Governance, Risk, and Compliance (GRC) Data Analyst | Technology Services

City and County of Denver•Denver, CO
•$74,276 - $98,500•Hybrid

About The Position

The City and County of Denver (CCD) approaches Governance, Risk, and Compliance (GRC) holistically ensuring that risks and vulnerabilities are evaluated not only from a system-security standpoint, but also through the lens of the end user and the application. The Governance, Risk, and Compliance Analyst position is a key stakeholder on the CCD GRC, Data Protection Team, contributing to a comprehensive program that spans vendor risk, policy governance, audit coordination, and access controls. This role is responsible for advancing CCD Technology Services' (TS) governance, risk, and compliance objectives across several interconnected areas: Vendor Risk Management — Manage the TS Vendor Risk Assessment Program, ensuring all new and existing Citywide technology vendors are evaluated through initial and annual risk assessments. Determine the scope of required reviews, coordinate with vendors and internal stakeholders, and communicate assessment conclusions, including compliance and contract-language needs, approvals, and denials. Policy & Standards Governance — Manage TS policies and standards, ensuring all Citywide technology policies are reviewed and updated annually. Advise policy stakeholders on language and, when needed, take the lead on creating new policies and standards. Audit Coordination — Serve as the primary liaison between the CCD Auditor's Office and Technology Services. Manage and coordinate external audits, assist in gathering and creating deliverables, brief TS leadership on audit status and potential findings, and advise on and at times draft responses to audit finding recommendations. Access & Controls — Periodically audit system user permissions, recommend appropriate access levels, and ensure administrative privileges are restricted to those with a documented business need. Security Awareness & Training — Determine employee training needs based on identified user behavior and risk, partner with HR/Workday Learning to provision training to applicable employees, and monitor completion with timely follow-up. Broader GRC Support — Support additional GRC activities such as approving or denying third-party file-share requests, conducting risk assessments, ensuring regulatory compliance, and contributing to initiatives such as the role-based access control project. Act as an ongoing GRC subject-matter expert and liaison for other CCD agencies, advising on best practices to reduce risk and promote regulatory compliance. Key duties, tasks, and responsibilities of this position include: Utilizing ServiceNow to manage vendor risk assessments, TS audits, policies, and third-party file-share permission requests Responding to and organizing responses to third-party risk assessment requests from across CCD Collaborating with the CCD Auditor's Office throughout audit engagements and managing external audits end to end Assisting in the collection and creation of audit deliverables and providing leadership briefings on audit status and potential findings Advising TS stakeholders on the implementation of internal controls and safeguards in response to audit findings, and provide written responses to audit recommendations Identifying and conducting risk assessments across vendors, systems, and processes Reviewing access roles and permissions, ensuring proper safeguards and validated business needs Reviewing, selecting, and managing security-awareness training material and monitoring completion Collaborating with TS teams and CCD agencies to mitigate identified risk and promote regulatory compliance

Requirements

  • 2–3 years of experience in data protection and/or governance, risk, and compliance (relevant experience may supplement education requirements)
  • Knowledge of, and experience applying, the following regulatory frameworks: U.S. Department of Commerce, National Institute of Standards and Technology (NIST) Cybersecurity and Privacy Frameworks, Payment Card Industry Data Security Standard (PCI-DSS), U.S. Department of Health and Human Services, Health Insurance Portability and Accountability Act (HIPAA)
  • Experience using Workday, OneTrust, ServiceNow, and Box platforms
  • A continuous‑improvement mindset, with the ability to evaluate processes, identify gaps, and implement effective, scalable solutions
  • Demonstrated ability to work independently, manage priorities, and drive tasks to completion with minimal supervision
  • A collaborative, relationship‑building approach, and a desire to support a culture of equity, inclusion, and continuous improvement
  • Bachelor's Degree in Information Technology or a related field based on a specific position(s).
  • Two years of experience with data protection, governance, risk assessment, and compliance with information technology systems.
  • One (1) year of the appropriate type and level of experience may be substituted for each required year of post-high school education.
  • Additional appropriate education may be substituted for the minimum experience requirements.

Nice To Haves

  • Strong foundation in governance, risk, and compliance
  • Experience in policy creation, audits, and technical writing
  • Comfortable working independently
  • Takes initiative
  • Proactively identifies opportunities to streamline and improve processes

Responsibilities

  • Manage the TS Vendor Risk Assessment Program, ensuring all new and existing Citywide technology vendors are evaluated through initial and annual risk assessments.
  • Determine the scope of required reviews, coordinate with vendors and internal stakeholders, and communicate assessment conclusions, including compliance and contract-language needs, approvals, and denials.
  • Manage TS policies and standards, ensuring all Citywide technology policies are reviewed and updated annually.
  • Advise policy stakeholders on language and, when needed, take the lead on creating new policies and standards.
  • Serve as the primary liaison between the CCD Auditor's Office and Technology Services.
  • Manage and coordinate external audits, assist in gathering and creating deliverables, brief TS leadership on audit status and potential findings, and advise on and at times draft responses to audit finding recommendations.
  • Periodically audit system user permissions, recommend appropriate access levels, and ensure administrative privileges are restricted to those with a documented business need.
  • Determine employee training needs based on identified user behavior and risk, partner with HR/Workday Learning to provision training to applicable employees, and monitor completion with timely follow-up.
  • Support additional GRC activities such as approving or denying third-party file-share requests, conducting risk assessments, ensuring regulatory compliance, and contributing to initiatives such as the role-based access control project.
  • Act as an ongoing GRC subject-matter expert and liaison for other CCD agencies, advising on best practices to reduce risk and promote regulatory compliance.
  • Utilize ServiceNow to manage vendor risk assessments, TS audits, policies, and third-party file-share permission requests.
  • Respond to and organize responses to third-party risk assessment requests from across CCD.
  • Collaborate with the CCD Auditor's Office throughout audit engagements and manage external audits end to end.
  • Assist in the collection and creation of audit deliverables and provide leadership briefings on audit status and potential findings.
  • Advise TS stakeholders on the implementation of internal controls and safeguards in response to audit findings, and provide written responses to audit recommendations.
  • Identify and conduct risk assessments across vendors, systems, and processes.
  • Review access roles and permissions, ensuring proper safeguards and validated business needs.
  • Review, select, and manage security-awareness training material and monitor completion.
  • Collaborate with TS teams and CCD agencies to mitigate identified risk and promote regulatory compliance.

Benefits

  • Competitive pay
  • Great benefits
  • A guaranteed life-long monthly pension, once vested after 5 years of service
  • 457B Retirement Plan
  • 140 hours of PTO earned within first year
  • 11 paid holidays
  • 1 personal holiday
  • 1 volunteer day per year
  • Competitive medical, dental and vision plans effective within 1 month of start date
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service