1

Grc Risk Analyst Jobs in Oklahoma (NOW HIRING)

Senior GRC Analyst

Tulsa, OK · On-site

$80 - $110/hr

The Sr. GRC Analyst will also assume ownership of Human Risk Management (HRM) including the ... delivery of comprehensive security awareness education, the end‑to‑end execution of phishing ...

IT Assurance and Compliance Analyst

Oklahoma City, OK · On-site

$87K - $87K/yr

CACI is seeking an experienced and relationshipfocused Cyber Risk and IT Compliance professional to ... Experience using ServiceNow IRM or other GRC/compliance management platforms. - What You Can Expect:

$40/hr

Provide analysis and trending of security log data from a large number of various security devices ... Our AI-powered platform unifies finance, risk, and sustainability on a single, secure foundation ...

$40/hr

Provide analysis and trending of security log data from a large number of various security devices ... Our AI-powered platform unifies finance, risk, and sustainability on a single, secure foundation ...

$40/hr

Provide analysis and trending of security log data from a large number of various security devices ... Our AI-powered platform unifies finance, risk, and sustainability on a single, secure foundation ...

$40/hr

Provide analysis and trending of security log data from a large number of various security devices ... Our AI-powered platform unifies finance, risk, and sustainability on a single, secure foundation ...

$40/hr

Provide analysis and trending of security log data from a large number of various security devices ... Our AI-powered platform unifies finance, risk, and sustainability on a single, secure foundation ...

$40/hr

Provide analysis and trending of security log data from a large number of various security devices ... Our AI-powered platform unifies finance, risk, and sustainability on a single, secure foundation ...

next page

Showing results 1-20

Grc Risk Analyst information

What is a GRC Risk Analyst?

GRC Risk Analysts are professionals who specialize in Governance, Risk, and Compliance (GRC) within an organization. They assess and manage risks related to business operations, ensure compliance with relevant laws and regulations, and help implement policies and controls to mitigate potential threats. These analysts work closely with management to identify vulnerabilities, develop risk management strategies, and monitor the effectiveness of compliance programs. Their goal is to protect the organization from financial, legal, and reputational harm while supporting business objectives.

What are the key skills and qualifications needed to thrive as a GRC Risk Analyst?

To thrive as a GRC (Governance, Risk, and Compliance) Risk Analyst, you need a solid understanding of risk management principles, regulatory requirements, and compliance frameworks, often supported by a degree in information security, business, or a related field. Familiarity with GRC platforms (such as RSA Archer or MetricStream), risk assessment methodologies, and certifications like CRISC or CISA is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and convey findings to stakeholders. These skills are critical for ensuring organizational compliance, minimizing risk exposure, and supporting informed decision-making.

What are some common challenges a GRC Risk Analyst might face when implementing new risk management frameworks within an organization?

A GRC Risk Analyst often encounters challenges such as resistance to change from stakeholders, integrating new frameworks with existing processes, and ensuring consistent understanding across departments. Aligning risk management practices with organizational goals while adhering to regulatory requirements can also be complex. Success in this role requires strong communication skills, adaptability, and the ability to educate and collaborate with team members from diverse backgrounds.

What is the difference between Grc Risk Analyst vs Compliance Analyst?

AspectGrc Risk AnalystCompliance Analyst
CertificationsISO 31000, FRM, CRISCISO 19600, CCEP, CISA
Work EnvironmentRisk management teams, corporate officesRegulatory departments, corporate offices
Industry UsageFinance, banking, insurance, corporate riskFinancial services, healthcare, manufacturing
Job FocusIdentifying, assessing, and mitigating risks across enterpriseEnsuring compliance with laws and regulations

While both roles involve regulatory and risk considerations, a Grc Risk Analyst focuses on enterprise-wide risk management strategies, whereas a Compliance Analyst concentrates on adherence to specific laws and regulations. Both roles require similar certifications and often work in overlapping industries, but their core responsibilities differ in scope and focus.

What job categories do people searching Grc Risk Analyst jobs in Oklahoma look for?

The top searched job categories for Grc Risk Analyst jobs in Oklahoma are:

What cities in Oklahoma are hiring for Grc Risk Analyst jobs?

Cities in Oklahoma with the most Grc Risk Analyst job openings:

Infographic showing various Grc Risk Analyst job openings in Oklahoma as of June 2026, with employment types broken down into 91% Full Time, 1% Temporary, and 8% Contract. Highlights an 77% Physical, 8% Hybrid, and 15% Remote job distribution.

Senior GRC Analyst

Sky Mavis

Tulsa, OK • On-site

$80 - $110/hr

Other

Medical, Dental, Vision, Life, Retirement, PTO

Posted 19 days ago


Key responsibilities

  • Assumes operational ownership of the Third‑Party Risk Management (TPRM) process to assess security practices, compliance levels, and potential risks of third-party vendors.

  • Owns the Human Risk Management (HRM) program, including delivering security awareness education, executing phishing simulations, and maintaining security awareness platforms.

  • Conducts due diligence on vendors, reviews security documentation, and collaborates with legal and stakeholder teams to ensure contractual security requirements.


Job description

About Us

Clayco is a full-service, turnkey real estate development, master planning, architecture, engineering, and construction firm that safely delivers clients across North America the highest quality solutions on time, on budget, and above and beyond expectations. With $8.1 billion in revenue for 2025, Clayco specializes in the "art and science of building," providing fast track, efficient solutions for mission critical, industrial, life sciences, power & energy, aviation, commercial, institutional, residential and sports & entertainment related building projects.

