Senior GRC Analyst
Oliver James · Des Moines
Senior GRC Analyst at Oliver James, based in Des Moines. This is a permanent role.
- Salary
- Competitive
- Location
- Des Moines
- Contract
- Permanent
- Posted
- 1 day ago
- Closes
- 25 Aug 2026
- Sector
- Legal
Reference JOB-082026-312512_1787002376
About the role
Senior GRC Analyst
About the Opportunity
Join a large, well-established financial services organization during a period of significant technology transformation. As the company invests heavily in AI and emerging technology, the Technology Risk team is helping build governance around these changes from the ground up - rather than simply maintaining an existing, mature program. This is a lean, high-visibility team within a large enterprise, offering meaningful ownership and the opportunity to directly shape how technology and AI risk are managed going forward.
The Role
This position sits within the organization's Technology Risk function as a second-line risk role, focused on governance, risk management, controls, and cross-functional stakeholder engagement rather than hands-on technical cybersecurity work. You'll work closely with Technology, Cybersecurity, Enterprise Risk, Legal, Compliance, and Internal Audit teams.
Key Responsibilities
Lead technology and cyber risk assessments across the organization
Manage and maintain the technology risk register
Support internal and external audits, as well as regulatory exams
Help build and mature governance frameworks around AI and other emerging technologies
Contribute to continuous improvement of the broader GRC program and processes
Partner cross-functionally with stakeholders across the business to influence and improve governance practices
What We're Looking For
Bachelor's degree (or equivalent experience) and 5+ years of experience in IT risk management, cybersecurity governance, IT audit, GRC, compliance, consulting, or professional services
Strong knowledge of regulatory and governance frameworks such as NIST, SOX, NYDFS, BMA, ISO 27001, and COBIT
Experience with enterprise GRC platforms; ServiceNow GRC experience highly valued
Background in Big Four consulting, IT audit, or compliance strongly preferred (candidates with experience limited to third-party risk management alone are unlikely to have the breadth needed)
Strong communication skills and executive presence, with the ability to engage and influence stakeholders across the organization
Self-starter who can work both independently and collaboratively in a fast-paced environment
What Sets This Role Apart
Direct exposure to AI governance as the organization actively rolls out generative AI tools and invests in responsible adoption of emerging technology
Roughly a 50/50 mix of ongoing risk/governance work and project-based initiatives
Strong potential for growth into a technical lead position for high performers, with increasing responsibility and visibility over time
Highly collaborative culture that emphasizes autonomy with accountability, continuous learning, and proactive communication
Schedule
Hybrid - 4 days in-office, 1 remote day per week after training
Reference: JOB-082026-312512_1787002376 · Posted 1 day ago · Closes 25 Aug 2026 · Listed via Oliver James
Apply for this job
This role is listed via Oliver James. Applications are handled on the employer's site.
Apply on employer siteOpens the employer's website in a new tab.
Safe applying: a genuine employer will never ask you to pay for a DBS check, training or equipment, or move you onto WhatsApp before you are hired. If this listing does, report it and do not pay anything.