Jobs and Careers
GR

Information Security Governance, Risk and Compliance Analyst

Green Thumb Industries
United Statesfull_timeVerifiedPosted 15 Jan 2026
💰 $100,000/yr($80,000/yr$100,000/yr)

About the role

The Role 

We're looking for an Information Security Governance, Risk & Compliance Analyst to join our growing Information Security team. This role will be reporting to the Manager of Information Security Governance, Risk & Compliance. Our security team works to create a strong Information Security function within GTI that enables the business to continue its tremendous growth. The Information Security Governance, Risk & Compliance Analyst is responsible for maintaining continuous compliance with security policies, industry laws, and regulations (HIPAA, SOX, NIST, etc.). The candidate must communicate effectively with business partners and team members to help raise the level of security awareness, security compliance, and security risk. The candidate will perform environment-specific risk assessments factoring in both qualitative and quantitative risks and assist with the deployment of various controls based on those assessments. This role will also involve ongoing monitoring and improvement of security governance, ensuring a proactive approach to risk management. 

The role is based out of our Chicago, office. While the role is primarily remote, you need to live in the Chicagoland area and commute to the office on an as needed basis. 

Responsibilities 

  • Own the relationship working with IT and business stakeholders to perform ongoing internal and vendor risk assessments, providing reporting to stakeholders, and ensuring appropriate action is taken.  
  • Update and track KPIs from the Information Security risk register and work with stakeholders on developing Corrective Action Plans to address risks. 
  • Provide guidance to newer staff working with internal IT stakeholders for vulnerability management, ensuring vulnerabilities are remediated in accordance with policy and SLAs. 
  • Own the process for working with IT and business stakeholders to perform ongoing compliance reviews in line with security policies, information security regulations (HIPAA, SOX/ITGC), and security frameworks (NIST, MITRE, etc.). 
  • Assist with ongoing internal operations and tasks, including ITGC security reviews. 
  • Spearhead the ongoing internal and external SOX and HIPAA audits and other security audits that are relevant to GTI’s business. 
  • Provide updates and insight during the development and maintenance of Information Security policies, standards and procedures, aligning with NIST. 
  • Lead the identification of security training and awareness initiatives for the organization. 
  • Participate in incident response tabletops, business continuity tests, and other compliance activities and exercises. 
  • Maintain KPIs and KRIs for Information Security risk & compliance activities. 
  • Execute tasks as a member of the Information Security team as assigned by management. 
  • Provide mentorship and guidance to Associate Information Security GRC Analysts.  
  • Stay up to date on relevant laws and regulations to ensure continuous compliance and audit readiness. 
  • Collaborate with the IT and security teams in response to security incidents, ensuring proper documentation and reporting. 

Qualifications  

  • 3+ years of experience with responsibilities relating to security and compliance. 

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Green Thumb Industries

View company profile →