IT GRC Analyst II
Raleigh, NC · On-site
Third party risk management * Working knowledge of various industry security standards and frameworks including: NIST, ISO 27001, ISF Standard of Good Practice (SoGP), etc. Desired Knowledge ...
Raleigh, NC · On-site
Third party risk management * Working knowledge of various industry security standards and frameworks including: NIST, ISO 27001, ISF Standard of Good Practice (SoGP), etc. Desired Knowledge ...
Raleigh, NC · On-site
Third party risk management * Working knowledge of various industry security standards and frameworks including: NIST, ISO 27001, ISF Standard of Good Practice (SoGP), etc. Desired Knowledge ...
... third-party vendor risk management program. * Other duties, as assigned, are based on the ongoing evolution of the Information Security program. KNOWLEDGE, SKILLS, AND ABILITIES: * Proficiency with ...
Quick apply
... third-party vendor risk management program. * Other duties, as assigned, are based on the ongoing evolution of the Information Security program. KNOWLEDGE, SKILLS, AND ABILITIES: * Proficiency with ...
Partner with Business Owners, Third Party Risk Management (TPRM) and Legal to establish standards for contract language, supplier negotiations, overall management, and dispute resolution. Ensures all ...
Partner with Business Owners, Third Party Risk Management (TPRM) and Legal to establish standards for contract language, supplier negotiations, overall management, and dispute resolution. Ensures all ...
Partner with Business Owners, Third Party Risk Management (TPRM) and Legal to establish standards for contract language, supplier negotiations, overall management, and dispute resolution. Ensures all ...
Partner with Business Owners, Third Party Risk Management (TPRM) and Legal to establish standards for contract language, supplier negotiations, overall management, and dispute resolution. Ensures all ...
... third-party vendor risk management program. * Other duties, as assigned, are based on the ongoing evolution of the Information Security program. KNOWLEDGE, SKILLS, AND ABILITIES: * Proficiency with ...
... third-party vendor risk management program. * Other duties, as assigned, are based on the ongoing evolution of the Information Security program. KNOWLEDGE, SKILLS, AND ABILITIES: * Proficiency with ...
Raleigh, NC · On-site +1
$101K - $150K/yr
Provide subject matter expertise and strategic guidance on resilience-related initiatives, including business continuity, third-party risk, and crisis management. * Champion a culture of resilience ...
Raleigh, NC · On-site +1
$101K - $150K/yr
Provide subject matter expertise and strategic guidance on resilience-related initiatives, including business continuity, third-party risk, and crisis management. * Champion a culture of resilience ...
Raleigh, NC · On-site
$67K - $103K/yr
... Third Party Risk Management, documenting items in the Archer system of record, etc. Lastly, this role supports risk maturity in a growing organization, coordinating and supporting 2nd and 3rd Line ...
Raleigh, NC · On-site
$67K - $103K/yr
... Third Party Risk Management, documenting items in the Archer system of record, etc. Lastly, this role supports risk maturity in a growing organization, coordinating and supporting 2nd and 3rd Line ...
Raleigh, NC · On-site +1
$67K - $103K/yr
... Third Party Risk Management, documenting items in the Archer system of record, etc. Lastly, this role supports risk maturity in a growing organization, coordinating and supporting 2nd and 3rd Line ...
Raleigh, NC · On-site +1
$67K - $103K/yr
... Third Party Risk Management, documenting items in the Archer system of record, etc. Lastly, this role supports risk maturity in a growing organization, coordinating and supporting 2nd and 3rd Line ...
Raleigh, NC · On-site +1
$67K - $103K/yr
... Third Party Risk Management, documenting items in the Archer system of record, etc. Lastly, this role supports risk maturity in a growing organization, coordinating and supporting 2nd and 3rd Line ...
Raleigh, NC · On-site +1
$67K - $103K/yr
... Third Party Risk Management, documenting items in the Archer system of record, etc. Lastly, this role supports risk maturity in a growing organization, coordinating and supporting 2nd and 3rd Line ...
Vendor and third-party risk: Assess and manage security risk associated with vendors, contractors, and third-party service providers. * Future team leadership: Lay the groundwork to scale the ...
Vendor and third-party risk: Assess and manage security risk associated with vendors, contractors, and third-party service providers. * Future team leadership: Lay the groundwork to scale the ...
