We use cookies. Find out more about it here. By continuing to browse this site you are agreeing to our use of cookies.
#alert
Back to search results
Remote New

Senior, Governance Risk & Compliance Analyst (Virtual, US)

Sirva
retirement plan
United States
Feb 02, 2026

The Senior IT Governance Risk and Compliance Analyst, (ITGRCA) oversees the Information Security risk management program, third party risk assessments, and risk council for capital and expense projects. This role is also responsible for leading a variety of annual/quarterly/monthly/bi-weekly/weekly procedures, controls and meetings. This role also manages the interface between IT management and both internal and external auditors for the Service Organization Control (SOC 2&3) and other compliance initiatives such as Sarbanes-Oxley (SOX), including providing requested audit inputs. This role reports to the Global Chief Information Security Officer.


* The Analyst manages the security risk assessments for capital projects and service providers. This involves identifying the risks presented by technological and process changes. This may include the review of architecture design, supporting processes/ procedures, etc. to ensure the proper controls are in place and risks are appropriately mitigated.


* Manage the Identity Management Program to ensure proper authorized access is maintained in critical applications.


* Enterprise Risk Management: Manage the process for gathering enterprise risks (strategic, operational, financial and legal/regulatory). Lead the initiative to analyze residual risk and benchmark against other risks across the Company. Compile feedback and lead the presentation for the ERM Committee, made up of key members of Executive Management


* Maintain a risk register and support continuous improvement of IT risk management processes. * Assist with the Disaster Recovery and Business Continuity Plan testing annually.


* IT Regulatory Examinations and Internal Audits: Supports IT Audits to ensure their success. Provide assistance to IT managers and associates in writing up reports, the effective controls and action plans for any deficiencies.


* IT Risk Consulting: Works with management and associates to assess risks associated with technology solutions and ensures appropriate remediation strategies are employed. Consults with managers and associates to identify and assess current and emerging risks and strategic initiatives.


* Visit and perform an annual review of the security of the main data center. Monthly review the access to the data centers and computer rooms for reasonableness. Ensure physical security of all data centers, computer rooms and offices are sufficient and rules are communicated to appropriate personnel.


* IT Risk Metrics and Reporting: Leads the development of risk metric and reporting frameworks for Information Security. Delivers these metrics and reports on weekly, monthly and quarterly basis.


* Review 3rd Party SOC 1 Reports and analyze the competency of their controls.


* Gather relevant business, regulatory, process, and system information; validate/update process flows, risks, and controls; prepares accurate, complete, clear, and timely analysis and documentation that reflects an ability to identify risks and independently assess the adequacy and effectiveness of IT internal controls and their compliance with applicable laws, regulations, policies, and procedures. * Monitor vulnerabilities, communicate them to owners, and hold owners accountable for remediation; follow up.


* Draft and distribute security alerts across the organization * Coordinate Security Awareness Training initiatives.


* Maintain and prioritize a list of action items for the Information and Cybersecurity Departments


* Define action plans and timelines with process owners and manage them to completion/implementation


* Manage testing request lists from internal and external auditors, providing the interface between IT management and the auditors.


* Create, update and administer IT policies, standards and procedures. Ensure all IT policies, standards and procedures meet the guidelines established for each; ensures they are properly housed, refreshed, inventoried and approved.


* Draft Information Security deliverables to both internal and external partners on a variety of security and privacy topics.


* Schedule, compile presentations for and lead regularly held (quarterly, monthly, bi-weekly and weekly) meetings to update leadership, hold others accountable, bridge communications between departments and follow best practices. * Information Security Incident Management: Ability to investigate, document and report on security incidents from identity theft to technology level incidents.


At Sirva, we are committed to fair and transparent compensation practices. In accordance with applicable provincial and federal laws, we provide the following salary information for this position:

* Position Title: Senior, Governance Risk & Compliance Analyst
* Salary Range: $128,554-$161,000 CAD
* Benefits: Comprehensive benefits package that includes choice of two Medical plans and two dental plans; Retirement plan, RRSP employer match (after 1 year), Life & Disability Insurance, and more. Benefits are based on employment status and may not be available for temporary or part-time employees

Salary ranges may vary based on location, market conditions, and other factors such as experience and qualifications. The final compensation will be determined during the hiring process based on these considerations.

For positions available outside Canada, salaries will take into account local currency and market conditions, which may differ from the CAD salary range. If you have any questions about salary or benefits, we encourage you to ask during the hiring process.



  • * Artificial Intelligence Usage: Artificial intelligence tools may be used to assist with administrative tasks such as notetaking and advanced candidate searches during the recruitment process. All screening, assessment, and hiring decisions are made by human recruiters and hiring managers.
  • Vacancy Status: This posting reflects an existing vacancy within our organization.


Sirva Worldwide Relocation and Moving is a global leader in moving and relocation services, offering solutions for mobility programs to companies of every size. With 75 owned locations and more than 1,000 franchised and agent locations in 177 countries, we offer unmatched global breadth supported by localized attention and innovative technology that strikes the right balance of self service and human support. From relocation and household goods to commercial moving and storage, our portfolio of Brands (Sirva, Team Relocations, Allied, & northAmerican) provides the only integrated moving/relocation solution in the industry. By leveraging our global network, we deliver a superior experience that only a "one-stop shop" can provide. We're a team that works globally to provide the best service locally - a company that is everything you need, everywhere you need it. For more information please visit www.sirva.com.



Sirva brings together strong, collaborative people in a dynamic culture of mutual respect, support, and passion for the brand and product. We believe innovation drives winning performance, and we constantly challenge ourselves to be the very best we can in every aspect of our business. You will be surrounded by some of the brightest and most driven people in the industry. At Sirva, you will be in great company!

Sirva is an equal opportunity employer. We evaluate qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, military status, genetic information or any other consideration made unlawful by applicable federal, state, or local laws. Sirva also prohibits harassment of applicants and employees based on any of these protected categories.



If you need a reasonable accommodation because of a disability of any part of the employment process, please send an email to Human Resources at HRSirva@Sirva.com and let us know the nature of your request and your contact information.

Applied = 0

(web-54bd5f4dd9-d2dbq)