Lead Security Governance, Risk & Compliance Analyst

Early Warning®Chicago, IL
$116,000 - $174,000Hybrid

About The Position

This position supports the Security Governance, Risk Analytics, and Compliance function by improving the effectiveness, consistency, and scalability of security compliance activities. The role establishes repeatable operating practices for audits, assessments, evidence management, compliance obligations, and remediation activities while helping Security, Technology, Risk, Audit, and business stakeholders understand and meet applicable requirements. The position serves as a lead partner for complex compliance activities, improving evidence quality, clarifying accountability, identifying recurring process gaps, and developing practical solutions that reduce unnecessary effort while strengthening audit and assessment readiness. The role uses data, workflow improvements, automation, and cross-functional coordination to improve compliance outcomes and support the organization's broader security and risk management objectives.

Requirements

  • Education and/or experience typically obtained through completion of a bachelor's degree or equivalent practical experience.
  • Typically has 7 years of experience or demonstrated portfolio consistent with experience required of the role.
  • Relevant experience in security governance, risk and compliance, information security, technology risk, IT audit, control testing, regulatory readiness, or a comparable operational governance discipline.
  • Demonstrated understanding of control environments, evidence requirements, audit and assessment processes, issue management, and remediation tracking.
  • Experience translating security or compliance requirements into practical processes, operating procedures, or guidance for business and technology stakeholders.
  • Demonstrated program, project, or workstream management skills, including the ability to coordinate cross-functional activities with competing priorities, dependencies, and ownership.
  • Experience identifying root causes and implementing sustainable process or workflow improvements.
  • Strong written and verbal communication skills, including experience preparing process documentation, stakeholder guidance, management reporting, or executive-level summaries.
  • Demonstrated ability to build stakeholder alignment and influence outcomes without relying on direct authority.
  • Experience working with GRC, workflow, reporting, collaboration, or comparable enterprise systems.
  • Strong analytical skills and attention to evidence quality, documentation, traceability, and follow-through.

Nice To Haves

  • Experience supporting security or technology compliance within financial services, payments, banking, or another regulated or complex operating environment.
  • Familiarity with security and control frameworks or standards such as NIST, CRI, ISO 27001/27002, SOC 2, PCI DSS, FFIEC, or comparable frameworks.
  • Experience supporting customer audits, regulatory examinations, internal audits, external assessments, or security attestations.
  • Experience with issue management, risk acceptance, remediation validation, risk and control self-assessments, control testing, or policy and standards governance.
  • Experience improving compliance processes through workflow automation, reusable evidence repositories, reporting dashboards, standardized templates, or process redesign.
  • Experience with tools such as Jira, ServiceNow, GRC platforms, Confluence, SharePoint, Excel, or comparable systems.
  • Relevant professional certifications such as CISA, CRISC, CISSP, CISM, PMP, or equivalent demonstrated experience.

Responsibilities

  • Establish and improve repeatable processes for security audits, assessments, customer requests, regulatory activities, control reviews, evidence collection, and related compliance obligations.
  • Define and maintain clear intake, triage, ownership, evidence, review, escalation, and closure practices in coordination with Security stakeholders and first-line risk management partners.
  • Identify and implement workflow and automation opportunities that improve audit readiness, evidence management, compliance tracking, and operational efficiency.
  • Maintain visibility into compliance activities through appropriate GRC, workflow, collaboration, and reporting platforms, including clear ownership, due dates, status, dependencies, blockers, and closure evidence.
  • Develop reusable evidence packages, control narratives, evidence maps, templates, playbooks, checklists, and guidance for recurring compliance activities.
  • Review evidence and compliance responses for completeness, consistency, traceability, and readiness before submission to audit, assessment, regulatory, or customer stakeholders.
  • Partner with Security, Technology, and business subject matter experts to identify recurring audit and assessment issues, reduce duplicative requests, and address root causes of evidence and process gaps.
  • Monitor adherence to applicable security controls, standards, procedures, remediation commitments, and assessment outcomes; identify overdue, incomplete, or ineffective activities and facilitate appropriate escalation.
  • Coordinate findings, observations, and remediation activities by establishing clear ownership, target dates, validation requirements, supporting evidence, escalation paths, and closure criteria.
  • Maintain alignment between operational tracking, GRC records, remediation documentation, and governance or leadership reporting, as applicable.
  • Develop and report metrics related to compliance workload, cycle time, evidence quality, service-level performance, aging items, recurring requests, remediation progress, and closure readiness.
  • Analyze audit, assessment, control, issue, and compliance data to identify recurring themes, systemic process opportunities, emerging concerns, and areas requiring leadership attention.
  • Prepare clear reporting and supporting narratives for Security leadership, cross-functional governance forums, auditors, regulators, customers, and other stakeholders, as appropriate.
  • Translate compliance requirements into practical operating guidance for business and technology teams and provide support that enables stakeholders to understand requirements, ownership, expected evidence, and completion criteria.
  • Support retrospectives and continuous-improvement activities following significant audits, assessments, customer reviews, or remediation efforts.
  • Support the company's commitment to risk management and protecting the integrity, confidentiality, and availability of systems and data.

Benefits

  • Competitive medical (PPO/HDHP), dental, and vision plans as well as company contributions to your Health Savings Account (HSA) or pre-tax savings through flexible spending accounts (FSA) for commuting, health & dependent care expenses.
  • 100% Company Safe Harbor Match on your first 6% deferral immediately upon eligibility.
  • Flexible Time Off for Exempt (salaried) employees, as well as generous PTO for Non-Exempt (hourly) employees, plus 11 paid company holidays and a paid volunteer day.
  • 12 weeks of Paid Parental Leave
  • Maven Family Planning – provides support through your Parenting journey including egg freezing, fertility, adoption, surrogacy, pregnancy, postpartum, early pediatrics, and returning to work.
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service