- Company Name
- Concero
- Job Title
- GRC Analyst
- Job Description
-
**Job title**
GRC Analyst
**Role Summary**
Designs, implements, and monitors governance, risk, and compliance (GRC) programs focused on global data privacy and information security. Utilizes Microsoft Purview to enforce data classification, retention, DLP, and privacy policies, while conducting risk assessments, audits, and vendor risk management across cloud and on‑premises environments.
**Expectations**
- Maintain adherence to GDPR, CCPA, PIPL, PIPEDA and other privacy laws.
- Deliver evidence and remediation for internal/external audits.
- Respond to data subject requests and privacy incidents rapidly and compliantly.
- Teach privacy and security best practices organization‑wide.
- Travel occasionally, including cross‑border visits as needed.
**Key Responsibilities**
- Lead Microsoft Purview adoption: data classification, retention policies, DLP, encryption, and compliance dashboards.
- Conduct risk assessments, control reviews, and compliance audits; document gaps and remediate.
- Create, update and audit policies, procedures, standards, and guidance aligned with regulatory requirements.
- Monitor regulatory changes, assess impact, and advise stakeholders.
- Coordinate audits, compile evidence, draft responses, and track remediation.
- Deliver privacy and security awareness training programs.
- Manage data subject request handling and privacy incident responses.
- Integrate privacy‑by‑design into projects with IT, Legal, HR, and business units.
- Maintain vendor risk management program, including third‑party assessments and ongoing monitoring.
- Produce compliance metrics, dashboards, and executive reports.
**Required Skills**
- Deep understanding of global privacy regulations (GDPR, CCPA, PIPL, PIPEDA).
- Expertise in Microsoft Purview features: classification, retention, DLP, information protection, compliance management.
- Proficiency in risk assessment frameworks (COBIT, COSO) and audit management.
- Vendor risk assessment and contract compliance knowledge.
- Strong analytical skills, meticulous attention to detail, and confidentiality.
- Ability to handle multiple concurrent projects and balance competing priorities.
- Excellent communication skills for training, stakeholder guidance, and report generation.
**Required Education & Certifications**
- Bachelor’s degree in Information Systems, Business Administration, Cybersecurity, Legal Studies, or related field.
- 5+ years experience in GRC, compliance, data privacy, or information security, or equivalent education/experience combination.
- Preferred certifications: CISA, CISM, CRISC, CISSP, CIPM, CIPP or equivalent.
---