Overview The IT GRC Analyst operates within the enterprise Cybersecurity Operations function and ... Serve as liaison between internal IT/IS/Cyber teams and Enterprise Risk and Audit to facilitate ...
Overview The IT GRC Analyst operates within the enterprise Cybersecurity Operations function and ... Serve as liaison between internal IT/IS/Cyber teams and Enterprise Risk and Audit to facilitate ...
The IT GRC Analyst operates within the enterprise Cybersecurity Operations function and supports ... Serve as liaison between internal IT/IS/Cyber teams and Enterprise Risk and Audit to facilitate ...
The IT GRC Analyst operates within the enterprise Cybersecurity Operations function and supports ... Serve as liaison between internal IT/IS/Cyber teams and Enterprise Risk and Audit to facilitate ...
Overview The IT GRC Analyst operates within the enterprise Cybersecurity Operations function and ... Serve as liaison between internal IT/IS/Cyber teams and Enterprise Risk and Audit to facilitate ...
Overview The IT GRC Analyst operates within the enterprise Cybersecurity Operations function and ... Serve as liaison between internal IT/IS/Cyber teams and Enterprise Risk and Audit to facilitate ...
Cybersecurity GRC Analyst I, II, or III (Depending on experience) Salary: Starting at $90,000/year ... The role includes vendor cybersecurity assessments, continuous cyber monitoring, Security ...
Cybersecurity GRC Analyst I, II, or III (Depending on experience) Salary: Starting at $90,000/year ... The role includes vendor cybersecurity assessments, continuous cyber monitoring, Security ...
Cybersecurity GRC Analyst I, II, or III
Santa Ana, CA · On-site
$90K/yr
Overview Position: Cybersecurity GRC Analyst I, II, or III (Depending on experience) Salary ... The role includes vendor cybersecurity assessments, continuous cyber monitoring, Security ...
Cybersecurity GRC Analyst I, II, or III
Santa Ana, CA · On-site
$90K/yr
Overview Position: Cybersecurity GRC Analyst I, II, or III (Depending on experience) Salary ... The role includes vendor cybersecurity assessments, continuous cyber monitoring, Security ...
Cybersecurity GRC Analyst I, II, or III
Santa Ana, CA · On-site
$90K/yr
Overview Position: Cybersecurity GRC Analyst I, II, or III (Depending on experience) Salary ... The role includes vendor cybersecurity assessments, continuous cyber monitoring, Security ...
Cybersecurity GRC Analyst I, II, or III
Santa Ana, CA · On-site
$90K/yr
Overview Position: Cybersecurity GRC Analyst I, II, or III (Depending on experience) Salary ... The role includes vendor cybersecurity assessments, continuous cyber monitoring, Security ...
Cybersecurity GRC Analyst I, II, or III
Santa Ana, CA · On-site
$90K/yr
Overview Position: Cybersecurity GRC Analyst I, II, or III (Depending on experience) Salary ... The role includes vendor cybersecurity assessments, continuous cyber monitoring, Security ...
Cybersecurity GRC Analyst I, II, or III
Santa Ana, CA · On-site
$90K/yr
Overview Position: Cybersecurity GRC Analyst I, II, or III (Depending on experience) Salary ... The role includes vendor cybersecurity assessments, continuous cyber monitoring, Security ...
Senior Director - GRC Engineer
Indianapolis, IN · On-site
$101K - $138K/yr
... synthesizing GRC Analyst outputs, KRI/KPI performance data, and assessment findings, into a ... This role also serves as the DLO's peer-level liaison to Cyber Engineering and Security ...
Senior Director - GRC Engineer
Indianapolis, IN · On-site
$101K - $138K/yr
... synthesizing GRC Analyst outputs, KRI/KPI performance data, and assessment findings, into a ... This role also serves as the DLO's peer-level liaison to Cyber Engineering and Security ...
Senior Director - GRC Engineer
Indianapolis, IN · On-site
$101K - $138K/yr
... synthesizing GRC Analyst outputs, KRI/KPI performance data, and assessment findings, into a ... This role also serves as the DLO's peer-level liaison to Cyber Engineering and Security ...
Senior Director - GRC Engineer
Indianapolis, IN · On-site
$101K - $138K/yr
... synthesizing GRC Analyst outputs, KRI/KPI performance data, and assessment findings, into a ... This role also serves as the DLO's peer-level liaison to Cyber Engineering and Security ...
The GRC Analyst will assist in maintaining compliance with the NIST Cybersecurity Framework (NIST CSF), Cybersecurity Maturity Model Certification (CMMC), Cyber Essentials Plus, SOC 2, and ISO/IEC ...
