Governance, Risk & Compliance (GRC) Analyst

Frazier & DeeterAtlanta, GA
Hybrid

About The Position

As Frazier & Deeter continues to expand its technology capabilities and strengthen its security posture, we are seeking a Governance, Risk & Compliance (GRC) Analyst to support critical governance, risk management, compliance, and audit readiness initiatives. This role is ideal for a detail-oriented professional who enjoys building structure, managing risk, and partnering across the organization to help ensure compliance with regulatory, security, and business requirements. The GRC Analyst will play a key role in supporting the firm's commitment to protecting client information, managing third-party risk, and maintaining strong governance practices.

Requirements

  • 2+ years of experience in governance, risk and compliance, information security compliance, risk management, audit, vendor risk management, or IT governance.
  • Strong documentation, organization, evidence management, and follow-up skills.
  • Understanding of access reviews, vendor oversight, policy governance, compliance reporting, and audit readiness activities.
  • Strong written communication skills and ability to coordinate with stakeholders across technology, legal, procurement, audit, and business teams.

Nice To Haves

  • Experience reviewing SOC 1 reports, SOC 2 Type II reports, ISO 27001 certifications, security questionnaires, risk assessments, or compliance frameworks preferred.
  • Preferred certifications may include CRISC, CISA, CGRC, Security+, ISO 27001 Lead Auditor / Implementer, or Certified Third-Party Risk Professional.

Responsibilities

  • Administer recurring governance, risk, compliance, vendor oversight, audit readiness, and access governance activities.
  • Coordinate quarterly user access reviews, certification activities, evidence collection, and follow-up on overdue or unresolved access items.
  • Support SOC 2 Type II readiness by organizing control evidence, documentation, policy artifacts, remediation tracking, and audit support materials.
  • Review and track vendor compliance documentation, including SOC reports, ISO certifications, security questionnaires, and related due diligence artifacts.
  • Maintain vendor risk records, enterprise risk documentation, remediation tracking, governance reporting, and compliance documentation repositories.
  • Support acquisition integration by helping ensure retained tools, vendors, access models, and compliance obligations are reviewed and documented.
  • Partner with Security Leadership, Technology Operations, Legal, Procurement, Internal Audit / SOQM, and business stakeholders on governance activities.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service