1

Governance Risk And Compliance Analyst Jobs in Silver Spring, MD

... or risk/compliance analyst in a regulated industry. * Demonstrated experience in review roles such as third-party risk assessments, information security assessments, RCSAs, or privacy risk ...

... or risk/compliance analyst in a regulated industry. * Demonstrated experience in review roles such as third-party risk assessments, information security assessments, RCSAs, or privacy risk ...

... or risk/compliance analyst in a regulated industry. * Demonstrated experience in review roles such as third-party risk assessments, information security assessments, RCSAs, or privacy risk ...

next page

Showing results 1-20

Governance Risk And Compliance Analyst information

See Silver Spring, MD salary details

$15

$41

$68

How much do governance risk and compliance analyst jobs pay per hour?

As of Sep 3, 2026, the average hourly pay for governance risk and compliance analyst in Silver Spring, MD is $41.85, according to ZipRecruiter salary data. Most workers in this role earn between $30.82 and $50.96 per hour, depending on experience, location, and employer.

What is a Governance Risk and Compliance analyst?

A Governance, Risk, and Compliance (GRC) Analyst is a professional responsible for helping organizations manage risks, ensure compliance with laws and regulations, and implement governance frameworks. They assess internal processes, identify potential risks, and recommend strategies to mitigate those risks. GRC Analysts also develop and monitor policies to ensure that business operations align with regulatory requirements and industry standards. Their work is essential in protecting an organization from financial, legal, and reputational harm.

How does a Governance Risk and Compliance analyst typically collaborate with other departments within an organization?

GRC Analysts work closely with various departments such as IT, legal, finance, and operations to ensure that organizational policies and procedures align with regulatory requirements and internal controls. They often facilitate cross-functional meetings to assess risks, discuss compliance gaps, and implement corrective measures. Effective communication and coordination are key, as GRC Analysts must translate complex regulations into actionable steps for different teams, ensuring a unified approach to risk management and compliance throughout the organization.

What are the key skills and qualifications needed to thrive as a Governance Risk and Compliance analyst, and why are they important?

To thrive as a Governance Risk and Compliance (GRC) Analyst, you need a solid understanding of risk management frameworks, regulatory requirements, and compliance standards, often supported by a degree in information security, business, or a related field. Familiarity with GRC software platforms, risk assessment tools, and certifications such as CISA or CRISC is typically required. Exceptional analytical skills, attention to detail, and strong communication abilities help you effectively interpret regulations and collaborate across departments. These competencies ensure that organizations can identify risks, maintain compliance, and build a strong foundation for operational resilience.

What is the difference between Governance Risk And Compliance Analyst vs Compliance Analyst?

AspectGovernance Risk And Compliance AnalystCompliance Analyst
CertificationsISO 31000, CRISC, CISAISO 37001, CCEP, CCEP
Work EnvironmentCorporate, financial, or regulatory sectorsHealthcare, finance, manufacturing
Employer & Industry UsageUsed in organizations with complex risk management needsUsed in organizations ensuring regulatory compliance

The Governance Risk And Compliance Analyst focuses on managing overall governance frameworks, assessing risks, and ensuring compliance with policies and regulations. In contrast, the Compliance Analyst primarily concentrates on adhering to specific laws and standards. While both roles require understanding of regulations and certifications, the Governance Risk And Compliance Analyst has a broader scope involving risk management and governance strategies.

What are popular job titles related to Governance Risk And Compliance Analyst jobs in Silver Spring, MD?

For Governance Risk And Compliance Analyst jobs in Silver Spring, MD, the most frequently searched job titles are:

What job categories do people searching Governance Risk And Compliance Analyst jobs in Silver Spring, MD look for?

The top searched job categories for Governance Risk And Compliance Analyst jobs in Silver Spring, MD are:

What cities near Silver Spring, MD are hiring for Governance Risk And Compliance Analyst jobs?

Cities near Silver Spring, MD with the most Governance Risk And Compliance Analyst job openings:

Infographic showing various Governance Risk And Compliance Analyst job openings in Silver Spring, MD as of August 2026, with employment types broken down into 1% As Needed, 80% Full Time, 15% Part Time, and 4% Contract. Highlights an 92% Physical, 4% Hybrid, and 4% Remote job distribution, with an average salary of $87,054 per year, or $41.9 per hour.

Information Governance Compliance Analyst

Ropes & Gray

Washington, DC

$106K - $107K/yr

Full-time

Re-posted yesterday


Job description

About Ropes & Gray

Ropes & Gray is a preeminent global law firm. The firm has been ranked in the top three on The American Lawyer's prestigious A-List for eight consecutive years and #1 on Law.com's UK A-List twice in the past three years-rankings that honor the "best of the best" law firms.

The firm has approximately 2,500 lawyers and professionals serving clients in major centers of business, finance, technology, and government in Boston, Chicago, Dublin, Hong Kong, London, Los Angeles, Milan, New York, Paris, San Francisco, Seoul, Shanghai, Silicon Valley, Singapore, Tokyo and Washington, D.C.

The firm has consistently been recognized for its leading practices in many areas, including asset management, private equity, M&A, finance, real estate, tax, antitrust, life sciences, health care, intellectual property, litigation & enforcement, privacy & cybersecurity, and business restructuring.

Ropes & Gray is an equal opportunity employer.

Overview

The Information Governance Compliance Analyst supports the firm's Information Governance program with a focus on compliance, risk mitigation, data lifecycle management, and IG operational support for the DC office. The IG Compliance Analyst assists in developing and maintaining procedures, controls, and programs that promote compliance with legal, regulatory, client, and firm requirements. The IG Compliance Analyst partners with Information Security and business stakeholders to identify governance risks, support audit and assessment activities, and improve the firm's overall information governance maturity, including providing support on how evolving technologies, such as AI tools, are reviewed and governed. The IG Compliance Analyst combines technical skills with strong analytical, customer service, and communication skills, performing core duties with guidance from senior team members.

