1

Governance Risk And Compliance Jobs in Springfield, IL

Lead, Service Management

Springfield, IL · On-site

$15.75 - $20.75/hr

Governance, risk, and compliance is a separate, independent function and a close partner of this role, particularly on audit, SOC 2, and risk. You are also the link between the technology teams and ...

New

... AI governance frameworks addressing model risk management, explainability, fairness, compliance, and responsible AI practices Lead and approve Enterprise Architecture Assessments, including AI ...

Ensure compliance with governance, financial, and organizational policies while effectively managing business risk. * Travel up to 50% to meet with customers, prospects, partners, and internal ...

Finance Director

Springfield, IL · On-site

$175 - $215/hr

Establish budgeting timelines, templates, and governance processes to ensure consistency and ... Captive Insurance & Risk Management * Serve as the primary financial liaison for the organization ...

next page

Showing results 1-20

Governance Risk And Compliance information

See Springfield, IL salary details

$98.1K

$190.1K

$380.6K

How much do governance risk and compliance jobs pay per year?

As of Aug 10, 2026, the average yearly pay for governance risk and compliance in Springfield, IL is $190,058.00, according to ZipRecruiter salary data. Most workers in this role earn between $167,000.00 and $188,800.00 per year, depending on experience, location, and employer.

What are governance risk and compliance roles?

Governance, Risk, and Compliance (GRC) roles are positions within organizations focused on ensuring that business operations align with legal standards, manage risk effectively, and follow internal policies. Professionals in GRC help organizations set up frameworks to oversee compliance with laws and regulations, identify and mitigate potential risks, and establish governance structures to guide decision-making. These roles are essential for protecting organizations from financial, legal, and reputational harm while promoting ethical practices and efficient processes.

What is the work of governance risk and compliance?

Governance, Risk, and Compliance (GRC) professionals develop and implement policies to ensure organizations adhere to legal and regulatory requirements, manage risks effectively, and maintain ethical standards. They often use tools like risk assessments, audits, and compliance frameworks to identify vulnerabilities and ensure organizational integrity.

Is governance risk and compliance a good career?

Governance, Risk, and Compliance (GRC) is a growing field that offers opportunities in industries such as finance, healthcare, and technology. It requires skills in regulatory knowledge, risk assessment, and often certifications like CISA or CRISC, making it a stable and in-demand career path for those interested in organizational integrity and security.

What are the key skills and qualifications needed to thrive as a governance risk and compliance professional?

To thrive as a Governance, Risk, and Compliance (GRC) professional, you need a solid understanding of regulatory frameworks, risk assessment methodologies, and compliance requirements, often supported by a degree in business, finance, or a related field. Familiarity with GRC platforms (like RSA Archer or MetricStream), audit management tools, and relevant certifications such as CISA, CRISC, or CISSP is highly beneficial. Strong analytical thinking, attention to detail, and effective communication skills set top performers apart in this field. These skills are crucial for identifying risks, ensuring organizational compliance, and supporting informed decision-making to protect the business.

What are some common challenges faced by professionals in governance risk and compliance roles, and how can they be addressed?

Professionals in Governance, Risk, and Compliance (GRC) roles often face challenges such as staying updated with changing regulations, ensuring company-wide adherence to policies, and managing cross-functional collaboration. To address these, GRC specialists must develop strong communication skills to educate and train staff, leverage technology to automate compliance tracking, and build effective relationships with departments such as IT, legal, and operations. Regular professional development and proactive engagement with regulatory updates are also key to overcoming these challenges and maintaining effective governance.

What is the difference between Governance Risk And Compliance vs Compliance Analyst?

AspectGovernance Risk And ComplianceCompliance Analyst
CertificationsISO 31000, ISO 27001, Certified Risk Management ProfessionalCertified Compliance & Ethics Professional (CCEP), ISO 19600
Work EnvironmentCorporate, regulated industries, risk management departmentsLegal, audit, compliance departments within organizations
Employer & Industry UsageFinancial services, healthcare, energy, governmentFinancial institutions, healthcare, manufacturing, retail

Governance Risk And Compliance professionals focus on establishing frameworks, managing risks, and ensuring overall compliance strategies across organizations. Compliance Analysts primarily focus on implementing and monitoring specific compliance policies, often within legal or audit teams. While both roles require understanding regulations and certifications, Governance Risk And Compliance roles have a broader scope involving risk management and governance structures.

What job categories do people searching Governance Risk And Compliance jobs in Springfield, IL look for? The top searched job categories for Governance Risk And Compliance jobs in Springfield, IL are:
What cities near Springfield, IL are hiring for Governance Risk And Compliance jobs? Cities near Springfield, IL with the most Governance Risk And Compliance job openings:
Infographic showing various Governance Risk And Compliance job openings in Springfield, IL as of August 2026, with employment types broken down into 89% Full Time, and 11% Contract. Highlights an 67% In-person, and 33% Remote job distribution, with an average salary of $190,058 per year, or $91.4 per hour.

