Skip to content

Open nowPosted today

IT GRC Lead Analyst

Core Specialty Insurance Holdings, Inc.61 open roles

Where
Cincinnati, OH
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowIT GRC Lead AnalystCore Specialty Insurance Holdings, Inc. · Cincinnati, OH
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Core Specialty Insurance Holdings, Inc.'s own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.2% of postings close within 7 days. Measured by our own scanner across the market. Core Specialty Insurance Holdings, Inc. postings stay open a median of 29 days.

Share of postings closed within
  1. 1.8%1 day
  2. 3.6%3 days
  3. 8.2%7 days
  4. 15.2%14 days
  5. 34.0%30 days
This job: posted today

Core Specialty Insurance Holdings, Inc. median: 29 days open

The posting

-

IT GRC Lead Analyst reports to the AVP of IT Compliance and is responsible for leading governance, risk, and compliance activities across the IT organization. This role supports the design, execution, and ongoing maturity of the IT Governance, Risk, and Compliance (GRC) program by helping ensure IT policies, standards, controls, risks, and compliance activities align with regulatory requirements, audit expectations, enterprise risk objectives, and recognized frameworks such as SOX, NYDFS, COBIT, NIST, and ISO 27001.

The IT GRC Lead Analyst serves as a key partner to IT leadership, control owners, cybersecurity, internal audit, external auditors, compliance, and enterprise risk teams. This role leads activities across IT governance, IT risk management, and IT compliance, including control monitoring, risk assessments, audit readiness, issue remediation, policy governance, framework alignment, reporting, and continuous improvement.

Key Accountabilities/Deliverables:

  • Lead and directly execute day-to-day IT GRC activities across IT governance, IT risk, and IT compliance under the direction of the AVP of IT Compliance.
  • Support the execution and maturity of the IT GRC program by both coordinating team activities and personally performing key deliverables, including risk assessments, control reviews, evidence validation, audit support, and remediation tracking.
  • Lead and perform IT governance activities, including policy, standard, and procedure reviews; control ownership documentation; framework mapping; exception tracking; approval evidence; and governance reporting.
  • Conduct IT risk assessments, including identifying risks, evaluating control design and operating effectiveness, documenting findings, assigning risk ratings, recommending remediation actions, and tracking issues through closure.
  • Perform IT compliance monitoring activities, including control testing, evidence review, issue identification, remediation tracking, and validation of corrective actions.
  • Coordinate and actively support audit readiness efforts by managing evidence requests, preparing control owners, reviewing documentation, tracking audit deliverables, and responding to internal and external auditor requests.
  • Prepare and maintain IT GRC artifacts, including risk registers, control matrices, control narratives, testing records, audit artifacts, remediation trackers, policy inventories, issue logs, and governance dashboards.
  • Monitor, analyze, and report on IT GRC KPIs, KRIs, audit issues, control gaps, policy exceptions, remediation progress, overdue items, and emerging areas of concern.
  • Partner directly with IT control owners to strengthen control design, improve process documentation, resolve control gaps, and support sustainable remediation of findings.
  • Serve as a key working liaison between IT, cybersecurity, internal audit, external audit, enterprise risk, compliance, legal, control owners, and business stakeholders on GRC-related activities.
  • Provide hands-on guidance, coaching, task coordination, and quality review for IT GRC analysts, including reviewing evidence, workpapers, risk assessments, status updates, and remediation documentation.
  • Identify and implement improvements to IT GRC processes, reporting, evidence collection, governance workflows, control monitoring, and audit readiness practices.
  • Escalate significant risks, control gaps, overdue remediation items, audit concerns, and governance issues to the AVP of IT Compliance in a timely manner.
  • Support IT compliance and governance awareness by helping communicate policy expectations, control responsibilities, risk obligations, and audit readiness requirements across IT.

