Grainger Logo

Grainger

Security Analyst - Risk

Posted 20 Hours Ago
Be an Early Applicant
Hybrid
Lake Forest, IL
68K-113K Annually
Mid level
Hybrid
Lake Forest, IL
68K-113K Annually
Mid level
The Security Analyst will assess, manage, and mitigate information security risks, evaluate security controls and collaborate with various stakeholders to document and report on risk management efforts.
The summary above was generated by AI
Work Location Type: Hybrid
Req Number 327126
About Grainger:
W.W. Grainger, Inc., is a leading broad line distributor with operations primarily in North America, Japan and the United Kingdom. At Grainger, We Keep the World Working® by serving more than 4.5 million customers worldwide with products and solutions delivered through innovative technology and deep customer relationships. Known for its commitment to service and award-winning culture, the Company had 2024 revenue of $17.2 billion across its two business models. In the High-Touch Solutions segment, Grainger offers approximately 2 million maintenance, repair and operating (MRO) products and services, including technical support and inventory management. In the Endless Assortment segment, Zoro.com offers customers access to more than 14 million products, and MonotaRO.com offers more than 24 million products. For more information, visit www.grainger.com.
Compensation:
The anticipated base pay compensation range for this position is $67,900.00 to $113,200.00.
This position is not eligible for any form of sponsorship now or in the future. Individuals requiring sponsorship (e.g. OPT or H1B visa status) should not apply. Only individuals authorized to work in the United States now and for the foreseeable future will be considered for this position.
Rewards and Benefits
With benefits starting on day one, our programs provide choice and flexibility to meet team members' individual needs, including:
  • Medical, dental, vision, and life insurance plans with coverage starting on day one of employment and 6 free sessions each year with a licensed therapist to support your emotional wellbeing.
  • 18 paid time off (PTO) days annually for full-time employees (accrual prorated based on employment start date) and 6 company holidays per year.
  • 6% company contribution to a 401(k) Retirement Savings Plan each pay period, no employee contribution required.
  • Employee discounts, tuition reimbursement, student loan refinancing and free access to financial counseling, education, and tools.
  • Maternity support programs, nursing benefits, and up to 14 weeks paid leave for birth parents and up to 4 weeks paid leave for non-birth parents.

For additional information and details regarding Grainger's benefits, please click on the link below:
https://experience100.ehr.com/grainger/Home/Tools-Resources/Key-Resources/New-Hire
The pay range provided above is not a guarantee of compensation. The range reflects the potential base pay for this role at the time of this posting based on the job grade for this position. Individual base pay compensation will depend, in part, on factors such as geographic work location and relevant experience and skills.
The anticipated compensation range described above is subject to change and the compensation ultimately paid may be higher or lower than the range described above.
Grainger reserves the right to amend, modify, or terminate its compensation and benefit programs in its sole discretion at any time, consistent with applicable law.
Position Details
The Information Security Risk Advisory professional supports the organization's efforts to identify, assess, and manage information security and technology risks. You will work closely with security, IT, business, and third-party stakeholders to evaluate security controls, assess risk exposure, and provide practical, risk-based recommendations that align with business objectives.
You will collaborate with internal audit, legal, privacy, and compliance teams to support audits, risk reporting, and ongoing monitoring activities. They help translate technical security concepts into clear, actionable insights for stakeholders and contribute to the development and maintenance of risk documentation, metrics, and reporting.
This position is not eligible for any form of sponsorship now or in the future. Individuals requiring sponsorship (e.g. OPT or H1B visa status) should not apply. Only individuals authorized to work in the United States now and for the foreseeable future will be considered for this position.
You will
  • Perform information security risk assessments, control testing, and security reviews across systems, applications, and processes.
  • Support compliance efforts by assessing alignment with internal policies, regulatory requirements, and industry frameworks such as NIST CSF, PCI DSS 4.0, and related standards, and by assisting in the identification and tracking of remediation activities.
  • Contribute to third-party risk management activities, including reviewing vendor security documentation, conducting risk assessments, and supporting risk rating, issue tracking, and risk acceptance processes.
  • Support technology initiatives-such as new system implementations, cloud services, and process changes-by identifying potential risks and control gaps and advising on mitigation strategies.
  • Strong analytical and communication skills, attention to detail, and the ability to manage multiple priorities.
  • Work independently on assigned assessments while escalating complex risks as needed, contributing to continuous improvement of the organization's information security risk management program.