Risk and Compliance Manager

State of Illinois

Springfield, IL • On-site

$8.3K - $12K/mo

Other

Medical, Dental, Vision, Life, Retirement, PTO

Posted 18 days ago


State Of Illinois rating

7.9

Company rating: 7.9 out of 10

Based on 74 frontline employees who took The Breakroom Quiz

14th of 50 rated states


Job description

Agency: Board of Elections 
Closing Date/Time: Thursday, August 6th, 2026 at 11:59 p.m.
Anticipated Starting Salary: $8,334 - $10,834 per month

Full Range:  $8,334 - $12,917 per month

County: Sangamon
Number of Vacancies: 1

FLSA Status: Exempt

The SBE is a non-code agency.
 

All applicants who want to be considered for this position MUST apply electronically through the illinois.jobs2web.com website. State of Illinois employees should click the link near the top left to apply through the SuccessFactors employee career portal.

Applications submitted via email or any paper manner (mail, fax, hand delivery) will not be considered.

As a State of Illinois employee, you receive a comprehensive benefits package including:
    Competitive Group Insurance benefits including health, life, dental and vision plans
    Flexible work schedules (when available and dependent upon position)    10 -25 days of paid vacation time annually (10 days for first year of state employment)
    12 days of paid sick time annually which carryover year to year
    3 paid personal business days per year
    13 paid holidays per year
    12 weeks of paid parental leave
    Pension plan through the State Employees Retirement System
    Deferred Compensation Program - voluntary supplemental retirement plan
    Optional pre-tax programs -Medical Care Assistance Plan (MCAP) & Dependent Care Assistant Plan (DCAP)
    Tuition Reimbursement Program and Federal Public Service Loan Forgiveness Program eligibility

For more information regarding State of Illinois Benefits follow this link: https://www2.illinois.gov/cms/benefits/Pages/default.aspx

Work Hours: 8:00 - 4:30 PM Monday - Friday
Work Location: 2329 S. MacArthur Blvd, Springfield IL 62704
Agency Contact: dmartinez@elections.il.gov
Posting Group: Science, Technology, Engineering and Mathmatics


****A RESUME IS REQUIRED FOR THIS JOB POSTING****

Please attach a DETAILED Resume/Curriculum Vitae (CV), a copy of your transcripts or diploma for all degrees earned, and a copy of any applicable professional licensures to the MY DOCUMENTS section of your application. 

Why Work for Illinois?

Working with the State of Illinois is a testament to the values of compassion, equity, and dedication that define our state. Whether you're helping to improve schools, protect our natural resources, or support families in need, you're part of something bigger-something that touches the lives of every person who calls Illinois home.

No matter what state career you're looking for, we offer jobs that fit your life and your schedule-flexible jobs that provide the gold standard of benefits. Our employees can take advantage of various avenues to advance their careers and realize their dreams. Our top-tier benefits and great retirement packages can help you build a rewarding career and lasting future with the State of Illinois.

Functional Statement

Reporting to the Chief Information Security Officer (CISO), the Risk & Compliance Manager is responsible for: Designing, implementing, and leading a modern enterprise cybersecurity Governance, Risk, Compliance (GRC) program; Ensuring continuous improvements of governance, risk, and compliance capabilities; Ensuring cybersecurity risk is identified, measured, clearly understood, and managed in alignment with adopted frameworks, agency priorities, regulatory requirements, and overall technology strategy; Continuously monitor cybersecurity risk posture, perform gap analysis and provide recommendations for compensating technical, administrative, and physical controls; Tracking the agency's alignment to information security standards; Collaborating with agency stakeholders to develop prescriptive guidance to reduce risk; Reviewing policies, standards, procedures, controls documentation, and audit results; Managing third-party risk by maintaining an inventory of all technology providers and service organizations as well as performing continuous security posture monitoring; Overseeing the agency's security awareness program.

Essential Function 1

Develops and implements risk management plans and processes that are aligned to business objectives and security requirements. Collaborates with agency stakeholders and control owners to develop and implement testing and evidence gathering methodologies. Analyzes and interprets audit results and provides recommendations to system owners and senior leadership to reduce risk. Serves as risk management subject matter expert in support of agency projects. Leverages GRC, vulnerability management, and service desk tools to track progress and distribute compliance and risk remediation task assignments.

Essential Function 2

Conducts third-party service organization risk assessments to ensure supply chain risk is managed throughout the business relationship lifecycle. Establishes and maintains relationships with third-party vendors. Continuously monitors third-party risk by periodically gathering and analyzing vendor documentation such as System and Organization Controls (SOC2 Type II), International Organization for Standardization (ISO 27001), technical diagrams, penetration test results, continuity plans, etc. Reports on the benefits and risks for the agency as well as requirements for service provider compliance. Creates, maintains, and distributes third-party vendor security questionnaires. Serves as the agency's liaison to ensure successful external third-party risk and vulnerability assessments. Communicates assessment results to leadership, business stakeholders, and program managers. Documents Corrective Action Plans (CAP) as needed and assists with the creation of agency Plan of Action & Milestones (POA&M).