Responsibilities
  • Support the development and execution of information disposition and defensible deletion programs across hardcopy, electronic, email, cloud, and SaaS repositories. Assist in identifying records eligible for disposition, coordinating with stakeholders to confirm retention requirements, and documenting defensible deletion activities.
  • Assist with network share governance and remediation initiatives, including supporting the classification of data stored on network shares in accordance with firm data classification standards. Collaborate with content owners and IT teams to inventory, classify, and remediate data stored on firm network drives, working toward migration of content into approved repositories or appropriate disposition.
  • Support the governance of firm-approved software platforms and cloud-based solutions, including emerging technologies such as AI tools. Assist in maintaining an inventory of approved tools, monitoring compliance with governance requirements, identifying risks associated with unauthorized or unsanctioned technology use, and preparing materials for review of new software and services by the IT Architectural Review Board.
  • Perform administration, monitoring, and reporting activities related to governance technologies, including Microsoft Purview and Varonis. Generate reports, escalate anomalies or policy violations to senior team members, and assist with configuration and maintenance of governance tooling under direction from the team.
  • Contribute to the development and execution of compliance monitoring, reporting, and remediation programs, including routine audits to confirm compliance with firm processes and procedures. Assist in designing and running compliance assessments, analyzing results, tracking remediation activities, and preparing status reports for management and stakeholders.
  • Support the monitoring of and compliance with Information Governance processes, procedures, and technologies. Identify potential gaps or areas for improvement and make recommendations to senior team members. Assist in the execution of plans to address identified gaps and enhance existing policies and procedures.
  • Assist with responses to client audits in collaboration with the Information Security Risk & Compliance team. Respond to Outside Counsel Guideline (OCG) requests, working in collaboration with Information Security and other members of the Information Governance Risk & Compliance team.
  • Support best practices and requirements for storing files containing Protected Health Information (PHI) and Personally Identifiable Information (PII). Assist in monitoring compliance with PHI and PII document storage requirements in the DMS and other approved firm repositories, maintaining user-facing documentation, supporting PHI and PII best practices training, and participating in routine audits to confirm sensitive data is not retained longer than necessary.
  • Coordinate with paralegals, attorneys, and other stakeholders to obtain and execute Business Associate Agreements and Sub-Business Associate Agreements. Assist in maintaining the firm's BAA and sub-BAA libraries. Coordinate with IG team members when a PHI document storage request requires a BAA on file. Perform routine audits to ensure BAAs are in place where needed.
  • Provide operational support for Information Governance activities, including file management, matter mobility and file transfer reviews, attorney departure and personal document reviews, and end-user training. Approximately 15-20% of the role's time is dedicated to these information governance operational support activities, ensuring continuity of day-to-day IG services for the Washington, DC office.
  • Provide analysis, support, and training to attorneys, paralegals, and staff on email management best practices and document management procedures. Assist end users with organizing email folders and linking content to workspaces, as appropriate. Support user education, awareness, and change management initiatives related to Information Governance policies and best practices.
  • Assist with review of requests for exceptions to standard processes around the use removable media and cloud-based storage or collaboration services, such as Box.com, in limited use cases. Evaluate requests under established criteria, escalate complex or ambiguous situations to senior team members for determination, and respond to related support tickets as needed.
Qualifications
  • Bachelor's degree required. Degree in a related field strongly preferred.
  • 3-5 years of law firm experience required, preferably in the area of Information Governance, compliance, records management, or legal technology.
  • Experience with iManage Records Manager (IRM) strongly preferred.
  • Familiarity with security and privacy standards and regulations such as HIPAA or GDPR.
  • Experience with iManage Work and associate support tools strongly preferred.
  • Strong Excel, Word, and Outlook skills required. PowerPoint skills preferred.
  • Experience with or exposure to governance and monitoring technologies such as Microsoft Purview, Microsoft E5 Compliance and Information Protection, Varonis, or similar platforms preferred.
  • Experience with cloud software services and generative AI strongly preferred, including Box.com.
  • Strong business analysis, troubleshooting, problem solving, quality assurance and project management skills. Ability to build project plans and communicate progress to stakeholders.
  • Exceptional attention to detail required.
  • Ability to work collaboratively with a variety of people at all levels within the organization, including the ability to provide training on InfoGov best practices.
  • Clear and precise communication skills, written and oral.
  • Ability to manage competing projects, individually and as part of a team, while prioritizing work based on the needs of the department, user needs, and ticket due dates.
  • Must have the ability to lift boxes weigh 25 lbs repeatedly.
Compensation and Total Rewards Package

Ropes & Gray is proud to offer a comprehensive Total Rewards package to our business support team members. The firm also offers comprehensive health and well-being benefits, personal and professional development, career growth opportunities and a collegial and supportive culture. The anticipated pay range for this role is listed below and represents our good faith and reasonable estimate of the starting salary range at the time of posting. In addition, this role is eligible for a discretionary bonus based on performance. The actual offered rate for this position will be determined based on job-related, non-discriminatory factors, including qualifications and experience, geographic location, education, external market data and consideration of internal equity.

Washington, D.C.: $88,600 - $135,100

Working Conditions

This position requires hybrid on-site presence as an essential function of the role. Consistent and predictable on-site presence is required for ongoing business continuity, professional development and effective collaboration with colleagues and management.

Employment Type: OTHER