GRC Analyst

Posted 7 Hours Ago
Be an Early Applicant
Hiring Remotely in United States
Remote
110K-120K Annually
Senior level
Fintech • News + Entertainment • Software
The Role
Manage third-party vendor risk program, complete and respond to security questionnaires, support compliance automation (Drata/Andromeda), collect SOC 1/2 audit evidence, maintain security policies and controls, monitor audit readiness, advise stakeholders on remediation, and report risks to leadership.
Summary Generated by Built In

About Us

At Cast & Crew, we’ve empowered creativity and supported the global entertainment industry for decades. Together with our family of brands - Backstage, CAPS, Checks & Balances, Final Draft, Media Services, Sargent-Disc, and The TEAM Companies – we operate as a combined entertainment technology and services provider offering industry standard screenwriting accounting software, digital payroll products, data & reporting, and a host of creative tools.  The industry continues to move faster than ever, and the need for our expertise, our technology, and our people has never been greater.  We are a production’s best ally every step of the way. #OneCastOneCrew

Position Overview:

The GRC Analyst supports the Information Security Office by managing third-party vendor risk, processing security questionnaires, and assisting with audit and compliance activities across the enterprise. This role is well-suited for someone with a strong compliance background who is looking to grow within information security. The ideal candidate is detail-oriented, organized, and experienced working with compliance frameworks, audit processes, and GRC tools such as Drata or similar platforms. A willingness to learn security concepts and stay current on evolving practices is essential.

Essential Functions

  • Managing the end-to-end third-party vendor risk management program, including onboarding assessments, periodic reviews, and ongoing monitoring of vendor security posture.
  • Supporting an internal ISRM program focused on uncovering cybersecurity risk and adding it to a risk register for prioritization and acceptance and ownership or remediation
  • Completing and responding to inbound security questionnaires (e.g., SIG, CAIQ, custom questionnaires) from clients and partners in a timely and accurate manner.
  • Coordinating information gathering and interviewing of internal stakeholders to support third-party security questionnaire responses.
  • Supporting and maintaining the organization's compliance automation platforms (e.g., Drata and Andromeda), including evidence collection, control mapping, and readiness tracking.
  • Supporting SOC 1 Type 2 and SOC 2 Type 2 audits, including evidence collection, auditor coordination, and remediation of identified gaps.
  • Developing, maintaining, and improving security documentation, policies, standards, procedures, and runbooks.
  • Monitoring and reporting on internal control effectiveness and audit readiness posture.
  • Advising internal lines of business, IT partners, and third parties on how to remediate security gaps identified through assessments or audits.
  • Understanding applicable regulations, guidelines, and industry best practices to manage risk and ensure compliance.
  • Drafting and presenting risk reports and proposals to executive leadership and senior staff.
  • Performing other duties as directed.

Qualifications:

The following certifications are a plus, but are not expected at the time of hire:

  • CISA or CISM (compliance/audit-focused; strongly relevant to this role)
  • CRISC (risk and controls focus)
  • CISSP, GIAC/GSEC, or vendor certifications (AWS/Azure)

Requirements:

5+ years of experience in compliance, audit, GRC, or a related field, with exposure to information security concepts. Equivalent experience in risk management, regulatory compliance, or internal audit will be considered. Candidates should have working knowledge of the following:

  • Compliance frameworks, audit processes, or risk management programs
  • SOC 1 or SOC 2 audit support or audit evidence collection (direct audit experience a plus)
  • Development or maintenance of policies, procedures, and compliance documentation
  • Third-party or vendor risk processes (experience with formal TPRM programs a plus)
  • GRC or compliance automation tools (e.g., Drata, Andromeda, or similar platforms)

Communications:

  • Excellent oral communication skills and comfortable in group or small team settings
  • Excellent written communication skills
  • Ability to take highly technical material and present/communicate it to a non-technical audience

Relationship Building:

  • Builds excellent working relations with all IT colleagues and users, works effectively with department and executive management, and maintains a professional relationship with outside clients and vendors

Planning, Organizing, Prioritizing, Delivering:

  • Exhibits mature organization and time management skills
  • Excellent problem-solving skills
  • Effectively planning and organizing daily work following priorities set by the Risk Manager
  • Demonstrates strong follow-up and follow-through skills in ensuring timely completion of projects
  • Self-starter who actively takes responsibility to resolve issues but also knows when to ask questions to avoid major delays in delivery of work product

Knowledge of:

