1

Governance Risk Compliance Jobs in Kentucky (NOW HIRING)

IT Security and Governance Analyst

Louisville, KY · On-site

$43.25 - $57.50/hr

Brown-Forman is a premium spirits company that offers a dynamic opportunity for an experienced IT Governance/Risk/Compliance Analyst. In this role, you will identify and mitigate IT risks, ensure ...

$41.75 - $55.75/hr

The IT Governance/Risk/Compliance Analyst position offers a dynamic opportunity for an experienced analyst to help shape the future of our governance, risk, and compliance initiatives. In this role ...

The Compliance Manager plays a critical, enterprise-wide role in shaping and advancing Sazerac ... Strong expertise in governance, risk management, and internal audit frameworks * Ability to travel ...

This leader will drive a proactive, risk-based compliance culture-ensuring alignment with domestic ... Strong expertise in governance, risk management, and internal audit frameworks * Ability to travel ...

Experience using Governance, Risk, and Compliance (GRC) platforms or audit management tools. * Familiarity with cloud environments, information security controls, and third-party risk management.

Experience using Governance, Risk, and Compliance (GRC) platforms or audit management tools. * Familiarity with cloud environments, information security controls, and third-party risk management.

next page

Showing results 1-20

Governance Risk Compliance information

What are jobs in governance risk compliance?

Governance risk compliance (GRC) is a method for managing and strategizing an organization's regulations regarding governance, financial or physical risk, and regulatory compliance. It aligns the IT aspects with business objectives and works to improve the efficiency of a company. There are GRC consultants and GRC analysts who provide an assessment of a business’s GRC, identify risks, analyze the data, develop policies to benefit the workplace, and consult on the best choice of action. Your duties may involve optimizing GRC systems, implementing tactics to lower risk, providing internal audits, assisting with cybersecurity, creating routine reports, and ensuring regulatory compliance.

What is the work of governance risk compliance?

Governance, Risk, and Compliance (GRC) professionals develop and implement policies to ensure organizations adhere to legal and regulatory requirements, manage risks, and maintain ethical standards. They analyze business processes, conduct audits, and use tools like risk management software to identify vulnerabilities and ensure compliance across departments.

What is governance risk compliance?

Governance, Risk, and Compliance (GRC) is a coordinated strategy that organizations use to manage overall governance, enterprise risk management, and compliance with regulations and standards. GRC professionals help organizations align their business objectives with risk management practices and regulatory requirements. This role involves identifying potential risks, implementing policies to mitigate those risks, and ensuring that the organization adheres to legal, ethical, and internal standards. Effective GRC management can improve decision-making, optimize processes, and protect the organization from financial or reputational harm.

How does a governance risk compliance professional typically collaborate with other departments within an organization?

GRC professionals work closely with a variety of departments, including IT, legal, finance, and operations, to ensure that organizational policies and regulatory requirements are consistently met. Collaboration often involves leading risk assessments, facilitating compliance training, and coordinating audits to identify and mitigate potential risks. Effective communication and relationship-building are key, as GRC teams must translate complex regulations into actionable steps for different business units. This cross-functional approach helps embed a culture of compliance and risk awareness throughout the organization.

What is the difference between Governance Risk Compliance vs Risk Analyst?

AspectGovernance Risk ComplianceRisk Analyst
CertificationsCRISC, CISA, CISSPCFA, FRM, CRISC
Work EnvironmentCorporate, regulated industriesFinancial, consulting firms
Employer & Industry UsageFinancial institutions, healthcare, governmentBanking, investment firms, insurance

Governance Risk Compliance focuses on establishing policies, ensuring regulatory adherence, and managing enterprise-wide risks. Risk Analysts primarily assess specific financial or operational risks through data analysis. While both roles involve risk management, Governance Risk Compliance has a broader scope related to organizational compliance and governance frameworks, whereas Risk Analysts concentrate on analyzing and quantifying particular risks.

What are the key skills and qualifications needed to thrive as a governance risk compliance professional?

To thrive as a Governance Risk Compliance professional, you need a solid understanding of regulatory frameworks, risk management principles, and policy development, often supported by a degree in business, law, or information security. Familiarity with GRC software platforms, compliance management systems, and certifications like CISA, CRISC, or CISSP is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills set top performers apart in this field. These competencies are essential for ensuring organizational compliance, minimizing risks, and maintaining robust corporate governance.
What are the most commonly searched types of Governance Risk Compliance jobs in Kentucky? The most popular types of Governance Risk Compliance jobs in Kentucky are:
What are popular job titles related to Governance Risk Compliance jobs in Kentucky? For Governance Risk Compliance jobs in Kentucky, the most frequently searched job titles are:
What job categories do people searching Governance Risk Compliance jobs in Kentucky look for? The top searched job categories for Governance Risk Compliance jobs in Kentucky are:
What cities in Kentucky are hiring for Governance Risk Compliance jobs? Cities in Kentucky with the most Governance Risk Compliance job openings:
Infographic showing various Governance Risk Compliance job openings in Kentucky as of August 2026, with employment types broken down into 1% As Needed, 84% Full Time, 11% Part Time, and 4% Contract. Highlights an 93% Physical, 3% Hybrid, and 4% Remote job distribution.

IT Security and Governance Analyst

Brown-Forman

Louisville, KY • On-site

$43.25 - $57.50/hr

Full-time

Re-posted 29 days ago


Brown‑Forman rating

7.7

Company rating: 7.7 out of 10

Based on 8 frontline employees who took The Breakroom Quiz

122nd of 436 rated food and drinks producers


Job description

Job Summary:
Brown-Forman is a premium spirits company that offers a dynamic opportunity for an experienced IT Governance/Risk/Compliance Analyst. In this role, you will identify and mitigate IT risks, ensure regulatory compliance, and enhance the organization's security posture through governance frameworks and controls.
Responsibilities:
• Develop and maintain IT governance frameworks and policies that align with industry standards and regulatory requirements, which are then implemented by IT owners.
• Support our IT risk management program to ensure both internal and third-party IT risks are identified, assessed, prioritized and remediated.
• Raise awareness within the organization of IT governance, risk and compliance programs that are risk based and align with compliance requirements.
• Track and ensure compliance with internal policies and external regulations through periodic audits and assessments.
• Ensure data security and privacy compliance by providing guidance on appropriate access controls, data classification protocols, and data protection measures.
• Collaborate with key stakeholders throughout the IT organization as well as with Internal Audit, Compliance, and Legal.
• Monitor evolving regulations, compliance standards, and best practices to strengthen our IT GRC capabilities and frameworks.
Qualifications:
Required:
• 3+ years of experience focused on governance, compliance, risk, audit or similar functions.
• Knowledge of IT governance and risk management frameworks including compliance practices (e.g., PCI, NIST, GDPR, COBIT, NIS2, Operation Technology, etc.).
• Strong analytical skills, attention to detail, and a problem-solving mindset.
• Excellent collaboration, communication and influencing skills with the ability to develop effective working relationships with all levels of the company.
• Exposure to risk assessments, policy development, and internal control audits.
Preferred:
• Bachelor’s degree within a related area of study.
• Information security related training or certifications such as CISA, CRISC, PCI QSA.
• Experience working with GRC platforms and tools.
• Familiarity with third-party risk management and vendor compliance.
Company:
Brown‑Forman Corporation is a global leader in the spirits industry, responsibly building exceptional beverage alcohol brands for more than 155 years. Founded in 1870, the company is headquartered in Louisville, USA, with a team of 5001-10000 employees. The company is currently Late Stage.

What Brown‑Forman employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom