Hiring.Camp

Governance, Risk, and Compliance (GRC) Data Analyst | Technology Services

Denver means seeing yourself working

·

Today

Salary
$74k – $123k
Location
Webb Building Floor 03, United States of America
Workplace
Hybrid, Onsite
Type
Full-time
Department
IT
Experience
2+ years
Education
Bachelor
Closing date
Today
Source
Workday

Description

About Our Job


With competitive pay, great benefits, and endless opportunities, working for the City and County of Denver means seeing yourself working with purpose — for you, and those who benefit from your passion, skills and expertise. Join our diverse, inclusive and talented workforce of more than 11,000 team members who are at the heart of what makes Denver, Denver.

 

Application Deadline and Materials


This job posting will accept applications until 11:59PM on Sunday, October 11.

 

We kindly request that you submit a resume with your application materials.

 

What We Offer


The City and County of Denver offers a competitive salary commensurate with education and experience. The hiring salary range for this position is $74,276/year - $98,500/year, based on experience. We also offer generous benefits for full-time employees which include, but are not limited to:

 

  • A guaranteed life-long monthly pension, once vested after 5 years of service
  • 457B Retirement Plan
  • 140 hours of PTO earned within first year + 11 paid holidays, 1 personal holiday and 1 volunteer day per year
  • Competitive medical, dental and vision plans effective within 1 month of start date

 

More information about the perks and benefits we provide to full-time employees to allow them to find balance, thrive, and build a mile high career can be found on our website.

 

Location & Hybrid Schedule


The City and County of Denver supports a hybrid workplace model. In this position, you can expect to work on-site at the Webb Municipal Building (201 W. Colfax Ave.) two (2) days per week. Employees must work within the state of Colorado on their off-site days.

 

Who We Are


The Technology Services Department (TS) of the City and County of Denver use state-of-the-art technologies and methodologies to deliver and improve the systems, applications, and operations to our customers. Technology Services supports the people, agencies, and ideas that make the City and County of Denver a world-class city. The city offers a unique opportunity to work with a diverse business and technology environment on a large scale as we employ more than 13,000 people, of which 9,000+ are daily technology consumers in support of a diverse population over 700,000 Denverites.

 

What You’ll Do


The City and County of Denver (CCD) approaches Governance, Risk, and Compliance (GRC) holistically ensuring that risks and vulnerabilities are evaluated not only from a system-security standpoint, but also through the lens of the end user and the application. The Governance, Risk, and Compliance Analyst position is a key stakeholder on the CCD GRC, Data Protection Team, contributing to a comprehensive program that spans vendor risk, policy governance, audit coordination, and access controls.

 

This role is responsible for advancing CCD Technology Services' (TS) governance, risk, and compliance objectives across several interconnected areas:

 

  • Vendor Risk Management — Manage the TS Vendor Risk Assessment Program, ensuring all new and existing Citywide technology vendors are evaluated through initial and annual risk assessments. Determine the scope of required reviews, coordinate with vendors and internal stakeholders, and communicate assessment conclusions, including compliance and contract-language needs, approvals, and denials.

  • Policy & Standards Governance — Manage TS policies and standards, ensuring all Citywide technology policies are reviewed and updated annually. Advise policy stakeholders on language and, when needed, take the lead on creating new policies and standards.

  • Audit Coordination — Serve as the primary liaison between the CCD Auditor's Office and Technology Services. Manage and coordinate external audits, assist in gathering and creating deliverables, brief TS leadership on audit status and potential findings, and advise on and at times draft responses to audit finding recommendations.

  • Access & Controls — Periodically audit system user permissions, recommend appropriate access levels, and ensure administrative privileges are restricted to those with a documented business need.

  • Security Awareness & Training — Determine employee training needs based on identified user behavior and risk, partner with HR/Workday Learning to provision training to applicable employees, and monitor completion with timely follow-up.

