1

Governance Risk Compliance Jobs in Florida (NOW HIRING)

next page

Showing results 1-20

Governance Risk Compliance information

See Florida salary details

$23.5K

$51.4K

$83.7K

How much do governance risk compliance jobs pay per year?

As of Aug 15, 2026, the average yearly pay for governance risk compliance in Florida is $51,363.00, according to ZipRecruiter salary data. Most workers in this role earn between $36,600.00 and $64,600.00 per year, depending on experience, location, and employer.

What are jobs in governance risk compliance?

Governance risk compliance (GRC) is a method for managing and strategizing an organization's regulations regarding governance, financial or physical risk, and regulatory compliance. It aligns the IT aspects with business objectives and works to improve the efficiency of a company. There are GRC consultants and GRC analysts who provide an assessment of a business’s GRC, identify risks, analyze the data, develop policies to benefit the workplace, and consult on the best choice of action. Your duties may involve optimizing GRC systems, implementing tactics to lower risk, providing internal audits, assisting with cybersecurity, creating routine reports, and ensuring regulatory compliance.

What is the work of governance risk compliance?

Governance, Risk, and Compliance (GRC) professionals develop and implement policies to ensure organizations adhere to legal and regulatory requirements, manage risks, and maintain ethical standards. They analyze business processes, conduct audits, and use tools like risk management software to identify vulnerabilities and ensure compliance across departments.

What is governance risk compliance?

Governance, Risk, and Compliance (GRC) is a coordinated strategy that organizations use to manage overall governance, enterprise risk management, and compliance with regulations and standards. GRC professionals help organizations align their business objectives with risk management practices and regulatory requirements. This role involves identifying potential risks, implementing policies to mitigate those risks, and ensuring that the organization adheres to legal, ethical, and internal standards. Effective GRC management can improve decision-making, optimize processes, and protect the organization from financial or reputational harm.

How does a governance risk compliance professional typically collaborate with other departments within an organization?

GRC professionals work closely with a variety of departments, including IT, legal, finance, and operations, to ensure that organizational policies and regulatory requirements are consistently met. Collaboration often involves leading risk assessments, facilitating compliance training, and coordinating audits to identify and mitigate potential risks. Effective communication and relationship-building are key, as GRC teams must translate complex regulations into actionable steps for different business units. This cross-functional approach helps embed a culture of compliance and risk awareness throughout the organization.

What is the difference between Governance Risk Compliance vs Risk Analyst?

AspectGovernance Risk ComplianceRisk Analyst
CertificationsCRISC, CISA, CISSPCFA, FRM, CRISC
Work EnvironmentCorporate, regulated industriesFinancial, consulting firms
Employer & Industry UsageFinancial institutions, healthcare, governmentBanking, investment firms, insurance

Governance Risk Compliance focuses on establishing policies, ensuring regulatory adherence, and managing enterprise-wide risks. Risk Analysts primarily assess specific financial or operational risks through data analysis. While both roles involve risk management, Governance Risk Compliance has a broader scope related to organizational compliance and governance frameworks, whereas Risk Analysts concentrate on analyzing and quantifying particular risks.

What are the key skills and qualifications needed to thrive as a governance risk compliance professional?

To thrive as a Governance Risk Compliance professional, you need a solid understanding of regulatory frameworks, risk management principles, and policy development, often supported by a degree in business, law, or information security. Familiarity with GRC software platforms, compliance management systems, and certifications like CISA, CRISC, or CISSP is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills set top performers apart in this field. These competencies are essential for ensuring organizational compliance, minimizing risks, and maintaining robust corporate governance.

What are the most commonly searched types of Governance Risk Compliance jobs in Florida?

The most popular types of Governance Risk Compliance jobs in Florida are:

What job categories do people searching Governance Risk Compliance jobs in Florida look for?

The top searched job categories for Governance Risk Compliance jobs in Florida are:

What cities in Florida are hiring for Governance Risk Compliance jobs?

Cities in Florida with the most Governance Risk Compliance job openings:

Infographic showing various Governance Risk Compliance job openings in Florida as of August 2026, with employment types broken down into 1% As Needed, 83% Full Time, 12% Part Time, and 4% Contract. Highlights an 93% Physical, 3% Hybrid, and 4% Remote job distribution, with an average salary of $51,363 per year, or $24.7 per hour.

Governance, Risk & Compliance Analyst II

COMTECH TELECOMMUNICATIONS

Orlando, FL • On-site

$73K - $91K/yr

Full-time

Posted 5 days ago


Job description




Title: Governance, Risk & Compliance Analyst II

Department: Admin & compliance 802900

Revision Date: 8/6/2026

FLSA Status: Exempt

Location: Remote

Level: P2

Company Overview

Comtech Telecommunications Corp. is a leading global technology company providing terrestrial and wireless network solutions, next-generation 9-1-1 emergency services, satellite and space communications technologies, and cloud native capabilities to commercial and government customers around the world. Our unique culture of innovation and employee empowerment unleashes a relentless passion for customer success. With multiple facilities located in technology corridors throughout the United States and around the world, Comtech leverages our global presence, technology leadership, and decades of experience to create the world’s most innovative communications solutions. For more information, please visit www.comtech.com.


