Junior Governance, Risk, and Compliance Specialist in Albany, New York at NY CREATES
Explore Related Opportunities
Job Description
Position Title: Junior Governance, Risk, and Compliance Specialist
Location: Albany, NY Category: Administrative Job Type: Full-Time Posted On: Tue Sep 1 2026 Job Description:
Position Summary, Junior Governance, Risk, and Compliance Specialist
The Junior GRC Specialist supports the organization's governance, risk, and compliance activities and helps maintain a risk-aware, evidence-driven GRC program across NY Creates. This role provides day-to-day support for risk assessments, risk register maintenance, third-party vendor risk reviews, cybersecurity policies and standards, internal audit activities, compliance documentation, and security awareness initiatives.
Working under the direction of the Director of GRC and Trade Compliance and senior GRC personnel, the Junior GRC Specialist assists with collecting and organizing compliance evidence, tracking remediation activities, maintaining GRC records, coordinating requests with control owners, and supporting assessments and audits. The incumbent develops practical knowledge of applicable requirements and frameworks, including NIST 800-171, CMMC 2.0, NIST Cybersecurity Framework, CIS Controls, NSPM-33, and applicable ITAR/EAR requirements.
Key Responsibilities
- Assist with enterprise risk assessments by gathering information, documenting risks, supporting risk discussions, and maintaining assigned portions of the risk register.
- Support third-party risk management activities by coordinating questionnaires, collecting and organizing vendor documentation, tracking outstanding items, and escalating concerns to senior GRC staff.
- Assist with maintaining cybersecurity policies, standards, procedures, and related documentation; help track reviews, approvals, and required updates.
- Support internal cybersecurity audits by organizing evidence, documenting control activities, tracking findings, and monitoring remediation actions.
- Assist with compliance and assessment preparation, including collecting evidence, maintaining documentation, and coordinating requests for information under the direction of senior GRC staff.
- Maintain GRC records, evidence repositories, risk registers, policy records, vendor information, and audit documentation with a high degree of accuracy.
- Assist with GRC reporting and dashboards by gathering data, updating metrics, and preparing routine reports for review by GRC leadership.
- Support security awareness and compliance training activities by maintaining training records, coordinating communications, and assisting with completion tracking.
- Assist with the administration and use of enterprise GRC tools, including workflows for risk, policy, vendor, audit, and evidence management.
- Coordinate with IT, cybersecurity, legal, procurement, and other control owners to obtain information and support compliance activities.
- Monitor assigned compliance and remediation activities and communicate overdue items or issues to the appropriate GRC team member.
- Develop working knowledge of applicable laws, regulations, contractual requirements, and cybersecurity frameworks relevant to NY Creates' environment.
- Demonstrate critical thinking, attention to detail, dependability, and the ability to organize multiple priorities in a deadline-driven environment.
- Communicate effectively with technical and non-technical personnel and maintain professional written documentation.
- Other reasonable duties as assigned.
Job Requirements:
Minimum Qualifications, Junior Governance, Risk, and Compliance Specialist
- Two (2) to three (3) years of experience in governance, risk management, cybersecurity, compliance, information technology, audit, or a related field. Relevant internship, academic, or equivalent experience may be considered.
- Bachelor's degree in Cybersecurity, Information Technology, Risk Management, Business Administration, Computer Science, or a related field from an accredited institution; equivalent relevant education and experience may be considered.
- Foundational knowledge of information security, risk management, compliance, or audit principles.
- Familiarity with one or more information security or compliance frameworks, such as NIST Cybersecurity Framework, NIST Special Publication 800-171, CMMC, CIS Controls, or ISO 9001.
- Ability to collect, organize, analyze, and accurately document information from multiple sources.
- Strong attention to detail and ability to manage multiple assignments and deadlines.
- Effective written and verbal communication skills, with the ability to communicate with both technical and non-technical personnel.
- Proficiency with Microsoft Office applications, including Word, Excel, Outlook, and PowerPoint.
This position is contingent on the satisfactory completion of a background check.
Preferred Requirements, Junior Governance, Risk, and Compliance Specialist
- Experience supporting cybersecurity, GRC, compliance, audit, risk management, or information security activities in a regulated, research, technology, federal contractor, or critical infrastructure environment.
- Familiarity with NIST 800-171, CMMC 2.0, NIST CSF, CIS Controls, or other recognized cybersecurity frameworks.
- Experience with a GRC, ticketing, compliance, document management, or audit management platform.
- Experience maintaining risk registers, audit evidence, compliance documentation, policies, or remediation tracking.
- Relevant entry-level certification such as Security+, ISC2 Certified in Cybersecurity (CC), or another related cybersecurity, audit, or compliance certification.
- Familiarity with third-party/vendor risk management processes.
- Exposure to ITAR/EAR, federal contracting, CMMC, or other regulatory requirements is a plus.
This position is contingent on the satisfactory completion of a background check; this position may require annual background checks.
Don't meet every requirement? At NY Creates we are dedicated to building a welcoming team. If you are excited about working for NY Creates but your experience doesn't exactly align perfectly with the job description, we encourage you to apply anyway, you might still be a perfect fit for this or another role.
Benefits
- Medical, Vision, and Dental
- Competitive Pay and PTO
- Flexible Heath Spending and Dependent Care Accounts
- Basic / Optional Life Insurance
- Post-Retirement Health Insurance
- Employer contribution of 7% of earnings to a Basic Retirement plan after meeting one year of service.
- Optional employee contributed retirement account
Location: 257 Fuller Road, Albany, NY 12203
Salary Range: $75,000-$95,000
*Posted salary ranges re determined upon experience and education.
Additional Information:
NOTE: Some positions require access to export-controlled commodities, technical data, technology, software, or restricted programs where U.S. Government authorization may be required.
For positions requiring such access, offers of employment are contingent upon the employer being able to obtain the necessary authorization, including, if required, an export license from the U.S. Department of Commerce's Bureau of Industry and Security, the U.S. Department of State's Directorate of Defense Trade Controls, or other government agencies. The decision to pursue an export license application is at The Research Foundation for SUNY's sole discretion. Proof of status may be required prior to employment in connection with necessary authorizations.
Employment is with the Research Foundation for SUNY. The Research Foundation is an Equal Opportunity Employer, including individuals with disabilities and protected veterans.
In compliance with the Americans with Disabilities Act (ADA), if you have a disability and require a reasonable accommodation to apply please call Human Resources at 518-437-8686.