Genuine Parts / NAPA logo

GRC Analyst (Governance) - Global Industrial

Genuine Parts / NAPA

Birmingham, AL · HybridFull-timePosted 1w agoStill listed 1w ago

Most applications go out cold — see where you stand first. No sign-up to start.

Watch jobs like this.

At a glance

Compensation
No compensation found
Location
Birmingham, ALHybrid
Schedule
Full-time
Work Authorization
Not specified

Olive lists jobs from US employers, including remote roles you can work from the United States.

Requirements

Credentials this posting asks for.

Bachelor's degree

Job overview

The Governance, Risk & Compliance Analyst II supports Motion’s GRC functions, handling vulnerability management, policy development, privacy program operations, risk assessments, and third‑party compliance while reporting to the GRC Lead.

Skills & qualifications

RequiredNice to have

Skills

AnalyticalOrganizationalDocumentationWritten CommunicationVerbal CommunicationIndependent WorkDetail‑OrientedSelf‑DirectedGRC Tooling PlatformsSpecific Framework Experience

Qualifications

Bachelor’s Degree in Computer Science or Software Engineering or Related FieldThree to Five Years of Related Experience or Equivalent CombinationRelevant Certification or Progress Toward Certification

Benefits

Medical Insurance
401(k) Match
Tuition Assistance
Paid Time Off

Full job description

SUMMARY: Under general supervision the Governance, Risk & Compliance (GRC) Analyst II will support Motion's Governance, Risk & Compliance functions, which may include Privacy, Compliance, Risk Management, Third-Party Risk, Governance, or Attack Surface Management. This role executes day-to-day GRC activities within their assigned domain, and reports to the GRC Lead.

JOB DUTIES

  • Monitors vulnerability scanning results and maintain visibility into Motion's external attack surface.
  • Tracks and prioritizes vulnerabilities for remediation, partnering with IT Operations and Application Development.
  • Owns vulnerability management reporting and metrics and scanning tool administration.
  • Drives remediation service level agreements and escalate cross-team blockers as needed.
  • Develops, maintains, and periodically reviews information security policies and standards.
  • Owns the IT Security Awareness program, including content updates and tracking participation amongst stakeholders.
  • Manages policy exceptions and the exception/acceptance process.
  • Represents Governance in cross-team initiatives and audits.
  • Supports compliance activities across pertinent platforms.
  • Supports Operational Technology (OT) compliance efforts in partnership with the Cyber Defense Engineering & Architecture team.
  • Manages privacy notices, cookie compliance, and consent/preference management across digital properties.
  • Supports privacy program operations, including gap identification and remediation tracking.
  • Assists with Privacy Impact Assessments (PIAs) and Data Privacy Impact Assessments (DPIAs).
  • Manages intake and processing of Data Subject Access Requests (DSARs).
  • Assist with compliance audits and assessments including evidence coordination.
  • Produces privacy and compliance metrics and reporting data for the Lead, and support development of privacy training and awareness content.
  • Maintains and update the cyber risk register and track security issues through the remediation lifecycle, following up with control owners on outstanding items.
  • Supports execution of IT risk assessments and third-party/vendor risk assessments including periodic reviews and quality assurance of risk documentation.
  • Tracks and communicate risk exceptions and remediation action plans to stakeholders.
  • Collaborates with business partners and vendor stakeholders to identify improvement opportunities in risk processes.
  • Maintains awareness of relevant risk frameworks and standards.

EDUCATION & EXPERIENCE

  • Typically requires a bachelor’s degree in computer science, software engineering, or a related field and three (3) to five (5) years of related experience or equivalent combination.

KNOWLEDGE, SKILLS, ABILITIES

  • Strong analytical, organizational, and documentation skills.
  • Excellent written and verbal communication skills.
  • Ability to work independently in a lean team environment.
  • Detail-oriented and self-directed.
  • Relevant certification or progress toward certification.
  • Familiarity with GRC tooling/platforms.
  • Experience in a specific framework relevant to the functional area assigned.

PHYSICAL DEMANDS:

LICENSES & CERTIFICATIONS:

SUPERVISORY RESPONSIBILITY: No Supervisory Responsibility

BUDGET RESPONSIBILITY: No

COMPANY INFORMATION: Motion offers an excellent benefits package which includes options for healthcare coverage, 401(k), tuition reimbursement, vacation, sick, and holiday pay.

DISCLAIMER: This job description illustrates the general nature and level of work performed by employees within this job classification. It is not intended to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and skills required. Management retains the right to add or modify duties at any time.

Not the right fit? Let us know you're interested in a future opportunity by joining our Talent Community on jobs.genpt.com or create an account to set up email alerts as new job postings become available that meet your interest!

GPC conducts its business without regard to sex, race, creed, color, religion, marital status, national origin, citizenship status, age, pregnancy, sexual orientation, gender identity or expression, genetic information, disability, military status, status as a veteran, or any other protected characteristic. GPC's policy is to recruit, hire, train, promote, assign, transfer and terminate employees based on their own ability, achievement, experience and conduct and other legitimate business reasons.

Similar jobs, posted recently

Open roles like this one, listed in the last 30 days.

You've read the whole posting — now see how you match it.