Base Career helps you apply smarter for this job.
The IT GRC Analyst operates within the enterprise Cybersecurity Operations function and supports the Information Technology, Information Systems, and other technology teams aligned under the Chief Information Officer.
This role executes governance, risk, and compliance activities aligned with regulatory frameworks and internal policies.
include ensuring operational alignment with frameworks such as GLBA, FFIEC, SOX, NIST CSF, and the Computer Risk Institute (CRI) Profile; conducting IT assessments and Risk Control Self Assessments (RCSAs); maintaining control libraries; and supporting recurring testing, reporting, and metrics analysis and response.
The analyst contributes to recurring reporting cycles, supports departmental risk remediation and response efforts associated with findings and risks, and helps drive continuous improvement of governance practices through collaboration, documentation, and control maturity efforts.
The analyst collaborates with Enterprise Risk, Audit (internal and external), Compliance, and Policy Management teams to execute these activities effectively.
Day-to-day responsibilities include control documentation, testing coordination, assistance with reviewing and updating policies, standards, and control libraries, and policy lifecycle support.
Familiarity with GRC platforms (e.g., AuditBoard), ITSM tools (e.g., ServiceNow), and regulatory compliance in financial services is strongly preferred.
The analyst also contributes to the development and maintenance of IT policies and procedures and supports the definition and tracking of key performance indicators (KPIs) and key risk indicators (KRIs).
Success in this role requires strong technical writing skills, cross-functional engagement, and a focus on building and maintaining automation to streamline control testing and reporting processes.
The role demands a self-driven desire to continuously learn and improve along with a collaborative mindset and a willingness to meet teammates and coworkers where they are in their processes.
The analyst must be committed to helping develop, strengthen, and sustain a resilient and effective IT GRC program across the organization.
This position may be filled as a Level I, II or III.
Additional responsibilities and qualifications apply.
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
, USA
Houston, USA
Greenville, USA
Jackson, USA
Houston, USA
Mobile, USA
Jackson, USA
, USA
Additional qualifications required for Level II:
Additional qualifications required for Level III:
Must be able to sit for long periods of time and use computer keyboard and/or mouse requiring hand and wrist manipulation, while viewing computer screens.
Management retains the right to add, delete or modify the responsibilities and qualifications of the position at any time.
Trustmark Bank does not accept unsolicited resumes from agencies and/or search firms for any job postings on this site.
Resumes submitted to any Trustmark Bank employee by a third-party agency and/or search firm without a valid, written search agreement signed by Trustmark, will become the sole property of Trustmark Bank.
No fee will be paid if a candidate is hired for a position as a result of an unsolicited agency or search firm referral.
Parent group profile
Public bank holding company providing banking and wealth-management solutions to consumers and businesses through Trustmark Bank.
Visit parent group websiteFull-time
Entry
Remote
Apply faster on company sites with our extension.