Sr. GRC Analyst
Chicago, IL
Category: Information Technology
Reference ID: 10081639
Shortcut: http://addisongroup.gosnaphop.com/Nkz3ij
Senior GRC Analyst
Industry: Professional Services / Information Security
Location: Chicago, IL
Work Schedule: Hybrid – Onsite Monday, Wednesday & Thursday
Assignment Type: Contract-to-Hire
Start Date: ASAP
Pay: $115,000-$125,000
About the Opportunity
Our client, a national professional services organization, is seeking a Senior Governance, Risk & Compliance (GRC) Analyst to help build and mature its internal Information Security GRC program.
This is a net-new position within an evolving security organization. The environment is still developing from a GRC process and tooling perspective, so this is an opportunity for someone who enjoys building—not simply maintaining an already mature compliance program.
The Senior GRC Analyst will play a hands-on role across SOC 2, enterprise risk management, security risk assessments, policy management, NIST Cybersecurity Framework (CSF), audit readiness, remediation tracking, and executive reporting.
The ideal candidate is a hands-on problem solver who can walk into an environment where every process or tool may not yet exist, identify what needs to improve, and develop practical solutions.
This is a senior individual-contributor position with no direct reports. The Senior GRC Analyst will also provide guidance and mentorship to another GRC resource while working closely with senior Information Security leadership.
Key Responsibilities
SOC 2, Compliance & Audit
- Help strengthen and drive the organization's SOC 2 compliance and readiness program.
- Coordinate audit requests, evidence collection, and control-owner responses.
- Perform or coordinate control testing and validation.
- Identify control deficiencies and compliance gaps.
- Track audit findings and corrective actions through closure.
- Partner with control owners to develop practical remediation plans.
- Coordinate directly with auditors and internal stakeholders throughout compliance activities.
- Improve the overall structure and sustainability of the SOC 2 program.
Enterprise Risk Management
- Establish and maintain the enterprise information security risk register.
- Lead security risk assessments across the organization.
- Perform control-gap analyses and security maturity assessments.
- Identify, analyze, document, and prioritize security risks.
- Develop risk-treatment and remediation plans.
- Manage risk acceptance and security exceptions.
- Identify and document compensating controls.
- Track remediation activities through completion.
- Translate technical security risks into clear, business-focused recommendations for leadership.
Governance & NIST CSF
- Help operationalize the organization's information security governance program using NIST CSF 2.0.
- Apply NIST CSF to risk assessments, governance processes, controls, policies, and maturity evaluations.
- Maintain governance calendars, control assessments, risk reviews, and reporting cycles.
- Establish clear ownership and accountability for security controls.
- Identify systemic control gaps and opportunities to improve the overall security program.
- Help translate security frameworks into practical processes that can be consistently executed across the organization.
Policy Management
- Own and improve the information security policy lifecycle.
- Develop, review, update, and maintain security policies, standards, and procedures.
- Coordinate policy review and approval processes.
- Maintain policy publication, version control, and evidence retention.
- Map policies, standards, and procedures to NIST CSF 2.0 and applicable compliance requirements.
- Maintain policy exceptions and residual-risk documentation.
- Help ensure security policies are operationalized rather than simply documented.
Reporting & Program Improvement
- Develop GRC dashboards, metrics, KRIs and KPIs.
- Provide leadership with clear reporting on:
- Enterprise security risk
- SOC 2 readiness
- Compliance status
- Policy governance
- Remediation progress
- Identify weaknesses in existing GRC processes and develop practical improvements.
- Help establish repeatable, scalable GRC processes where formal processes or tooling may not yet exist.
- Drive multiple GRC initiatives simultaneously using a strong project-management mindset.
The position owns key activities spanning risk assessments and the risk register, policy lifecycle management, SOC 2, security exceptions, remediation, reporting, and NIST CSF governance.