Technical Knowledge and Understanding:

  • Strong understanding of IT governance, IT risk management, and IT compliance principles, including how policies, standards, risks, controls, and evidence support regulatory, audit, and business requirements.
  • Working knowledge of key frameworks, standards, and regulations such as SOX, NYDFS Cybersecurity Regulation, COBIT, NIST CSF, ISO 27001, COSO, HIPAA, and other applicable requirements.
  • Strong understanding of IT General Controls, including access management, privileged access, change management, computer operations, backup and recovery, incident management, system development lifecycle, and third-party technology controls.
  • Hands-on knowledge of IT control testing practices, including test planning, evidence review, control performance validation, issue documentation, remediation tracking, and management reporting.
  • Knowledge of IT governance practices, including policy and standard lifecycle management, control ownership, approval workflows, exceptions, framework mapping, document repositories, and governance dashboards.
  • Ability to interpret regulatory, framework, and control requirements and translate them into practical testing procedures, evidence requests, governance activities, risk assessments, and remediation actions.
  • Understanding of cybersecurity and technology risk areas, including identity and access management, vulnerability management, endpoint security, data protection, logging and monitoring, cloud controls, business continuity, disaster recovery, and third-party risk.
  • Strong analytical, documentation, communication, stakeholder management, and leadership skills, with the ability to explain risk, control, and compliance matters to both technical and non-technical stakeholders.
  • Ability to lead workstreams while also performing hands-on execution, including reviewing evidence, preparing work papers, documenting findings, tracking remediation, and preparing status reporting.

Requirements:

Applicants must be authorized to work for any employer in the U.S. We are unable to sponsor or take over work authorization sponsorship now or in the future for this position.

  • Bachelor's degree in Information Systems, Cybersecurity, Risk Management, Information Assurance, Business Administration, or related field; or equivalent experience.
  • 5+ years of experience in IT Governance, Risk Management, Compliance, IT Audit, Cybersecurity Governance, Internal Controls, or a related technology risk discipline.
  • Demonstrated experience leading or coordinating IT compliance programs, control monitoring activities, risk assessments, governance initiatives, audit engagements, and remediation efforts.
  • Strong understanding of governance frameworks, risk management methodologies, internal control concepts, compliance monitoring practices, and issue management processes.
  • Experience supporting compliance with regulatory and industry requirements including SOX, NYDFS, HIPAA, ISO 27001, NIST CSF, COBIT, COSO, privacy regulations, or similar frameworks.
  • Experience developing, maintaining, and interpreting IT policies, standards, procedures, control documentation, and governance artifacts.
  • Experience performing or overseeing risk assessments, compliance reviews, control evaluations, certification activities, and control attestation processes.
  • Experience supporting external audits, internal audits, regulatory examinations, customer due diligence activities, and management responses.
  • Experience preparing executive reporting, dashboards, metrics, KPIs, KRIs, committee materials, and compliance status updates.
  • Experience managing risk registers, corrective action plans, compliance exceptions, findings, and remediation tracking activities.
  • Experience collaborating with technology, security, legal, privacy, audit, business, and executive stakeholders in a highly regulated environment.
  • Experience using GRC, reporting, workflow, and evidence management tools such as Jira, Confluence, SharePoint, Microsoft 365, Power BI, or similar platforms.
  • Strong analytical, organizational, project coordination, and communication skills, including the ability to lead initiatives with minimal supervision.
  • Professional certifications such as CISA, CRISC, CISSP, CISM, CGEIT, ISO 27001 Lead Auditor, ISO 27001 Lead Implementer, or equivalent certifications preferred.
  • Experience within insurance, financial services, healthcare, or other regulated industries preferred.

#LI-Hybrid

-

At Core Specialty, you will receive a competitive salary and opportunities for professional development and advancement. We offer medical, dental, vision, and life insurances; short and long-term disability; a Company-match of 100% of a 6% contribution 401(k) plan; an Employee Assistance Plan; Health Savings Account, Flexible Spending Account, Health Reimbursement Account, and a wellness program

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Core Specialty Insurance Holdings, Inc.'s own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Core Specialty Insurance Holdings, Inc.'s form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Core Specialty Insurance Holdings, Inc.'s answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.