CMG Financial Logo

CMG Financial

Senior IT GRC Analyst

Posted 2 Days Ago
Remote
Hiring Remotely in United States
Senior level
Remote
Hiring Remotely in United States
Senior level
Leads IT governance, risk, and compliance activities, including SOC 2 readiness, audit planning and execution, policy development, control assessments, evidence gathering, remediation tracking, and regulatory research. Partners with auditors, control owners, IT leadership, and GRC team members to maintain compliance with NIST CSF and financial services regulations. Provides guidance on audit and policy matters while improving GRC processes and tooling.
The summary above was generated by AI

The Senior IT GRC Analyst leads policy development and audit execution within CMG's IT Governance, Risk, and Compliance program, with particular emphasis on CMG's upcoming SOC 2 readiness effort. This role works closely with the GRC team and the broader IT department to plan and execute audit engagements, maintain the policy framework, and manage auditor relationships. The Senior IT GRC Analyst operates with a high degree of autonomy and is expected to navigate ambiguity in a regulated environment.

 

 

ESSENTIAL DUTIES and RESPONSIBILITIES, includes the following responsibilities, but not limited to:

  • Lead CMG's SOC 2 readiness assessment, including scope definition, gap analysis, and control design, in partnership with the IT GRC Manager.
  • Serve as a point of contact during audit engagements and regulatory exams.
  • Develop, maintain, and update IT policies, standards, and procedures to align with NIST CSF and other applicable regulatory requirements.
  • Plan and execute audit activities, including scheduling, control walkthroughs, evidence gathering, and findings documentation.
  • Identify control gaps, coordinate remediation planning with control owners, tracking findings and remediation status through the risk register.
  • Provide guidance to other GRC team members and IT leadership on audit and policy matters.
  • Research regulatory and framework changes relevant to mortgage lending and financial services, and translate them into policy updates.
  • Contribute to the ongoing development and improvement of GRC processes and tooling.

 

 

REQUIRED QUALIFICATIONS:

  • Bachelor's degree in Information Technology, Cybersecurity, or a related field (equivalent experience considered).
  • 5+ years of experience in IT audit, compliance, or GRC in an enterprise IT environment.
  • Demonstrated experience managing SOC 2 audit cycles (Type I or Type II) from scoping through remediation.
  • Direct experience in financial services, mortgage lending, or related regulated industries, with working knowledge of applicable regulations (GLBA, CFPB, NYDFS).
  • Strong working knowledge of relevant IT compliance frameworks, such as NIST CSF, ISO 27001, or SOX.
  • Strong policy writing and documentation skills.
  • Ability to work independently amid ambiguity, exercising sound judgment on scope and prioritization.
  • Excellent written and verbal communication skills, with the ability to explain technical and compliance matters to varied audiences.
  • Relevant certifications preferred: CISA, CRISC, or GRCP.

 

 

SUPERVISORY RESPONSIBILITIES:

Direct Reports: N/A

 

 

PHYSICAL and ENVIRONMENTAL CONDITIONS

This role operates in an ADA compliant office environment, utilizing typical office equipment and tasks including computer work. The position may involve partial stationary positions and moving throughout the day. Flexibility to work overtime to meet project deadlines is required.

 

 

Base Compensation Information– This role is a remote position that is currently allocated for candidates within geographic regions that do not currently require base wage disclosure. The compensation range for this position will be provided upon request. (Due to their geographic location, residents of the states of CA & CO, and for NY are excluded from this role at this time.) 

Similar Jobs

59 Seconds Ago
Remote or Hybrid
55K-75K Annually
Junior
55K-75K Annually
Junior
Artificial Intelligence • Fintech • Insurance • Marketing Tech • Software • Analytics
Handle inbound calls and warm leads, consult customers on insurance needs, recommend appropriate property and casualty coverage, and convert prospects into policyholders. The role includes paid training and licensing, customer relationship management, sales closing, and representing the Liberty Mutual brand. Employees work remotely on fixed weekday and weekend schedules and must maintain a professional home workspace with reliable wired internet.
Top Skills: Cable/Fiber/Dsl InternetPcWired High-Speed Internet
5 Minutes Ago
Remote
United States
230K-235K Annually
Expert/Leader
230K-235K Annually
Expert/Leader
Artificial Intelligence • Information Technology • Professional Services • Software • Analytics • Generative AI • Big Data Analytics
Leads complex AI-enabled digital transformation engagements for healthcare, life sciences, and B2B clients. Advises C-suite executives, develops enterprise AI strategies and target operating models, integrates change management across transformation programs, and drives stakeholder engagement, training, governance, and adoption. The role also leads strategic pursuits, contributes to significant annual presales activity, develops healthcare growth strategies, and connects transformation outcomes to EBIT and ROI. Requires extensive consulting experience, healthcare expertise, executive presence, and frequent client travel.
Top Skills: Artificial Intelligence (Ai)
7 Minutes Ago
Easy Apply
Remote
United States
Easy Apply
163K-225K Annually
Senior level
163K-225K Annually
Senior level
Artificial Intelligence • Fintech • Hardware • Information Technology • Sales • Software • Transportation
Own Motive’s global financial products compliance program across AML/BSA, sanctions, KYC/KYB, PEP screening, transaction monitoring, lending compliance, audits, and regulatory relationships. Develop policies and controls, ensure operational effectiveness, manage bank and card network partners, monitor regulatory changes, support compliant product launches, and establish governance across multiple jurisdictions including the US, Canada, and UK/EU. Build the compliance function and advise leadership on compliance risk.
Top Skills: Aml/BsaCard NetworksData Protection RegimesFincenFintrac/PcmltfaKyc/KybOfacPep ScreeningSanctions ScreeningTransaction MonitoringUk/Eu Aml

What you need to know about the Austin Tech Scene

Austin has a diverse and thriving tech ecosystem thanks to home-grown companies like Dell and major campuses for IBM, AMD and Apple. The state’s flagship university, the University of Texas at Austin, is known for its engineering school, and the city is known for its annual South by Southwest tech and media conference. Austin’s tech scene spans many verticals, but it’s particularly known for hardware, including semiconductors, as well as AI, biotechnology and cloud computing. And its food and music scene, low taxes and favorable climate has made the city a destination for tech workers from across the country.

Key Facts About Austin Tech

  • Number of Tech Workers: 180,500; 13.7% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Dell, IBM, AMD, Apple, Alphabet
  • Key Industries: Artificial intelligence, hardware, cloud computing, software, healthtech
  • Funding Landscape: $4.5 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Live Oak Ventures, Austin Ventures, Hinge Capital, Gigafund, KdT Ventures, Next Coast Ventures, Silverton Partners
  • Research Centers and Universities: University of Texas, Southwestern University, Texas State University, Center for Complex Quantum Systems, Oden Institute for Computational Engineering and Sciences, Texas Advanced Computing Center

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account