The Role We Want You For

Under the direction of and in collaboration with the GRC Manager, the Sr. GRC Analyst, Third‑Party & Human Risk Management (TPHRM) is a risk‑focused, highly analytical role that ensures all human and third‑party risk to Clayco is identified, quantified, documented, and treated to an acceptable level across the Clayco organization. This role will assume ownership of the Third‑Party Risk Management (TPRM) process to gather details on the security practices and compliance levels for each third‑party being considered or contracted for a solution or services to assess the potential for compromise due to a control gap or exploitable misconfiguration as well as non‑compliance with legal and regulatory requirements. Additional contribution will be expected for internal assessments and 3rd Party audits to gather and submit discovery and transactional responses and artifacts. The Sr. GRC Analyst will also assume ownership of Human Risk Management (HRM) including the delivery of comprehensive security awareness education, the end‑to‑end execution of phishing simulation programs, and the technical maintenance and life‑cycle management of security awareness platforms. Beyond simple training, the position focuses on Human Risk Management (HRM), using data‑driven insights to identify high‑risk user groups and implementing targeted interventions to proactively mitigate human‑centric threats to cultivate a security‑first culture internally through education and behavioral change. Additional responsibilities will be assigned as deemed necessary. Any travel is usually planned in advance, but issues may arise which warrant immediate travel to one or more satellite locations.

The Specifics of the Role
  • Assumes operational ownership of the 3rd Party Vendor Risk Management program identifying, assessing, and mitigating risks associated with external vendors, suppliers, and service providers
  • Conducts due diligence on new and existing vendors by reviewing security questionnaires, SOC reports, compliance certifications, and other supporting attestations
  • Captures, analyzes, and recommends treatment, assignment, and tracking of identified issues
  • Collaborates with legal and stakeholder teams to ensure contracts include specific clauses for data protection, service‑level agreements (SLAs), and AI governance
  • Documents and communicates all relevant findings and recommendations to stakeholders
  • Tracks, monitors, and reports on execution of remediation action plans and escalates inadequate responses or progress
  • Assumes ownership of the Security Awareness program determining appropriate topics, themes, scopes, and timing of cyber awareness communications, events, and content delivery
  • Conducts regular, simulated social engineering exercises to assess and improve employee recognition of real‑world attacks
  • Develops engaging, simple materials—such as infographics, newsletters, and videos—that translate complex technical risks into lay'​man'​s terms
  • Maintains Security Awareness training and simulation platforms to support content delivery and End User interaction, including support for any Client‑side functionality (i.e., "Report Phish" button)
  • Plans, coordinates, and executes activities for Cybersecurity month
  • Partners with Employee Relations, Legal, and Marketing to ensure security messaging is integrated into the broader corporate culture
  • Tracks Key Risk Indicators (KRI s) such as actual phishing click‑through rates, failed simulations, and missed training as well as Key Performance Indicators (KPIs) like suspicious email reporting, passed simulations, and successful training completion status to measure program effectiveness for leadership
Requirements
  • 6–8+ years’ experience in Risk & Compliance Assessment, Audit & Reporting, or similar functions, preferably within the Information Security or Technology fields
  • 3–4+ years working specifically in Information Security roles involving Risk Analysis, Information System Security Assessment, and/or Security Awareness and Human Risk Management
  • Bachelor's degree in Information Technology or related field, or equivalent experience
  • Required Certifications: Certified in Risk & Information Systems Control (CRISC), SANS Security Awareness Professional (SSAP), and Certified Third‑party Risk Professional Certification (CTPRP) (Current status, or obtained within 9 months of assuming role)
  • Strong experience leveraging auditing principles and methods to evaluate policies, processes, systems, and vendors to identify business risks and control gaps
  • Strong knowledge of regulations, frameworks, and standards such as NIST 800‑171/CSF/RMF, ISO 27001, CIS Critical Security Controls, etc.
  • Strong, technical knowledge of modern Systems, Services, Cloud Applications/Platforms, Identity Services, and Data Storage/Handling and their areas of Risk and Threat exposure
  • Experience with administering, maintaining, and leveraging a Risk Register to track and communicate identified Risk and its required remediation
  • Knowledge of statistics, reporting and analytical tools to analyze and solve complex problems
  • Proficiency in necessary productivity tools (i.e., Microsoft Excel, PowerPoint, Word, etc.) for analytics and presentations
  • Operate with strong integrity with ability to manage projects of a confidential nature
  • Ability to translate technical or abstract concepts into a narrative that is easily understood
  • Ability to thrive in fast‑paced environment
  • Background check with mandatory drug testing (comprehensive background check included)
  • Position is classified as a safety‑sensitive role in accordance with applicable state and federal laws
Benefits
  • Discretionary annual bonus: Subject to company and individual performance.
  • Comprehensive benefits package including: Medical, dental and vision plans, 401k, generous PTO and paid company holidays, employee assistance program, flexible spending accounts, life insurance, disability coverage, learning & development programs and more!
Compensation
  • The salary range for this position considers a wide range of factors in making compensation decisions including but not limited to: education, qualifications, skills, training, experience, certifications, internal equity, and location. Compensation decisions are dependent on the facts and circumstances of each case.
#J-18808-Ljbffr