The GRC Analyst will assist in maintaining compliance with the NIST Cybersecurity Framework (NIST CSF), Cybersecurity Maturity Model Certification (CMMC), Cyber Essentials Plus, SOC 2, and ISO/IEC ...
AI GRC Architect
Columbus, OH · Hybrid
Partnering with program owners, cyber/risk stakeholders, legal/compliance teams, and platform ... Mentor engineers and analysts through architecture standards, implementation playbooks, and design ...
AI GRC Architect
Columbus, OH · Hybrid
Partnering with program owners, cyber/risk stakeholders, legal/compliance teams, and platform ... Mentor engineers and analysts through architecture standards, implementation playbooks, and design ...
The GRC Analyst will assist in maintaining compliance with the NIST Cybersecurity Framework (NIST CSF), Cybersecurity Maturity Model Certification (CMMC), Cyber Essentials Plus, SOC 2, and ISO/IEC ...
The GRC Analyst will assist in maintaining compliance with the NIST Cybersecurity Framework (NIST CSF), Cybersecurity Maturity Model Certification (CMMC), Cyber Essentials Plus, SOC 2, and ISO/IEC ...
Support cyber GRC activities, including tracking information security risks, risk exceptions, and ... impact analysis, and post incident followup. * Contribute to security awareness and training ...
Support cyber GRC activities, including tracking information security risks, risk exceptions, and ... impact analysis, and post incident followup. * Contribute to security awareness and training ...
AI GRC Architect
Berkeley Heights, NJ · Hybrid
Partnering with program owners, cyber/risk stakeholders, legal/compliance teams, and platform ... Mentor engineers and analysts through architecture standards, implementation playbooks, and design ...
AI GRC Architect
Berkeley Heights, NJ · Hybrid
Partnering with program owners, cyber/risk stakeholders, legal/compliance teams, and platform ... Mentor engineers and analysts through architecture standards, implementation playbooks, and design ...
AI GRC Architect
Alpharetta, GA · Hybrid
Partnering with program owners, cyber/risk stakeholders, legal/compliance teams, and platform ... Mentor engineers and analysts through architecture standards, implementation playbooks, and design ...
AI GRC Architect
Alpharetta, GA · Hybrid
Partnering with program owners, cyber/risk stakeholders, legal/compliance teams, and platform ... Mentor engineers and analysts through architecture standards, implementation playbooks, and design ...
... Cyber Governance, Risk, and Compliance (GRC) projects and will be a critical member of the ... Manage the process of gathering, analyzing, and assessing the current and future threat landscape ...
... Cyber Governance, Risk, and Compliance (GRC) projects and will be a critical member of the ... Manage the process of gathering, analyzing, and assessing the current and future threat landscape ...
... Cyber Governance, Risk, and Compliance (GRC) projects and will be a critical member of the ... Manage the process of gathering, analyzing, and assessing the current and future threat landscape ...
... Cyber Governance, Risk, and Compliance (GRC) projects and will be a critical member of the ... Manage the process of gathering, analyzing, and assessing the current and future threat landscape ...
GRC Cybersecurity Analyst III
Chubbuck, ID · On-site
$105 - $150/hr
This role provides strategic oversight of cyber and IT operational risk assessments, regulatory compliance, IT audit coordination, and IT policy development. GRC Cybersecurity Analyst III serves as a ...
GRC Cybersecurity Analyst III
Chubbuck, ID · On-site
$105 - $150/hr
This role provides strategic oversight of cyber and IT operational risk assessments, regulatory compliance, IT audit coordination, and IT policy development. GRC Cybersecurity Analyst III serves as a ...
Principal Security GRC Analyst
$150K - $200K/yr
As a Principal Security GRC Analyst, you will serve as a senior individual contributor driving ... ISO 27001, Cyber Essentials, CSA and others. * You will lean into AI to enable our products to ...
New
Principal Security GRC Analyst
$150K - $200K/yr
As a Principal Security GRC Analyst, you will serve as a senior individual contributor driving ... ISO 27001, Cyber Essentials, CSA and others. * You will lean into AI to enable our products to ...
New
Cyber GRC Schedule: Full-Time Shift: Day Job Travel: Yes - 10% of the time Minimum Clearance ... ORA_ON_SITE Description SAIC is seeking a Defensive Cyber Operations Analyst to support the ...
Cyber GRC Schedule: Full-Time Shift: Day Job Travel: Yes - 10% of the time Minimum Clearance ... ORA_ON_SITE Description SAIC is seeking a Defensive Cyber Operations Analyst to support the ...
