Business Analyst - GRC - US Citizen
This is the employer's own posting, not a copy on a job board.
What we know
Is it still open?
Confirmed still open
Last checked 2h ago — checked against the employer's own applicant tracking system, which is the company answering directly.
We re-read the employer's own applicant tracking system and the posting was still there. That is the company answering directly.
How old is it?
Posted 29d ago
The date the source published, not the day we noticed it (2026-09-04). Last seen at its source just now.
Is it remote?
Marked remote on the employer's board
Their board carries a remote setting on this posting — a field they filled in, not wording we read. The location field names somewhere specific, which is usually where the team or the entity sits.
Who may apply?
United States
The description states no restriction of its own. This is the source's own tag.
Pay not stated
Similar roles pay $105k–181.3k/yr
Middle 50% of 1123 listings that do state pay — Operations · all levels · United States · USD/year. This employer has published no salary; this is what comparable listings we hold disclose, never converted between currencies or periods. How this is calculated.
Skills named in the ad
Recognised terms only, from a fixed vocabulary — this is what CV matching compares against.
Carried by 1 source
-
bamboohr employer's own board first seen 2h ago · last seen just now
The listing
US Citizen Applicants Only
SafePaaS is seeking a
Business Analyst with a compliance and IT risk background
to bridge business stakeholders, client teams, and technical delivery on GRC implementations. This role focuses on requirements gathering, data analysis, and dashboard/reporting delivery for clients using SafePaaS to manage SoD violations, access risk, and regulatory controls — rather than deep ERP security configuration itself. It's ideal for someone who understands financial risk, fraud patterns, and regulatory frameworks, and can translate those into system requirements, controls logic, and stakeholder-facing reporting.
Key Responsibilities
- Elicit and document business requirements from client stakeholders (compliance, audit, risk, and IT teams) for SoD rules, access controls, and risk libraries within the SafePaaS platform.
- Translate regulatory requirements into functional specifications and user stories for the SafePaaS product/config team.
- Build dashboards and reports visualizing SoD violations, remediation status, control effectiveness, and audit-readiness metrics for client stakeholders and internal leadership.
- Support client onboarding by mapping business processes and risk taxonomies to SafePaaS rule sets, working alongside technical configuration teams.
- Facilitate Agile ceremonies for platform enhancement and client implementation projects, managing requirements in JIRA/Confluence.
- Prepare audit-ready documentation: functional specs, SOPs, control narratives, and remediation reports.
- Serve as a liaison between clients' compliance/audit teams and SafePaaS's technical delivery team, ensuring requirements are accurately captured and delivered.
- Stay current on emerging risk areas — including AI/non-human identity (NHI) governance and evolving regulatory frameworks — and help incorporate them into requirements.
Required Qualifications
- Bachelor's degree in Business, Systems Engineering, Finance, or related field.
- 4+ years of Business Analyst experience, ideally within financial compliance, fraud/risk, or regulatory environments.
- Strong SQL skills and experience validating/reconciling data across multiple systems.
- Experience with Agile/Scrum delivery (JIRA, Confluence) and writing user stories/functional specs.
- Strong dashboard/reporting skills (Power BI or equivalent BI tools).
- Understanding of internal controls frameworks (SOX, COSO, ITGC) and segregation of duties concepts.
- Excellent stakeholder communication skills, with experience working across compliance, audit, and technical teams.
Preferred Qualifications
- Familiarity with ERP security/access governance concepts (Oracle GRC/AACG/CCG/PCG, SAP GRC, or similar platforms) — hands-on config experience not required but a plus.
- Experience supporting regulatory/government clients (SEC, FHFA, financial institutions).
- US Federal Agency Security Clearance