Durham, NC · On-site
Vendor and third-party risk: Assess and manage security risk associated with vendors, contractors, and third-party service providers. * Future team leadership: Lay the groundwork to scale the ...
Durham, NC · On-site
Vendor and third-party risk: Assess and manage security risk associated with vendors, contractors, and third-party service providers. * Future team leadership: Lay the groundwork to scale the ...
Raleigh, NC · Remote
$101K - $150K/yr
Provide subject matter expertise and strategic guidance on resilience-related initiatives, including business continuity, third-party risk, and crisis management. * Champion a culture of resilience ...
Raleigh, NC · Remote
$101K - $150K/yr
Provide subject matter expertise and strategic guidance on resilience-related initiatives, including business continuity, third-party risk, and crisis management. * Champion a culture of resilience ...
Raleigh, NC · Remote
$101K - $150K/yr
Provide subject matter expertise and strategic guidance on resilience-related initiatives, including business continuity, third-party risk, and crisis management. * Champion a culture of resilience ...
Raleigh, NC · Remote
$101K - $150K/yr
Provide subject matter expertise and strategic guidance on resilience-related initiatives, including business continuity, third-party risk, and crisis management. * Champion a culture of resilience ...
Set firm aligned compliance requirements across audit methodology, SDLC, privacy, cybersecurity, third party risk, AI/GenAI, and data management lifecycle. Shape how risk and compliance are embedded ...
Set firm aligned compliance requirements across audit methodology, SDLC, privacy, cybersecurity, third party risk, AI/GenAI, and data management lifecycle. Shape how risk and compliance are embedded ...
Raleigh, NC · On-site
$95K - $113K/yr
Experience with project risk management, including failure mode effect analysis and planning * Experience implementing solutions utilizing third party vendors and third party products. * Project ...
Raleigh, NC · On-site
$95K - $113K/yr
Experience with project risk management, including failure mode effect analysis and planning * Experience implementing solutions utilizing third party vendors and third party products. * Project ...
Raleigh, NC · On-site
... project risk management, including failure mode effect analysis • Experience implementing solutions utilizing third party vendors and third party products • IT Project Management experience ...
Raleigh, NC · On-site
... project risk management, including failure mode effect analysis • Experience implementing solutions utilizing third party vendors and third party products • IT Project Management experience ...
Experience with project risk management, including failure mode effect analysis and planning * Experience implementing solutions utilizing third party vendors and third party products * Project ...
Experience with project risk management, including failure mode effect analysis and planning * Experience implementing solutions utilizing third party vendors and third party products * Project ...
... management, asset inventories). Controls Monitoring & Assurance * Establish and operate a ... Familiarity with third-party risk and vendor compliance monitoring. * Relevant certifications ...
... management, asset inventories). Controls Monitoring & Assurance * Establish and operate a ... Familiarity with third-party risk and vendor compliance monitoring. * Relevant certifications ...
... management, asset inventories). Controls Monitoring & Assurance * Establish and operate a ... Familiarity with third-party risk and vendor compliance monitoring. * Relevant certifications ...
... management, asset inventories). Controls Monitoring & Assurance * Establish and operate a ... Familiarity with third-party risk and vendor compliance monitoring. * Relevant certifications ...
Raleigh, NC · On-site
Experience with project risk management, including failure mode effect analysis Experience implementing solutions utilizing third party vendors and third party products IT Project Management ...
Raleigh, NC · On-site
Experience with project risk management, including failure mode effect analysis Experience implementing solutions utilizing third party vendors and third party products IT Project Management ...
$50.1K - $60.5K
4% of jobs
$60.5K - $71K
6% of jobs
$71K - $81.5K
11% of jobs
$85.4K is the 25th percentile. Wages below this are outliers.
$81.5K - $91.9K
11% of jobs
The median wage is $100.3K / yr.
$91.9K - $102.4K
23% of jobs
$102.4K - $112.9K
13% of jobs
$119.8K is the 75th percentile. Wages above this are outliers.