  • SOC 1 Type 2 and SOC 2 Type 2 audit processes and control frameworks
  • GRC and compliance automation tools, with preference for Drata
  • Security questionnaire frameworks (e.g., SIG, CAIQ, NIST) and third-party risk methodologies
  • Evidence collection, reporting, and security documentation best practices

Skill In:

  • Coordinating SOC audit activities, evidence collection, and auditor communication
  • Working with compliance frameworks such as NIST CSF, NIST 800-53, or ISO/IEC 27001 (familiarity sufficient; deep expertise not required)
  • Completing or supporting security questionnaire responses (SIG, CAIQ, or similar)
  • Writing clear, well-organized compliance documentation and communicating requirements across teams

Physical Demands:

SEDENTARY - Exerts up to 30 lbs. of force occasionally and/or a negligible amount of force frequently or constantly to lift, carry, push, or pull. Involves sitting most of the time but may involve walking or standing for brief periods of time.

Benefits 

Cast & Crew provides a comprehensive package of employee benefits including: Medical, Dental, Vision, PTO, health and wellness programs, employee discounts, and more! Note: Cast & Crew benefits are subject to eligibility requirements.

Cast & Crew is an equal opportunity employer committed to hiring a diverse workforce and sustaining an inclusive culture. It is our policy to provide equal employment opportunities to all individuals based on job-related qualifications and ability to perform a job, without regard to age, gender, gender identity, sexual orientation, race, color, religion, creed, national origin, disability, genetic information, veteran status, citizenship or marital status, and to maintain a non-discriminatory environment free from intimidation, harassment or bias based upon these grounds.

CA residents
Your personal information may be collected in connection with certain services provided by Cast & Crew or its affiliated companies.  A summary of your California privacy rights can be found at: https://www.castandcrew.com/privacy-policy/

Compensation is commensurate with various factors including, but not limited to, relevant experience, qualifications, skills, training, licensure, certifications, geographic cost of labor, and other business and organizational needs. Compensation range for candidates in other locations may differ based on the cost of labor in that location. The compensation range for this position is: $110,000.00 - $120,000.00 per year.

Skills Required

  • 5+ years of experience in compliance, audit, GRC, or related field (risk management, regulatory compliance, or internal audit considered)
  • Working knowledge of compliance frameworks, audit processes, or risk management programs
  • SOC 1 or SOC 2 audit support and audit evidence collection (SOC 1 Type 2 and SOC 2 Type 2 experience)
  • Development or maintenance of policies, procedures, compliance documentation, and runbooks
  • Third-party/vendor risk processes and TPRM program experience (onboarding assessments, periodic reviews, monitoring)
  • Experience with GRC or compliance automation tools (e.g., Drata, Andromeda, or similar platforms)
  • Experience completing or supporting security questionnaire responses (SIG, CAIQ, custom questionnaires, NIST)
  • Evidence collection, control mapping, and readiness tracking for compliance automation platforms
  • Excellent oral and written communication; ability to present technical material to non-technical audiences
  • Certifications such as CISA, CISM, CRISC, CISSP, GIAC/GSEC, or vendor certs (AWS/Azure)
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Chicago, IL
151 Employees
Year Founded: 2001

What We Do

There’s nothing more exciting than a live event, and there’s no better way to reach an audience than with a well-made commercial. With our modern solutions and responsive approach to customer success, CAPS is here to simplify productions, no matter what our customers’ goals are. CAPS joined the Cast & Crew family in 2016 and continues to provide forward-thinking workflow solutions to the Commercial, Music Tour, and Live Event industries. Our passion for thrilling experiences is matched only by our expertise in helping to make them happen. From understanding tax incentives and workers' compensation to payroll solutions and productivity enhancements, we’re here to help, every step of the way. In the ever-evolving arena of commercials, live performances, exhibitions, and venues, we understand how to navigate the unique landscape. Our wide breadth of experience is complimented by our specialized knowledge base, industry expertise, and tailored software. These tools help us deliver the personalized service our customers need.

Similar Jobs

Cast & Crew LLC Logo Cast & Crew LLC

GRC Analyst

Digital Media • Events • News + Entertainment
Remote
United States
1079 Employees
110K-120K Annually
In-Office or Remote
Chicago, IL, USA
381 Employees
75K-80K Annually
Remote
United States
833 Employees

Vercel Logo Vercel

GRC Analyst

Artificial Intelligence • Cloud • Software
Easy Apply
Remote or Hybrid
United States
134K-202K Annually

Similar Companies Hiring

Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Kepler  Thumbnail
Fintech • Software
New York, New York
6 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account