Logo for CMG Financial

Senior IT GRC Analyst

Role overview

Qualifications

  • Bachelor's degree in Information Technology, Cybersecurity, or a related field (equivalent experience considered)
  • 5+ years of experience in IT audit, compliance, or GRC in an enterprise IT environment
  • Demonstrated experience managing SOC 2 audit cycles (Type I or Type II) from scoping through remediation
  • Strong working knowledge of relevant IT compliance frameworks, such as NIST CSF, ISO 27001, or SOX

Responsibilities

  • Lead CMG's SOC 2 readiness assessment, including scope definition, gap analysis, and control design
  • Serve as a point of contact during audit engagements and regulatory exams
  • Develop, maintain, and update IT policies, standards, and procedures to align with NIST CSF and other applicable regulatory requirements
  • Plan and execute audit activities, including scheduling, control walkthroughs, evidence gathering, and findings documentation

Key facts

  • Remote from: United States
  • Full time
  • Senior (5-10 years)
  • English

Other skills

  • Communication
  • Teamwork
  • Problem Solving

About the company

CMG Financial logo

CMG Financial

Mortgage & Real Estate Finance

Nationwide mortgage lender with Correspondent, Wholesale, and Retail origination channels. NMLS# 1820 Throughout the mortgage industry, CMG Financial is known for its innovation of product and continued investment in technology. From HomeFundIt, the down payment gifting platform to the All In One Loan, the smarter way to borrow, CMG develops mortgage solutions that serve the needs of every borrower.CMG Financial holds federal agency lending approvals with HUD, VA, RHS, GNMA, FNMA and FHLMC and makes its products and services available through three distinct origination channels: Retail, Correspondent, and Wholesale Lending. Team CMG specializes in all new purchase and refinance mortgage needs and act as financial counselors to help borrowers make informed decisions. Find out what β€œEvery Customer, Every Time. No Exceptions, No Excuses.” means to us!

Company details

Company typeSME
IndustryMortgage & Real Estate Finance
Company size501 - 1000

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

Description

The Senior IT GRC Analyst leads policy development and audit execution within CMG's IT Governance, Risk, and Compliance program, with particular emphasis on CMG's upcoming SOC 2 readiness effort. This role works closely with the GRC team and the broader IT department to plan and execute audit engagements, maintain the policy framework, and manage auditor relationships. The Senior IT GRC Analyst operates with a high degree of autonomy and is expected to navigate ambiguity in a regulated environment.

 

 

ESSENTIAL DUTIES and RESPONSIBILITIES, includes the following responsibilities, but not limited to:

  • Lead CMG's SOC 2 readiness assessment, including scope definition, gap analysis, and control design, in partnership with the IT GRC Manager.
  • Serve as a point of contact during audit engagements and regulatory exams.
  • Develop, maintain, and update IT policies, standards, and procedures to align with NIST CSF and other applicable regulatory requirements.
  • Plan and execute audit activities, including scheduling, control walkthroughs, evidence gathering, and findings documentation.
  • Identify control gaps, coordinate remediation planning with control owners, tracking findings and remediation status through the risk register.
  • Provide guidance to other GRC team members and IT leadership on audit and policy matters.
  • Research regulatory and framework changes relevant to mortgage lending and financial services, and translate them into policy updates.
  • Contribute to the ongoing development and improvement of GRC processes and tooling.

 

 

REQUIRED QUALIFICATIONS:

  • Bachelor's degree in Information Technology, Cybersecurity, or a related field (equivalent experience considered).
  • 5+ years of experience in IT audit, compliance, or GRC in an enterprise IT environment.
  • Demonstrated experience managing SOC 2 audit cycles (Type I or Type II) from scoping through remediation.
  • Direct experience in financial services, mortgage lending, or related regulated industries, with working knowledge of applicable regulations (GLBA, CFPB, NYDFS).
  • Strong working knowledge of relevant IT compliance frameworks, such as NIST CSF, ISO 27001, or SOX.
  • Strong policy writing and documentation skills.
  • Ability to work independently amid ambiguity, exercising sound judgment on scope and prioritization.
  • Excellent written and verbal communication skills, with the ability to explain technical and compliance matters to varied audiences.
  • Relevant certifications preferred: CISA, CRISC, or GRCP.

 

 

SUPERVISORY RESPONSIBILITIES:

Direct Reports: N/A

 

 

PHYSICAL and ENVIRONMENTAL CONDITIONS

This role operates in an ADA compliant office environment, utilizing typical office equipment and tasks including computer work. The position may involve partial stationary positions and moving throughout the day. Flexibility to work overtime to meet project deadlines is required.

 

 

Base Compensation Information – This role is a remote position that is currently allocated for candidates within geographic regions that do not currently require base wage disclosure. The compensation range for this position will be provided upon request.β€―(Due to their geographic location, residents of the states of CA & CO, and for NY are excluded from this role at this time.) 

CMG Financial is an equal opportunity employer and does not unlawfully discriminate in employment decisions. CMG will consider all qualified applicants without regard to race, religion, national origin, sex, age, veteran status, disability, familial status, marital status, actual or perceived sexual orientation, or actual or perceived gender identity. Applicants requiring reasonable accommodation to the application and/or interview process should notify a representative of CMG Financial or reach out to [email protected].

CMG MORTGAGE, INC. NMLS #1820 If you are a recruiter or placement agency, please do not submit resumes to any person or email address at CMG Financial prior to having a signed agreement . CMG Financial is not liable for and will not pay placement fees for candidates submitted by any agency other than its approved recruitment partners. Furthermore, any resumes sent to us without an agreement in place will be considered your company’s gift to CMG Financial and may be forwarded to our recruiters for their attention.

Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
Β·

Related jobs

Other jobs at CMG Financial

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.