Essential Function 3

Assists with the research, creation, maintenance, implementation and communication of Information Security policies, standards, controls, and procedures documentation. Evaluates and documents technical, administrative, and physical controls to ensure the agency demonstrates compliance and meets the requirements of its regulatory obligations. Leads efforts to remediate control gaps and presents findings to leadership. Facilitates data collection and eDiscovery efforts to support investigations of policy violations. Collaborates with the Information Security Operations team and other agency stakeholders to analyze security incidents and provide recommendations to reduce risk. Establishes and maintains a detailed risk register for the organization. Oversee organization-wide Business Impact Analysis (BIA) processes. Collaborate with agency stakeholders to establish and maintain Continuity of Operations Planning (COOP) and Disaster Recovery Planning (DRP).

Essential Function 4

Develops and matures the agency's security awareness program. Utilizes a combination of third-party education resources and services, threat intelligence, and industry trends to create and distribute annual and supplemental security awareness trainings. Periodically provides agency staff with additional education opportunities such as presentations or workshops that are focused on information security, risk, and compliance.

Essential Function 5

Continues education by attending training, seminars, conferences, and obtaining industry certifications. Maintains a current understanding of the threat landscape by monitoring online information security related websites, blogs, articles, reports, as well as other security intelligence sources to remain current on the latest threats, indicators of compromise (IOCs) and trends. Participates in cybersecurity focused organizations.

Essential Function 6

Performs other duties as required or assigned which are reasonably within the scope of the duties enumerated above. Provides off-hours support as required.

Minimum Qualifications 1

Bachelor's degree in a Cybersecurity or Information Technology field, and a minimum of 10 years in Information Technology roles including 5 years of combined professional experience in information security and risk management. 

Minimum Qualifications 2

Advanced knowledge in information security technologies, design, and architecture in on-premises and cloud hosted environments. 

Minimum Qualifications 3

Experience with the selection, implementation, and management of third-party GRC, exposure management, and awareness platforms such as Bitsight, Knowbe4, ServiceNow, Netwrix, Qualys, and Tenable. 

Minimum Qualifications 4

Solid understanding of cyber risk management, strategy, and security frameworks such as: NIST, CIS, OWASP, COSO, ISO, FAIR, etc. 

Minimum Qualifications 5

Must have excellent analytical and planning skills and be highly organized and detail oriented.

Minimum Qualifications 6

Possesses the ability to write and communicate effectively with both technical and non-technical audiences. 

Minimum Qualifications 7

Comfortability presenting to executive leadership. 

Minimum Qualifications 8

Ability to take unpopular positions when necessary to ensure risk is fully and accurately communicated to agency leadership.

Minimum Qualifications 9

The following professional certifications are required:

ISACA Certified in Risk and Information Systems Control (CRISC)

ISC2 Certified Information Systems Security Professional (CISSP)

ISC2 Certified Cloud Security Professional (CCSP)

Preferred Qualifications 1

The following professional certifications are also desired:

EC Council Certified Ethical Hacker (CEH)                           
CompTIA Project+     
CompTIA Cloud+
ISC2 Certified in Governance, Risk and Compliance (CGRC) 
  CompTIA Network+    
COBIT: Control Objectives for Information and Related Technology  
ITIL: Information Technology Infrastructure Library

The State Board of Elections welcomes all and promotes workplace diversity. It is our individual traits, character, and experiences that make each of us special and unique. It is only when we bring that individualism together and work as a diverse team that we thrive. There is no place for discrimination based on race, religion, culture, sexual identity or orientation, age, or disability at the State Board of Elections.

APPLICATION INSTRUCTIONS

Use the "Apply" button at the top right or bottom right of this posting to begin the application process.
If you are not already signed in, you will be prompted to do so.
State employees should sign in to the career portal for State of Illinois employees - a link is available at the top left of the Illinois.jobs2web.com homepage in the blue ribbon. 
Non-State employees should log in on the using the "View Profile" link in the top right of the Illinois.jobs2web.com homepage in the blue ribbon.  If you have never before signed in, you will be prompted to create an account.
If you have questions about how to apply, please see the following resources:
State employees: Log in to the career portal for State employees and review the Internal Candidate Application Job Aid
Non-State employees: on Illinois.jobs2web.com - click "Application Procedures" in the footer of every page of the website.


What State Of Illinois employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


State of Illinois logo

About State of Illinois

Sourced by ZipRecruiter

The State of Illinois is not a traditional company, but rather a governmental entity encompassing diverse agencies and departments that serve the constituents of Illinois. Based in Illinois, United States, this governmental body communicates with its citizens through the official website illinois.gov. The website is a one-stop resource for Illinois residents to access information about the state's services, including education, healthcare, transportation, and public safety, among others.

Company size

11 - 50 Employees

Headquarters location

Springfield, IL, US

Year founded

2009

Social media