Required Qualifications
- 5+ years of experience in Information Security, GRC, IT Risk, Security Compliance, Audit, or a related discipline.
- Strong hands-on experience with SOC 2 compliance and readiness.
- Experience taking meaningful ownership of SOC 2 activities—not solely collecting audit evidence.
- Experience coordinating controls, evidence, findings, remediation, and audit activities.
- Demonstrated experience leading security risk assessments.
- Experience identifying and evaluating control gaps.
- Hands-on experience developing and maintaining risk registers.
- Experience developing risk-treatment and remediation plans.
- Ability to drive identified risks and remediation items through closure.
- Strong experience developing, reviewing, and maintaining information security policies, standards, and procedures.
- Practical experience applying NIST Cybersecurity Framework (NIST CSF).
- Experience performing security maturity and/or gap assessments.
- Demonstrated ability to operate successfully within an evolving or immature GRC environment.
- Ability to create effective processes when mature tools or established workflows do not already exist.
- Strong project-management and organizational skills.
- Ability to manage multiple concurrent GRC initiatives.
- Strong analytical and problem-solving capabilities.
- Excellent written and verbal communication.
- Ability to communicate effectively with technical teams, non-technical business stakeholders, and senior leadership.
- Bachelor's degree in a relevant discipline or equivalent practical experience.
The formal qualifications specifically call for hands-on SOC 2, risk assessment/risk-register ownership, policy management, practical NIST CSF application, and the ability to build solutions in an immature GRC environment.
Preferred Qualifications
- CISA
- CRISC
- CISM
- CISSP
- Security+ or comparable security/GRC certification
- ISO 27001 experience
- IT General Controls (ITGC) experience
- Third-party risk management
- Client security questionnaires / assurance
- AI governance
- Data protection / privacy-related security experience
- Security awareness program experience
- Experience with GRC and workflow technologies such as:
- AuditBoard
- ServiceNow GRC
- OneTrust
- Archer
- Jira
- SharePoint
Certifications are valued, but practical GRC experience and demonstrated ownership are more important for this position.
What We're Looking For
This is not a role for someone who needs an established GRC program, mature tooling, or highly defined processes in order to be successful.
The ideal candidate is comfortable hearing:
"We know this needs to be better—help us figure out how to fix it."
You should be able to assess the current state, identify gaps, prioritize what matters, develop a practical solution, gain stakeholder buy-in, and then drive the work through implementation.
We're particularly interested in candidates who can provide specific examples of personally:
- Driving or significantly improving a SOC 2 program
- Leading a security risk assessment
- Building or improving an enterprise risk register
- Identifying control gaps and developing remediation plans
- Driving remediation through closure
- Developing or restructuring security policies
- Applying NIST CSF to a real-world security program
- Building GRC processes without sophisticated tooling
- Working directly with auditors
- Coordinating technical and business stakeholders
- Managing several GRC initiatives simultaneously
The goal of the position is to help turn an immature GRC environment into a more structured and sustainable program across SOC 2, risk management, remediation, policy governance, and NIST CSF.
Leadership & Mentorship
This is a senior individual-contributor position—not a people-management role.
The Senior GRC Analyst will:
- Serve as a trusted GRC advisor to technical and business stakeholders.
- Provide guidance and mentorship to another GRC Analyst.
- Share GRC best practices and practical knowledge.
- Help improve the consistency and quality of GRC work.
- Partner closely with Information Security leadership.
- Help drive accountability across control owners and stakeholders.
The position has no direct reports but is expected to provide mentorship and senior-level guidance.