Cyber Grc Analyst information
See salary details
$34K - $46.9K
4% of jobs
$46.9K - $59.8K
0% of jobs
$59.8K - $72.7K
4% of jobs
$72.7K - $85.6K
7% of jobs
$96.2K is the 25th percentile. Wages below this are outliers.
$85.6K - $98.5K
11% of jobs
$98.5K - $111.5K
5% of jobs
The median wage is $116.7K / yr.
$111.5K - $124.4K
44% of jobs
$124.4K - $137.3K
10% of jobs
$137.3K - $150.2K
11% of jobs
$150.2K - $163.1K
2% of jobs
$163.1K - $176K
0% of jobs
$34K
$112.9K
$176K
How much do cyber grc analyst jobs pay per year?
What is a Cyber GRC Analyst?
How does a Cyber GRC Analyst typically collaborate with other departments to manage organizational risk?
What are the key skills and qualifications needed to thrive as a Cyber GRC Analyst, and why are they important?
What is the difference between Cyber Grc Analyst vs Cyber Security Analyst?
| Aspect | Cyber Grc Analyst | Cyber Security Analyst |
|---|---|---|
| Certifications | ISO 27001, CISSP, CISA | CISSP, CEH, Security+ |
| Work Environment | Policy, compliance, risk management | Threat detection, incident response |
| Employer & Industry Usage | Financial, healthcare, government | Tech, finance, retail |
Cyber Grc Analysts focus on governance, risk, and compliance, ensuring organizations meet security standards. Cyber Security Analysts primarily handle threat detection and incident response. While both roles require security certifications and work in related environments, their core responsibilities differ, with GRC analysts emphasizing policies and compliance, and security analysts focusing on technical security measures.
Is GRC cybersecurity a good job?
What does a cybersecurity GRC analyst do?
What cities are hiring for Cyber Grc Analyst jobs?
Cities with the most Cyber Grc Analyst job openings:
What states have the most Cyber Grc Analyst jobs?
States with the most job openings for Cyber Grc Analyst jobs include:
What job categories do people searching Cyber Grc Analyst jobs look for?
The top searched job categories for Cyber Grc Analyst jobs are:

Full-time
Re-posted 12 days ago
Trustmark National Bank rating
8.2
Based on 19 frontline employees who took The Breakroom Quiz
51st of 171 rated banks
Job description
The IT GRC Analyst operates within the enterprise Cybersecurity Operations function and supports the Information Technology, Information Systems, and other technology teams aligned under the Chief Information Officer. This role executes governance, risk, and compliance activities aligned with regulatory frameworks and internal policies. Core responsibilities include ensuring operational alignment with frameworks such as GLBA, FFIEC, SOX, NIST CSF, and the Computer Risk Institute (CRI) Profile; conducting IT assessments and Risk Control Self Assessments (RCSAs); maintaining control libraries; and supporting recurring testing, reporting, and metrics analysis and response. The analyst contributes to recurring reporting cycles, supports departmental risk remediation and response efforts associated with findings and risks, and helps drive continuous improvement of governance practices through collaboration, documentation, and control maturity efforts.
The analyst collaborates with Enterprise Risk, Audit (internal and external), Compliance, and Policy Management teams to execute these activities effectively. Day-to-day responsibilities include control documentation, testing coordination, assistance with reviewing and updating policies, standards, and control libraries, and policy lifecycle support. Familiarity with GRC platforms (e.g., AuditBoard), ITSM tools (e.g., ServiceNow), and regulatory compliance in financial services is strongly preferred.
The analyst also contributes to the development and maintenance of IT policies and procedures and supports the definition and tracking of key performance indicators (KPIs) and key risk indicators (KRIs). Success in this role requires strong technical writing skills, cross-functional engagement, and a focus on building and maintaining automation to streamline control testing and reporting processes. The role demands a self-driven desire to continuously learn and improve along with a collaborative mindset and a willingness to meet teammates and coworkers where they are in their processes. The analyst must be committed to helping develop, strengthen, and sustain a resilient and effective IT GRC program across the organization.
This position may be filled as a Level I, II or III. Additional responsibilities and qualifications apply.
Responsibilities- Serve as liaison between internal IT/IS/Cyber teams and Enterprise Risk and Audit to facilitate compliance efforts and assessments (GLBA, FFIEC, SOX, CRI/NIST CSF).
- Coordinate the collection of sufficient, appropriate evidence for assessments, including facilitating questionnaires and direct engagement with engineers and operational personnel.
- Execute and document testing procedures in spreadsheets and GRC platforms; draft reports based on results and environmental context.
- Utilize GRC tools to manage questionnaires, evidence collection, assessment documentation, and asset definitions.
