GRC Analyst

TLDR

Support the GRC program through vendor risk assessment and ongoing vendor management, ensuring compliance and enhancing the risk management framework.

About Juniper Square

Our mission is to unlock the full potential of private markets. Privately owned assets like commercial real estate, private equity, and venture capital make up half of our financial ecosystem yet remain inaccessible to most people. We are digitizing these markets, and as a result, bringing efficiency, transparency, and access to one of the most productive corners of our financial ecosystem. If you care about making the world a better place by making markets work better through technology – all while contributing as a member of a values-driven organization – we want to hear from you. 

Juniper Square offers employees a variety of ways to work, ranging from a fully remote experience to working full-time in one of our physical offices. We invest heavily in digital-first operations, allowing our teams to collaborate effectively across 27 U.S. states, 2 Canadian Provinces, India, Luxembourg, and England. We also have physical offices in San Francisco, New York City, Mumbai and Bangalore for employees who prefer to work in an office some or all of the time.

About your role

The GRC Analyst is responsible for supporting the organisation's GRC program including the third-party risk management program. The ideal candidate will have a strong understanding and experience building scalable, right-sized risk processes compliant with applicable laws and customer commitments. The successful candidate will also possess strong analytical and problem-solving skills, as well as excellent communication and interpersonal skills. This role will work closely with a broad set of cross-functional stakeholders within the company and should be able to build a rapport and influence towards appropriate risk management outcomes.

What you’ll do

  • Vendor and contractor risk assessment process during onboarding, adhering to a defined Service Level Agreement (SLA).

  • Conduct annual vendor monitoring and re-assessment processes for existing vendors.

  • Maintain the vendor inventory and collaborate with vendors on an ongoing basis to reduce identified risks.

  • Triage incoming technical security requests for vendor application/system integrations and route to appropriate teams for input.

  • Help mature the classification and management framework for critical vendors.

  • Benchmark, identify, drive, and manage improvements to the vendor security risk management program.

  • Develop, maintain, and analyze reporting and metrics to provide leadership with clear visibility into the vendor and third-party risk posture.

1. Customer Trust and Assurance

  • Compliance

    • Work with cross-functional teams to procure controls evidence to provide to external auditors timely and issue reports timely.

    • Monitor and test effectiveness of compliance control health throughout the year; not just during audits

  • Customer Trust

    • Maintain our trust center by keeping security documents and knowledge base up-to-date

    • Support sales teams with open security and privacy questions

    • Support customer security and privacy audits

2. Governance

  • Policy Management

    • Update policies and procedures annually while incorporating stakeholder feedback and obtain approval

    • Define and manage incoming policy exceptions on an ongoing basis to manage associated risk

  • Security and Privacy Training and Awareness

    • Develop and implement role and team specific security and privacy training working closely with key business partners.

    • Manage the roll-out, escalation and completion of all security and privacy training modules.

3. GRC Metrics and Reporting

  • Collect and report on key GRC performance metrics

4. Risk Management

  • Maintain business unit risk registers with existing teams on a monthly basis to appropriately address key risks areas

Qualifications

  • Bachelor's degree in information systems, engineering, business, risk management, or a related field

  • 5+ years of security/GRC experience, including substantial experience with vendor security risk management and performing vendor security reviews/audits.

  • Proven experience in managing and improving vendor security risk programs, including familiarity with vendor security questionnaires for third-party assessments.

  • Direct experience, knowledge and understanding of major security frameworks, regulations, and standards such as SOC 2 and ISO 27001.

  • Experience working effectively with diverse teams to influence security and compliance outcomes across the organization (e.g., Procurement, IT, Security, Engineering, Legal)

  • Experience developing and maintaining scalable GRC processes

  • Ability to partner with stakeholders collaboratively to implement a scalable approach to TPRM

  • Excellent communication and interpersonal skills

Nice to Have

  • Prior experience with major GRC software solutions

Juniper Square is dedicated to unlocking the potential of private markets by digitizing assets like commercial real estate and private equity. Our platform enhances efficiency and transparency, making these traditionally inaccessible investment opportunities available to a broader audience. We’re transforming how individuals and institutions engage with one of the most vital segments of the financial ecosystem.

View all jobs
Ace your job interview

Understand the required skills and qualifications, anticipate the questions you may be asked, and study well-prepared answers using our sample responses.

GRC Analyst Q&A's
Report this job
Apply for this job