Core GRC Focus Areas
- SOC 2
- NIST CSF 2.0
- Enterprise Risk Management
- Security Risk Assessments
- Risk Registers
- Risk Treatment
- Control Gap Analysis
- Security Maturity Assessments
- Information Security Policy Management
- Audit Readiness
- Control Testing
- Evidence Management
- Findings & Remediation
- Security Exceptions
- Compensating Controls
- KRIs / KPIs
- Executive Reporting
- Third-Party Risk
- GRC Process Improvement
Work Environment
- Hybrid position based in downtown Chicago
- Onsite Monday, Wednesday, and Thursday
- Contract-to-hire
- Highly visible position within the internal Information Security organization
- Significant interaction with IT, Legal, Privacy, HR, and business leadership
- Opportunity to directly influence how the organization's GRC program is built and matured
Additional Details
- Net-new position
- ASAP start
- Senior individual-contributor role
- No direct reports
- Two-step interview process:
- Initial video interview with Information Security leadership
- Final onsite interview with additional team stakeholders
- Strong emphasis on practical experience, ownership, communication, and problem solving
Benefits
Eligible consultants may receive:
- Medical and prescription drug coverage
- Dental insurance
- Vision insurance
- Health Savings Account (HSA)
- Flexible Spending Accounts (FSA)
- Short-Term and Long-Term Disability Insurance
- Supplemental Life Insurance
- 401(k)
- Weekly pay
If you're a hands-on Senior GRC Analyst who has personally driven SOC 2, risk assessments, policy management, remediation, and NIST CSF initiatives—and you enjoy building programs rather than simply maintaining them—apply today to learn more.
| Addison Group is an Equal Opportunity Employer. Addison Group provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, gender, sexual orientation, national origin, age, disability, genetic information, marital status, amnesty, or status as a covered veteran in accordance with applicable federal, state and local laws. Addison Group complies with applicable state and local laws governing non-discrimination in employment in every location in which the company has facilities. Reasonable accommodation is available for qualified individuals with disabilities, upon request. |
-
CMMC GRC Consultant
Danvers, MA
Role: CMMC GRC Consultant Industry: Cybersecurity / Managed Services / Consulting Location: Remote – U.S. Based Assignment Type: 4–6 Month Contract-to-Hire Conversion Salary: $95,000 – $115,000 / year Travel: Limited – Approximately 1–2 Team Meetings p...
Recommended
-
Senior Information Security Lead
Woodland Hills, CA
Title: Senior Information Security Lead Location: Woodland Hills, CA Salary: $125 - 165k This position is not eligible for sponsorship Benefits: health insurance disability insurance life insurance retirement plans (like a 401(k)) paid time off (PTO) i...
Recommended
-
Workday Security Operations Engineer
Oklahoma City, OK
Job Title: Workday Security Operations Engineer Location (City, State): Oklahoma City, OK Assignment Type: Direct Hire - Must be authorized to work in the United States now and in the future without assistance. Pay: $115,000–$140,000 annually, plus a 1...
Recommended
-
Cybersecurity Network Engineer
Houston, TX
Role: Cybersecurity / Network Engineer Location: Houston, TX (Hybrid) Pay Range: $120,000 - $125,000 / year Benefits: This position is eligible for medical, dental, vision and 401(k) About the Role We are seeking a Cybersecurity / Network Engineer to t...
Recommended
-
Technical Project Manager, Security
Bentonville, AR
Position: Technical Project Manager Duration: 3–6-month contract Remote: 100% remote **Must be located in the United States** - working CST hours Pay: $60-65/HR This position is eligible to enroll in medical, dental, vision after 60 days. In addition, ...
Recommended
-
Cybersecurity Engineer
Phoenix Metro Area, Arizona
Title: Cybersecurity Engineer Location: Phoenix, AZ (Onsite) Contract: 12 month Schedule: Monday-Friday | 8:00 AM-5:00 PM Benefits: This position is eligible for medical, dental, vision, and 401(k). Pay: 55$ - 63$ an hour Position Summary We are seekin...
Recommended
-
Lead Cyber Security Threat Operations Engineer
Anywhere
Title - Lead Cyber Security Threat Operations Engineer Location REMOTE IN THESE STATES ONLY (Colorado, Florida, Georgia, Illinois, Maryland, New Jersey, New York, North Carolina, Ohio, Pennsylvania, Tennessee, Texas, Virginia, and West Virginia, plus t...
