UDR Governance, Risk & Compliance Analyst II in Highlands Ranch, CO

pin
pin

UDR, Inc. is now hiring a Governance, Risk & Compliance Analyst II to join our team at our corporate office in Highlands Ranch.

GENERAL SUMMARY OF DUTIES: The GRC Analyst role(s) will be responsible for the implementation, operation, and maintenance of UDR’s IT Governance, Risk & Compliance (GRC) program in accordance with business objectives and legal requirements. All levels will work on growing and maintaining the enterprise’s audit readiness, AI governance, third-party risk management, and consumer privacy programs. These roles collaborate closely with appropriate business personnel to support the confidentiality, integrity, and availability of enterprise data and the responsible deployment of AI systems.

GRC Analyst II shall take increased ownership of GRC processes and tool utilization while working towards delivery of strategic goals, including AI governance initiatives.

SUPERVISION RECEIVED: Reports directly to the Director &- Cyber Risk and Privacy

SUPERVISION EXERCISED: N/A

ESSENTIAL FUNCTIONS:

1. Lead evidence collection and coordination for external and internal audits, including Sarbanes-Oxley (SOX) and NIST CSF, working directly with both internal and external auditors as well as internal control owners.

2. Identify control gaps and remediation opportunities through audit findings and proactively communicate recommendations to management.

3. Lead AI governance implementation tasks, including maintaining enterprise AI technical feasibility assessments, conducting AI vendor risk assessments, and supporting the development of AI use policies and standards.

4. Advise business stakeholders on AI-related risks, including fair-housing implications of AI-assisted leasing or screening tools, and SEC disclosure obligations related to material AI risks.

5. Manage vendor due diligence and third-party risk assessments, with specialized focus on evaluating AI-enabled vendor tools for algorithmic transparency, bias testing, and data governance practices.

6. Manage and track vendor certification/recertification status and maintain the approved vendor list.

7. Manage the program to document, analyze, and fulfill all consumer data privacy requests received by UDR, including state-specific requirements.

8. Advise the business on federal and state privacy compliance issues and best practices in accordance with applicable state laws.

9. Research new and evolving legal requirements as they relate to consumer privacy, AI governance, and relevant GRC domain areas.

10. Advise project teams on data privacy and AI risks associated with specific business activities and data use.

11. Create and edit organizational policies as they pertain to information technology, AI governance, and GRC.

12. Lead the implementation and maintenance of GRC applications, tools, and systems in accordance with program policy and industry best practice.

13. Create and design reporting, metrics, and dashboards to support compliant and transparent IT operations.

14. Communicate with consumers and across the enterprise in a timely, professional, and precise manner.

15. Manage processes for digital forensics and evidence chain of custody for any incident or investigation related to data privacy.

16. Consult with key stakeholders on privacy and AI governance assessments; serve as a subject matter expert for IT Operations.

17. Lead organizational data privacy and AI governance training and awareness efforts.

18. Perform other duties as assigned or as necessary.

EDUCATION AND EXPERIENCE:

1. Bachelor’s degree in Information Systems, Cybersecurity, a related field, or equivalent experience required.

2. Minimum of three years’ experience in GRC, data privacy, risk management, audit support, and/or information security.

3. Demonstrable advanced knowledge and understanding of data privacy laws, including state-specific laws in Colorado, California, and emerging state privacy laws.

4. Hands-on experience supporting SOX and/or NIST CSF audits, including evidence gathering and control testing.

5. Experience evaluating third-party and vendor risk, including vendors utilizing AI-enabled tools.

6. Working knowledge of AI governance principles, including AI risk assessment, vendor transparency requirements, and fair-housing implications of automated decision-making tools.

7. Work experience with data privacy, third-party risk management, and contract lifecycle management software and tools.

8. Work experience with policy lifecycle processes to include drafting, editing, and publishing preferred.

9. CIPP/US, CIPM, CIPT, CISA, or other related certification preferred.

Benefits Offered:

  • Medical, Dental, Vision Plans
  • Medical Flexible Spending Account
  • Dependent Care Spending Account
  • Lifestyle Spending Account
  • Supplemental Term Life Insurance
  • Critical Illness Plan
  • Supplemental Short-Term Disability Insurance / AD&D Insurance
  • Voluntary Long Term Care Insurance
  • 401(k) Plan with company match

Salary Range:
& $85,000.00/yr. &- $100,000.00/yr., depends on experience

Bonus Potential:
& Eligible for 10% annual bonus potential, based on personal and company performance

Anticipated Close Date: July 1, 2026

UDR is proud to provide equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, or local laws.

This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training.

UDR is committed to providing and maintaining a diverse workforce and an inclusive work environment with equitable access and opportunity for associates to participate, grow, and reach their full potential.

