Job Description
Bennett Thrasher is seeking an IT Governance, Risk & Compliance (GRC) Analyst to support our technology compliance, risk, and data-governance programs.
This hands-on role helps maintain year-round SOC 2 readiness, coordinates IT controls and access reviews, supports Microsoft Purview and data-retention initiatives, administers security awareness activities, and ensures compliance documentation remains organized and audit-ready.
The ideal candidate has experience in IT audit, GRC, cybersecurity compliance, or technology risk and is ready to continue developing their expertise.
What You’ll Do
- Maintain the SOC 2 control calendar and coordinate recurring control activities.
- Collect, review, and maintain audit evidence and documentation.
- Track control gaps, exceptions, remediation plans, and outstanding items.
- Coordinate SOC 2 readiness activities and external auditor requests.
- Perform and document recurring user and privileged-access reviews.
- Support Microsoft Purview, including data classification, DLP, sensitivity labeling, and retention.
- Assist with development and implementation of the firm’s data-retention program.
- Administer security awareness campaigns, phishing simulations, and reporting.
- Maintain IT compliance and security policies and coordinate periodic reviews.
- Review change requests for compliance, risk, data protection, and audit requirements, ensuring proper approvals and documentation.
- Assist with technology risk assessments, vendor security reviews, and client security questionnaires.
- Maintain risk and remediation registers and follow up with control owners.
- Prepare compliance reporting for IT leadership.
- Identify opportunities to automate compliance monitoring and evidence collection.
- Escalate significant control failures, risks, and policy exceptions.
- Review change requests for compliance, risk, data protection, and audit requirements, ensuring proper approvals and documentation.
What We’re Looking For
- 4+ years of experience in IT GRC, IT audit, cybersecurity compliance, technology risk, SOC/SOX controls, or information security.
- Understanding of IT controls, audit evidence, and risk-management concepts.
- Experience with Microsoft 365 or similar enterprise technology environments.
- Strong organization, documentation, communication, and follow-through skills.
- Ability to work independently and coordinate across multiple teams.
Preferred
- SOC 2 audit or readiness experience.
- Microsoft Purview, Entra ID, DLP, or data-retention experience.
- Experience with access reviews or GRC/compliance platforms.
- Vendor/third-party risk experience.
- Security awareness program administration.
- Experience in accounting, financial services, professional services, or another environment handling sensitive client information.
- Security+, CISA, CRISC, CGRC, Microsoft security/compliance, or similar certification—or interest in pursuing one.