1

Governance Risk And Compliance Analyst Jobs in Pennsylvania

... Governance Analyst role sits within the Technology Risk & Compliance function and focuses on ... This role will report to the Technology Risk and Compliance Sr. Director. This is a hybrid position ...

IT Risk Compliance Specialist

Pittsburgh, PA · On-site

$95.60K/yr

Strong analytical and problem-solving abilities. * Excellent communication and documentation skills ... Certified in Governance, Risk, and Compliance (CGRC) BENEFITS: • Full-Time employees are eligible ...

AI Governance Analyst

Crum Lynne, PA

$79.30K - $94.10K/yr

... Governance Analyst role sits within the Technology Risk & Compliance function and focuses on ... This role will report to the Technology Risk and Compliance Sr. Director. This is a hybrid position ...

Job Overview The Senior Enterprise Risk Analyst is expected to leverage their subject matter ... Manage Operational Risk Incidents in the GRC (Governance, Risk & Compliance) tooling. * Advising ...

Job Overview The Senior Enterprise Risk Analyst is expected to leverage their subject matter ... Manage Operational Risk Incidents in the GRC (Governance, Risk & Compliance) tooling. * Advising ...

next page

Showing results 1-20

Governance Risk And Compliance Analyst information

See Pennsylvania salary details

$15

$40

$66

How much do governance risk and compliance analyst jobs pay per hour?

As of May 28, 2026, the average hourly pay for governance risk and compliance analyst in Pennsylvania is $40.58, according to ZipRecruiter salary data. Most workers in this role earn between $29.86 and $49.38 per hour, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Governance Risk and Compliance Analyst, and why are they important?

To thrive as a Governance Risk and Compliance (GRC) Analyst, you need a solid understanding of risk management frameworks, regulatory requirements, and compliance standards, often supported by a degree in information security, business, or a related field. Familiarity with GRC software platforms, risk assessment tools, and certifications such as CISA or CRISC is typically required. Exceptional analytical skills, attention to detail, and strong communication abilities help you effectively interpret regulations and collaborate across departments. These competencies ensure that organizations can identify risks, maintain compliance, and build a strong foundation for operational resilience.

How do Governance Risk and Compliance (GRC) Analysts typically collaborate with other departments within an organization?

GRC Analysts work closely with various departments such as IT, legal, finance, and operations to ensure that organizational policies and procedures align with regulatory requirements and internal controls. They often facilitate cross-functional meetings to assess risks, discuss compliance gaps, and implement corrective measures. Effective communication and coordination are key, as GRC Analysts must translate complex regulations into actionable steps for different teams, ensuring a unified approach to risk management and compliance throughout the organization.

What is a Governance, Risk, and Compliance (GRC) Analyst?

A Governance, Risk, and Compliance (GRC) Analyst is a professional responsible for helping organizations manage risks, ensure compliance with laws and regulations, and implement governance frameworks. They assess internal processes, identify potential risks, and recommend strategies to mitigate those risks. GRC Analysts also develop and monitor policies to ensure that business operations align with regulatory requirements and industry standards. Their work is essential in protecting an organization from financial, legal, and reputational harm.

What is the difference between Governance Risk And Compliance Analyst vs Compliance Analyst?

AspectGovernance Risk And Compliance AnalystCompliance Analyst
CertificationsISO 31000, CRISC, CISAISO 37001, CCEP, CCEP
Work EnvironmentCorporate, financial, or regulatory sectorsHealthcare, finance, manufacturing
Employer & Industry UsageUsed in organizations with complex risk management needsUsed in organizations ensuring regulatory compliance

The Governance Risk And Compliance Analyst focuses on managing overall governance frameworks, assessing risks, and ensuring compliance with policies and regulations. In contrast, the Compliance Analyst primarily concentrates on adhering to specific laws and standards. While both roles require understanding of regulations and certifications, the Governance Risk And Compliance Analyst has a broader scope involving risk management and governance strategies.

