1

Governance Risk Compliance Specialist Jobs (NOW HIRING)

next page

Showing results 1-20

Governance Risk Compliance Specialist information

See salary details

$38K

$100.5K

How much do governance risk compliance specialist jobs pay per year?

As of Aug 7, 2026, the average yearly pay for governance risk compliance specialist in the United States is $94,940.00, according to ZipRecruiter salary data. Most workers in this role earn between $98,500.00 and $98,500.00 per year, depending on experience, location, and employer.

What is a governance risk compliance specialist?

A Governance Risk Compliance (GRC) Specialist is a professional responsible for ensuring that an organization adheres to regulatory requirements, manages risks, and maintains effective governance practices. They develop and implement policies, conduct risk assessments, and monitor compliance to prevent legal or regulatory issues. GRC Specialists often work closely with various departments to identify vulnerabilities, recommend solutions, and ensure the organization's operations align with industry standards and laws.

How does a governance risk compliance specialist typically collaborate with other departments within an organization?

A Governance Risk Compliance (GRC) Specialist works closely with a variety of departments, such as IT, legal, internal audit, and operations, to ensure that risk management and compliance initiatives are effectively implemented. Collaboration often involves leading risk assessments, developing and communicating compliance policies, and offering guidance on regulatory changes. GRC Specialists frequently facilitate training sessions, coordinate audits, and serve as a resource to department leaders for interpreting compliance requirements. This cross-functional teamwork is essential for fostering a culture of accountability and maintaining organizational integrity.

What are the key skills and qualifications needed to thrive as a governance risk compliance specialist, and why are they important?

To thrive as a Governance Risk Compliance Specialist, you need a solid understanding of regulatory frameworks, risk management principles, and compliance standards, often supported by degrees in business, law, or information security. Familiarity with GRC platforms (such as RSA Archer or ServiceNow), data analysis tools, and certifications like CISA, CRISC, or CISSP is typically required. Strong analytical thinking, attention to detail, and effective communication are vital soft skills for interpreting regulations and collaborating across departments. These competencies ensure organizations proactively manage risks, meet legal requirements, and maintain robust internal controls.

What is the difference between Governance Risk Compliance Specialist vs Compliance Analyst?

AspectGovernance Risk Compliance SpecialistCompliance Analyst
CertificationsISO, CRISC, CISACPA, CIA, CCEP
Work EnvironmentCorporate, financial, healthcare sectorsRegulatory agencies, corporations, consulting firms
Primary FocusDeveloping governance frameworks, managing risk, ensuring complianceMonitoring compliance, conducting audits, analyzing regulations

While both roles focus on compliance, the Governance Risk Compliance Specialist has a broader scope including governance and risk management, whereas the Compliance Analyst primarily concentrates on monitoring and auditing compliance adherence.

More about Governance Risk Compliance Specialist jobs
Infographic showing various Governance Risk Compliance Specialist job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 84% Full Time, 11% Part Time, and 4% Contract. Highlights an 94% Physical, 2% Hybrid, and 4% Remote job distribution, with an average salary of $94,940 per year, or $45.6 per hour.

Director, Governance, Risk & Compliance

MX Technologies, Inc.

Lehi, UT โ€ข On-site

Other

Posted 6 days ago


Job description

As we continue to grow our platform and expand our customer base, we're looking for an experienced Director of Governance, Risk & Compliance (GRC) to lead our enterprise Information Security Governance, Risk, Compliance, and Privacy programs. This leader will partner across Security, Engineering, Legal, Product, Sales, Customer Success, and Operations to ensure MX maintains industry-leading security and privacy standards while enabling the business to move quickly and responsibly.

Reporting directly to the VP & Chief Information Security Officer (CISO), you will lead the Compliance team and own the strategy, execution, and continuous improvement of MX's security governance, privacy, and regulatory compliance programs.

ย What You'll DoLead Governance, Risk & Compliance
  • Develop and execute MX's enterprise Governance, Risk & Compliance (GRC) strategy.
  • Build, mature, and continuously improve security, privacy, and risk management programs that align with business objectives and regulatory requirements.
  • Develop, maintain, and operationalize enterprise-wide security policies, standards, controls, and governance processes.
  • Establish scalable compliance frameworks that support continued company growth while reducing organizational risk.
Own Privacy & Regulatory Compliance
  • Lead the company's global privacy program across multiple jurisdictions.
  • Ensure compliance with applicable privacy regulations, including GDPR, CCPA, HIPAA, PIPEDA, UK Data Protection Act, and other emerging regulations.
  • Partner with Legal, Engineering, Product, and business stakeholders to perform Privacy Impact Assessments (PIAs) and advise on privacy requirements throughout the product lifecycle.
  • Develop governance frameworks for responsible data collection, storage, processing, retention, and sharing.
  • Oversee data mapping initiatives, vendor privacy reviews, and data governance practices.
Manage Audits & Customer Assurance
  • Own all internal and external security, privacy, and compliance audits.
  • Lead certification efforts including SOC 2, ISO 27001, PCI DSS, and other applicable frameworks.
  • Serve as the executive owner for customer security and privacy questionnaires.
  • Partner with Sales and Customer Success to support enterprise customer due diligence and security reviews.
Drive Risk Management
  • Continuously assess organizational security, compliance, and privacy risks.
  • Monitor effectiveness of security controls and recommend improvements where necessary.
  • Build reporting and metrics that provide executive leadership visibility into organizational risk posture.
  • Develop mitigation strategies and partner across engineering and operations to reduce risk.
Lead & Develop the Team
  • Lead, mentor, and grow a high-performing Compliance and Privacy team.
  • Foster a culture of accountability, operational excellence, and continuous improvement.
  • Develop scalable processes that improve efficiency while maintaining regulatory compliance.
Build Cross-Functional Partnerships
  • Partner closely with Security, Engineering, Legal, Product, Sales, Support, and Operations to embed security and privacy into business processes.
  • Influence stakeholders across the organization to balance business objectives with regulatory obligations.
  • Lead company-wide privacy and compliance awareness initiatives and employee training programs.
Basic Qualifications
  • Bachelor's degree in Information Technology, Computer Science, Cybersecurity, Information Systems, Business, Legal Studies, or a related field.
  • 10+ years of experience leading Information Security Governance, Risk, Compliance, Privacy, or Security Operations programs.
  • Deep expertise with compliance frameworks
  • Experience implementing Governance, Risk & Compliance (GRC) platforms and common control frameworks.
Preferred Qualifications
  • Professional certifications such as: CIPP, CIPM, CIPT, CISM, CISA
  • Experience working within fintech or highly regulated industries.
  • Knowledge of Business Continuity Planning and Disaster Recovery.
  • Experience supporting multinational organizations with global regulatory requirements.
  • Familiarity with Web Application Firewalls (WAFs), Content Delivery Networks (CDNs), and modern cloud infrastructure.
ย