Senior GRC Analyst

2 weeks ago


Byron Center, United States SpartanNash Full time

At SpartanNash, we deliver the ingredients for a better life through customer-focused innovation. We do this for our supply chain customers and U.S. military commissaries, retail store guests and, most importantly, our Associates. In fact, we see a day when each will say, "I can't live without them."

Our SpartanNash family of Associates is 17,000 strong, ranging from bakery managers to order selectors; from IT developers to vice presidents of finance; from HR Business Partners to export specialists. Each of them plays an integral role in SpartanNash's People First culture, Operational Excellence and Insights that Drive Solutions. Ready to contribute to the success of our food solutions company? Apply now

Location:
850 76th Street S.W. - Byron Center, Michigan 49315

Job Description:

Position Summary:

The Senior Governance, Risk, and Compliance (GRC) Security Analyst is responsible for supporting the security direction of the business and elevating the company's security posture. The Senior GRC Security Analyst is expected to support the security strategy of the business within new and existing information system capabilities. The position requires both an understanding of legacy systems, as well as new technologies and requirements. The Senior GRC Security Analyst is also responsible for maintaining the risk register and collaborating with IT teams to effectively drive risk reduction to manage corporate risk and strengthen security posture.

The role oversees the business' security requirements and obligations mandated by standards and regulations such as the Gramm-Leach-Bliley Act (GLBA), Sarbanes-Oxley Act (SOX), Health Information Portability and Accountability Act (HIPAA) and Payment Card Industry Data Security Standard (PCI DSS). In tandem with security leadership, the GRC security analyst consistently assesses and validates the assurance of the security program. As a primary point of contact for internal and external auditors, the Senior GRC Security Analyst monitors progress and enforces resolution of outstanding issues that may lead to non-compliance or security threats to the business. As a key member of the security team, the Senior GRC Security Analyst must focus on strong risk management and corporate resiliency, and not be driven solely by compliance. The Senior GRC Security Analyst will report to the Manager, IT Governance, Risk & Compliance.

Here's what you'll do:

  • Conduct enterprise-wide, ongoing risk analysis in tandem with compliance and security to identify potential risk and maintain oversight in a GRC-related platform.
  • Identify strengths and weaknesses in the security program as they relate to privacy, security, business resiliency, and compliance frameworks.
  • Document and enforce areas of security improvement that balance risk with business operations and do not diminish efficiencies or innovation.
  • Maintain strong oversight of third parties, vendors, and business partners to safeguard against undue risk presented by external entities. Escalate to security management and business unit leads when points of weakness are discovered.
  • Analyze findings, document, recommend, and report program gaps to security leadership.
  • Monitor current and proposed security changes impacting regulatory, privacy, and security industry best practice guidance.
  • Support audit practices and processes and work with the IT organization to ensure findings are remediated.
  • Document and capture qualitative and quantitative metrics to assess the success of the security program and provide regular reports to security and business leadership.
  • Ensure security and technology teams maintain up-to-date configuration documentation for systems and processes.
  • Liaison with auditors, both internal and external, to maintain and implement controls for compliance and privacy laws.
  • Foster strong relationships with internal business units and excel in risk management, technical controls, and cybersecurity communication.
  • Travel as needed to office locations and third-party on-site engagements.
  • Perform other duties as assigned.
Here's what you'll need:
  • Bachelor's degree in information assurance, MIS, cybersecurity, business, or equivalent experience.
  • Master's degree preferred.
  • At least five years of IT or cybersecurity experience (or IT coupled with cybersecurity), with at least two years in an operationally focused IT Assurance or security practitioner role.
  • Experience and understanding of various regulatory requirements and laws, including but not limited to PCI, SOX, HIPAA, and GLBA.
  • Experience with Payment Card Industry (PCI) assessments, PCI-P certification preferred.
  • Experience creating and maintaining cybersecurity policies, standards, and procedures.
  • Demonstrated knowledge of operating systems, networking security concepts, and industry best practices.
  • Demonstrated understanding of legacy and progressive technology and security controls along with respective risk.
  • Skilled at leading projects, collaborating with diverse teams, and promoting enterprise-wide risk management rigor and a security-first culture.
  • Excellent analytical, problem-solving, troubleshooting, and decision-making skills.
  • Highly organized and detail oriented, with excellent written and verbal communication skills.
  • Track record of acting with integrity, taking pride in work, seeking to excel, and being curious and adaptable.
  • Must be able to work independently and in a team setting.
  • CISSP, CRISC, CGEIT or GRCP are preferred, but not required.


