Forward Financing logo
Forward Financing
Posted 2 days agoVerified live 1d ago

GRC Analyst

Brief overview

Remote
UndergradOr in progress
$85k–$108k/yrStated range
1+ yrsMinimum
Third-Party Risk ManagementRisk AssessmentSecurity Policies, Standards, and ProceduresSOC 2 Compliance AuditsInternal AuditingAWSArtificial Intelligence

Job description

Summary

Forward Financing is a financial technology company focused on providing capital to small businesses. The GRC Analyst will contribute to the Governance, Risk, and Compliance program, with a primary focus on third-party risk management, policy maintenance, risk analysis, and support for the annual SOC2 audit. The role will also use AI and machine learning tools to improve GRC processes and promote security and risk awareness.

Responsibilities

  • Conduct and manage third-party risk assessments, including initial due diligence and ongoing monitoring of vendors
  • Collaborate with internal teams to help create and maintain security policies, standards, and procedures
  • Assist with risk analysis to identify, evaluate, and track risks across the organization
  • Support our annual SOC2 audit by helping to gather evidence, coordinate with stakeholders, and track findings
  • Contribute to the development and maintenance of the GRC program to ensure it aligns with our business objectives
  • Help promote a culture of security and risk awareness through clear communication and collaboration
  • Utilize artificial intelligence and machine learning tools to automate routine tasks, identify patterns, and enhance the efficiency of governance, risk, and compliance processes
  • Conduct internal audits of systems, processes, etc
  • Take on ambiguous or unfamiliar problems as they arise, ask the right questions to get oriented quickly, and build the skills needed to solve them

Skills

  • Bachelor's degree in a related field or equivalent practical experience
  • 1-2+ years of experience in a GRC, risk, or compliance role
  • Experience with third-party/vendor risk management processes, including conducting due diligence and assessments
  • Familiarity with creating or maintaining policies, standards, and procedures
  • Understanding of risk assessment methodologies and the ability to help identify and evaluate risks
  • Experience supporting compliance audits, such as SOC2, by gathering evidence and coordinating with teams
  • Strong organizational and communication skills
  • Excellent verbal and written english language skills
  • Demonstrated versatility — comfortable moving between tasks, tools, and priorities, and willing to stretch into work outside your immediate comfort zone
  • A track record of asking good questions rather than guessing when something is unclear; you know the difference between productive independence and working in the dark
  • Intellectual curiosity about risk, compliance, and security, with a genuine interest in understanding the "why" behind a process, not just the "how."
  • Familiarity with AI and use cases within business settings
  • A solid understanding of AWS or other cloud structures

Qualifications

Must Haves

  • Bachelor's degree in a related field or equivalent practical experience
  • 1-2+ years of experience in a GRC, risk, or compliance role
  • Experience with third-party/vendor risk management processes, including conducting due diligence and assessments
  • Familiarity with creating or maintaining policies, standards, and procedures
  • Understanding of risk assessment methodologies and the ability to help identify and evaluate risks
  • Experience supporting compliance audits, such as SOC2, by gathering evidence and coordinating with teams
  • Strong organizational and communication skills
  • Excellent verbal and written english language skills
  • Demonstrated versatility — comfortable moving between tasks, tools, and priorities, and willing to stretch into work outside your immediate comfort zone
  • A track record of asking good questions rather than guessing when something is unclear; you know the difference between productive independence and working in the dark
  • Intellectual curiosity about risk, compliance, and security, with a genuine interest in understanding the "why" behind a process, not just the "how."

Nice to Haves

  • Familiarity with AI and use cases within business settings
  • A solid understanding of AWS or other cloud structures

Benefits

  • Annual Target Bonus: 10%
  • Remote work

More jobs like this