1

Governance Risk And Compliance Analyst Jobs in Rochester, NY

Chief Compliance Officer

Rochester, NY · On-site

$160K - $210K/yr

... risk assessments, testing and monitoring, policy governance, complaint management, regulatory ... Strong ability to analysis problem situations and craft clearly defined action plans to rectify.

Senior Tax Manager

Rochester, NY · On-site +1

$140K - $150K/yr

Tax Compliance serves as a key leader within the global tax organization, responsible for ... Controls, Governance & Risk Management Serve as principal owner of tax related SOX controls ...

Senior Tax Manager

Rochester, NY · On-site

$140K - $150K/yr

Tax Compliance serves as a key leader within the global tax organization, responsible for ... Governance & Risk Management • Serve as principal owner of tax related SOX controls, ensuring ...

Senior Cyber Security Manager

Fairport, NY · On-site

$105K - $142K/yr

Improve access governance and reduce identity-related risk * Risk & Compliance: ISO 27001, NIS2, GDPR, EU AI Act, DORA where applicable, internal audit * Translate regulatory and framework ...

Senior Cyber Security Manager

Fairport, NY

$105K - $142K/yr

Improve access governance and reduce identity-related risk * Risk & Compliance: ISO 27001, NIS2, GDPR, EU AI Act, DORA where applicable, internal audit * Translate regulatory and framework ...

Senior Cyber Security Manager

Fairport, NY

$105K - $142K/yr

Improve access governance and reduce identity-related risk * Risk & Compliance: ISO 27001, NIS2, GDPR, EU AI Act, DORA where applicable, internal audit * Translate regulatory and framework ...

Showing results 21-40

Governance Risk And Compliance Analyst information

See Rochester, NY salary details

$15

$39

$64

How much do governance risk and compliance analyst jobs pay per hour?

As of Sep 3, 2026, the average hourly pay for governance risk and compliance analyst in Rochester, NY is $39.95, according to ZipRecruiter salary data. Most workers in this role earn between $29.42 and $48.61 per hour, depending on experience, location, and employer.

What is a Governance Risk and Compliance analyst?

A Governance, Risk, and Compliance (GRC) Analyst is a professional responsible for helping organizations manage risks, ensure compliance with laws and regulations, and implement governance frameworks. They assess internal processes, identify potential risks, and recommend strategies to mitigate those risks. GRC Analysts also develop and monitor policies to ensure that business operations align with regulatory requirements and industry standards. Their work is essential in protecting an organization from financial, legal, and reputational harm.

How does a Governance Risk and Compliance analyst typically collaborate with other departments within an organization?

GRC Analysts work closely with various departments such as IT, legal, finance, and operations to ensure that organizational policies and procedures align with regulatory requirements and internal controls. They often facilitate cross-functional meetings to assess risks, discuss compliance gaps, and implement corrective measures. Effective communication and coordination are key, as GRC Analysts must translate complex regulations into actionable steps for different teams, ensuring a unified approach to risk management and compliance throughout the organization.

What are the key skills and qualifications needed to thrive as a Governance Risk and Compliance analyst, and why are they important?

To thrive as a Governance Risk and Compliance (GRC) Analyst, you need a solid understanding of risk management frameworks, regulatory requirements, and compliance standards, often supported by a degree in information security, business, or a related field. Familiarity with GRC software platforms, risk assessment tools, and certifications such as CISA or CRISC is typically required. Exceptional analytical skills, attention to detail, and strong communication abilities help you effectively interpret regulations and collaborate across departments. These competencies ensure that organizations can identify risks, maintain compliance, and build a strong foundation for operational resilience.

What is the difference between Governance Risk And Compliance Analyst vs Compliance Analyst?

AspectGovernance Risk And Compliance AnalystCompliance Analyst
CertificationsISO 31000, CRISC, CISAISO 37001, CCEP, CCEP
Work EnvironmentCorporate, financial, or regulatory sectorsHealthcare, finance, manufacturing
Employer & Industry UsageUsed in organizations with complex risk management needsUsed in organizations ensuring regulatory compliance

The Governance Risk And Compliance Analyst focuses on managing overall governance frameworks, assessing risks, and ensuring compliance with policies and regulations. In contrast, the Compliance Analyst primarily concentrates on adhering to specific laws and standards. While both roles require understanding of regulations and certifications, the Governance Risk And Compliance Analyst has a broader scope involving risk management and governance strategies.

What are popular job titles related to Governance Risk And Compliance Analyst jobs in Rochester, NY?

For Governance Risk And Compliance Analyst jobs in Rochester, NY, the most frequently searched job titles are:

What job categories do people searching Governance Risk And Compliance Analyst jobs in Rochester, NY look for?

The top searched job categories for Governance Risk And Compliance Analyst jobs in Rochester, NY are:

What cities near Rochester, NY are hiring for Governance Risk And Compliance Analyst jobs?

Cities near Rochester, NY with the most Governance Risk And Compliance Analyst job openings:

Infographic showing various Governance Risk And Compliance Analyst job openings in Rochester, NY as of August 2026, with employment types broken down into 82% Full Time, 9% Part Time, and 9% Contract. Highlights an 100% In-person job distribution, with an average salary of $83,087 per year, or $39.9 per hour.