Position Summary

The GRC Analyst II is a midlevel compliance professional responsible for supporting Comtech’s enterprise cybersecurity governance, risk management, regulatory compliance, and audit readiness programs. This role plays a critical part in maintaining compliance with Department of Defense (DoD) requirements, including CMMC, DFARS 252.2047012/7019/7020, and NIST SP 800-171.

The Analyst II will work closely with IT, Security, Engineering, Manufacturing, and external assessment partners to ensure Comtech systems, processes, and documentation meet federal, contractual, and industry cybersecurity standards.


Responsibilities:

Governance & Policy Management

  • Review, update, and maintain Comtech cybersecurity policies, standards, and procedures.
  • Ensure documentation aligns with DFARS, CMMC, NIST SP 800171, NIST CSF, and internal compliance objectives.
  • Assist in drafting new policies and procedures to address regulatory gaps and audit findings.

Compliance Program Execution

  • Collect and maintain evidence for NIST SP 800171 controls across all families.
  • Perform internal control testing; validate control operation through screenshots, configurations, and interviews with system owners.
  • Support readiness activities for external CMMC assessments and DIBCAC audits.
  • Document compliance gaps and work with stakeholders to track remediation plans.

Risk Management

  • Support enterprise risk assessments and risk tracking activities.
  • Document identified risks, evaluate severity, and develop mitigation recommendations.
  • Conduct reviews of privileged access, separation of duties, and user lifecycle management.

CUI Identification & Handling

  • Assist in documenting CUI data flow, system boundaries, network diagrams, and CUI storage/transmission locations.
  • Validate enforcement of CUI access controls, session lock/termination parameters, and security notices.
  • Support ongoing reviews of systems handling CUI to maintain administrative and technical compliance.

Access Control & Identity Governance

  • Perform and document role based access reviews, privileged account audits, and separation of duties analysis.
  • Coordinate with business unit system owners (e.g., M2K, ERP, AD administrators) to compile lists of authorized users, devices, and system accounts.
  • Validate configurations related to failed logon thresholds, session timeouts, security banners, and role permissions.

Internal Audit & External Assessment Support

  • Work with internal audit teams and external partners (e.g., RISC Point) to prepare audit packages and evidence submissions.
  • Maintain organized repositories of assessment artifacts, reports, and compliance documents.
  • Support quarterly and annual control reviews.

Incident Response & Business Continuity Support

  • Assist in maintaining and updating IR, DR, and BCP documentation.
  • Collect evidence and support after action reviews, helping to improve response plans and procedures.

Operational Support & Ticket Management

  • Resolve compliance related tickets requiring documentation, evidence updates, or access verification.
  • Ensure timely response and remediation for aging compliance tasks.

Skills:

  • Prior experience supporting compliance within a DoD contractor environment.
  • Prior experience supporting NIST 800-171 requirements
  • Familiarity with CUI identification and marking requirements.
  • Experience with system administration basics (e.g., Active Directory roles/permissions review).
  • Certifications: Security+, CGRC, CAP, CMMC-RP, CCP, CISA, or similar governance/compliance credentials.


Requirements:

  • Strong understanding of NIST SP 800171 (R2/R3), DFARS, CMMC Level 2, and federal cybersecurity compliance.
  • Experience performing access reviews, control evidence collection, and audit preparation.
  • Ability to read and interpret technical configurations, logs, and administrative settings.
  • Excellent writing skills for policy review, control documentation, and evidence narratives.
  • Strong analytical capabilities with attention to detail and accuracy.
  • Ability to work cross functionally with IT, security, engineering, and external assessors.
  • Proficiency with Microsoft 365, SharePoint, and compliance documentation management.


Education and Experience:

  • Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Business IT, or related field.
  • 2–5 years of experience in GRC, IT audit, cybersecurity compliance, or risk management.



About:

This position requires compliance with Comtech’s Drug-Free Workplace Program. Candidates must successfully complete a pre-employment drug screening as a condition of hire. Employees may be subject to random, reasonable suspicion, and post-incident testing. Illegal drug use — including marijuana, regardless of state law — is disqualifying under federal adjudicative guidelines and DoD DFARS requirements.

The pay range reflects the expected base salary for this position. Final compensation will be based on role, level, skills, experience, and geographic location.

Comtech Telecommunications Corp. is an Equal Opportunity Employer. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability protected veteran status or other characteristics protected by law.