- Track, document, and support remediation of findings, risk exceptions, and issues identified through audits, assessments, or operational testing, escalating unresolved items as appropriate.
- Collaborate with internal IT/IS teams to maintain and review policy/standards documentation.
- Research, implement, and monitor compliance initiatives to protect organizational assets.
- Assess systems for compliance gaps and oversee sustainable remediation efforts.
- Manage new and recurring compliance initiatives by conducting control assessments and recommending remediation or compensating controls.
- Collaborate with peers and leadership to review and refine assessment work.
- Stay current on regulatory changes and industry best practices to maintain alignment with standards.
- Facilitate cross-functional collaboration (IT, Engineering, Legal, HR) to address security risks.
- Advise IT and IS leadership on risk impacts and governance priorities.
- Assist with the design and monitoring of KPIs and KRIs aligned to operational objectives.
- Support timely execution of user access reviews and associated remediation efforts.
- Perform other duties commensurate with responsibilities of an IT GRC department.
- Associates are expected to perform all additional duties as assigned.
- Bachelor's degree in information security, Information Systems/Technology, Risk Management, Cybersecurity, or a similar discipline.
- 1 year of experience in IT GRC, IT audit, or a closely related compliance or risk function.
- Ability to coordinate with operational and IT/IS personnel to gather evidence, clarify processes, and support control implementation.
- Proficiency with Microsoft Office 365, including Excel and SharePoint for documentation and collaboration.
- Strong written and verbal communication skills, including drafting audit findings and control narratives.
- Familiarity with enterprise infrastructure components such as operating systems, directory services, and security technologies.
- External-facing project experience (e.g., consulting, public accounting) is a plus.
- Strong Preference for candidates located within commuting distance of Ridgeland, MS or willing to work hybrid/remote with occasional in-person sessions.
Additional qualifications required for Level II:
- 3 years of experience in IT GRC, IT audit, or a closely related compliance or risk function.
- Demonstrated ability to work independently with minimal oversight.
- Experience documenting control testing results in GRC platforms or structured formats.
- Working knowledge of GRC platforms (e.g., Archer, AuditBoard, ServiceNow).
- At least one relevant certification (e.g., CISSP, CISM, CISA, CIA, CRISC, CGRC).
- Experience translating regulatory requirements into detailed policies, standards, and control procedures, with the ability to explain technical and regulatory concepts clearly to non-GRC stakeholders.
- Understanding of cybersecurity infrastructure (e.g., firewalls, vulnerability management, IDS/IPS).
- Proactively identifies tasks and next steps rather than waiting for work to be assigned.Approaches problems from a solution oriented perspective and brings proposed options when raising issues.
- Recognizes and corrects gaps or weaknesses in own work prior to submission.
- Produces well structured, professionally formatted reports, presentations, and spreadsheets suitable for executive, audit, and regulatory audiences, with minimal need for substantive review, rework, or edits.
Additional qualifications required for Level III:
- 5 years of experience in IT GRC, IT audit, or a closely related compliance or risk function.
- Proven ability to manage cross-functional collaboration across IT, Engineering, Legal, HR, and other stakeholders.
- Advanced analytical skills with experience using tools like Alteryx, Tableau, Power BI, or Python for reporting and automation.
- Independently identifies, prioritizes, and drives work with minimal direction, proactively voicing and coordinating areas where effort is needed.
- Provides guidance, instruction, and informal training to Analyst I and Analyst II team members.
- Leads project execution by bringing structure, ideas, and recommended solutions, and translating detailed analysis into clear direction.
- Reviews the work of others constructively, identifying weaknesses and improvement opportunities.
- Produces work requiring minimal review and demonstrates sound judgment in improving overall team output beyond personal deliverables.
Physical Requirements & Working Conditions:
Must be able to sit for long periods of time and use computer keyboard and/or mouse requiring hand and wrist manipulation, while viewing computer screens.
Disclaimer:
Management retains the right to add, delete or modify the responsibilities and qualifications of the position at any time.
Trustmark Bank does not accept unsolicited resumes from agencies and/or search firms for any job postings on this site. Resumes submitted to any Trustmark Bank employee by a third-party agency and/or search firm without a valid, written search agreement signed by Trustmark, will become the sole property of Trustmark Bank. No fee will be paid if a candidate is hired for a position as a result of an unsolicited agency or search firm referral.
Employment Type: FULL_TIMEWhat Trustmark National Bank employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom
About Trustmark National Bank
Sourced by ZipRecruiter
Company size
1,001 - 5,000 Employees
Headquarters location
Jackson, MS, US
Year founded
1889