1

Governance Risk Compliance Analyst Jobs (NOW HIRING)

$72/hr

AI Risk & Compliance Analyst Location: New York, NY or Charlotte, NC Duration: 6-Month Contract ... This is a hands-on role focused on AI governance, responsible AI practices, regulatory compliance ...

IT Governance, Risk & Compliance Analyst

Winona, MN · On-site

$91K - $91K/yr

They are seeking a Full-time IT Governance, Risk & Compliance Analyst to support the assurance of IT GRC across the organization, ensuring compliance with industry laws and regulations while managing ...

next page

Showing results 1-20

Governance Risk Compliance Analyst information

See salary details

$15

$40

$65

How much do governance risk compliance analyst jobs pay per hour?

As of Jun 20, 2026, the average hourly pay for governance risk compliance analyst in the United States is $40.49, according to ZipRecruiter salary data. Most workers in this role earn between $29.81 and $49.28 per hour, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Governance Risk Compliance Analyst, and why are they important?

To thrive as a Governance Risk Compliance (GRC) Analyst, you need a solid understanding of risk management, regulatory frameworks, and auditing, typically supported by a degree in business, finance, or a related field. Familiarity with GRC software platforms (like RSA Archer or MetricStream), as well as certifications such as CISA or CRISC, are commonly required. Analytical thinking, attention to detail, and excellent communication skills help you navigate complex regulations and collaborate with various stakeholders. These competencies ensure organizations maintain compliance, manage risks effectively, and uphold strong corporate governance.

What are some common challenges faced by Governance Risk Compliance Analysts when implementing new compliance frameworks?

Governance Risk Compliance (GRC) Analysts often encounter challenges such as ensuring organization-wide adoption of new compliance policies, interpreting evolving regulations, and integrating compliance requirements into existing business processes. They must frequently collaborate with multiple departments, which can involve aligning different stakeholders’ priorities and addressing resistance to change. Successfully navigating these challenges requires strong communication skills, the ability to translate complex regulations into practical steps, and a proactive approach to continuous training and awareness.

Is a GRC analyst a good entry level job?

A Governance Risk Compliance (GRC) analyst can be suitable as an entry-level position for individuals interested in risk management, compliance, and cybersecurity frameworks. It typically requires foundational knowledge of regulations, policies, and tools like audit software, with opportunities for professional growth through certifications such as CISA or CISSP.

What does a governance risk and compliance analyst do?

A governance risk and compliance analyst evaluates an organization’s policies, procedures, and controls to ensure adherence to legal and regulatory requirements. They identify potential risks, develop mitigation strategies, and monitor compliance using tools like audit software, often supporting risk management frameworks and reporting processes.

What is the difference between Governance Risk Compliance Analyst vs Compliance Analyst?

AspectGovernance Risk Compliance AnalystCompliance Analyst
CertificationsISO 31000, CRISC, CISAISO 37001, CCEP, CIA
Work EnvironmentCorporate, financial, or regulatory settingsVarious industries, including healthcare, finance, and manufacturing
Primary FocusRisk management, governance frameworks, compliance policiesEnsuring adherence to laws, regulations, and standards

The Governance Risk Compliance Analyst primarily focuses on establishing and maintaining risk management and governance frameworks within organizations, while the Compliance Analyst concentrates on ensuring adherence to specific laws and regulations. Both roles require similar certifications and often work in corporate environments, but their core responsibilities differ in scope and focus.

What is the salary of governance risk compliance?

The salary for a Governance Risk Compliance Analyst typically ranges from $60,000 to $110,000 annually, depending on experience, location, and industry. Entry-level positions may start lower, while experienced professionals with certifications like CRISC or CISA can earn higher salaries. The role often requires knowledge of regulatory frameworks and risk management tools.

What does a Governance Risk Compliance (GRC) Analyst do?

A Governance Risk Compliance (GRC) Analyst is responsible for ensuring an organization adheres to regulatory requirements, internal policies, and risk management best practices. They identify potential risks, evaluate the effectiveness of existing controls, and recommend improvements to mitigate risks. GRC Analysts also help develop and maintain compliance frameworks, conduct audits, and provide training to staff on compliance matters. Their work helps protect organizations from legal penalties, reputational damage, and operational disruptions.

Is governance risk and compliance a good career?

Governance, Risk, and Compliance (GRC) analysts play a key role in helping organizations manage regulatory requirements, security policies, and risk mitigation. The field offers steady demand, opportunities for certification such as CISA or CRISC, and potential for career advancement in various industries. It is suitable for individuals with strong analytical skills, attention to detail, and knowledge of compliance frameworks like ISO or GDPR.
More about Governance Risk Compliance Analyst jobs
What cities are hiring for Governance Risk Compliance Analyst jobs? Cities with the most Governance Risk Compliance Analyst job openings:
Governance Risk & Compliance Analyst

Governance Risk & Compliance Analyst

System One

Denver, CO • Remote

Contractor

Medical, Dental, Vision, Life, Retirement

Posted 2 days ago


Job description

Job Title: Governance Risk & Compliance Analyst Location: Lakewood, CO Work Model: Hybrid – onsite and remote Overview System One is seeking a GRC Analyst for an opportunity in Lakewood, CO. The GRC Analyst is a member of the Governance, Risk & Compliance function within the Global Information Security Office and supports the implementation of company?wide security governance, risk management, and compliance programs. Under the direction of the GRC Functional Leader, the analyst contributes to policy development, risk oversight, and continuous improvement of the organization’s security posture. The role also works closely with regional Information Security Officers (ISOs) and cross?functional teams to support the deployment of global standards and local regulatory requirements. Responsibilities

