Job Title: Governance Risk and Compliance Analyst II
Division: Governance, Risk & Compliance – IT Security
Position Summary
The GRC Analyst will act as a key contributor to Vertiv’s Governance, Risk, and Compliance initiatives, driving risk assessments, security reviews, audit readiness, and third-party risk management efforts. This role supports continuous improvement of the risk register and policy exception processes, partners with cross-functional stakeholders, and helps develop a scalable security and compliance posture across the organization.
Key Responsibilities
• Lead IT risk assessments, mitigation planning, and control monitoring activities.
• Oversee risk register updates and coordinate with risk owners and SMEs to track mitigation actions.
• Drive third-party risk reviews and assessments using OneTrust and SecurityScorecard, escalating high-risk vendors for action.
• Conduct contract reviews focused on information security terms and recommend necessary revisions.
• Respond to customer security questionnaires with input from SMEs using Loopio.
• Supervise compliance training rollouts (e.g., phishing campaigns, annual security awareness training).
• Review and recommend changes to IT security policies and standards aligned with ISO 27001, NIST CSF, and other frameworks.
• Generate and present GRC dashboards and KPIs to leadership to inform risk posture and team performance.
• Act as an escalation point for GRC process inquiries and ticket-related exceptions.
• Mentor junior analysts and support GRC program maturity through playbooks, SOPs, and process documentation.
Qualifications
• Bachelor’s degree in information systems, Cybersecurity, or a related field.
• 5+ years of experience in GRC, IT Risk Management, or Information Security.
• Strong understanding of ITGC, SOX, ISO 27001, NIST CSF, and data privacy regulations (e.g., HIPAA, GDPR).
• Experience with GRC platforms such as ServiceNow GRC, OneTrust, and SecurityScorecard.
• Strong documentation and analytical skills with experience preparing audit-ready evidence.
• Certifications such as CISA, CISSP, ISO 27001 Lead Implementer or Auditor (preferred).
• Excellent communication and stakeholder management skills across global teams.
• Strong organizational skills and ability to manage multiple deliverables independently.
Skills Required
- Bachelor's degree in information systems, cybersecurity, or a related field
- 5+ years of experience in GRC, IT risk management, or information security
- Strong understanding of ITGC, SOX, ISO 27001, NIST CSF, and data privacy regulations including HIPAA and GDPR
- Experience with ServiceNow GRC, OneTrust, and SecurityScorecard
- Strong documentation and analytical skills, including preparing audit-ready evidence
- CISA, CISSP, ISO 27001 Lead Implementer, or ISO 27001 Auditor certification
- Excellent communication and stakeholder management skills across global teams
- Strong organizational skills and ability to manage multiple deliverables independently
Vertiv Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Vertiv and has not been reviewed or approved by Vertiv.
-
Healthcare Strength — Health coverage is described as comprehensive, with standard medical, dental, and vision plans plus wellness and mental-health resources. Core offerings also include disability and life insurance and an Employee Assistance Program.
-
Leave & Time Off Breadth — Time off includes paid holidays and PTO typical of large employers, and many U.S. salaried roles feature flexible or "unlimited" PTO approaches. These programs are part of a structured, global total rewards framework.
-
Fair & Transparent Compensation — Pay is considered fair at start for many office-based, engineering, and field service roles, and total compensation packages are viewed as stable. In some hourly manufacturing settings, overtime opportunities help boost overall earnings.
Vertiv Insights
What We Do
Vertiv (NYSE: VRT) brings together hardware, software, analytics and ongoing services to ensure its customers’ vital applications run continuously, perform optimally and grow with their business needs. Vertiv solves the most important challenges facing today’s data centers, communication networks and commercial and industrial facilities with a portfolio of power, cooling and IT infrastructure solutions and services that extends from the cloud to the edge of the network. Headquartered in Columbus, Ohio, USA, Vertiv employs approximately 20,000 people and does business in more than 130 countries. For more information, and for the latest news and content from Vertiv, visit Vertiv.com.