What are popular job titles related to Governance Risk And Compliance Analyst jobs in Pennsylvania? For Governance Risk And Compliance Analyst jobs in Pennsylvania, the most frequently searched job titles are:
What job categories do people searching Governance Risk And Compliance Analyst jobs in Pennsylvania look for? The top searched job categories for Governance Risk And Compliance Analyst jobs in Pennsylvania are:
What cities in Pennsylvania are hiring for Governance Risk And Compliance Analyst jobs? Cities in Pennsylvania with the most Governance Risk And Compliance Analyst job openings:
Governance, Risk & Compliance Analyst, Specialist

Governance, Risk & Compliance Analyst, Specialist

Vangard, Inc.

Malvern, PA • On-site

Full-time

Posted 16 days ago


Job description

About The Job

In this role, you will help deliver on our investment in GRC modernization. You will lead risk assessments, design and scale forward-looking governance, risk, and compliance programs, and serve as a trusted advisor who helps teams move faster and smarter while staying audit-ready and compliant.

The Governance, Risk & Compliance Analyst, Specialist is a key member of Vanguard's Global Enterprise Security's Governance, Risk, Compliance (GRC) and Strategic Operations team. This position recommends, develops, implements, and monitors enterprise-wide information security policies, standards, and operational guidelines. It assesses the end-to-end integrated GRC framework of information security policies, standards, and operational control linkages to manage cyber security risks within tolerances, satisfy regulatory obligations, and address expanding requirements, with exceptional stakeholder experience. Data-driven approaches will be used to predict risk issues, develop solutions, and partner with key owners and stakeholders. Automation will be used to accelerate delivery and improve effectiveness.

Responsibilities

  • Works with Enterprise Security and Fraud subdivisions and business units as the technical authority regarding security of application and systems software, equipment, and related capabilities and performance characteristics to evaluate their effectiveness at meeting defined requirements, determining integration requirements and identifying ramifications on operations of their implementation.
  • Conducts security and fraud assessments, risk analyses and assesses contingency plans for to verify existence and effectiveness of safeguards.
  • Supports the development and maintenance of a portfolio of global security and fraud policies and standards. Monitors and maintains the lifecycle of the portfolio. Responsible for oversight of management and decisions related to methodology and policy for all Security and fraud functions.
  • Advises key stakeholders and security policy owners during policy and standards discussions. Interfaces with clients on all inquiries related to Information and IT Security and fraud capabilities.
  • Works with Compliance and Regional Security and Fraud teams to understand global regulatory requirements, develop global and regional policies and standards, and oversee implementation. Interfaces with external regulators for Information and IT Security and Fraud.
  • Reviews and analyzes current and proposed policy and standards directives and IT technical issues which may affect the implementation of Information Security and Fraud across the enterprise.
  • Recommends, develops, implements and coordinates new security policies, standards, controls and operating doctrine at all levels across the company. Interprets policy relating to Vanguard information security and frau functions and provides guidance, as required.
  • Defines and implements automations to accelerate delivery and improve effectiveness.
  • Defines and implements data-driven approaches and dashboards to predict risk issues, develop solutions, and partner with key owners and stakeholders.
  • Designs, implements and supports modernized GRC process and tool capabilities.
  • Participates in special projects and performs other duties as assigned.

Qualifications

  • Seven years related work experience, Information Security or fraud experience required.
  • Undergraduate degree or equivalent combination of training and experience. Computer Science degree preferred.
  • In-depth knowledge of relevant frameworks and standards (i.e., NIST CSF, NIST 800-53, CIS Controls, ISO 27002) and financial services industry cyber regulations and guidelines, and considered an expert in the domain.
  • Demonstrated experience with GRC solutions platform and automation capabilities.
  • Excellent communication and influencing skills.
  • Influence key stakeholders and security policy and control owners.
  • Professional certification (CISSP, CISM, CompTIA, SANS, ISC2) preferred.

Special Factors

Sponsorship

Vanguard is not offering visa sponsorship for this position.

About Vanguard

At Vanguard, we don't just have a mission-we're on a mission.

To work for the long-term financial wellbeing of our clients. To lead through product and services that transform our clients' lives. To learn and develop our skills as individuals and as a team. From Malvern to Melbourne, our mission drives us forward and inspires us to be our best.

How We Work

Vanguard has implemented a hybrid working model for the majority of our crew members, designed to capture the benefits of enhanced flexibility while enabling in-person learning, collaboration, and connection. We believe our mission-driven and highly collaborative culture is a critical enabler to support long-term client outcomes and enrich the employee experience.