The posting, in Zoro's own words
archived Oct 2, 2026Company Summary Zoro.com is a leading eCommerce platform offering nearly 12 million tools, parts and supplies for our business customers. Launched in 2011, we brought a B2C-like experience to the B2B industry, and continue to be at the forefront of digital innovation at the intersection of technology and distribution. We have rapidly grown to over $1 billion in annual revenue and we’re just getting started!
Job Summary:
The Governance, Risk & Compliance (GRC) Analyst supports the development, execution, and continuous improvement of Zoro's Governance, Risk & Compliance program with a primary focus on Operational Resilience, including Business Continuity, Disaster Recovery, and Incident Response governance. The role also supports broader GRC initiatives including SOX compliance, third-party risk management, technology risk assessments, and audit readiness.
Read the full posting ↓
Duties & Responsibilities:
Coordinate and continuously improve Zoro's Business Continuity and Disaster Recovery (BCDR) program by partnering with Grainger and cross-functional business and technology stakeholders to maintain Business Continuity Plans (BCPs), Disaster Recovery (DR) plans, Business Impact Analyses (BIAs), and annual plan refreshes. Coordinate and facilitate business continuity and disaster recovery exercises, tabletop exercises, and recovery testing while documenting results, tracking action items, and driving continuous improvement across the Operational Resilience program. Develop program metrics and identify opportunities to enhance organizational resilience beyond enterprise minimum requirements. Maintain governance documentation supporting Zoro's Incident Response Program (IRP), coordinate annual reviews and updates, and facilitate incident response tabletop exercises. Partner with stakeholders to coordinate post-incident remediation activities, track medium- and high-priority action items, and report on remediation status. Support governance, risk, and compliance initiatives including technology risk assessments, policy and standards development, audit readiness, and enterprise risk management activities. Partner with business and technology teams to strengthen governance processes, maintain risk documentation, and promote continuous improvement across the GRC program. Support expansion of Zoro's SOX program by onboarding new systems, applications, and business processes into SOX scope, coordinating design and implementation of new technology controls, and partnering with Grainger's Internal Controls organization on SOX governance activities. Support Zoro's Third-Party Risk Management (TPRM) program by coordinating vendor risk assessments, SOC report reviews, remediation tracking, and ongoing monitoring of third-party technology risk.
Qualifications:
Familiarity with Governance, Risk & Compliance disciplines, including Business Continuity & Disaster Recovery (BCDR), Incident Response, Third-Party Risk Management (TPRM), SOX compliance, and technology risk management. Knowledge of IT risk and control frameworks, including SOX IT requirements, COSO, COBIT, NIST Cybersecurity Framework (CSF), PCAOB, and PCI-DSS standards. Understanding of IT General Controls (ITGCs), IT Application Controls (ITACs), User Access Reviews (UARs), Segregation of Duties (SoD), and technology governance practices. Experience coordinating cross-functional initiatives and building effective working relationships with business and technology stakeholders. Experience working with cloud environments, enterprise applications, databases, and operating systems. Strong organizational, analytical, and problem-solving skills with the ability to manage multiple priorities simultaneously. Ability to write clearly and communicate technical concepts effectively to both technical and non-technical stakeholders across all levels of the organization. Bachelor's degree preferred. 2–5 years of experience in IT Audit, Governance, Risk & Compliance, Risk Management, Compliance, Cybersecurity, or Consulting (e.g., Big 4 or equivalent). Relevant professional certifications such as CISA, CRISC, CISSP, or CIA are preferred. Positive self-starter with a strong attention to detail and a continuous improvement mindset.