Company Summary
Zoro.com is a leading eCommerce platform offering nearly 12 million tools, parts and supplies for our business customers. Launched in 2011, we brought a B2C-like experience to the B2B industry, and continue to be at the forefront of digital innovation at the intersection of technology and distribution. We have rapidly grown to over $1 billion in annual revenue and we’re just getting started!
Job Summary:
The Governance, Risk & Compliance (GRC) Analyst supports the development, execution, and continuous improvement of Zoro's Governance, Risk & Compliance program with a primary focus on Operational Resilience, including Business Continuity, Disaster Recovery, and Incident Response governance. The role also supports broader GRC initiatives including SOX compliance, third-party risk management, technology risk assessments, and audit readiness.
Duties & Responsibilities:
- Coordinate and continuously improve Zoro's Business Continuity and Disaster Recovery (BCDR) program by partnering with Grainger and cross-functional business and technology stakeholders to maintain Business Continuity Plans (BCPs), Disaster Recovery (DR) plans, Business Impact Analyses (BIAs), and annual plan refreshes.
- Coordinate and facilitate business continuity and disaster recovery exercises, tabletop exercises, and recovery testing while documenting results, tracking action items, and driving continuous improvement across the Operational Resilience program.
- Develop program metrics and identify opportunities to enhance organizational resilience beyond enterprise minimum requirements.
- Maintain governance documentation supporting Zoro's Incident Response Program (IRP), coordinate annual reviews and updates, and facilitate incident response tabletop exercises.
- Partner with stakeholders to coordinate post-incident remediation activities, track medium- and high-priority action items, and report on remediation status.
- Support governance, risk, and compliance initiatives including technology risk assessments, policy and standards development, audit readiness, and enterprise risk management activities.
- Partner with business and technology teams to strengthen governance processes, maintain risk documentation, and promote continuous improvement across the GRC program.
- Support expansion of Zoro's SOX program by onboarding new systems, applications, and business processes into SOX scope, coordinating design and implementation of new technology controls, and partnering with Grainger's Internal Controls organization on SOX governance activities.
- Support Zoro's Third-Party Risk Management (TPRM) program by coordinating vendor risk assessments, SOC report reviews, remediation tracking, and ongoing monitoring of third-party technology risk.
Qualifications:
- Familiarity with Governance, Risk & Compliance disciplines, including Business Continuity & Disaster Recovery (BCDR), Incident Response, Third-Party Risk Management (TPRM), SOX compliance, and technology risk management.
- Knowledge of IT risk and control frameworks, including SOX IT requirements, COSO, COBIT, NIST Cybersecurity Framework (CSF), PCAOB, and PCI-DSS standards.
- Understanding of IT General Controls (ITGCs), IT Application Controls (ITACs), User Access Reviews (UARs), Segregation of Duties (SoD), and technology governance practices.
- Experience coordinating cross-functional initiatives and building effective working relationships with business and technology stakeholders.
- Experience working with cloud environments, enterprise applications, databases, and operating systems.
- Strong organizational, analytical, and problem-solving skills with the ability to manage multiple priorities simultaneously.
- Ability to write clearly and communicate technical concepts effectively to both technical and non-technical stakeholders across all levels of the organization.
- Bachelor's degree preferred.
- 2–5 years of experience in IT Audit, Governance, Risk & Compliance, Risk Management, Compliance, Cybersecurity, or Consulting (e.g., Big 4 or equivalent).
- Relevant professional certifications such as CISA, CRISC, CISSP, or CIA are preferred.
- Positive self-starter with a strong attention to detail and a continuous improvement mindset.
Preferred Qualifications:
- Experience with Compliance Tools (e.g. Auditboard (Optro), OneTrust, Zilla Security) and productivity tools (e.g. G-Suite, Lucidchart, Smartsheets, Slack, Jira Board)
Total Rewards
Zoro’s total compensation plan includes our Zoro Incentive Plan (ZIP) that is designed to foster and reward our team members for strong performance. Total compensation will be highly competitive.
In addition to competitive compensation, Zoro offers comprehensive benefits and perks including:
- Medical, dental, vision, and life insurance plans with coverage starting on day one of employment
- Maternity support programs, nursing benefits, and up to 14 weeks paid leave for birth parents and up to 4 weeks paid leave for non-birth parents. We also support growing your family through access to adoption assistance program
- 6 free sessions each year with a licensed therapist and Wellhub portal membership to support your mental and emotional wellbeing
- At least 18 paid time off days annually for full-time employees and 6 company holidays per year
- 6% company contribution to a 401K Retirement Savings Plan each pay period, no employee contribution required
- Tuition reimbursement, student loan refinancing and access to financial counseling, education, and tools
- Charitable Gift Program - match gift to an eligible educational, cultural, community health, and human service organizations
- Employee discounts and admission to various civic and cultural institutions around Chicago
- Zoro office perks including coffee bar, beer on tap, unlimited snacks, access to the onsite gym, and incredible city skyline views
For additional information and details regarding our benefits and our parent company, W. W. Grainger, please click on the link here.