Senior Security Compliance Specialist

LaBella Associates

Rochester, NY • On-site

$90K - $110K/yr

Full-time

Medical, Dental, Retirement, PTO

Posted 17 days ago


LaBella Associates rating

8.1

Company rating: 8.1 out of 10

Based on 8 frontline employees who took The Breakroom Quiz

185th of 452 rated engineering


Job description

We are currently looking to hire a Senior Security Compliance Specialist for LaBella's Operations Department. This position is located at our Rochester, NY office.

The primary responsibilities of this position are the program management, administration, and maintenance of LaBella's ISO 27001 and Information Security System (ISMS) program. 

Specific Duties/Responsibilities include but are not necessarily limited to the following:

  •  Management of LaBella's ISMS committee including scheduling, providing agendas, and keeping minutes of meetings, ensuring membership is maintained as current and relevant.
  • Management of LaBella's ISO 27001 and Information Security Management System (ISMS) program, in cooperation with the Security Operations Manager, including but not limited to:
    • Security policy, process, and procedure development and maintenance, in cooperation with Security, IT, and other department and division leadership.
    • ISO 27001 document control, including versioning, management reviews and approvals, communication to employees, and updating/maintaining ISO 27001 document management sites including internal and external facing document control web-based sites.
    • Developing and maintaining risk assessment and risk acceptance workflow, risk treatment/mitigation plans, and updating LaBella's risk register in coordination with relevant department and division leaders and executive management on required intervals.
    • Development of communication and coordination with executive, department, and division management, regional and office managers, internal and external communication managers, relevant third parties (clients, vendors, etc.), and LaBella data owners.
    • Coordinate ISO audits with internal and external resources and develop, track, and communicate corrective action plans
    • Collect and maintain ISO 27001/ ISMS evidence and control documentation, managing the GRC (Governance, Risk Management, and Compliance) platform
    • Establish and maintain an ISMS control ownership model, including assignment of control owners, control performers, approvers, review frequency, evidence requirements, and escalation paths for overdue or deficient controls.
    • Coordinate ISMS objectives, metrics, key performance indicators, and key risk indicators, and prepare recurring reporting for the ISMS committee, executive leadership, Security, IT, Operations, and other relevant stakeholders.
    • Maintain an ISMS compliance calendar covering internal audits, external audits, management reviews, policy reviews, risk assessments, access reviews, supplier reviews, evidence collection deadlines, training requirements, and certification milestones.
    • Coordinate with incident response, business continuity, disaster recovery, and crisis management stakeholders to ensure relevant plans, tests, lessons learned, and corrective actions are captured within the ISMS.
    • Promote continual improvement of the ISMS by identifying process gaps, control weaknesses, and opportunities to improve efficiency and consistency,
  • Coordinate with IT and Operations staff to ensure system performance and compliance with industry standards for physical and digital security items such as surveillance cameras, access control systems, endpoint management systems, 7x24 SOC, and information security management software as they relate to ISO 27001 certification.

Salary Range: $90,000 - $110,000 per year

The specific salary offered may be influenced by a variety of factors including but not limited to the candidate's relevant experience, education, and work location.

Requirements

  • Experience
    • Minimum of seven (7) years of experience in security compliance or audit program management.
  • Education
    • Bachelor's degree in Cybersecurity Management, technology compliance, or a related technology program management or auditing field. Directly related work experience may be substituted for formal education.
  • Technical Expertise
    • Strong understanding of IT infrastructure, networking, security, and software development.
  • Industry Certifications
    • Preferred certification includes PMP, CISSP, related auditor or ISO document control certification.
  • Competencies
    • Proven ability to work in a team environment, to foster teamwork, and to build collaborative relationships.
    • Self-motivated to continuously seek ways to aid and improve processes.
    • Strong communication and organization skills.
    • An uncompromised ability to keep information confidential.
    • Ability to follow and relay complex oral and written instructions, policies, procedures, and technical information clearly and effectively to both technical and non-technical audiences.

Benefits

Body, mind, and wallet-LaBella's benefits support a holistic approach to your health and wellness, creating the foundation for physical, mental, and financial well-being. Our benefit offerings cover the must-haves (healthcare and retirement), the just-in-cases (insurances and employee assistance programs), and the cherry-on-tops (fitness reimbursements, year-end incentive pay, and tuition assistance). Visit our website for more details on benefits listed below.

  • Flexible Work Schedule
  • Health/Dental Insurance
  • 401k Plan with Employer Match
  • Paid Parental Leave
  • Short & Long Term Disability
  • Profit Sharing
  • Paid Time Off
  • Leadership Development Program
  • Fitness Reimbursement
  • Tuition Reimbursement
  • Referral Bonus Program
  • Wellness Program
  • Team Building Events
  • Community Service Events

LaBella is committed to facilitating a culture where diversity, equity, and inclusion are respected, valued, and celebrated by implementing thoughtful, practical, and innovative strategies that support our employees and serve the communities in which we reside. All applicants will be considered for employment without regard to race, color, religion, age, national origin, ancestry, ethnicity, gender (including pregnancy, childbirth, breastfeeding or other related medical conditions), gender identity, gender expression, sexual orientation, marital status, veteran status, disability, genetic information, citizenship status, characteristic or membership in any other group protected by federal, state or local laws.

LaBella Associates does not accept unsolicited resumes from recruiting professionals or agencies, nor do we accept resumes from any source that does not reference a specific, open position. LaBella Associates will not be responsible for any fees arising from the use of resume submitted by recruiting professionals or agencies that do not have a current placement fee agreement with LaBella Associates. All initial communication with recruiting professionals or agencies must go through human resources.


What LaBella Associates employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom