Job Summary The Sr. Cybersecurity Risk Analyst is responsible for leading and maturing the ... Mentor junior analysts and contribute to the maturity of the GRC function. Qualifications Required
Job Summary The Sr. Cybersecurity Risk Analyst is responsible for leading and maturing the ... Mentor junior analysts and contribute to the maturity of the GRC function. Qualifications Required
Job Summary The Sr. Cybersecurity Risk Analyst is responsible for leading and maturing the ... Mentor junior analysts and contribute to the maturity of the GRC function. Qualifications Required
Job Summary The Sr. Cybersecurity Risk Analyst is responsible for leading and maturing the ... Mentor junior analysts and contribute to the maturity of the GRC function. Qualifications Required
Summary Statement The Senior IT Security Risk Analyst is responsible for leading the organization ... Experience in Logicgate or another GRC tool. * Experience using AI driven tools to enhance ...
Summary Statement The Senior IT Security Risk Analyst is responsible for leading the organization ... Experience in Logicgate or another GRC tool. * Experience using AI driven tools to enhance ...
Summary Statement The Senior IT Security Risk Analyst is responsible for leading the organization ... Experience in Logicgate or another GRC tool. * Experience using AI driven tools to enhance ...
Summary Statement The Senior IT Security Risk Analyst is responsible for leading the organization ... Experience in Logicgate or another GRC tool. * Experience using AI driven tools to enhance ...
Summary Statement The Senior IT Security Risk Analyst is responsible for leading the organization ... Experience in Logicgate or another GRC tool. * Experience using AI driven tools to enhance ...
Summary Statement The Senior IT Security Risk Analyst is responsible for leading the organization ... Experience in Logicgate or another GRC tool. * Experience using AI driven tools to enhance ...
Configure and implement SAP GRC Access Control capabilities, including Access Risk Analysis, Access Request Management, Emergency Access Management, and Business Role Management * Support SAP GRC ...
Configure and implement SAP GRC Access Control capabilities, including Access Risk Analysis, Access Request Management, Emergency Access Management, and Business Role Management * Support SAP GRC ...
Job Title: Information Security Governance Risk and Compliance Analyst Number of Positions: 1 ... This position will also help with the daily GRC operations. Primary Job Responsibilities: * Partner ...
Job Title: Information Security Governance Risk and Compliance Analyst Number of Positions: 1 ... This position will also help with the daily GRC operations. Primary Job Responsibilities: * Partner ...
Sr. Information Security GRC Analyst
$115K - $125K/yr
Overview: Sr. Information Security GRC Analyst Location: Tire Rack - South Bend, IN (On-Site ... What You'll Do Governance, Risk & Compliance Leadership * Advise IT and business stakeholders on ...
Sr. Information Security GRC Analyst
$115K - $125K/yr
Overview: Sr. Information Security GRC Analyst Location: Tire Rack - South Bend, IN (On-Site ... What You'll Do Governance, Risk & Compliance Leadership * Advise IT and business stakeholders on ...
Sr. Information Security GRC Analyst
$115K - $125K/yr
Overview: Sr. Information Security GRC Analyst Location: Tire Rack - South Bend, IN (On-Site ... What You'll Do Governance, Risk & Compliance Leadership * Advise IT and business stakeholders on ...
Sr. Information Security GRC Analyst
$115K - $125K/yr
Overview: Sr. Information Security GRC Analyst Location: Tire Rack - South Bend, IN (On-Site ... What You'll Do Governance, Risk & Compliance Leadership * Advise IT and business stakeholders on ...
Sr. Information Security GRC Analyst
$115K - $125K/yr
Overview: Sr. Information Security GRC Analyst Location: Tire Rack - South Bend, IN (On-Site ... What You'll Do Governance, Risk & Compliance Leadership * Advise IT and business stakeholders on ...
Sr. Information Security GRC Analyst
$115K - $125K/yr
Overview: Sr. Information Security GRC Analyst Location: Tire Rack - South Bend, IN (On-Site ... What You'll Do Governance, Risk & Compliance Leadership * Advise IT and business stakeholders on ...
Sr. Information Security GRC Analyst
$115K - $125K/yr
Overview: Sr. Information Security GRC Analyst Location: Tire Rack - South Bend, IN (On-Site ... What You'll Do Governance, Risk & Compliance Leadership * Advise IT and business stakeholders on ...
Sr. Information Security GRC Analyst
$115K - $125K/yr
Overview: Sr. Information Security GRC Analyst Location: Tire Rack - South Bend, IN (On-Site ... What You'll Do Governance, Risk & Compliance Leadership * Advise IT and business stakeholders on ...
Job Title: Information Security Governance Risk and Compliance Analyst Number of Positions: 1 ... Administers the enterprise GRC platform, including control libraries, evidence workflows, and ...