The pay range provided is not a guarantee of compensation. The range listed reflects the expected base pay for this position at the time of posting, based on the role's job grade. Actual compensation may vary depending on factors such as location, relevant experience and individual qualifications.
Our Culture
Zoro was founded in 2011 with a simple idea: make it easy for businesses to get the tools, parts, and supplies they need to keep things running. We've grown by staying curious, moving quickly, and solving everyday challenges in smart, practical ways. Backed by W.W. Grainger and inspired by our endless assortment business model, we’re on a clear path toward our next big milestone: $2 billion in revenue—and beyond.
At Zoro, we don’t just follow a playbook—we help build it. You’ll get to work on real problems with a supportive team that shares ideas freely, learns from each other, and celebrates wins together. Our culture is grounded in values that guide how we show up every day: Winning & Learning Together, Being Customer Obsessed, Being Transparent, and Taking Ownership. We don’t have all the answers, but we’re always asking good questions.
Zoro’s culture has been recognized by Fortune, Best Places to Work, and Built In Chicago—but the recognition we care about most comes from our team members, who make this place what it is.
We also know that flexibility matters. Our hybrid work model gives you space to focus and the flexibility to live your life — asking team members to be onsite at least two days a week. Our Chicago HQ (right above Ogilvie Transportation Center in the Accenture Tower) is always open and ready for connection, collaboration, or just a good cup of coffee.
At Zoro, we’re growing fast toward big aspirations — and we’re continuously excited about the new challenges we get to solve together.
We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex (including pregnancy), national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or expression, protected veteran status, or any other protected characteristic under federal, state, or local law. We are proud to be an equal opportunity workplace. We are also committed to fostering an inclusive, accessible work environment that includes both providing reasonable accommodations to individuals with disabilities during the application and hiring process as well as throughout the course of one’s employment. Should you need a reasonable accommodation during the application and selection process, including, but not limited to use of our website, any part of the application, interview, or hiring process, please advise us so that we can provide appropriate assistance.
Skills Required
- Familiarity with Governance, Risk, and Compliance disciplines, including BCDR, Incident Response, TPRM, SOX compliance, and technology risk management
- Knowledge of IT risk and control frameworks, including SOX IT requirements, COSO, COBIT, NIST Cybersecurity Framework, PCAOB, and PCI DSS
- Understanding of IT General Controls, IT Application Controls, User Access Reviews, Segregation of Duties, and technology governance practices
- Experience coordinating cross-functional initiatives and working with business and technology stakeholders
- Experience with cloud environments, enterprise applications, databases, and operating systems
- Strong organizational, analytical, and problem-solving skills with the ability to manage multiple priorities
- Ability to communicate technical concepts clearly to technical and non-technical stakeholders
- Two to five years of experience in IT Audit, GRC, Risk Management, Compliance, Cybersecurity, or Consulting
- Bachelor's degree
- Relevant certifications such as CISA, CRISC, CISSP, or CIA
- Experience with AuditBoard, OneTrust, Zilla Security, G-Suite, Lucidchart, Smartsheet, Slack, or Jira
Zoro Compensation & Benefits Highlights
-
Retirement Support — Feedback suggests retirement support is unusually strong, with a 6% employer 401(k) contribution provided even if employees do not contribute. This is consistently highlighted as a standout element of the package.
-
Healthcare Strength — Healthcare is portrayed as robust, with medical, dental, and vision coverage beginning on day one and mentions of mental-health support. Feedback suggests coverage is generally viewed as decent to good.
-
Leave & Time Off Breadth — Time off is described as solid, with at least 18 days of PTO plus paid holidays noted across employer materials. Feedback suggests this baseline is seen as a meaningful part of the package.
Zoro Insights
What We Do
Our e-commerce website has everything businesses and consumers need to make their business go, at prices that make sense. We have over 12 million products on our website (and counting) to help your business run that are shipped fast and often free. Throw in our award-winning workplace culture and you’ll find Zoro an amazing place to work and grow.
Why Work With Us
We've worked hard to foster a unique company culture built on transparency, collaboration, and innovation. We've also won a number of awards for our company culture along the way. Of course, it's not the awards that matter—it's the people. We pride ourselves on building a culture that allows our team members to bring their authentic selves to work!
Gallery
Zoro Offices
Hybrid Workspace
Employees engage in a combination of remote and on-site work.
At Zoro, we believe in balance—so we’ve made hybrid work a win-win! Team members are asked to work on-site in our office 2 days a week.





