GRCInfoSec Analyst Regulatory Exam Findings
Mount Laurel, NJ - USA
Job Summary
Location: Mount Laurel NJ
Onsite Flexibility: Hybrid 2 days onsite 3 days remote (subject to change up to 5 days per week onsite based on business needs; anchor days are flexible)
- Position Type: Contract
- Contract Duration: 13 months (with possibility of extension based on business needs and performance; conversion to permanent also possible based on business needs and performance)
- Pay Rate: $75.00$90.00 / Hour (USD)
- Shift / Schedule: MondayFriday core business hours 40 hours per week 8 hours per day; overtime possibility
- Travel Requirements: Not required
- Work Authorization: Applicants must be authorized to work for ANY employer in the U.S. We are unable to sponsor or take over sponsorship of an employment Visa at this time.
This role supports a Technology Controls Governance & Reporting team that manages technology issues throughout the full issue-management lifecycle covering regulatory issues 1st 2nd and 3rd line of defense audit compliance issues data analytics and automation. The team governs the technology issue-management lifecycle sitting above the remediation function: they do not perform remediation or control testing themselves but rather govern the process to ensure it stays on track escalating up or down as needed.
There are two open positions both focused on Technology Governance Risk & Control (GRC) / Issue Management. One role is more regulatory-focused; the other focuses on 1st 2nd and 3rd line of defense issues. The roles have very similar skill sets the primary difference is the type of findings and issues managed. The team is seeking a Senior GRC / Technology Risk / Issue Management professional with strong governance control/risk lifecycle stakeholder communication reporting and organizational skills who can oversee technology issues and remediation without needing to perform the technical remediation or control testing themselves.
The typical day involves 34 hours in meetings to collect status and collaborate followed by 23 hours performing governance activities and then BAU work including providing updates and creating reports. There can be frequent fire drills because the GRC process is still being matured and executives may request information ad hoc and quickly so candidates must be able to retrieve and summarize status rapidly.
Banking experience is not mandatory skills are considered transferable across industries. 10 years of experience is preferred but flexible if the candidate has strong relevant experience.
- Govern the technology issue-management lifecycle
- Track issues and findings through remediation
- Monitor deadlines milestones and progress
- Identify and escalate blockers
- Provide executive visibility and reporting
- Prepare initial drafts and templates for regulatory communications
- Ensure issues stay on track through governance (think of issues as tickets requiring remediation this team oversees the process rather than performing the technical fix)
- Collaborate with senior stakeholders across internal teams to collect status updates and drive governance activities
- Draft communications intended for regulators (candidates will not be communicating directly with regulators)
- Provide updates and create reports on a BAU basis including ad hoc executive requests requiring rapid retrieval and summarization of status
- 10 years of experience in regulatory exam findings internal audits technology issues management or technology GRC
- Proficiency in Microsoft Suite PowerPoint Word Excel Visio
- Previous control testing and audit experience
- Ability to write reporting intended for executive-level audiences
- Strong communication skills verbal and written
- Strong critical thinking skills
- Strong attention to detail proactive and organized
- Ability to work independently
- Understanding of the lifecycle process of issue remediation and technology controls remediation
- Understanding of what a control is what an issue is industry standards and toll gate processes
- Strong organizational and project/program management skills to stay on top of multiple concurrent issues
- Ability to analyze data
- Ability to draft communications to regulators
- Governance Risk and Controls (GRC) experience
- Big 4 consulting firm experience
- Alteryx Power BI Tableau or any other automation tools for reporting
- CISA and CRISC certifications or equivalent (strongly preferred for the issues management project)
- CISA/CISSP-type certifications (beneficial; strong relevant experience can compensate certification is not the primary selection factor)
- Experience with ServiceNow AGRC module Power BI SharePoint Confluence Excel (Macros) or Microsoft Access
- 10 years of overall experience in regulatory exam findings internal audits technology issues management or technology GRC (10 years preferred; flexible for candidates with strong relevant experience)
- Strong transferable backgrounds include: Internal Audit Technology Risk Management GRC Control Testing or Control-Testing Oversight/Review Control Design Issue Management/Remediation Governance First/Second/Third Line of Defense Big 4 Consulting Technology Governance and/or strong Project/Program Management
- Post-secondary education required; certifications are an asset
- CISA CRISC CISA/CISSP-type certifications are strongly preferred (particularly for the issues management project); strong relevant experience can compensate for the absence of certifications
- Hybrid work model: 2 days onsite 3 days remote per week (subject to potential change up to 5 days per week onsite based on business needs)
- Anchor days are flexible
- Available work locations: Mount Laurel NJ; Fort Lauderdale FL; Charlotte NC
- Approximately 34 hours per day in meetings (status collection collaboration); remainder of day focused on governance activities BAU updates and reporting
- Fast-paced environment with frequent ad hoc executive requests and occasional fire drills as the GRC process continues to mature
- Internal interactions only; no access to customer data
- There are two open positions. Please indicate in your submittal comments whether your candidate is a strong fit for both projects or which one you feel they would be a stronger fit for: (1) Governance monitoring and tracking of regulatory exam findings or (2) Governance and oversight of the technology issues management program.
- Interview process: 2 rounds virtual with the manager and then with the team lead (approximately 30 minutes each).
- Candidates with a pattern of job hopping (multiple short-term full-time positions) will be disqualified from consideration.
- Medical Vision and Dental Insurance Plans
- 401k Retirement Fund
This client is a leading financial services and banking institution operating across the U.S. and Canada with a global security and technology organization supporting thousands of professionals in roles spanning IT governance risk management compliance data analytics and technology controls. The institution employs software developers release train strategists GRC analysts IT risk professionals and a wide range of technology specialists who collaborate across agile fast-paced teams. The organization places strong emphasis on long-term growth team culture and building foundational governance and reporting capabilities at scale.
GTT is a minority-owned staffing firm and a subsidiary of Chenega Corporation a Native American-owned company in Alaska. We highly value diverse and inclusive workplaces and support Fortune 500 organizations across banking financial services technology life sciences biotech utilities and retail sectors throughout the U.S. and Canada.
Job Number: 26-14816 Industry: Data & Analytics
#gttjobs #LI-GTT #LI-Hybrid
Required Experience:
IC