GRC Analyst (Third-Party & Client Questionnaire Management)

Remote Full-time
Job Title: GRC Analyst (Third-Party & Client Questionnaire Management)

Job Summary:
The GRC Analyst – Third-Party & Client Questionnaire Management is responsible for supporting and managing security, risk, compliance, and due diligence questionnaires received from clients, prospects, vendors, and business partners. This role serves as a subject matter resource for industry-standard compliance frameworks and plays a critical role in ensuring responses are accurate, consistent, auditable, and aligned with the organization’s approved control language and evidence.
The position emphasizes GRC platform enablement, automation, quality assurance, and continuous improvement to streamline questionnaire response processes, reduce cycle times, and support the organization’s overall risk and compliance posture.

Essential Functions:
Questionnaire Management & Stakeholder Coordination
Support the completion of security, risk, compliance, and due diligence questionnaires from clients, prospects, vendors, and partners.
Serve as a subject matter resource for responding to questionnaires related to HITRUST, PCI DSS, SOC 2, NCQA, and general security and privacy controls.
Coordinate with internal stakeholders, including IT, Security, Compliance, Legal, and Operations, to validate questionnaire responses and obtain supporting documentation or evidence.
Ensure all responses are accurate, consistent, current, and aligned with approved control language, policies, and audit artifacts.
Manage timelines and prioritize questionnaire requests to meet internal and external deadlines.

GRC Platform Enablement & Automation
Configure, maintain, and enhance questionnaire libraries within the GRC platform to support automated and semi-automated responses.
Map questionnaire questions to existing controls, policies, procedures, and evidence within the GRC system to enable reuse, consistency, and standardization.
Continuously enhance automation rules and response logic to reduce manual effort and improve response turnaround time.
Review system-generated responses for accuracy, completeness, and appropriateness prior to submission.
Maintain version control and approval workflows for standardized questionnaire responses.
Track questionnaire requests, response status, and performance metrics through the GRC tool.

Quality Assurance & Continuous Improvement
Perform periodic reviews of standardized questionnaire content to ensure alignment with current control posture, certifications, and audit outcomes.
Update approved responses following control changes, audit findings, framework updates, or regulatory changes.
Identify recurring questions, inefficiencies, or content gaps and proactively address them through control enhancements, documentation updates, or process improvements.
Provide reporting and metrics to leadership on questionnaire volume, turnaround time, automation effectiveness, and emerging risk trends.
Support continuous improvement initiatives related to third-party risk management, client assurance, and compliance operations.

Minimum Requirements:
Specific Job Skills:
Minimum of 2 years of experience in Governance, Risk, and Compliance (GRC), information security, third-party risk management, or compliance operations.
Demonstrated experience completing and managing security, risk, compliance, and due diligence questionnaires for clients, prospects, vendors, or partners.
Working knowledge of common compliance and assurance frameworks, including HITRUST, SOC 2, PCI DSS, NCQA, and general security and privacy control frameworks.
Experience coordinating with cross-functional stakeholders (e.g., IT, Security, Compliance, Legal, Operations) to validate responses and obtain supporting evidence.
Hands-on experience using a GRC platform to manage controls, evidence, workflows, and questionnaire responses.
Ability to ensure accuracy, consistency, and version control of standardized responses and supporting documentation.
Strong written communication skills with the ability to clearly articulate technical and control-related concepts to internal and external audiences.
Strong organizational skills and the ability to manage multiple questionnaire requests and deadlines simultaneously.
Proficiency with standard business tools, including Microsoft Office or Google Workspace.
Education: Bachelor’s degree in Information Security, Risk Management, Business, Information Systems, or a related field, or equivalent professional experience.
Experience: 2–5 years of experience in GRC, information security, compliance, risk management, or third-party risk management.
Supervision: N/A
Certifications: N/A
Language Skills:
Ability to read, analyze and interpret general business periodicals, professional journals, technical procedures or governmental regulations. Ability to write reports, business correspondence and procedure manuals. Ability to effectively present information and respond to questions from a variety of both internal and external sources.

Physical Capabilities: Standard categories
The physical capabilities described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

While performing the duties of this job, the employee is regularly required to sit; use hands to finger, handle, or feel; reach with hands and arms; and talk or hear. The employee is occasionally required to stand and walk. The employee must occasionally lift and/or move up to 10 pounds. Specific vision abilities required by this job include close vision, distance vision, color vision, peripheral vision, depth perception, and ability to adjust focus.

RevSpring is an equal opportunity employer. All applicants will be considered for employment without attention to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran or disability status.

Note: This Job Description may not describe all of the job responsibilities and standards assigned to this position. The duties may change from time to time. RevSpring does not discriminate against any group in hiring or employment practices. Nothing in this job description constitutes a contract for employment.

Apply tot his job

Apply To this Job
Apply Now

Similar Opportunities

Experienced Registered Behavior Technician for In-Home ABA Therapy - Atlanta, GA

Remote Full-time

Immediate Hiring: Experienced Registered Behavioral Technician (RBT) for Clinic-Based ABA Therapy Services

Remote Full-time

Experienced Registered Behavioral Technician (RBT) - ABA Therapy for Children with Autism Spectrum Disorder

Remote Full-time

Experienced Registered Nurse - Telehealth: Providing Remote Care Coordination and Patient Support

Remote Full-time

Experienced Substitute Teacher for Riverside County Schools - Join Scoot Education's Innovative Team

Remote Full-time

Experienced Substitute Teacher for San Bernardino County - Flexible Schedules & Competitive Pay

Remote Full-time

Experienced School Year Instructional Coach for High-Dosage Tutoring Programs in Edgewater Park, NJ

Remote Full-time

Experienced School Year Tutor for K-8 Students in Math and Literacy - Mickleton, NJ

Remote Full-time

Experienced Secondary Social Studies Teacher for Kansas - Flexible Hybrid Remote Arrangement

Remote Full-time

USPS Office Helper

Remote Full-time

Legal Assistant (Entry Level) - Remote

Remote Full-time

**Experienced Customer Success Manager (Contract) – Drive Business Growth and Customer Satisfaction at arenaflex**

Remote Full-time

Experienced Customer Service Advocate II – Remote Health Insurance Support and Education Specialist

Remote Full-time

Experienced Data Entry Consultant for Global Equity Management – Remote Work Opportunity with Competitive Hourly Rate

Remote Full-time

Head of Regulatory Compliance & Senior Risk Manager

Remote Full-time

Overnight Work-from-Home Jobs - Part-Time, Earn $25-$35/Hour

Remote Full-time

Experienced Full Time Live Chat Agent for Customer Support and Service – Remote Work Opportunity with blithequark

Remote Full-time

Experienced Part-Time Operations Assistant for Christian Churches and Faith-Based Non-Profits – 20-29 Hours Per Week, Remote Work Arrangement

Remote Full-time

**Experienced Full Stack Data Entry Clerk / Administrative Assistant – Remote Opportunity at blithequark**

Remote Full-time

Urgent Hiring Travel HVAC Technician II_ 100% Remote

Remote Full-time
← Back to Home