Senior IT GRC Analyst

Posted Yesterday
Hiring Remotely in United States
Remote
Senior level
Financial Services
The Role
Leads IT governance, risk, and compliance activities, including SOC 2 readiness, audit planning and execution, policy development, control assessments, evidence gathering, remediation tracking, and regulatory research. Partners with auditors, control owners, IT leadership, and GRC team members to maintain compliance with NIST CSF and financial services regulations. Provides guidance on audit and policy matters while improving GRC processes and tooling.
Summary Generated by Built In

The Senior IT GRC Analyst leads policy development and audit execution within CMG's IT Governance, Risk, and Compliance program, with particular emphasis on CMG's upcoming SOC 2 readiness effort. This role works closely with the GRC team and the broader IT department to plan and execute audit engagements, maintain the policy framework, and manage auditor relationships. The Senior IT GRC Analyst operates with a high degree of autonomy and is expected to navigate ambiguity in a regulated environment.

 

 

ESSENTIAL DUTIES and RESPONSIBILITIES, includes the following responsibilities, but not limited to:

  • Lead CMG's SOC 2 readiness assessment, including scope definition, gap analysis, and control design, in partnership with the IT GRC Manager.
  • Serve as a point of contact during audit engagements and regulatory exams.
  • Develop, maintain, and update IT policies, standards, and procedures to align with NIST CSF and other applicable regulatory requirements.
  • Plan and execute audit activities, including scheduling, control walkthroughs, evidence gathering, and findings documentation.
  • Identify control gaps, coordinate remediation planning with control owners, tracking findings and remediation status through the risk register.
  • Provide guidance to other GRC team members and IT leadership on audit and policy matters.
  • Research regulatory and framework changes relevant to mortgage lending and financial services, and translate them into policy updates.
  • Contribute to the ongoing development and improvement of GRC processes and tooling.

 

 

REQUIRED QUALIFICATIONS:

  • Bachelor's degree in Information Technology, Cybersecurity, or a related field (equivalent experience considered).
  • 5+ years of experience in IT audit, compliance, or GRC in an enterprise IT environment.
  • Demonstrated experience managing SOC 2 audit cycles (Type I or Type II) from scoping through remediation.
  • Direct experience in financial services, mortgage lending, or related regulated industries, with working knowledge of applicable regulations (GLBA, CFPB, NYDFS).
  • Strong working knowledge of relevant IT compliance frameworks, such as NIST CSF, ISO 27001, or SOX.
  • Strong policy writing and documentation skills.
  • Ability to work independently amid ambiguity, exercising sound judgment on scope and prioritization.
  • Excellent written and verbal communication skills, with the ability to explain technical and compliance matters to varied audiences.
  • Relevant certifications preferred: CISA, CRISC, or GRCP.

 

 

SUPERVISORY RESPONSIBILITIES:

Direct Reports: N/A

 

 

PHYSICAL and ENVIRONMENTAL CONDITIONS

This role operates in an ADA compliant office environment, utilizing typical office equipment and tasks including computer work. The position may involve partial stationary positions and moving throughout the day. Flexibility to work overtime to meet project deadlines is required.

 

 

Base Compensation Information– This role is a remote position that is currently allocated for candidates within geographic regions that do not currently require base wage disclosure. The compensation range for this position will be provided upon request. (Due to their geographic location, residents of the states of CA & CO, and for NY are excluded from this role at this time.) 

Skills Required

  • Bachelor's degree in Information Technology, Cybersecurity, or a related field, or equivalent experience
  • At least 5 years of experience in IT audit, compliance, or GRC within an enterprise IT environment
  • Experience managing SOC 2 audit cycles from scoping through remediation
  • Direct experience in financial services, mortgage lending, or another regulated industry
  • Working knowledge of GLBA, CFPB, and NYDFS requirements
  • Strong knowledge of IT compliance frameworks including NIST CSF, ISO 27001, or SOX
  • Strong policy writing and documentation skills
  • Ability to work independently in ambiguous situations and exercise sound judgment
  • Excellent written and verbal communication skills
  • CISA, CRISC, or GRCP certification
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: San Ramon, CA
1,782 Employees
Year Founded: 1993

What We Do

For over 25 years, CMG Financial NMLS#1820 has delivered the personal service of a local lender, leveraging the resources of a national brand. Currently operating in all 50 states and the District of Columbia, CMG Financial branches have earned over 1200 Zillow reviews praising reliable preapprovals, ease of transaction, on-time closings, and transparency and communication throughout the mortgage process. Throughout the mortgage industry, CMG Financial is known for its innovation of product and continued investment in technology. From HomeFundIt, the down payment crowdfunding platform to the All In One Loan, the smarter way to borrow, CMG develops mortgage solutions that serve the needs of every borrower. CMG Financial holds federal agency lending approvals with HUD, VA, RHS, GNMA, FNMA and FHLMC and makes its products and services available through three distinct origination channels: Retail, Correspondent, and Wholesale Lending. Team CMG specializes in all new purchase and refinance mortgage needs and act as financial counselors to help borrowers make informed decisions. Find out what “Every Customer, Every Time. No Exceptions, No Excuses.” means to us!

Similar Jobs

DraftKings Logo DraftKings

Incident Manager

Digital Media • Gaming • Information Technology • Software • Sports • Esports • Big Data Analytics
Remote or Hybrid
Oregon, USA
6400 Employees
72K-90K Annually

DraftKings Logo DraftKings

Incident Manager

Digital Media • Gaming • Information Technology • Software • Sports • Esports • Big Data Analytics
Remote or Hybrid
Hawaii, USA
6400 Employees
72K-90K Annually

DraftKings Logo DraftKings

Reliability Engineer

Digital Media • Gaming • Information Technology • Software • Sports • Esports • Big Data Analytics
Remote or Hybrid
United States
6400 Employees
168K-210K Annually

DraftKings Logo DraftKings

Incident Manager

Digital Media • Gaming • Information Technology • Software • Sports • Esports • Big Data Analytics
Remote or Hybrid
Washington, DC, USA
6400 Employees
72K-90K Annually

Similar Companies Hiring

Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account