The GRC Analyst role(s) will be responsible for the implementation, operation, and maintenance of UDR's IT Governance, Risk & Compliance (GRC) program in accordance with business objectives and legal requirements. All levels will work on growing and maintaining the enterprise's audit readiness, AI governance, third-party risk management, and consumer privacy programs. These roles collaborate closely with appropriate business personnel to support the confidentiality, integrity, and availability of enterprise data and the responsible deployment of AI systems. GRC Analyst II shall take increased ownership of GRC processes and tool utilization while working towards delivery of strategic goals, including AI governance initiatives. SUPERVISION RECEIVED: Reports directly to the Director - Cyber Risk and Privacy SUPERVISION EXERCISED: N/ A ESSENTIAL FUNCTIONS: 1. Lead evidence collection and coordination for external and internal audits, including Sarbanes-Oxley (SOX) and NIST CSF, working directly with both internal and external auditors as well as internal control owners. 2. Identify control gaps and remediation opportunities through audit findings and proactively communicate recommendations to management. 3. Lead AI governance implementation tasks, including maintaining enterprise AI technical feasibility assessments, conducting AI vendor risk assessments, and supporting the development of AI use policies and standards. 4. Advise business stakeholders on AI-related risks, including fair-housing implications of AI-assisted leasing or screening tools, and SEC disclosure obligations related to material AI risks. 5. Manage vendor due diligence and third-party risk assessments, with specialized focus on evaluating AI-enabled vendor tools for algorithmic transparency, bias testing, and data governance practices. 6. Manage and track vendor certification/recertification status and maintain the approved vendor list. 7. Manage the program to document, analyze, and fulfill all consumer data privacy requests received by UDR, including state-specific requirements. 8. Advise the business on federal and state privacy compliance issues and best practices in accordance with applicable state laws. 9. Research new and evolving legal requirements as they relate to consumer privacy, AI governance, and relevant GRC domain areas. 10. Advise project teams on data privacy and AI risks associated with specific business activities and data use. 11. Create and edit organizational policies as they pertain to information technology, AI governance, and GRC. 12. Lead the implementation and maintenance of GRC applications, tools, and systems in accordance with program policy and industry best practice. 13. Create and design reporting, metrics, and dashboards to support compliant and transparent IT operations. 14. Communicate with consumers and across the enterprise in a timely, professional, and precise manner. 15. Manage processes for digital forensics and evidence chain of custody for any incident or investigation related to data privacy. 16. Consult with key stakeholders on privacy and AI governance assessments; serve as a subject matter expert for IT Operations. 17. Lead organizational data privacy and AI governance training and awareness efforts. 18. Perform other duties as assigned or as necessary. EDUCATION AND EXPERIENCE: 1. Bachelor's degree in Information Systems, Cybersecurity, a related field, or equivalent experience required. 2. Minimum of three years' experience in GRC, data privacy, risk management, audit support, and/or information security. 3. Demonstrable advanced knowledge and understanding of data privacy laws, including state-specific laws in Colorado, California, and emerging state privacy laws. 4. Hands-on experience supporting SOX and/or NIST CSF audits, including evidence gathering and control testing. 5. Experience evaluating third-party and vendor risk, including vendors utilizing AI-enabled tools. 6. Working knowledge of AI governance principles, including AI risk assessment, vendor transparency requirements, and fair-housing implications of automated decision-making tools. 7. Work experience with data privacy, third-party risk management, and contract lifecycle management software and tools. 8. Work experience with policy lifecycle processes to include drafting, editing, and publishing preferred. 9. CIPP/ US, CIPM, CIPT, CISA, or other related certification preferred. Benefits Offered: Medical, Dental, Vision Plans Medical Flexible Spending Account Dependent Care Spending Account Lifestyle Spending Account Supplemental Term Life Insurance Critical Illness Plan Supplemental Short-Term Disability Insurance / AD&D Insurance Voluntary Long Term Care Insurance 401(k) Plan with company match Salary Range: - $85,000.00/yr. - $100,000.00/yr., depends on experience Bonus Potential: - Eligible for 10% annual bonus potential, based on personal and company performance Anticipated Close Date: July 1, 2026 UDR is proud to provide equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, or local laws. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training. UDR is committed to providing and maintaining a diverse workforce and an inclusive work environment with equitable access and opportunity for associates to participate, grow, and reach their full potential.
search terms: Compliance Analyst+Risk
pin
pin
Local Job Bulletin is an independent Job Search Engine. Local Job Bulletin is not endorsed, sponsored or affiliated with the actual employer of the job. All trademarks, service marks, logos, domain names, and job descriptions are the property of their respective holder.
Upload your Resume - Let Employers find you!
pin
pin
 
 
Local Job Bulletin is an independent Job Search Engine. Local Job Bulletin is not an agent or representative and is not endorsed, sponsored or affiliated with any employer. Local Job Bulletin uses proprietary technology to keep the availability and accuracy of its job listings and their details. All trademarks, service marks, logos, domain names, job descriptions and other company descriptions / details are the property of their respective holder. Local Job Bulletin does not have its users apply for a job on the LocalJobBulletin.com website. Additionally, Local Job Bulletin may provide a list of third-party job listings that may not be affiliated with any employer. Please make sure you understand and agree to the website's Terms & Conditions and Privacy Policies you are applying on as they may differ from ours and are not in our control.;
pin
pin