1. Home
  2. Jobs
  3. United States
  4. Georgia
  5. Atlanta
  6. GRC Analyst
  7. Governance, Risk & Compliance (GRC) Analyst
Frazier & Deeter logoF&
Frazier & Deeterfrazierdeeter.com

Governance, Risk & Compliance (GRC) Analyst

Atlanta, Georgia, United States (Hybrid)Full-time2 hr. ago

Join Frazier & Deeter and be a part of a rapidly growing Top 50 accounting & advisory firm that has been repeatedly named a Best Firm to Work For, a Best Firm for Women and a Pacesetter firm among U.S. accounting firms. With several offices across the U.S., UK, and India, there is a spot for you!  

We serve clients of all sizes across the United States and the globe, with a suite of services that grow every year. Our growth mindset and entrepreneurial environment translates into variety and opportunity for our people. 

At Frazier & Deeter, we’re committed to training, mentoring, and developing our staff members. With our emphasis on Investing in Relationships to Make a Difference and a Firmwide Focus on Inclusion, we help each other grow in every aspect of life.  

Job Summary:

As Frazier & Deeter continues to expand its technology capabilities and strengthen its security posture. We are seeking a Governance, Risk & Compliance (GRC) Analyst to support critical governance, risk management, compliance, and audit readiness initiatives. This role is ideal for a detail-oriented professional who enjoys building structure, managing risk, and partnering across the organization to help ensure compliance with regulatory, security, and business requirements. The GRC Analyst will play a key role in supporting the firm's commitment to protecting client information, managing third-party risk, and maintaining strong governance practices.

Duties & Responsibilities:

  • Administer recurring governance, risk, compliance, vendor oversight, audit readiness, and access governance activities.
  • Coordinate quarterly user access reviews, certification activities, evidence collection, and follow-up on overdue or unresolved access items.
  • Support SOC 2 Type II readiness by organizing control evidence, documentation, policy artifacts, remediation tracking, and audit support materials.
  • Review and track vendor compliance documentation, including SOC reports, ISO certifications, security questionnaires, and related due diligence artifacts.
  • Maintain vendor risk records, enterprise risk documentation, remediation tracking, governance reporting, and compliance documentation repositories.
  • Support acquisition integration by helping ensure retained tools, vendors, access models, and compliance obligations are reviewed and documented.
  • Partner with Security Leadership, Technology Operations, Legal, Procurement, Internal Audit / SOQM, and business stakeholders on governance activities.

Education & Experience: 

  • 2+ years of experience in governance, risk and compliance, information security compliance, risk management, audit, vendor risk management, or IT governance.
  • Bachelor's degree in a related field preferred; relevant experience may be considered in lieu of a degree.
  • Experience reviewing SOC 1 reports, SOC 2 Type II reports, ISO 27001 certifications, security questionnaires, risk assessments, or compliance frameworks preferred.
  • Strong documentation, organization, evidence management, and follow-up skills.
  • Understanding of access reviews, vendor oversight, policy governance, compliance reporting, and audit readiness activities.
  • Strong written communication skills and ability to coordinate with stakeholders across technology, legal, procurement, audit, and business teams.
  • Preferred certifications may include CRISC, CISA, CGRC, Security+, ISO 27001 Lead Auditor / Implementer, or Certified Third-Party Risk Professional.

#LI - hybrid