1

Grc Third Party Risk Analyst Jobs in Michigan (NOW HIRING)

... the IS GRC - Risk & Compliance Senior Analyst will support the firm's Governance, Risk, and ... Conduct third-party security risk assessments, including review of: * Security questionnaires

Information Security experience (preferably Third Party Risk Management and Compliance) Familiarity with SOC 1 (SSAE 16*) and SOC 2 (**AT101) reports Ability to write process, procedures, flowcharts ...

Non Exempt Job Summary The Partnership Risk Analyst plays a key role in maintaining and enhancing ... Demonstrates the ability to build and maintain positive third-party partner relationships by ...

next page

Showing results 1-20

Grc Third Party Risk Analyst information

What are some typical challenges a GRC Third Party Risk Analyst may encounter when assessing vendors?

As a GRC Third Party Risk Analyst, you may face challenges such as obtaining timely and complete responses from vendors, especially when dealing with large or international organizations. Navigating varying levels of vendor maturity in risk management practices can also be difficult. Additionally, balancing the need for thorough risk assessments with fast-paced business timelines requires strong communication and prioritization skills. Collaborating closely with procurement, legal, and IT teams is essential to ensure all risks are properly identified and managed.

What are the key skills and qualifications needed to thrive as a GRC Third Party Risk Analyst, and why are they important?

To thrive as a GRC Third Party Risk Analyst, you need a strong understanding of risk management frameworks, compliance regulations, and vendor risk assessment methodologies, typically supported by a degree in information security, business, or a related field. Familiarity with GRC platforms (like Archer or ServiceNow), third-party risk management tools, and certifications such as CISA or CRISC is highly beneficial. Strong analytical thinking, attention to detail, and effective communication skills are essential soft skills for this role. These competencies ensure that organizations can accurately assess and mitigate third-party risks, maintaining compliance and protecting sensitive data.

What is a GRC Third Party Risk Analyst?

A GRC Third Party Risk Analyst is a professional who assesses and manages the risks associated with an organization’s external vendors, suppliers, or partners. Their role involves evaluating third-party compliance with regulatory standards and internal policies, identifying potential risks such as data breaches or non-compliance, and recommending mitigation strategies. They use frameworks like GRC (Governance, Risk, and Compliance) to help ensure that third-party relationships do not compromise the organization's security or reputation. This role often collaborates with procurement, legal, and IT teams to maintain robust risk management processes.

What is the difference between Grc Third Party Risk Analyst vs Grc Vendor Risk Analyst?

AspectGrc Third Party Risk AnalystGrc Vendor Risk Analyst
CertificationsCertifications like CRISC, CISA often preferredSame certifications commonly required
Work EnvironmentFocuses on third-party relationships and risk assessmentsPrimarily evaluates vendor-specific risks and compliance
Industry UsageUsed across finance, healthcare, and tech sectorsCommonly found in industries with extensive vendor networks

The Grc Third Party Risk Analyst and Grc Vendor Risk Analyst roles overlap significantly in certifications and work environment. The main difference lies in scope: the Third Party Risk Analyst assesses overall third-party relationships, while the Vendor Risk Analyst concentrates specifically on individual vendors. Both roles are vital for managing third-party risks in various industries.

What job categories do people searching Grc Third Party Risk Analyst jobs in Michigan look for? The top searched job categories for Grc Third Party Risk Analyst jobs in Michigan are:
What cities in Michigan are hiring for Grc Third Party Risk Analyst jobs? Cities in Michigan with the most Grc Third Party Risk Analyst job openings:
Infographic showing various Grc Third Party Risk Analyst job openings in Michigan as of August 2026, with employment types broken down into 1% As Needed, 84% Full Time, 12% Part Time, and 3% Contract. Highlights an 88% Physical, 4% Hybrid, and 8% Remote job distribution.

GRC Analyst

Saanvi Technologies

Southfield, MI • On-site

Contractor

Posted 7 days ago


Job description

About the Role

As a member of the Information Security team, the IS GRC – Risk & Compliance Senior Analyst will support the firm's Governance, Risk, and Compliance (GRC) program by managing security risks, maintaining the risk register, conducting risk assessments, coordinating control testing, and supporting audit activities. The role partners closely with IT leadership, business stakeholders, and third-party vendors to ensure security and compliance objectives are achieved.


Key Responsibilities

Security Risk Management

  • Support the CISO with annual and periodic security risk assessments.
  • Manage and maintain the enterprise risk register.
  • Conduct security risk assessments and evaluate risk and control effectiveness.
  • Track remediation activities through closure and report status to leadership.
  • Interview SMEs and gather information for risk assessments.
  • Develop and support risk mitigation strategies with cross-functional teams.
  • Conduct third-party security risk assessments, including review of:
    • Security questionnaires
    • Supporting documentation
    • Independent audit reports
  • Identify vendor security gaps, assign risk ratings, and recommend mitigations.

Control Framework & Compliance Testing

  • Design, execute, and monitor security control testing.
  • Ensure compliance with contractual, regulatory, and internal security requirements.
  • Partner with IT and business control owners.
  • Prepare audit evidence and documentation for internal and external audits.
  • Report metrics and compliance status to the IS GRC Manager, Director, and CISO.
  • Improve and automate GRC processes where possible.
  • Perform additional responsibilities as assigned.

Required Qualifications

  • Bachelor's degree in Information Technology or a related field (or equivalent experience).
  • 3+ years of professional experience.
  • Experience in one or more of the following:
    • Information Security
    • Governance, Risk & Compliance (GRC)
    • IT Risk
    • Information Technology
    • Audit
  • Experience with security frameworks or regulations such as:
    • ISO 27001
    • SOC 2
    • PCI DSS
    • HIPAA
    • Other global security/compliance standards
  • Strong experience in:
    • Risk assessments
    • Risk registers
    • Control testing
    • Security compliance
    • Third-party/vendor risk management
  • Excellent analytical, communication, and documentation skills.
  • Experience with Microsoft Office Suite.
  • ServiceNow experience is preferred.

Preferred Certifications

  • CISSP (Preferred)
  • CISA (Preferred)
  • CRISC (Nice to have)
  • Willingness to pursue security certifications is highly valued.

Additional Information

  • Core business hours: 8:30 AM – 5:30 PM (Monday–Friday).
  • Occasional work outside standard business hours may be required.
  • Hybrid work schedule:
    • Onsite: Tuesday, Wednesday & Thursday
    • Remote: Monday & Friday
  • No relocation assistance or benefits are provided for this contract position.
Thanking you 
Jeevan@saanvi.us

Saanvi Technologies logo

About Saanvi Technologies

Sourced by ZipRecruiter

Saanvi Technologies is a staffing company that specializes in providing IT professionals to businesses. Our employees are experts in their field, and have the skills and experience necessary to help businesses grow and succeed. Saanvi Technologies is dedicated to helping businesses achieve their goals, and they have a proven track record of success. Our employees are qualified and reliable, and they always go above and beyond to meet the needs of their customers.

Company size

51 - 200 Employees

Headquarters location

Farmington, MI, US

Social media