$112.9K - $123.4K
12% of jobs
$123.4K - $133.8K
8% of jobs
$133.8K - $144.3K
6% of jobs
$144.3K - $154.8K
4% of jobs
$154.8K - $165.2K
2% of jobs
$50.1K
$108.4K
$165.2K
A Third Party Risk Management (TPRM) job involves assessing, monitoring, and mitigating risks associated with an organization's external vendors, suppliers, and service providers. Professionals in this role evaluate third parties for compliance, cybersecurity vulnerabilities, financial stability, and operational risks. They develop frameworks, conduct risk assessments, and ensure that vendors meet regulatory and organizational standards. TPRM specialists collaborate with internal teams like compliance, procurement, and IT security to protect the organization's interests. Their goal is to minimize potential disruptions, data breaches, or regulatory non-compliance stemming from third-party relationships.
One of the primary challenges in Third Party Risk Management is keeping up with evolving regulatory requirements and the diverse risk profiles of different vendors. Professionals in this role often encounter situations where they must coordinate risk assessments across multiple departments and ensure timely responses from both internal teams and external partners. To address these challenges, strong project management skills, proactive communication, and the use of dedicated risk management tools are essential. Many organizations also emphasize ongoing training and cross-functional collaboration to stay ahead of emerging risks and regulatory changes.
To thrive in Third Party Risk Management, you need a strong understanding of risk assessment, compliance regulations, vendor management, and data analysis, typically supported by a bachelor's degree in business, finance, or a related field. Familiarity with risk assessment tools, third-party risk management platforms (such as Archer or ProcessUnity), and certifications like Certified Third Party Risk Professional (CTPRP) are common in this field. Exceptional communication, negotiation, and analytical-thinking skills are crucial soft skills for engaging vendors and stakeholders effectively. These abilities ensure comprehensive risk mitigation and help organizations maintain compliance and security while building strong external partnerships.

Full-time
Posted 19 days ago
If you are motivated and believe in the credit union philosophy of "People Helping People," join our team!
The IT GRC Analyst 2 assess, tests, documents, and monitors the SECU technology ecosystem to ensure the IT control environment effectively mitigates risks associated with an everchanging threat landscape. The IT GRC Analyst will possess a wide range of technical and interpersonal skills to bridge the gap between technology organizations and the business. Must have a big-picture perspective, ability to execute end-to-end risk management processes, and ability to quickly establish trust and build productive relationships across multiple departments. The IT GRC Analyst will require expertise to perform technology risk assessments, provide input to and/or document IT policies, standards, and guidelines, develop, monitor, and track risk remediation plans, and aggregate and report key risk metrics to senior stakeholders.
Responsibilities:
20% - Identify, document, and monitor technology risks present across both internal and external (vendor / cloud) environments
20% - Quantify inherent and residual IT risk levels to enhance analytics, inform prioritizations, and for use in management reporting
20% - Work with risk remediation owners to establish remediation plans with milestones and target dates, and monitor progress towards remediation, escalating as appropriate
20% - Execute technology risk management processes and provide input to support continuous improvement of process and program design
10% - Perform risk and controls assessments while aggregating reporting for Audit and/or Regulatory issues.
10% - Partner with relevant stakeholders to establish clear and consistent IT risk reporting, metrics, KRIs, and KPIs to inform decision making
Required Relevant Experience - 5 Years
Required Knowledge, Abilities and Skills:
* Teamwork, collaboration, self-driven and effective communication skills - both written and verbal.
* 3+ years of IT Security and/or IT Risk Management experience working in a mid-to-large size company
* Basic proficiency or ability to learn one or more of the following: * Risk and controls assessments
* Documenting and maintaining IT Policies / Standards
* IT Risk aggregation, reporting, KPI/KRIs
* Issues management
* Third party risk management
* Working knowledge of various industry security standards and frameworks including: NIST, ISO 27001, ISF Standard of Good Practice (SoGP), etc.
Desired Knowledge, Abilities, Skills:
* Knowledge of modern enterprise and security architectures, their challenges, common approaches to overcome their challenges, and their inherent security strengths and weaknesses.
* Professional certifications such as: CISSP, CISA, CISM, GIAC, CGEIT, CRISC, OSCE, or other relevant industry certification
* Experience working in a financial institution.
* Experience working within a DevOps environment.
SECU provides equal employment opportunity to all qualified persons regardless of race, color, religion, age, sex, sexual orientation, gender identity, national origin, genetic information, disability, veteran status, or other classification protected by law.
Disclaimer
State Employees' Credit Union reserves the right to fill this role at a higher/lower level based on business need.