Information Technology • Consulting
As a GRC Services, Trust, and Assurance Analyst, you will oversee security programs for customer-facing applications, ensuring compliance and managing security risks with a focus on audit and GRC expertise.
Top Skills: AWSGoogle Cloud PlatformGrc ToolsAzure
4 Days Ago
Remote
United States
Mid level
Mid level
Cloud
The Cybersecurity Analyst II - SOC & GRC ensures security and compliance by managing controls, investigating incidents, and performing risk assessments.
Top Skills: Iso 27001Microsoft SentinelNessusNistQualysSplunk

What you need to know about the NYC Tech Scene

As the undisputed financial capital of the world, New York City is an epicenter of startup funding activity. The city has a thriving fintech scene and is a major player in verticals ranging from AI to biotech, cybersecurity and digital media. It also has universities like NYU, Columbia and Cornell Tech attracting students and researchers from across the globe, providing the ecosystem with a constant influx of world-class talent. And its East Coast location and three international airports make it a perfect spot for European companies establishing a foothold in the United States.

Key Facts About NYC Tech

  • Number of Tech Workers: 549,200; 6% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Capgemini, Bloomberg, IBM, Spotify
  • Key Industries: Artificial intelligence, Fintech
  • Funding Landscape: $25.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Greycroft, Thrive Capital, Union Square Ventures, FirstMark Capital, Tiger Global Management, Tribeca Venture Partners, Insight Partners, Two Sigma Ventures
  • Research Centers and Universities: Columbia University, New York University, Fordham University, CUNY, AI Now Institute, Flatiron Institute, C.N. Yang Institute for Theoretical Physics, NASA Space Radiation Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account