  • Broader GRC Support — Support additional GRC activities such as approving or denying third-party file-share requests, conducting risk assessments, ensuring regulatory compliance, and contributing to initiatives such as the role-based access control project. Act as an ongoing GRC subject-matter expert and liaison for other CCD agencies, advising on best practices to reduce risk and promote regulatory compliance

Key duties, tasks, and responsibilities of this position include:


  • Utilizing ServiceNow to manage vendor risk assessments, TS audits, policies, and third-party file-share permission requests
  • Responding to and organizing responses to third-party risk assessment requests from across CCD
  • Collaborating with the CCD Auditor's Office throughout audit engagements and managing external audits end to end
  • Assisting in the collection and creation of audit deliverables and providing leadership briefings on audit status and potential findings
  • Advising TS stakeholders on the implementation of internal controls and safeguards in response to audit findings, and provide written responses to audit recommendations
  • Identifying and conducting risk assessments across vendors, systems, and processes
  • Reviewing access roles and permissions, ensuring proper safeguards and validated business needs
  • Reviewing, selecting, and managing security-awareness training material and monitoring completion
  • Collaborating with TS teams and CCD agencies to mitigate identified risk and promote regulatory compliance

 

What You’ll Bring

 

The ideal candidate will have a strong foundation in governance, risk, and compliance, along with experience in policy creation, audits, and technical writing. We are also looking for someone who is comfortable working independently, takes initiative, and proactively identifies opportunities to streamline and improve processes.

 

  • 2–3 years of experience in data protection and/or governance, risk, and compliance (relevant experience may supplement education requirements)
  • Knowledge of, and experience applying, the following regulatory frameworks:
    • U.S. Department of Commerce, National Institute of Standards and Technology (NIST) Cybersecurity and Privacy Frameworks
    • Payment Card Industry Data Security Standard (PCI-DSS)
    • U.S. Department of Health and Human Services, Health Insurance Portability and Accountability Act (HIPAA)
  • Experience using Workday, OneTrust, ServiceNow, and Box platforms
  • A continuous‑improvement mindset, with the ability to evaluate processes, identify gaps, and implement effective, scalable solutions
  • Demonstrated ability to work independently, manage priorities, and drive tasks to completion with minimal supervision
  • A collaborative, relationship‑building approach, and a desire to support a culture of equity, inclusion, and continuous improvement

 

Required Minimum Qualifications


  • Education requirement: Bachelor's Degree in Information Technology or a related field based on a specific position(s).
  • Experience Requirement: Two years of experience with data protection, governance, risk assessment, and compliance with information technology systems.
  • Education/Experience Equivalency: One (1) year of the appropriate type and level of experience may be substituted for each required year of post-high school education. Additional appropriate education may be substituted for the minimum experience requirements.
  • Licensure/Certifications: None

About Everything Else

Job Profile

CI3432 IT Data Protection Analyst Associate

To view the full job profile including position specifications, physical demands, and probationary period, click here.

Position Type

Unlimited

Position Salary Range

$74,276.00 - $122,555.00

Target Pay

$74,276/year - $98,500/year, based on experience

Agency

Technology Services

Redeployment during Citywide Emergencies

City and County of Denver employees may be re-deployed to work in other capacities in their own agencies or in other city agencies to support core functions of the city during a citywide emergency declared by the Mayor.

The City and County of Denver provides equal employment opportunities to all employees and applicants for employment without regard to race, color, religion, national origin, sex, sexual orientation, gender identity, national origin, disability, genetic information, age, or any other status protected under federal, state, and/or local law. 

It is your right to access oral or written language assistance, sign language interpretation, real-time captioning via CART, or disability-related accommodations. To request any of these services at no cost to you, please contact [email protected] with three business days’ notice.

Applicants for employment with the City and County of Denver must have valid work authorization that does not require sponsorship of a visa for employment authorization in the U.S.

For information about right to work, click here for English or here for Spanish.