Job Title: Information Security Governance Risk and Compliance Analyst Number of Positions: 1 ... Administers the enterprise GRC platform, including control libraries, evidence workflows, and ...
Sr. Information Security GRC Analyst
$115K - $125K/yr
Overview: Sr. Information Security GRC Analyst Location: Tire Rack - South Bend, IN (On-Site ... What You'll Do Governance, Risk & Compliance Leadership * Advise IT and business stakeholders on ...
Sr. Information Security GRC Analyst
$115K - $125K/yr
Overview: Sr. Information Security GRC Analyst Location: Tire Rack - South Bend, IN (On-Site ... What You'll Do Governance, Risk & Compliance Leadership * Advise IT and business stakeholders on ...
Sr. Information Security GRC Analyst
$115K - $125K/yr
Overview: Sr. Information Security GRC Analyst Location: Tire Rack - South Bend, IN (On-Site ... What You'll Do Governance, Risk & Compliance Leadership * Advise IT and business stakeholders on ...
Sr. Information Security GRC Analyst
$115K - $125K/yr
Overview: Sr. Information Security GRC Analyst Location: Tire Rack - South Bend, IN (On-Site ... What You'll Do Governance, Risk & Compliance Leadership * Advise IT and business stakeholders on ...
Sr. Information Security GRC Analyst
$115K - $125K/yr
Overview: Sr. Information Security GRC Analyst Location: Tire Rack - South Bend, IN (On-Site ... What You'll Do Governance, Risk & Compliance Leadership * Advise IT and business stakeholders on ...
Sr. Information Security GRC Analyst
$115K - $125K/yr
Overview: Sr. Information Security GRC Analyst Location: Tire Rack - South Bend, IN (On-Site ... What You'll Do Governance, Risk & Compliance Leadership * Advise IT and business stakeholders on ...
Sr. Information Security GRC Analyst
$115K - $125K/yr
Overview: Sr. Information Security GRC Analyst Location: Tire Rack - South Bend, IN (On-Site ... What You'll Do Governance, Risk & Compliance Leadership * Advise IT and business stakeholders on ...
Sr. Information Security GRC Analyst
$115K - $125K/yr
Overview: Sr. Information Security GRC Analyst Location: Tire Rack - South Bend, IN (On-Site ... What You'll Do Governance, Risk & Compliance Leadership * Advise IT and business stakeholders on ...
GRC Administrator & Developer
Lansing, MI · On-site
The role focuses on maintaining and enhancing the State of Michigan's Web-based Governance, Risk ... Analyze GRC issues/incidents to identify root causes and work with vendor support to implement ...
Quick apply
GRC Administrator & Developer
Lansing, MI · On-site
The role focuses on maintaining and enhancing the State of Michigan's Web-based Governance, Risk ... Analyze GRC issues/incidents to identify root causes and work with vendor support to implement ...
Cyber - SAP Security and GRC Access & Process Control Consultant / Security Engineer II
Detroit, MI · On-site
Analyze segregation of duties risks, support ruleset updates, and perform user- and role-level risk assessments in SAP GRC 12.0. * Develop security solutions for custom transactions, tables, programs ...
Cyber - SAP Security and GRC Access & Process Control Consultant / Security Engineer II
Detroit, MI · On-site
Analyze segregation of duties risks, support ruleset updates, and perform user- and role-level risk assessments in SAP GRC 12.0. * Develop security solutions for custom transactions, tables, programs ...
Director SAP Security & Identity Access Management
Detroit, MI · On-site
$150K - $200K/yr
Manage SAP GRC capabilities including: * * Access Risk Analysis (ARA) * Access Request Management (ARM) * Emergency Access Management (EAM) * Process Control * Drive continuous improvement ...
Quick apply
Director SAP Security & Identity Access Management
Detroit, MI · On-site
$150K - $200K/yr
Manage SAP GRC capabilities including: * * Access Risk Analysis (ARA) * Access Request Management (ARM) * Emergency Access Management (EAM) * Process Control * Drive continuous improvement ...
Knowledge of Risk Management principles. Experience working in Agile environments and sprint-based ... Strong analytical, troubleshooting, and problem-solving skills. Excellent verbal and written ...
Knowledge of Risk Management principles. Experience working in Agile environments and sprint-based ... Strong analytical, troubleshooting, and problem-solving skills. Excellent verbal and written ...
Grc Risk Analyst information
What is the difference between Grc Risk Analyst vs Compliance Analyst?
| Aspect | Grc Risk Analyst | Compliance Analyst |
|---|---|---|
| Certifications | ISO 31000, FRM, CRISC | ISO 19600, CCEP, CISA |
| Work Environment | Risk management teams, corporate offices | Regulatory departments, corporate offices |
| Industry Usage | Finance, banking, insurance, corporate risk | Financial services, healthcare, manufacturing |
| Job Focus | Identifying, assessing, and mitigating risks across enterprise | Ensuring compliance with laws and regulations |
While both roles involve regulatory and risk considerations, a Grc Risk Analyst focuses on enterprise-wide risk management strategies, whereas a Compliance Analyst concentrates on adherence to specific laws and regulations. Both roles require similar certifications and often work in overlapping industries, but their core responsibilities differ in scope and focus.
