GRC Analyst

Benesch LawChicago, IL
$109,000 - $131,000Hybrid

About The Position

The Governance, Risk, and Compliance (GRC) Analyst is responsible for supporting the implementation, execution, and continuous improvement of the organization's GRC program. This role ensures that risk management, policy governance, and compliance activities align with organizational objectives, regulatory requirements, and industry best practices. This position is hybrid and has work from home flexibility. This role is perfect for the individual looking to be an essential part of a security team that focuses on supporting internal governance processes and developing policies and procedures. Join Benesch and play a pivotal role in shaping the success of our IT department.

Requirements

  • Bachelor's degree in Information Security, Cybersecurity, Information Technology, Business, or a related field, or equivalent professional experience.
  • A minimum of six years' experience is required for this position.
  • Foundational understanding of cybersecurity principles and risk management.
  • Knowledge of compliance frameworks such as ISO 27001, CIS, and NIST.
  • Strong analytical and documentation skills.
  • Excellent communication and stakeholder management abilities.
  • Detail-oriented, organized, collaborative, and proactive.
  • Ability to manage multiple priorities.
  • Able to work effectively with technical and non-technical teams.
  • Translate technical controls into business context.
  • Take ownership of assigned tasks.
  • Strong commitment to accuracy, follow-through and continuous improvement.
  • Professional presence, sound judgment and discretion in handling sensitive information.
  • Curiosity and strategic interest in legal market recognition, competitive positioning and process improvement.

Nice To Haves

  • Experience with GRC software platforms
  • CISA, CRISC, CGRC, Security+, ISO 27001 Internal Auditor, or CISM certification, whether in progress or completed
  • Experience supporting audits or risk assessments in a regulated environment

Responsibilities

  • Develops, maintains, and updates security and compliance policies, standards, and procedures.
  • Supports internal governance processes, including document lifecycle management, policy reviews, and approvals.
  • Tracks and reports on compliance with internal control frameworks and policies.
  • Leads third-party risk management activities, including vendor assessments, evidence review, and continuous monitoring.
  • Conducts and documents risk assessments across business units, systems, and processes.
  • Maintains the enterprise risk register and ensures risks are properly categorized, scored, and remediated.
  • Partners with stakeholders to identify risk treatment options and tracks remediation activities.
  • Assists with compliance efforts related to client obligations, outside counsel guidelines, and frameworks such as ISO 27001, CIS, SOC 2, NIST CSF/800-53, GDPR, HIPAA, PCI, or others relevant to the organization.
  • Collects, validates, and maintains evidence for internal/external audits.
  • Supports regulatory and certification audits by coordinating with internal teams and external auditors.
  • Monitors and reports on compliance gaps, exceptions, and corrective actions.
  • Helps develop and administer security awareness programs.
  • Supports phishing simulation campaigns and related analytics to track organizational improvement.
  • Produces regular and ad-hoc reports on risk, compliance posture, and control effectiveness.
  • Utilizes GRC tools (e.g., SIG, Archer, OneTrust, LogicGate, ZenGRC) to manage workflows and dashboards.
  • Tracks KPIs/KRIs to measure program maturity and effectiveness.

Benefits

  • Hybrid schedule
  • Career development and growth
  • Transparent and visible leadership teams
  • Diversity, equity and inclusion is celebrated
  • Full array of benefits
  • Discretionary bonus
  • Comprehensive benefits package
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service