You have
  • Bachelor's degree in Information Security, Information Systems, Computer Science, Risk Management, or a related field, or equivalent practical experience
  • 2-4 years of experience in information security, technology risk, cybersecurity, GRC, internal audit, or risk advisory roles
  • Working knowledge of information security and risk frameworks such as NIST CSF, NIST 800-53, or similar standards
  • Experience conducting risk assessments, control reviews, and gap analyses across applications, infrastructure, cloud environments, or business processes
  • Familiarity with third-party and vendor risk management, including review of security questionnaires, SOC reports, and other assurance artifacts
  • Ability to document findings clearly and communicate technical risks in business-focused language
  • Experience supporting audits, regulatory examinations, or compliance initiatives in collaboration with internal audit, legal, and compliance teams
  • Strong analytical, organizational, and time-management skills with the ability to manage multiple assessments concurrently

Preferred
  • Relevant certifications such as CISA, CRISC, CISSP, or progress toward certification
  • Understanding of common security domains (e.g., access management, data protection, incident response, vulnerability management, network security)
  • Experience in regulated environments (financial services, healthcare, technology, or similar)
  • Exposure to cloud security concepts (AWS, Azure, GCP) and modern technology environments
  • Experience preparing risk metrics, dashboards, or management-level reporting

We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex (including pregnancy), national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or expression, protected veteran status or any other protected characteristic under federal, state, or local law. We are proud to be an equal opportunity workplace.
We are committed to fostering an inclusive, accessible work environment that includes both providing reasonable accommodations to individuals with disabilities during the application and hiring process as well as throughout the course of one's employment, should you need a reasonable accommodation during the application and selection process, including, but not limited to use of our website, any part of the application, interview or hiring process, please advise us so that we can provide appropriate assistance.

Top Skills

AWS
Azure
GCP
Nist Csf
Pci Dss 4.0

Grainger Chicago, Illinois, USA Office

In the heart of Chicago's River North neighborhood, Grainger's offices at theMART are walking distance from many transit stations and moments from the expressway. This prime location and open floor offices help team members collaborate and build the best solutions as they bring new ideas to life.

Product Team

At Grainger, team members are always experimenting and discovering new ways to use technology to connect maintenance, repair and operations (MRO) customers to the products they need to keep their business up and running and their people safe. “Working on the Grainger Product team means I get to solve mission critical issues that move the entire business forward,” says Dahlia Block, Software Engineer, Product and Platform Engineering. Ryan Chamberlin, Manager of Product Engineering agrees, “Grainger is committed to continuous improvement and innovation, which creates exciting opportunities for employees to learn and grow.”

AI & Machine Learning Team

We are designing, delivering, and operating the digital experiences, tools, and information assets that solve customers’ problems. Our scale presents complex and interesting engineering challenges that are solved by technologists at the top of their game. Alan Cooney, Senior Manager of Applied Machine Learning shares, “Over the past few years, we have integrated ML into many aspects of our customer interactions- all with a focus of making the experience better for our customer’s." David Brenner, Director of Product Management shared similar sentiments, stating, “Grainger’s purpose: We Keep The World Working® is apparent in the way we design, deliver, and operate digital experiences, tools, and information that solve customers’ needs."

Similar Jobs at Grainger

20 Hours Ago
Hybrid
Lake Forest, IL, USA
105K-174K Annually
Expert/Leader
105K-174K Annually
Expert/Leader
eCommerce • Information Technology • Retail • Industrial
The Senior GPO Manager will design and implement a GPO strategy, drive profitable growth, manage contracts, and build customer relationships to meet financial objectives.
20 Hours Ago
Hybrid
Lake Forest, IL, USA
87K-145K Annually
Mid level
87K-145K Annually
Mid level
eCommerce • Information Technology • Retail • Industrial
The Infrastructure Administrator III will manage server environments, automate system tasks, provide technical support, and collaborate with teams to improve operational efficiency while mentoring peers.
Top Skills: Ansible Automation PlatformAWSRelational DatabasesSplunkTcp/IpTerraformZenoss
20 Hours Ago
Hybrid
Lake Forest, IL, USA
134K-224K Annually
Senior level
134K-224K Annually
Senior level
eCommerce • Information Technology • Retail • Industrial
As a Staff Software Engineer IV, you will design and build backend platforms for AI-enabled experiences and lead architecture efforts, ensuring reliability and scalability of backend services.
Top Skills: AWSAzureDatadogDockerFastapiFlaskGCPKibanaKubernetesPrometheusPython

What you need to know about the Chicago Tech Scene

With vibrant neighborhoods, great food and more affordable housing than either coast, Chicago might be the most liveable major tech hub. It is the birthplace of modern commodities and futures trading, a national hub for logistics and commerce, and home to the American Medical Association and the American Bar Association. This diverse blend of industry influences has helped Chicago emerge as a major player in verticals like fintech, biotechnology, legal tech, e-commerce and logistics technology. It’s also a major hiring center for tech companies on both coasts.

Key Facts About Chicago Tech

  • Number of Tech Workers: 245,800; 5.2% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: McDonald’s, John Deere, Boeing, Morningstar
  • Key Industries: Artificial intelligence, biotechnology, fintech, software, logistics technology
  • Funding Landscape: $2.5 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Pritzker Group Venture Capital, Arch Venture Partners, MATH Venture Partners, Jump Capital, Hyde Park Venture Partners
  • Research Centers and Universities: Northwestern University, University of Chicago, University of Illinois Urbana-Champaign, Illinois Institute of Technology, Argonne National Laboratory, Fermi National Accelerator Laboratory

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account