What are GRC Risk Analysts?
What are the key skills and qualifications needed to thrive as a GRC Risk Analyst, and why are they important?
What are some common challenges a GRC Risk Analyst might face when implementing new risk management frameworks within an organization?
UFP Industries rating
7.2
Based on 83 frontline employees who took The Breakroom Quiz
330th of 518 rated manufacturers
Job description
Job Summary
The Sr. Cybersecurity Risk Analyst is responsible for leading and maturing the organization's cybersecurity risk management program. This role is accountable for identifying, assessing, and communicating cybersecurity risks across the enterprise, while driving alignment with regulatory requirements, including CMMC. The position will play a key role in building and maintaining the enterprise risk register, developing a third-party risk management program, and partnering with IT teams to establish and maintain secure standards and practices.
The ideal candidate combines strong analytical skills with practical experience in governance, risk, and compliance, and can translate technical risk into actionable business decisions.
Location: Onsite out of our Grand Rapids, MI office.
Work Authorization: Applicants must be currently authorized to work.
Principal Duties and Responsibilities
Risk Management and Governance
Lead the development and ongoing maintenance of the enterprise cybersecurity risk register, including risk identification, classification, ownership, and tracking.
Conduct and lead risk assessments for systems, applications, projects, and business initiatives.
Develop and implement risk management processes, methodologies, and reporting metrics.
Facilitate risk review sessions with business and IT stakeholders to ensure accountability and transparency.
Develop and track risk mitigation and remediation plans to closure.
Regulatory Compliance (CMMC and Related Frameworks)
Support and maintain the organization's CMMC compliance program, including control mapping, evidence collection, and audit readiness.
Partner with internal stakeholders (IT, Legal, HR, Plant Operations) to ensure alignment with CMMC and other regulatory requirements.
Assist in preparing documentation and responses for assessments, audits, and regulatory inquiries.
Monitor evolving compliance requirements and translate them into actionable internal controls.
Third-Party Risk Management
Develop and mature a third-party cybersecurity risk management program.
Conduct security risk assessments of vendors, SaaS providers, Software, and external partners.
Evaluate vendor security posture, shared responsibility models, and contractual security requirements.
Partner with procurement and legal teams to integrate security requirements into vendor onboarding and contracting processes.
Security Standards and IT Partnership
Collaborate with IT and engineering teams to develop, implement, and maintain cybersecurity standards and secure configuration baselines.
Ensure security requirements are embedded into system design, architecture, and operational processes.
Provide risk-based guidance on system hardening, segmentation, and control implementation.
Support the development of policies, standards, and procedures that are practical, enforceable, and auditable.
Reporting and Communication
Communicate risk findings, trends, and recommendations to technical and non-technical stakeholders, including leadership.
Develop reporting for executive audiences, including risk summaries, metrics, and program maturity updates.
Support audit committee and leadership reporting as needed.
Continuous Improvement
Stay current on cybersecurity threats, regulatory changes, and industry best practices.
Identify opportunities to improve risk visibility, coverage, and program efficiency.
Mentor junior analysts and contribute to the maturity of the GRC function.
Qualifications
Required
Bachelor's degree in Information Security, Computer Science, or related field (or equivalent experience).
5+ years of experience in cybersecurity risk, governance, or compliance roles.
Experience building or maintaining a cybersecurity risk register and risk management processes.
Strong understanding of security frameworks (e.g., NIST, CMMC, ISO 27001).
Experience conducting third-party/vendor risk assessments.
Strong analytical, problem-solving, and risk evaluation skills.
Ability to translate technical risks into business impact.
Strong written and verbal communication skills.
Preferred
Experience supporting CMMC assessments or similar regulatory compliance programs.
Familiarity with manufacturing or operational technology (OT) environments.
Experience developing security standards or working closely with infrastructure and engineering teams.
Professional certifications such as CISSP, CISM, CRISC, or similar.
The Company is an Equal Opportunity Employer.
What UFP Industries employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom
About UFP Industries
Sourced by ZipRecruiter
Universal Forest Products, Inc., is a U.S.-based global corporation that finds reward in its roots and its hard-earned success. Founded in 1955 as a supplier of lumber to the manufactured housing industry, Universal today is a multibillion-dollar holding company with subsidiaries around the globe that serve three robust markets: retail, industrial and construction. Since 1993, Universal has been publicly traded (Nasdaq: UFPI). We re headquartered in Grand Rapids, Michigan.
Industry
Wood product manufacturing
Company size
10,000+ Employees
Headquarters location
Grand Rapids, MI, US
Year founded
1955