  • Support information security risk assessments for new projects, systems, and business processes.
  • Assist in conducting internal control reviews (e.g., J?SOX), preparing audit materials, and coordinating responses to internal and external auditors.
  • Track and follow up on remediation actions to ensure timely closure of identified risks.
  • Contribute to drafting, updating, and maintaining global information security policies, standards, and procedures.
  • Review relevant laws, regulations, and industry frameworks (e.g., ISO 27001, NIS2) and incorporate stakeholder feedback into documentation.
  • Support the rollout and implementation of policies across regions.
  • Monitor adherence to security and regulatory requirements, including ISO 27001, NIS2, and GDPR.
  • Collect and organize compliance evidence, track corrective actions, and support certification and regulatory readiness efforts such as ISO 27001/42001 and NIS2 programs.
  • Conduct third party security risk assessments by distributing questionnaires, analyzing responses, verifying controls, and documenting results in the GRC tracking systems.
  • Identify and escalate high risk findings to the GRC Functional Leader and support follow up mitigation activities.
  • Participate in the planning and implementation of security awareness programs for all associates.
  • Create e-learning materials and training materials, conduct phishing email exercises, and distribute disseminated content on internal portals.
  • Monitor and analyze global regulatory developments related to cybersecurity with a focus on industrial control systems (ICS), IT environments, and critical infrastructure.
  • Assist in evaluating how new or updated regulations (e.g., NIS2, FDA cybersecurity expectations, industrial cybersecurity standards, or country specific critical infrastructure laws) impact company operations.
  • Track emerging obligations, document requirements, and support gap assessments to ensure timely compliance.
  • Assist in the preparation, maintenance, and continuous improvement of the CISO Dashboard by collecting, validating, and analyzing security metrics across the Global GRC function.
  • Compile key performance indicators (KPIs) and key risk indicators (KRIs) related to compliance status, audit findings, supplier risk, incident trends, training completion, regulatory readiness, and other relevant security domains.
  • Support the visualization and communication of security posture to senior leadership by ensuring data accuracy, timely updates, and clarity in reporting.
  • Support the development and enforcement of governance controls for the secure use of artificial intelligence technologies across the organization.
  • Identify risks related to AI systems—such as model security, algorithmic integrity, and misuse—and contribute to risk assessments and mitigation plans.
  • Help evaluate third party AI tools.
  • Support the development and improvement of GRC processes, tools, and documentation to enhance operational efficiency and standardization.
  • Assist in preparing reports, presentations, and materials for leadership reviews, steering committees, and cross functional meetings.
  • Participate in internal security projects and initiatives, including process automation, metrics development, and enhancements to governance workflows.
  • Provide coordination and administrative support for security committees, working groups, and regional GRC activities.
  • Perform additional duties as assigned to support the Global Information Security Office and the broader GRC program.
Requirements
  • 3 to 5+ years of experience in information security, governance, risk management, compliance, IT audit, or a related discipline.
  • Experience supporting security programs in global or regulated environments is a plus.
  • Understanding of global and regional information security regulations (e.g., data protection laws, cybersecurity requirements) and familiarity with security frameworks such as ISO 27001.
  • Knowledge of internal control frameworks (e.g., JSOX) and IT governance practices is highly desirable.
  • Experience supporting audit activities is preferred.
  • Experience with risk assessment methodologies, control evaluation, and vulnerability or issue management processes.
  • Strong analytical and problem-solving skills, with the ability to identify risks, assess impacts, and support the development and tracking of corrective actions.
  • Ability to communicate security requirements, policies, and audit findings clearly and persuasively with stakeholders across regions and business units.
  • Strong coordination skills to build consensus and drive compliance.
  • Industry certifications such as CISSP, CISA, CISM, ISO 27001 Lead Implementer/Auditor, or similar are preferred but not required.
  • Bachelor’s degree in information security, Cybersecurity, Information Systems, Computer Science, or a related field; or equivalent professional experience.
  • Familiarity with governance, risk, and compliance tools (e.g., BitSight, Drata, OneTrust, Archer, or similar) for managing risks, audits, and compliance workflows.
  • Working knowledge of cybersecurity concepts such as identity and access management, endpoint protection, vulnerability management, cloud security, and secure system design.
  • Experience supporting cross-functional security or compliance initiatives, including requirements gathering, documentation, and progress tracking.
  • Ability to interpret risk metrics, compliance data, and audit results.
  • Experience with dashboards, KPI/KRI reporting, or data visualization tools is a plus.
  • Awareness of emerging cybersecurity regulations (e.g., NIS2, AI governance frameworks, critical infrastructure rules) and their potential impact on enterprise operations.

System One, and its subsidiaries including Joulé and Mountain Ltd., are leaders in delivering outsourced services and workforce solutions across North America. We help clients get work done more efficiently and economically, without compromising quality. System One not only serves as a valued partner for our clients, but we offer eligible employees health and welfare benefits coverage options including medical, dental, vision, spending accounts, life insurance, voluntary plans, as well as participation in a 401(k) plan. System One is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, age, national origin, disability, family care or medical leave status, genetic information, veteran status, marital status, or any other characteristic protected by applicable federal, state, or local law. #M-1 #LI-SG1 Ref: #558-Scientific