Recommended
-
Sr. Global Mobility & Immigration Program Manager
Plano, TX
Position Title: Senior Global Mobility & Immigration Program Manager Location: Plano, TX or Camas, WA Compensation: $130,000 -$140,000 / Annually / Depending on experience Employment Type: Direct Hire Benefits: This position is eligible for comprehensi...
Recommended
-
Senior Network Security Engineer
Chicago, IL
CONFIDENTIAL SEARCH – Senior Network Security Engineer Location: Chicago – Onsite Pay: $130 - $145K Base Benefits: This position is eligible for Medical, Dental, Vison, and 401(k) Confidential search for a Senior Network Security Engineer for a highly ...
Recommended
-
Workplace Tech Microsoft Platforms Manager
Dallas Metro Area, Texas
Title: Workplace Tech Microsoft Platforms Manager Location: Dallas, TX - Onsite 1 day a week Salary: $140k Benefits: This role is eligible for health, welfare, 401(k) savings plan with dollar-for-dollar match up to 5%, tuition reimbursement and 27 days...
Recommended
-
Cloud Engineer
Austin, TX
Job Title: Cloud Infrastructure Engineer (AWS) Location: Austin, TX - must be local and able to be onsite 1-2 days per week Duration: 6 month contract-to-hire Compensation: $75-$95/HR Work schedule: Monday-Friday (8 AM-5PM CST) - onsite 1-2x per week B...
Recommended
-
Enterprise Endpoint Engineer
Dallas, TX
Title: Enterprise Endpoint Engineer Location: Dallas, TX - Onsite 1 day a week Salary: $160k This position is not eligible for sponsorhip Benefits: Immediate eligibility for health and welfare benefits 401(k) savings plan with dollar-for-dollar match u...
Recommended
-
Senior Internal Auditor
Issaquah, WA
Job Title: Senior Internal Auditor Industry: Retail / Consumer Services Location: Greater Seattle area Assignment Type: Full-Time, Direct Hire Pay: $110k base - $125k base Work Schedule: Hybrid (3 days in office) after 90 days fully onsite. Benefits: T...
Recommended
-
Senior Business Development Partner
Dallas, TX
Business Development Partner Location: Dallas, TX Work Arrangement: Hybrid (Field-Based) Travel: Moderate travel required About the Opportunity Addison Group is partnering with an innovative professional services organization that helps enterprise clie...
Recommended
-
Interim Controller
Wilmington, NC
Position Title: Interim Controller Location: Wilmington, NC Compensation: $45.00 / Per Hour Employment Type: Contract, at least 2 months with potential to extend Benefits: This position is eligible for medical, dental, vision, and 401(k). Job Summary: ...
Recommended
-
Interim Director of Human Resources
Washington-Arlington-Alexandria Metro Area, District of Columbia
Job Title: Interim Director of Human Resources Industry: Nonprofit / Public Private Partnership Location (city, state): Washington, DC (fully remote with preference for candidates local to Washington DC) Assignment Type: Contract with potential to conv...
Recommended
-
Sr. Network Administrator
Chicago Metro Area, Illinois
Job Title: Senior Network Administrator Industry: Nonprofit Location (City, State): Chicago, IL Assignment Type: Long-Term Contract (12–24 Months) Pay: $45-55/hr W2 Work Schedule: Primarily remote for now, with onsite availability required for data cen...
Recommended
-
Data Architect
Austin, TX
Position: Data Architect Duration: 12 months to start, project up to 2 years Work Location: Austin, TX Hybrid: M & F remote, Tuesday-Thursday onsite Pay: $85-90/HR This position is eligible to enroll in medical, dental, vision after 60 days. In additio...
