1

Governance Risk Compliance Intern Jobs in Boston, MA

The Governance, Risk, and Compliance (GRC) team helps ensure technology and cybersecurity risks are identified, assessed, and communicated clearly across the organization. WHOOP is seeking a ...

The Director will oversee AI policy development, risk management, governance operations, technology platforms, regulatory compliance, and Responsible AI practices while partnering closely with Data ...

IT Risk & Compliance Analyst

Andover, MA ยท On-site +1

$95K - $95K/yr

Three to five years of experience in IT compliance, IT audit, internal audit, risk management, controls, governance, risk and compliance (GRC), or information security compliance. * Working knowledge ...

next page

Showing results 1-20

Governance Risk Compliance Intern information

See Boston, MA salary details

$28.8K

$50.8K

$80.4K

How much do governance risk compliance intern jobs pay per year?

As of Aug 23, 2026, the average yearly pay for governance risk compliance intern in Boston, MA is $50,847.00, according to ZipRecruiter salary data. Most workers in this role earn between $43,500.00 and $52,700.00 per year, depending on experience, location, and employer.

What does a governance risk compliance intern do?

A Governance Risk Compliance (GRC) Intern assists organizations in identifying, assessing, and managing risks related to governance, business processes, and regulatory compliance. Their tasks often include supporting audits, reviewing internal controls, assisting with policy creation, and helping ensure that the company adheres to relevant laws and regulations. GRC Interns work closely with different departments to monitor compliance efforts and help maintain documentation required for risk management and reporting. This role provides valuable exposure to corporate risk assessment and regulatory frameworks.

What types of projects or tasks can a governance risk compliance intern expect to work on during their internship?

As a Governance Risk Compliance Intern, you can expect to assist with a variety of tasks such as conducting risk assessments, analyzing company policies for compliance with regulations, and helping to prepare reports for audits. You'll often collaborate with different departments to gather information, support the development of internal controls, and participate in meetings on risk identification and mitigation. This role provides a great opportunity to learn about regulatory frameworks, gain hands-on experience with compliance tools, and build a foundation for a career in risk management or corporate governance.

What are the key skills and qualifications needed to thrive as a governance risk compliance intern, and why are they important?

To thrive as a Governance Risk Compliance Intern, you generally need a background in business, finance, or information systems along with a basic understanding of risk management principles. Familiarity with tools like Microsoft Excel, GRC software, and knowledge of standards such as ISO 27001 or SOX is often beneficial. Strong attention to detail, analytical thinking, and effective communication skills help you excel in collaborating with teams and identifying compliance gaps. These skills are crucial for supporting organizational integrity, mitigating risks, and ensuring adherence to regulatory requirements.

What is the difference between Governance Risk Compliance Intern vs Compliance Analyst?

AspectGovernance Risk Compliance InternCompliance Analyst
CredentialsTypically pursuing or recent graduate in related fieldBachelor's degree in law, business, or related field; certifications like CCEP are common
Work EnvironmentInternship setting, learning-focused, entry-level tasksFull-time role, responsible for monitoring and implementing compliance policies
Industry UsageUsed in organizations with compliance programs, often as a temporary positionEstablished role in compliance departments across industries

The Governance Risk Compliance Intern role is an entry-level, learning-focused position often held by students or recent graduates. In contrast, a Compliance Analyst is a full-time professional responsible for ensuring organizational adherence to regulations. While both roles involve understanding compliance principles, the intern role emphasizes gaining experience, whereas the analyst role involves active management and implementation of compliance strategies.

What are the most commonly searched types of Governance Risk Compliance jobs in Boston, MA?

The most popular types of Governance Risk Compliance jobs in Boston, MA are:

What are popular job titles related to Governance Risk Compliance Intern jobs in Boston, MA?

For Governance Risk Compliance Intern jobs in Boston, MA, the most frequently searched job titles are:

What job categories do people searching Governance Risk Compliance Intern jobs in Boston, MA look for?

The top searched job categories for Governance Risk Compliance Intern jobs in Boston, MA are:

What cities near Boston, MA are hiring for Governance Risk Compliance Intern jobs?

Cities near Boston, MA with the most Governance Risk Compliance Intern job openings:

Infographic showing various Governance Risk Compliance Intern job openings in Boston, MA as of August 2026, with employment types broken down into 1% As Needed, 82% Full Time, 12% Part Time, and 5% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution, with an average salary of $50,847 per year, or $24.4 per hour.

Principal Security Governance, Risk & Compliance Analyst

CarGurus

Boston, MA โ€ข On-site

Full-time

Posted yesterday

New


Job description

Role overview

The Principal Information Security GRC Analyst serves as a strategic leader responsible for designing, implementing, and continuously improving CarGurus' cybersecurity governance, risk, and compliance program. This role partners across Engineering, Product, IT, Legal, Privacy, Internal Audit, and Security Operations to ensure security controls effectively manage cyber risk while enabling the business.

The Principal GRC professional leads key initiatives across cyber risk management, customer trust, security compliance, AI governance, third-party risk, and security policy, helping scale security programs to support CarGurus' continued growth.

What you'll do

  • Lead the strategic direction and maturity of CarGurus' Governance, Risk, and Compliance program.
  • Build the cyber risk management program, including cybersecurity risk assessments, cyber risk register management, issue remediation tracking, risk reporting, and security metrics.
  • Lead and mature the SOC 2 Type II compliance program, including audit readiness, evidence management, control testing, remediation tracking, and continuous control monitoring.
  • Partner with Internal Audit to support SOX IT General Controls (ITGCs), application controls, and security-related SOX initiatives.
  • Develop and maintain security policies, standards, and governance processes aligned with business objectives and industry best practices.
  • Build and operationalize the AI Governance program, including AI risk assessments, acceptable use standards, AI inventory, third-party AI reviews, and governance aligned with the NIST AI Risk Management Framework and emerging regulatory requirements.
  • Perform cybersecurity risk assessments for cloud services, applications, infrastructure, AI solutions, and third-party vendors.
  • Partner with Engineering and Product teams to integrate security and AI governance into the secure software development lifecycle.
  • Lead third-party security risk management activities and vendor security assessments.
  • Support customer trust by leading security questionnaires, customer security reviews, and Trust Center initiatives.
  • Partner with Privacy and Legal on data classification, retention, privacy risk assessments, and regulatory compliance.
  • Develop executive reporting on cyber risk, compliance posture, and key security metrics.
  • Drive automation and continuous improvement across GRC processes and controls.

What you'll bring

  • 8+ years of experience in Information Security, Cyber Risk, GRC, or IT Audit.
  • Proven experience building and maturing cyber risk management programs in a cloud-native SaaS environment.
  • Extensive experience leading SOC 2 Type II compliance programs.
  • Experience supporting SOX ITGCs in partnership with Internal Audit.
  • Experience building AI governance frameworks and conducting AI security and risk assessments.
  • Strong knowledge of SOC 2, NIST ISO 27001, GDPR, CCPA, and AWS security principles.
  • Excellent executive communication skills with the ability to influence technical and business stakeholders.