Momentum

Momentum

GRC Analyst

Dallas, Texas · Vp · Full-time

Sponsorship not specifiedDetected 27 days ago
AWSGCPAzureCybersecurityComplianceProject ManagementAuditingCadenceLeadershipCommunicationInternal Audit

About the role

  • Join us in this full-time role, based in our Dallas Office at the Link: 2601 Olive Street, Dallas, TX.
  • Be part of a vibrant community where amazing people, data & insights, and perpetual innovation converge to shape the future of digital commerce!

Responsibilities

  • Own the internal SOC 2 Type II evidence collection process, keeping controls audit-ready year-round. Manage the audit timeline, day-to-day liaison with the external auditor, and remediation finding closure between cycles.
  • Own the NIST CSF remediation roadmap: maintain the gap register, report progress to the VP and vCISO on a defined cadence, and coordinate with portfolio company IT teams to assess and close control gaps.
  • Build and maintain a unified controls library mapping SOC 2 Trust Services Criteria, NIST CSF subcategories, and applicable regulatory requirements.
  • Develop and maintain the AI governance framework: tool intake review, data handling risk assessment, and acceptable use policy. Evaluate AI tools proposed across the corporate entity and portfolio companies against security and compliance standards.
  • Own AI-related policy documentation and track emerging regulatory requirements including the EU AI Act and NIST AI RMF.
  • Build and maintain a risk register with risk-to-control mapping. Define and document formal risk tolerance and appetite in coordination with the vCISO and leadership.
  • Own the third-party risk management program. Define and implement a tiered due diligence model (critical, high, medium, low) and conduct recurring reviews of critical service providers.
  • Manage vendor risk assessments for tools under evaluation - SASE, CASB, DLP, AI governance tooling, and security platform consolidation. Coordinate with the Data Privacy legal team on vendors with material data processing obligations.

Requirements

  • 5-7 years in GRC, security compliance, risk management, or a closely related security function.
  • Solid working knowledge of NIST CSF: gap assessments, control mapping, and remediation tracking.
  • Experience managing third-party and vendor risk assessments using a tiered risk model.
  • Experience responding to client security questionnaires: SIG, CAIQ, or similar formats.
  • Proven ability to work alongside a legal team without blurring lanes.
  • Strong written communication: you can translate technical controls into clear, accurate language for clients, auditors, and executives.
  • Familiarity with CASB, DLP, or cloud security posture tooling from a compliance and documentation standpoint.
  • Required
  • Hands-on experience owning or supporting a SOC 2 Type II audit: evidence collection, control mapping, and auditor coordination.
  • Demonstrated experience building or formalizing a security policy library, not just updating existing documents.
  • Clear understanding of the boundary between GRC and legal/privacy functions. Proven ability to work alongside a legal team without blurring lanes.
  • Disciplined project management: you own timelines, follow up without being asked, and don't let things fall through.
  • Active daily use of AI and automation. We operate at 100% internal AI adoption. Non-negotiable.
  • GRC platforms: OneTrust, Drata, Vanta, Whistic, or similar.
  • Security awareness platforms: KnowBe4 or equivalent.

Nice to have

  • Active daily use of AI and automation.
  • We operate at 100% internal AI adoption.
  • Preferred Technical Experience
  • Private equity, holding company, or multi-entity compliance environment experience strongly preferred.

Skills

  • the evidence, the frameworks, the audit coordination, and the vendor risk program.
  • ITGC working knowledge across identity (Okta), SaaS (Google Workspace), cloud (AWS, GCP, Azure), and endpoint (CrowdStrike).
  • BIA methodology, RTO/RPO definition, and tabletop exercise facilitation.

Compensation

  • Prepare the organization for bi-annual NIST CSF assessments, ensuring controls are documented and defensible.
  • Build and maintain annual policy attestation workflows across all employees. Bridge with the Data Privacy legal team on overlapping areas: data classification, retention, and incident notification.

Benefits

  • We are pleased to offer a comprehensive total rewards package designed to provide protection, peace of mind, and a focus on overall well-being while helping our people plan for the future.
  • In addition to the base salary, candidates may be eligible to receive a discretionary annual bonus, determined based on both the company's business performance and individual contributions.
  • Actual compensation will be determined by role, level, and location, considering additional factors such as job-related skills, experience, and relevant education or training.

Company info

  • At Momentum, we prioritize the well-being of the whole individual.
  • We are committed to supporting our people in every moment that matters on their journey with us!

This listing is sourced directly from Momentum's careers page and normalized into a canonical job model.