Momentum
GRC Analyst
Dallas, Texas · Vp · Full-time
Sponsorship not specifiedDetected 27 days ago
AWSGCPAzureCybersecurityComplianceProject ManagementAuditingCadenceLeadershipCommunicationInternal Audit
About the role
- Join us in this full-time role, based in our Dallas Office at the Link: 2601 Olive Street, Dallas, TX.
- Be part of a vibrant community where amazing people, data & insights, and perpetual innovation converge to shape the future of digital commerce!
Responsibilities
- Own the internal SOC 2 Type II evidence collection process, keeping controls audit-ready year-round. Manage the audit timeline, day-to-day liaison with the external auditor, and remediation finding closure between cycles.
- Own the NIST CSF remediation roadmap: maintain the gap register, report progress to the VP and vCISO on a defined cadence, and coordinate with portfolio company IT teams to assess and close control gaps.
- Build and maintain a unified controls library mapping SOC 2 Trust Services Criteria, NIST CSF subcategories, and applicable regulatory requirements.
- Develop and maintain the AI governance framework: tool intake review, data handling risk assessment, and acceptable use policy. Evaluate AI tools proposed across the corporate entity and portfolio companies against security and compliance standards.
- Own AI-related policy documentation and track emerging regulatory requirements including the EU AI Act and NIST AI RMF.
- Build and maintain a risk register with risk-to-control mapping. Define and document formal risk tolerance and appetite in coordination with the vCISO and leadership.
- Own the third-party risk management program. Define and implement a tiered due diligence model (critical, high, medium, low) and conduct recurring reviews of critical service providers.
- Manage vendor risk assessments for tools under evaluation - SASE, CASB, DLP, AI governance tooling, and security platform consolidation. Coordinate with the Data Privacy legal team on vendors with material data processing obligations.
Requirements
- 5-7 years in GRC, security compliance, risk management, or a closely related security function.
- Solid working knowledge of NIST CSF: gap assessments, control mapping, and remediation tracking.
- Experience managing third-party and vendor risk assessments using a tiered risk model.
- Experience responding to client security questionnaires: SIG, CAIQ, or similar formats.
- Proven ability to work alongside a legal team without blurring lanes.
- Strong written communication: you can translate technical controls into clear, accurate language for clients, auditors, and executives.
- Familiarity with CASB, DLP, or cloud security posture tooling from a compliance and documentation standpoint.
- Required
- Hands-on experience owning or supporting a SOC 2 Type II audit: evidence collection, control mapping, and auditor coordination.
- Demonstrated experience building or formalizing a security policy library, not just updating existing documents.
- Clear understanding of the boundary between GRC and legal/privacy functions. Proven ability to work alongside a legal team without blurring lanes.
- Disciplined project management: you own timelines, follow up without being asked, and don't let things fall through.
- Active daily use of AI and automation. We operate at 100% internal AI adoption. Non-negotiable.
- GRC platforms: OneTrust, Drata, Vanta, Whistic, or similar.
- Security awareness platforms: KnowBe4 or equivalent.
Nice to have
- Active daily use of AI and automation.
- We operate at 100% internal AI adoption.
- Preferred Technical Experience
- Private equity, holding company, or multi-entity compliance environment experience strongly preferred.
Skills
- the evidence, the frameworks, the audit coordination, and the vendor risk program.
- ITGC working knowledge across identity (Okta), SaaS (Google Workspace), cloud (AWS, GCP, Azure), and endpoint (CrowdStrike).
- BIA methodology, RTO/RPO definition, and tabletop exercise facilitation.
Compensation
- Prepare the organization for bi-annual NIST CSF assessments, ensuring controls are documented and defensible.
- Build and maintain annual policy attestation workflows across all employees. Bridge with the Data Privacy legal team on overlapping areas: data classification, retention, and incident notification.
Benefits
- We are pleased to offer a comprehensive total rewards package designed to provide protection, peace of mind, and a focus on overall well-being while helping our people plan for the future.
- In addition to the base salary, candidates may be eligible to receive a discretionary annual bonus, determined based on both the company's business performance and individual contributions.
- Actual compensation will be determined by role, level, and location, considering additional factors such as job-related skills, experience, and relevant education or training.
Company info
- At Momentum, we prioritize the well-being of the whole individual.
- We are committed to supporting our people in every moment that matters on their journey with us!
Apply directly at Momentum →Create a free account for alerts like thisView Momentum immigration profile
This listing is sourced directly from Momentum's careers page and normalized into a canonical job model.