Jobs and Careers
UN

IT GRC Program Administrator II

United Wholesale Mortgage
United Statesfull_timeVerifiedPosted 5 Aug 2026

About the role

 

As an IT GRC Program Administrator II at United Wholesale Mortgage, your role involves leading information security initiatives to minimize risk and maximize compliance. Responsibilities will include assessments, management of audit fulfillment and risk remediation, as well as governance of business data and records. You will also play a pivotal role in key programs like Business Continuity/Disaster Recovery, IT Risk Management, Third Party Risk Management, Data Governance, and Security Awareness.

 

Your function extends to monitoring adherence to security controls and compliance standards, spearheading specific initiatives, and nurturing an environment of security awareness through coaching. All planning, coordination, and execution of work assignments will align with the priorities established by the Information Security Team Lead.

WHAT YOU WILL BE DOING

  • Maintaining and enhancing corporate policies in line with industry standards and corporate needs.
  • Ensuring effective communication and comprehension of policy obligations across various stakeholders through multiple channels.
  • Regularly reviewing, updating, and modifying policies to align with organizational changes.
  • Improving and managing the implementation of metrics for GRC activities to monitor compliance adherence, risk treatment, and improvement projects.
  • Regularly reporting these metrics and progress to various audiences, including senior leadership.
  • Managing and optimizing a risk register that encapsulates all risks affecting the business and facilitating the gathering and tracking of these risks.
  • Continually refining our approach to risk evaluation and ensuring a common risk communication language across the organization.
  • Regularly monitoring and reassessing organizational risks, adjusting the organization's stance based on in-place controls.
  • Managing and enhancing our third-party risk management program, including refining evaluation criteria, expected evidence, reevaluation timeframe, and remediation processes.
  • Regularly evaluating new and existing vendors based on their criticality to the business and integrating third-party evaluations into workflows.
  • Identifying third-party issues and tracking them till remediation or business acceptance, and effectively managing third-party offboarding obligations.
  • Enhancing data standards, processes, and procedures to ensure data integrity and compliance, conducting regular audits for data accuracy, completeness, and reliability.
  • Collaborating with stakeholders to understand and document data privacy requirements and assisting with the development of data security models and design.
  • Collaborating with IT and business teams to develop a robust IT risk management framework, regularly reviewing and updating this framework in line with emerging trends, threats, and industry best practices such as ISO 27001, NIST, or COSO.
  • Implementing, managing, and enhancing comprehensive GRC frameworks and toolsets, ensuring they align with organizational needs.
  • Supporting incident management activities in accordance with established frameworks, including incident identification, assessment, tracking, and resolution.
  • Developing and delivering GRC-related training to enhance the organization's understanding of concepts related to compliance, risk, and cybersecurity
  • Facilitating internal and external due diligence requests in accordance with various regulatory agencies and managing the implementation of audit recommendations.
  • Collaborating with legal and regulatory bodies to ensure the organization's cybersecurity program is compliant with all relevant laws, regulations, and industry-standard frameworks.
  • Managing the organization's business continuity planning and disaster recovery efforts in line with accepted frameworks, ensuring plans are regularly updated and tested.
  • Driving the integration of GRC principles and frameworks into the organization's culture and daily activities.
  • Regularly reporting on the status of GRC activities to Senior Leadership and other stakeholders, providing insight into the organization's risk posture, compliance status, and governance effectiveness per established frameworks.
  • Developing and maintaining relationships with external vendors, partners, regulators, and industry bodies to keep abreast of developments in the GRC field, including emerging frameworks and best practices.

WHAT WE NEED FROM YOU

Must Have:

  • Bachelor's Degree in Information Technology, Information Security or equivalent, with preferred certifications in CISA, CISSP, CISM, GSEC, BCP, CGRC, or other relevant information security.
  • 2-4 years of experience in IT compliance, risk management, cybersecurity policy analysis, and audit-

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

United Wholesale Mortgage

View company profile →