1

Governance Risk Compliance Manager Jobs in Springfield, MA

Develop, implement and support strategies for PFAS compliance, risk reduction, and substitution in products, processes, and supply chains. * Conduct assessments of PFAS use and potential ...

Develop, implement and support strategies for PFAS compliance, risk reduction, and substitution in products, processes, and supply chains. * Conduct assessments of PFAS use and potential ...

next page

Showing results 1-20

Governance Risk Compliance Manager information

See Springfield, MA salary details

$38.4K

$94.8K

$156.4K

How much do governance risk compliance manager jobs pay per year?

As of Aug 20, 2026, the average yearly pay for governance risk compliance manager in Springfield, MA is $94,770.00, according to ZipRecruiter salary data. Most workers in this role earn between $69,800.00 and $116,100.00 per year, depending on experience, location, and employer.

What does a Governance Risk Compliance (GRC) manager do?

A Governance Risk Compliance (GRC) Manager is responsible for developing, implementing, and overseeing policies and procedures to ensure that an organization complies with regulatory requirements and manages risks effectively. They work closely with various departments to identify potential risks, ensure proper governance frameworks are in place, and monitor compliance with relevant laws and standards. GRC Managers play a key role in maintaining ethical practices, preventing legal issues, and helping organizations achieve their business objectives securely and efficiently.

How does a Governance Risk Compliance (GRC) manager typically collaborate with other departments to ensure effective risk management?

A GRC Manager works closely with various departments such as IT, legal, finance, and operations to identify, assess, and mitigate risks across the organization. This often involves facilitating cross-departmental meetings, guiding teams through compliance requirements, and ensuring that controls are implemented effectively. Strong communication and project management skills are essential, as GRC Managers must translate complex regulatory requirements into actionable steps for different teams. This collaborative approach helps ensure that risk management strategies are integrated into daily business processes and that compliance goals are met organization-wide.

What are the key skills and qualifications needed to thrive as a Governance Risk Compliance manager, and why are they important?

To thrive as a Governance Risk Compliance Manager, you need expertise in risk assessment, regulatory frameworks, and compliance management, typically supported by a degree in business, law, or a related field. Familiarity with GRC platforms (like RSA Archer or MetricStream), internal audit tools, and relevant certifications such as CISA, CISM, or CRISC is common. Strong analytical thinking, attention to detail, and effective communication help manage complex regulations and drive organizational compliance culture. These skills ensure the organization can proactively identify risks, comply with legal requirements, and maintain operational integrity.

What is the difference between Governance Risk Compliance Manager vs Compliance Analyst?

AspectGovernance Risk Compliance ManagerCompliance Analyst
CertificationsISO 31000, CRISC, CISACCA, CCEP, or similar
Work EnvironmentStrategic, managerial, policy-focusedOperational, detail-oriented, audit-focused
Employer & Industry UsageFinancial, healthcare, corporate sectorsRegulatory agencies, corporations, consulting firms
Search & Comparison IntentUnderstanding managerial roles in governance and riskDetailing compliance procedures and analysis

The Governance Risk Compliance Manager oversees organizational policies, risk management strategies, and compliance frameworks at a strategic level. In contrast, the Compliance Analyst focuses on implementing and monitoring compliance procedures, conducting audits, and ensuring adherence to regulations. Both roles require relevant certifications and are vital in maintaining organizational integrity, but they differ in scope and responsibilities.

Is governance risk compliance a good career?

A career as a Governance, Risk, and Compliance (GRC) Manager is considered stable and in demand, as organizations seek to manage regulatory requirements, cybersecurity threats, and operational risks. The role often requires knowledge of industry standards, certifications like CISA or CISSP, and strong analytical skills, making it a valuable and growing field in many industries.

What are the most commonly searched types of Governance Risk Compliance jobs in Springfield, MA?

The most popular types of Governance Risk Compliance jobs in Springfield, MA are:

What are popular job titles related to Governance Risk Compliance Manager jobs in Springfield, MA?

For Governance Risk Compliance Manager jobs in Springfield, MA, the most frequently searched job titles are:

What job categories do people searching Governance Risk Compliance Manager jobs in Springfield, MA look for?

The top searched job categories for Governance Risk Compliance Manager jobs in Springfield, MA are:

What cities near Springfield, MA are hiring for Governance Risk Compliance Manager jobs?

Cities near Springfield, MA with the most Governance Risk Compliance Manager job openings:

Infographic showing various Governance Risk Compliance Manager job openings in Springfield, MA as of August 2026, with employment types broken down into 100% Full Time. Highlights an 94% In-person, and 6% Hybrid job distribution, with an average salary of $94,770 per year, or $45.6 per hour.