As part of our People First culture, SpartanNash is proud to offer a robust and competitive Total Rewards benefits package.

SpartanNash is an Equal Opportunity Employer, including disability and veteran, that celebrates diversity and believes employing a diverse workforce is key to our success. We are committed to providing equal employment opportunities to all individuals.

We are not able to sponsor work visas for this position.

  • Byron Center, United States SpartanNash Full time

    The Security Operations Analyst III is primarily responsible for activities relating to monitoring and responding to security events. The Security Operations Analyst III receives, researches, triages, and documents all security events and alerts as they are received. This individual supports multiple security-related platforms, vulnerability management,...


  • Byron Center, United States SpartanNash Full time

    The Security Operations Analyst III is primarily responsible for activities relating to monitoring and responding to security events. The Security Operations Analyst III receives, researches, triages, and documents all security events and alerts as they are received. This individual supports multiple security-related platforms, vulnerability management,...


  • Byron Center, United States SpartanNash Full time

    At SpartanNash, we deliver the ingredients for a better life through customer-focused innovation. We do this for our supply chain customers and U.S. military commissaries, retail store guests and, most importantly, our Associates. In fact, we see a day when each will say, "I can't live without them." Our SpartanNash family of Associates is 17,500 strong,...


  • Byron Center, United States SpartanNash Full time

    At SpartanNash, we deliver the ingredients for a better life through customer-focused innovation. We do this for our supply chain customers and U.S. military commissaries, retail store guests and, most importantly, our Associates. In fact, we see a day when each will say, "I can't live without them." Our SpartanNash family of Associates is 17,000 strong,...


  • Westfield Center, United States Westfield Group, Insurance Full time

    The Sales Senior Analyst, working under limited supervision, is responsible for implementing the Business territory strategy in their assigned distribution channel territory. The responsibilities include driving profitable business growth and sales, meeting annual growth targets, overseeing marketing and production of insurance products within their...


  • Byron Center, United States SpartanNash Full time

    Job DescriptionPosition Summary:This role is responsible to evaluate complex business requirements for enterprise business application integration within assigned area(s) and deliver new or modified software systems enhancements or integration solutions. Conduct analyses of the business process, data integrity and application(s) and partner with...


  • Byron Center, United States SpartanNash Full time

    Job DescriptionPosition Summary:This role is responsible to evaluate complex business requirements for enterprise business application integration within assigned area(s) and deliver new or modified software systems enhancements or integration solutions. Conduct analyses of the business process, data integrity and application(s) and partner with...


  • Byron Center, United States SpartanNash Full time

    At SpartanNash, we deliver the ingredients for a better life through customer-focused innovation. We do this for our supply chain customers and U.S. military commissaries, retail store guests and, most importantly, our Associates. In fact, we see a day when each will say, "I can't live without them." Our SpartanNash family of Associates is 17,000 strong,...


  • Kennedy Space Center, United States AssuredPartners Full time

    We are seeking a Senior Compensation Analyst with a blend of technical expertise and strategic insight. If you excel in dynamic environments and have a passion for compensation, this opportunity is for you! In this critical role, you will develop and Compensation Analyst, Compensation, Analyst, HRIS, Remote, Project Management, Technology, Insurance


  • Stennis Space Center, United States ManTech Full time

    Secure our Nation, Ignite your FutureBecome an integral part of a diverse team while working at an Industry Leading Organization, where our employees come first. At ManTech International, you'll help protect our national security while working on innovative projects that offer opportunities for advancement.Currently, ManTech is seeking a motivated, career...


