GRC Analyst – Strategic Risk & Compliance Expert for Global Investment Management
Are you a detail-oriented GRC professional with a passion for safeguarding organizational integrity in the financial industry? Join a leading global investment management firm as a GRC Analyst, where your expertise will play a pivotal role in enhancing governance, managing risks, and ensuring compliance across complex operational landscapes. This hands-on, consulting-oriented position offers an exciting opportunity to collaborate with cross-functional teams, support vital audit processes, and elevate the firm’s overall security posture.
Key Responsibilities:
- Craft comprehensive responses to RFPs, RFIs, DDQs, ODD requests, and other external inquiries, ensuring accuracy and clarity.
- Collaborate with subject-matter experts to develop and maintain reusable, approved security and technology due-diligence content.
- Support SOC 1 and SOC 2 audits, managing evidence collection, auditor queries, control coordination, and remediation efforts.
- Assist with SOX IT controls, including documentation, testing, issue tracking, and remediation.
- Maintain and improve GRC frameworks—risk registers, control inventories, audit findings, policies, and exceptions.
- Conduct technology, cybersecurity, and operational risk assessments, working with control owners to address vulnerabilities.
- Lead third-party risk management activities, including vendor security assessments, SOC report reviews, and ongoing monitoring.
- Oversee governance of DLP and information-protection controls, supporting compliance and remediation strategies.
- Develop insightful reports on risks, audits, controls, and remediation activities for executive stakeholders.
- Drive process automation and improvements in GRC, evidence collection, and due-diligence workflows.
Required Skills:
- 3–6 years of experience in GRC, information security, technology risk, IT audit, or related fields.
- Proven track record responding to RFPs, DDQs, ODDs, and client security questionnaires.
- Experience supporting SOC 1, SOC 2, SOX, or internal/external audit processes.
- Knowledge of risk assessment methodologies, control design/testing, and policy governance.
- Familiarity with frameworks such as NIST CSF, ISO 27001, SOC 1/SOC 2, COBIT, CIS Controls.
- Strong written and verbal communication skills, capable of engaging with technical teams, auditors, and clients.
- Exceptional organizational skills with the ability to manage multiple concurrent projects.
Nice to Have Skills:
- Certifications like CISA, CRISC, CISM, CISSP, CIA, Security+, or ISO 27001.
- Experience with GRC platforms, questionnaire-management tools, workflow automation systems.
- Knowledge of information-protection and DLP governance best practices.
- Track record of automating manual GRC and due-diligence processes to boost efficiency.
- Exposure to asset management, institutional investment, or financial services industries.
Preferred Education & Experience:
- Bachelor’s degree in Information Security, Computer Science, Business, or related discipline.
- Prior experience within asset management or financial services firms is highly valued.
Other Requirements:
- This is a remote-capable role with occasional collaboration across global teams.
- Ability to operate independently, manage multiple deadlines, and challenge responses for completeness.
- A pragmatic approach to risk management, with sharp attention to detail and a proactive mindset.
Take your GRC expertise to the next level by supporting a prestigious firm committed to excellence in governance and risk mitigation. This is your opportunity to influence strategic decisions and contribute to a resilient and compliant organization on a global scale.





