GRC Analyst

Posted 10 Days Ago
Be an Early Applicant
Nashville, TN
In-Office
Senior level
Legal Tech
The Role
The GRC Analyst will manage vendor risk, ensure compliance with standards like ISO 27001, support audits, and maintain security policies.
Summary Generated by Built In
Nashville, TennesseeJob Description

Pillsbury Winthrop Shaw Pittman LLP is seeking a strategic and detail-oriented GRC (Governance, Risk & Compliance) Analyst to strengthen and scale our Governance, Risk, and Compliance (GRC) capabilities. This role is an integral part of the GRC team, with a strong emphasis on Vendor Risk Management, client trust, and compliance with ISO 27001 and related frameworks. You will support firmwide risk reduction efforts and lead initiatives that safeguard sensitive data while enabling business operations and client service delivery.

 

Responsibilities:

Vendor Risk Management

  • Lead the vendor security review process, including intake, risk assessment, documentation, and re-evaluation cycles.

  • Collaborate with IT and Legal to embed security and privacy requirements into contracts and onboarding workflows.

  • Maintain the vendor inventory and risk classification system; track remediation items and expiration of security attestations (SOC 2, ISO 27001, etc.).

  • Assess cloud platforms, SaaS tools, and third-party services against security, compliance, and privacy requirements.

 

Client Trust & Engagement

  • Coordinate responses to client security assessments, due diligence requests, and audits.

  • Coordinate with attorneys, business development, and compliance teams to support contractual commitments.

  • Maintain a centralized repository of audit evidence and standard responses using tools such as Loopio.

ISMS & Compliance Operations

  • Support the day-to-day management of our ISO 27001-certified ISMS, including control implementation and documentation.

  • Assist in preparation for surveillance and recertification audits and maintain alignment with ISO 27001:2022 control requirements.

  • Track risk treatment plans, control testing, and internal audit findings.

 

Policy & Control Governance

  • Draft, update, and socialize firmwide security and privacy policies.

  • Maintain a control library mapped across multiple frameworks including ISO 27001, NIST 800-171, CMMC, and client-specific standards.

  • Support the intake and processing of exceptions to security policies, ensuring proper documentation and leadership awareness.

 

Risk Monitoring & Incident Response Support

  • Assist with maintaining the risk register, including identification, analysis, and tracking of risks and mitigations.

  • Coordinate with internal teams during security incidents to ensure proper documentation, containment, and reporting.

Security Awareness & Training

  • Administer employee training programs including mandatory awareness training and role-specific modules.

  • Coordinate phishing simulations and follow-up education for at-risk users.

  • Partner with Marketing and IT to drive behavior change through campaigns, posters, and communication.

Program Enablement & Tooling

  • Maintain and optimize the GRC toolset (e.g., UpGuard, KnowBe4, Loopio).

  • Drive process improvements in risk assessments, audits, and reporting dashboards.

  • Support annual penetration testing coordination and track remediation progress.

Required Education, Knowledge & Experience 

  • Bachelor’s degree in information security, Risk Management, or a related field.

  • 5+ years of experience in security governance, compliance, or vendor risk management roles (legal or professional services industry preferred).

  • Proven experience conducting vendor security assessments and managing related compliance workflows.

  • Deep understanding of ISO 27001 and common security/privacy frameworks (NIST, SOC 2, CMMC, GDPR, etc.).

  • Strong writing, communication, and organizational skills.

  • Experience with GRC platforms and vendor risk tools.

  • Certifications such as ISO 27001 Lead Implementer, Security+ or CISM are a plus.

Physical Requirements 

  • Ability to sit and stand for extended periods. 

  • Ability to lift up to 20 pounds. 

Pillsbury Winthrop Shaw Pittman LLP is an Equal Opportunity Employer.

If you require an accommodation in order to apply for a position, please contact us at [email protected].

Top Skills

Cmmc
Gdpr
Iso 27001
Knowbe4
Loopio
Nist
Soc 2
Upguard
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
New York,, NY
1,896 Employees

What We Do

Pillsbury Winthrop Shaw Pittman LLP is an international law firm with a particular focus on the technology & media, energy, financial services, and real estate & construction sectors. Recognized by legal research firm BTI Consulting as one of the top 20 firms for client service, Pillsbury and its lawyers are highly regarded for their forward-thinking approach, their enthusiasm for collaborating across disciplines and their authoritative commercial awareness. To learn more, visit pillsburylaw.com.

To join the Pillsbury Network LinkedIn group for current and alumni attorneys and staff, go to http://www.linkedin.com/groups?gid=1043837

Comment policy for this page:
We reserve the right to remove any post that we deem offensive, inappropriate, or irrelevant to the purpose of this site.

Similar Jobs

Synovus Logo Synovus

Business Analyst

Fintech • Payments • Financial Services
In-Office
7 Locations
4707 Employees

Bevi Logo Bevi

Technical Partner Manager

Greentech • Hardware • Healthtech • Internet of Things
Easy Apply
Remote or Hybrid
United States
227 Employees
85K-104K Annually

Sprout Social Logo Sprout Social

Influencer and Creator Manager

Marketing Tech • Social Media • Software • Analytics • Business Intelligence
Easy Apply
Remote or Hybrid
US
1400 Employees
101K-139K Annually

CrowdStrike Logo CrowdStrike

Consultant

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
USA
10000 Employees
140K-195K Annually

Similar Companies Hiring

Atticus Thumbnail
Social Impact • Legal Tech • Insurance
Los Angeles, CA
210 Employees
Fulcrum GT Thumbnail
Software • Legal Tech • Cloud
Hoffman Estates, Illinois
501 Employees
Eve Thumbnail
Software • Legal Tech • Generative AI
San Mateo, CA
87 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account