  • Byron/Illinois/US Constellation Energy Full time

    COMPANY OVERVIEWAs the nation's largest producer of clean, carbon-free energy, Constellation is a company purposely-built to meet the challenges of the climate crisis. Constellation has been the leader in clean energy production for more than a decade and we are growing our company and capabilities. Now, we're accelerating, speeding our low-carbon or...


  • Naval Surface Weapons Center, United States Risk Mitigation Consulting (RMC) Full time

    RMC is seeking a Senior Data Network Analyst for a hybrid role in or around the Dahlgren, VA area. Are you ready to embark on a fulfilling and impactful career journey with Risk Mitigation Consulting (RMC)? We're in search of an exceptional Senior Cybersecurity Analyst to become a part of our mission-driven team, dedicated to making a difference in the...


  • Valley Center, Kansas, United States Olympus Corporation of the Americas Full time

    Working Location:PENNSYLVANIA, CENTER VALLEY Workplace Flexibility:Hybrid Are you looking for a company that cares about people's lives and health, including yours? Let's inspire healthier lives, together.Olympus, a leading medical technology company, has focused on making people's lives better for over 100 years.Our Purpose is to make people's lives...

  • Business Analyst

    3 weeks ago


    Michigan Center, United States RIT Solutions, Inc. Full time

    Business Analyst Location: Lansing Michigan 48933 United States (Need local Candidate within 50 to 60 miles ) Experience: 8+ years Required Top Skills & Years of Experience: • 5+ years of experience designing technical and business requirement documentation (mockups, business process models, workflow diagrams, etc.) • 5+ years of experience with...

  • Financial Analyst

    4 days ago


    Byron, United States KIHOMAC Full time

    Provide guidance to program managers in financial reporting objectives and standards to ensure accurate, compliant and useful financial reporting is produced Initiate, monitor and maintain proper project setup in Unanet Provide analysis for forward-looking financials and business-related projects Prepare forecasts and analysis of trends in...

  • Financial Analyst

    2 weeks ago


    Byron, United States KIHOMAC Full time

    Job DescriptionJob DescriptionProvide guidance to program managers in financial reporting objectives and standards to ensure accurate, compliant and useful financial reporting is producedInitiate, monitor and maintain proper project setup in UnanetProvide analysis for forward-looking financials and business-related projectsPrepare forecasts and analysis of...


  • Valley Center, Kansas, United States Olympus Corporation of the Americas Full time

    Working Location:PENNSYLVANIA, CENTER VALLEY Workplace Flexibility:Hybrid Are you looking for a company that cares about people's lives and health, including yours? Let's inspire healthier lives, together.Olympus, a leading medical technology company, has focused on making people's lives better for over 100 years.Our Purpose is to make people's lives...

  • FP&A Analyst

    2 weeks ago


    Kennedy Space Center, United States Worth AI Full time

    Worth AI is seeking a talented FP&A (Financial Planning and Analysis) Analyst to join our dynamic team in the computer software industry. As an FP&A Analyst, you will play a crucial role in our mission to revolutionize decision-making through the power of AI. Believing in the intrinsic value within each person and organization, Worth AI is committed to...

  • Tech Analyst

    6 days ago


    Sun City Center, Florida, United States HCA Healthcare Full time

    Description IntroductionDo you want to join an organization that invests in you as a(an) Tech Analyst? At HCA Florida South Shore Hospital, you come first. HCA Healthcare has committed up to 300 million in programs to support our incredible team members over the course of three years.BenefitsHCA Florida South Shore Hospital, offers a total rewards package...


  • Sioux Center, United States Automationtechies Full time

    With over 70 years in business, this engineering firm solves some of the most complex challenges and provides the most innovative solutions for industrial manufacturing and processing facilities worldwide. Summary of Role: As a Senior Control Systems Engineer you will take responsibility for the planning and design of significant portions of a control system...