Senior Governance Risk & Compliance Analyst

Varnum

Varnum

IT, Compliance / Regulatory

Grand Rapids, MI, USA

Posted 6+ months ago
Position: Senior Governance Risk & Compliance Analyst
Location: Grand Rapids, MI
Job Id: 254
# of Openings: 1

Senior Governance Risk & Compliance (GRC) Analyst
Job Summary:
Varnum LLP, a Michigan-based, full-service law firm with over 190 attorneys and six offices, has a full-time Senior Governance Risk & Compliance Analyst opening our technology department located in our Grand Rapids office. We are seeking a candidate who is organized and displays a keen attention to detail, with a superb commitment to client service. This individual should be comfortable working independently, as well as part of a team. In this pivotal role, you'll be instrumental in enhancing security operations, engineering, and architecture while nurturing our most significant asset—our people. This is an in-person role located in Grand Rapids, Michigan.
Position Summary:
The Senior GRC Analyst supports the firm’s governance, risk management, and compliance programs to ensure operational integrity, data protection, and adherence to client and regulatory requirements. This role plays a key part in maintaining trust, confidentiality, and compliance across legal operations and supporting the firm’s overall risk posture.
Key Responsibilities:
  • Lead risk assessments and manage mitigation activities across firm operations.
  • Develop and maintain GRC policies and frameworks aligned with ISO 27001, NIST, and HIPAA.
  • Oversee vendor and third-party risk management processes.
  • Maintain risk and compliance documentation within GRC tools.
  • Support client audits, due diligence, and internal compliance reporting.
  • Drive awareness and training to foster a culture of compliance and security.
Qualifications:
  • 5+ years in GRC, information security, or compliance.
  • Strong knowledge of data protection and U.S. regulatory standards.
  • Experience with GRC platforms (e.g., OneTrust, Archer, ServiceNow GRC).
  • Relevant certifications (CISA, CRISC, CISSP, ISO 27001 Lead Implementer, or IAPP) preferred.
  • Law firm experience preferred.
Job ID: 254

Apply for this Position