Skills

WorkdayServiceNowCybersecurityRisk ManagementComplianceTechnical WritingHIPAA

Similar Jobs

30

Governance Risk and Compliance I Analyst II

Vertiv·Mandaluyong City, Philippines

Today

Risk Governance and POA&M SME

LOGC2·Springfield, VA·Hybrid, Onsite

1d ago

Information Security Risk and Governance Specialist, Consultant

Blue Shield of California·Oakland, CA

1d ago

FY 27 - Intern - Assurance - GRC (Governance, Risk, and Compliance) Centralized team

Pwc·Jakarta - Gd. WTC 3, Indonesia

1d ago

Cybersecurity Governance, Risk and Compliance

Vitol·Geneva, GE

2d ago

Security Associate Manager – Governance, Risk and Compliance - Internal Corporate Function

BIP·Milano, Lombardia

3d ago

VP - Finance Risk and Governance

Mufgub·London Ropemaker place, UK

3d ago

Director Governance Risk and Compliance

surescripts·US

4d ago

Information Security Governance, Risk and Compliance Analyst II

Saintlukes·System Offices, MO·Remote

4d ago

Business Control Manager - Governance and Risk Program Manager

Ghr·Charlotte, US·Onsite

4d ago

Supply Chain Governance, Risk and Compliance Analyst, Supply Chain Management Unit, P-2 Copenhagen (209433)

United Nations Development Programme (UNDP)·Copenhagen, DK

5d ago

Governance, Risk and Compliance Specialist, Supply Chain Management Unit, P-4, Copenhagen (209474)

United Nations Development Programme (UNDP)·Copenhagen, DK

5d ago

Head of IT Governance, Risk, and Compliance (GRC)

"LabConnect, LLC"·Remote - US, 2304 Silverdale Drive·Remote

1w ago

Head of Risk and Governance

The Granite Group·Liverpool, UK

1w ago

Enterprise Governance Risk and Compliance Analyst

RBFCU Randolph·ASC - San Antonio, US

1w ago

Governance, Risk, and Compliance Analyst

Pike Engineering·SC, US

1w ago

Governance, Risk, and Compliance Senior Associate or Supervisor (IT)

Weaver·DALLAS, TX +3

1w ago

Governance, Risk, and Compliance (GRC) Specialist, AWS Security

Amazon·Remote

1w ago

Lead Analyst, Information Security (Risk and Governance)

Rxo·USNC-Charlot15, US·Onsite

1w ago

Senior Manager in Governance Risk and Compliance

Prometeia·Milano - Brera, Italy +3

1w ago

Governance, Risk and Compliance Analyst

Mission Australia·Sydney Office, Australia

1w ago

Enterprise Risk Management (ERM) - Policy and Governance Risk Analyst V

Keybank·127 Public Square, OH

1w ago

Governance Risk and Compliance Analyst

Polsinelli·Kansas City, MO +26

2w ago

Cyber Governance and Risk Senior Analyst

Cohesity·Cohesity - Dublin, Ireland +1·Hybrid, Remote

2w ago

Associate Director, Market Risk Governance and Controls

Rbc·BROOKFIELD PLACE FKA 3 WORLD FINANCIAL CENTER, 200 VESEY STREET:NEW YORK

2w ago

Cloud Engineer - Governance, Risk, and Compliance (GRC)

Peraton·US·Remote

2w ago

Senior Analyst, Cyber Governance, Risk and Compliance (GRC)

Higcapital·Coral Gables, US·Hybrid

2w ago

Senior Analyst – AI Models Risk and Governance

Rbc·RBC WATERPARK PLACE, 88 QUEENS QUAY W:TORONTO +1

2w ago

Staff IT Analyst II - IT Governance, Risk, and Controls

Western Alliance Bancorporation·Block 23, US +2

2w ago

Governance Risk and Compliance Consultant

Capco·Belgium - Brussels

2w ago