About the job
The MLB Information Security team is seeking a dedicated Governance, Risk & Compliance (GRC) Analyst for a seasonal position. This role is essential in supporting our governance, risk management, and compliance initiatives. The selected Analyst will engage in various GRC activities, including assisting with audit preparations, conducting risk assessments, monitoring risk registers, and updating internal policies and procedures.
Key Responsibilities
- Assist in the implementation of MLB’s data privacy, governance, and risk management programs.
- Facilitate the execution of PCI-DSS and SOC 1 Type II audits by reviewing evidence, coordinating with internal stakeholders, and maintaining audit readiness dashboards.
- Perform thorough vendor security and compliance risk assessments while providing recommendations for contractual security provisions.
- Refine and maintain vendor risk review workflows, manage the vendor repository, and apply risk tiering based on data access and criticality using MLB’s TPRM tool.
- Track and manage risk acceptances and policy exceptions, ensuring proper documentation and regular reviews.
- Support the fulfillment of Data Subject Access Requests (DSAR), ensuring compliance with statutory timelines required by applicable privacy laws.
- Assist in drafting compliance policies, procedures, and playbooks related to cybersecurity, privacy, confidentiality, and data protection.
- Develop and maintain KPIs and dashboards to evaluate the success of GRC programs and initiatives.