Recommended
-
Fire & Emergency Services PM
District of Columbia
Role: Fire & Emergency Services PM Location: Washington, DC (Hybrid) Pay Rate Range: $100,000 - $110,000 / year Internal Job ID: 10080297 Are you looking for a growth opportunity for a reputable company with a positive work environment? Our client is l...
Recommended
-
Sr. Data Engineer
Oklahoma City, OK
Job Title: Senior Data Engineer Location: Oklahoma City, OK Pay: $50 - $70 / Hour Work Schedule: Hybrid — 4 days onsite and 1 day remote initially Benefits: This position is eligible for medical, dental, vision, and 401(k). About The Company: A well-es...
Recommended
-
Controller
Chicago Metro Area, Illinois
Job Title: Controller Industry: Non-Profit Location (city, state): Chicago, IL Assignment Type: Direct Hire / Permanent Pay: Competitive, based on experience $130,000-$175,000 no bonus Work Schedule: Hybrid (3 days onsite: Tuesday–Thursday; 2 days remo...
Recommended
-
Executive Associate and Project Lead
Anywhere
Job Title: Executive Associate and Project Lead Industry: Nonprofit / Philanthropy Location: Remote (EST or CST preferred) Assignment Type: Direct Hire Pay: $85,000 to $120,000 commensurate with experience Work Schedule: Monday through Friday, 9am to 5...
Recommended
-
Learning and Development Specialist
Washington, DC
Job Title: Learning and Development Specialist Industry: Nonprofit / Association Location (city, state): Washington, DC Assignment Type: Contract (long term, 3 to 6 months, potential to extend or convert based on budget and performance) Pay: $30 - $34 ...
Recommended
-
Senior Automation & Controls Engineer
Forney, TX
Job Title: Senior Automation & Controls Engineer Location (City, State): Forney, TX Assignment Type: Direct Hire Pay: $125-140K Work Schedule: Full-Time | Monday–Friday Benefits: This position is eligible for medical, dental, vision, and 401(k). About ...
Recommended
-
Sr. IT Project Manager
Tulsa, OK
Job Title: Senior IT Project Manager Location (city, state): Tulsa, Oklahoma Assignment Type: Direct Hire Pay: $90,000 - $105,000 depending on experience Work Schedule: Monday–Friday, standard business hours Benefits: This position is eligible for medi...
Recommended
-
Senior Data Engineer
Austin, TX
Position: Senior Data Engineer Location: Austin, TX - Hybrid Compensation: $70.00 - $80.00 / Per Hour Employment Type: 12 month contract with contract-to-hire option Schedule: 2x per week remote, onsite 3x per week Benefits: This position is eligible f...
Recommended
-
Sr Power Platform Admin
Austin, TX
Compensation: $55 / Hour Benefits: This position is eligible for medical, dental, vision, and 401(k). My client is seeking a contractor with strong Microsoft Power Platform administration experience to assist with the governance, administration, automa...
Recommended
-
Operations Specialist
New York City Metro Area, New York
Job Title: Operations Specialist Industry: Service Location: Long Island, NY Assignment Type: Direct Hire Pay: $75000 -$85000 / Year Work Schedule: Monday-Friday | 9:00 AM-6:00 PM | Fully onsite, 5 days per week Benefits: This position is eligible for ...
Recommended
-
Senior Product Manager
Austin, TX
Position: Senior Product Manager Duration: 6 month contract-to-hire Pay: $70-80/HR Work Location: Austin, TX This position is eligible to enroll in medical, dental, vision after 60 days. In addition, this position is eligible to enroll in a 401(k) afte...
Recommended
-
Senior UX Researcher & Designer
Fort Worth, TX
Job Title: Senior UX Researcher & Designer Location (city, state): Fort Worth, TX Assignment Type: Direct Hire Pay: $110,000–$130,000 annually, plus a 7% target bonus and an employee stock ownership plan contribution valued at approximately 15% of annu...
Recommended