Senior IT Risk and Compliance Engineer

Jobtailor

Hartford, CT โ€ข On-site

$120 - $180/hr

Other

Posted 2 days ago

New


Job description

  • Partner with business units and IT leadership to develop, maintain, and operationalize information security policies, standards, and procedures
  • Collaborate with stakeholders across the enterprise to formulate security strategies and risk reduction guidelines that align with business objectives.
  • Consult with business and technology teams on building secure processes and information systems from the ground up
  • Help evolve the security awareness program, translating technical risk into clear communication for employees at all levels within the organization
  • Lead efforts with business units to assess, document, accept, and/or mitigate risk associated with enterprise-wide initiatives and third-party relationships
  • Perform detailed threat and vulnerability analysis, combining sound analytical skills with advanced knowledge of IT security risks
  • Evaluate the severity and potential impact of identified threats, translating findings into actionable recommendations for leadership and business stakeholders
  • Maintain a current understanding of the threat landscape through ongoing research into emerging risks and their potential impact on our environment
  • Lead and perform security assessments of third parties and partners, documenting findings and driving remediation
  • Serve as a key resource in preparing for internal audits, external audits, and state regulatory examinations including drafting responses, managing evidence, and tracking remediation commitments
  • Monitor ongoing compliance with information security policies and assist business units in managing exceptions to policy and standards
  • Provide oversight of managed security services, including vulnerability management, firewall operations, Security Operations Center, and data loss prevention
  • Investigate, document, and follow through on information security incidents and policy violations, ensuring appropriate resolution and lessons learned
  • Identify and implement opportunities to automate manual GRC and compliance workflows, reducing operational overhead and improving program consistency and accuracy
  • Develop metrics, dashboards, and reporting mechanisms to provide leadership clear visibility into risk posture and program health
  • Evaluate new and emerging security technologies leading proof-of-concept assessments and making recommendations to management

Requirements

  • Bachelorโ€™s degree in information security, Computer Science, Information Systems, or a related field.
  • Minimum of 7 years of cybersecurity experience with strong expertise in governance, risk, compliance, or audit support functions.
  • Industry-recognized certification such as CISSP, CISM, CRISC, or equivalent ISACA or GIAC credential.
  • Working knowledge of security frameworks including NIST 800-53, ISO 27001, and/or NIST CSF.
  • Demonstrated experience supporting regulatory examinations or external audits, including evidence preparation and remediation tracking.
  • Practical experience with cloud security controls (Azure, Oracle Cloud, or Microsoft 365).
  • Experience identifying and implementing process automation within GRC or compliance workflows.
  • Exceptional written and verbal communication skills, with the ability to convey technical risk clearly to non-technical audiences.
  • Strong organizational skills with the ability to manage multiple workstreams, priorities, and stakeholders simultaneously
  • Experience in the insurance or financial services industry, particularly in environments subject to state insurance department oversight is preferred
  • Familiarity with GRC platforms or security automation tooling (e.g., ServiceNow GRC, Archer, or similar) is a plus
  • Experience scripting or light automation skills (Python, PowerShell) applied to security or compliance use cases is a plus
  • Familiarity with vulnerability management programs and third-party risk assessment methodologies is preferred

Core Competencies

Demonstrates extensive expertise in cybersecurity governance, risk management, and compliance, with a strong focus on developing and operationalizing security policies and procedures. Proficient in translating technical risks into clear communication for diverse stakeholders while leading security assessments and managing third-party relationships.

Highest-signal resume keywords

  • Cybersecurity Experience
  • Governance, Risk, Compliance (GRC)
  • CISSP, CISM, CRISC Certification
  • NIST 800-53, ISO 27001 Frameworks
  • Cloud Security Controls (Azure, Oracle Cloud, Microsoft 365)

ATS Optimization Keywords

Hard Skills

  • Threat and Vulnerability Analysis
  • Security Assessments
  • Process Automation
  • Scripting (Python, PowerShell)
  • Metrics and Reporting Development

Soft Skills

  • Exceptional Written Communication
  • Strong Organizational Skills

Certifications & Qualifications

  • CISSP
  • CISM
  • CRISC

Industry Keywords

  • Insurance Industry
  • Financial Services
  • Regulatory Examinations
  • Third-Party Risk Assessment

Tools & Technologies

  • ServiceNow GRC
  • Archer
  • Security Operations Center
  • Data Loss Prevention
#J-18808-Ljbffr