1

Governance Risk Compliance Jobs in Tennessee (NOW HIRING)

Director, Cybersecurity & Compliance

Brentwood, TN · On-site

$105K - $141K/yr

Governance, Risk & Compliance * Maintain security policies, standards, risk registers, and governance documentation. * Support SOC 2, HIPAA, CMMC, and other compliance initiatives. * Conduct access ...

next page

Showing results 1-20

Governance Risk Compliance information

See Tennessee salary details

$28.6K

$62.4K

$101.7K

How much do governance risk compliance jobs pay per year?

As of Jul 29, 2026, the average yearly pay for governance risk compliance in Tennessee is $62,382.00, according to ZipRecruiter salary data. Most workers in this role earn between $44,500.00 and $78,500.00 per year, depending on experience, location, and employer.

Is GRC an entry level job?

Governance, Risk, and Compliance (GRC) roles can be entry-level or require experience depending on the specific position. Entry-level GRC jobs typically focus on supporting compliance activities and may require basic knowledge of regulations and tools like audit software, while more advanced roles demand prior experience and specialized certifications.

Is governance risk and compliance a good career?

Governance, Risk, and Compliance (GRC) is a growing field that offers opportunities in managing organizational policies, regulatory requirements, and risk mitigation. It often requires knowledge of industry standards, certifications like CISA or CRISC, and strong analytical skills. The role provides stability and advancement potential in various industries, including finance, healthcare, and technology.

What is the work of governance risk and compliance?

Governance, Risk, and Compliance (GRC) professionals develop and implement policies to ensure organizations adhere to legal and regulatory requirements, manage risks effectively, and maintain ethical standards. They often use tools like risk assessments, audits, and compliance frameworks to identify vulnerabilities and ensure organizational integrity. The role requires strong analytical skills and knowledge of industry regulations.

What Are Jobs in Governance, Risk and Compliance?

Governance risk compliance (GRC) is a method for managing and strategizing an organization's regulations regarding governance, financial or physical risk, and regulatory compliance. It aligns the IT aspects with business objectives and works to improve the efficiency of a company. There are GRC consultants and GRC analysts who provide an assessment of a business’s GRC, identify risks, analyze the data, develop policies to benefit the workplace, and consult on the best choice of action. Your duties may involve optimizing GRC systems, implementing tactics to lower risk, providing internal audits, assisting with cybersecurity, creating routine reports, and ensuring regulatory compliance.

What is the salary of governance risk compliance?

The salary for a Governance, Risk, and Compliance (GRC) professional typically ranges from $70,000 to $130,000 annually, depending on experience, location, and certifications such as CISA or CRISC. Entry-level roles may start lower, while senior positions or those in high-demand industries can earn higher salaries.

What is Governance, Risk, and Compliance (GRC)?

Governance, Risk, and Compliance (GRC) is a coordinated strategy that organizations use to manage overall governance, enterprise risk management, and compliance with regulations and standards. GRC professionals help organizations align their business objectives with risk management practices and regulatory requirements. This role involves identifying potential risks, implementing policies to mitigate those risks, and ensuring that the organization adheres to legal, ethical, and internal standards. Effective GRC management can improve decision-making, optimize processes, and protect the organization from financial or reputational harm.

How does a Governance, Risk, and Compliance (GRC) professional typically collaborate with other departments within an organization?

GRC professionals work closely with a variety of departments, including IT, legal, finance, and operations, to ensure that organizational policies and regulatory requirements are consistently met. Collaboration often involves leading risk assessments, facilitating compliance training, and coordinating audits to identify and mitigate potential risks. Effective communication and relationship-building are key, as GRC teams must translate complex regulations into actionable steps for different business units. This cross-functional approach helps embed a culture of compliance and risk awareness throughout the organization.

What is the difference between Governance Risk Compliance vs Risk Analyst?

AspectGovernance Risk ComplianceRisk Analyst
CertificationsCRISC, CISA, CISSPCFA, FRM, CRISC
Work EnvironmentCorporate, regulated industriesFinancial, consulting firms
Employer & Industry UsageFinancial institutions, healthcare, governmentBanking, investment firms, insurance

Governance Risk Compliance focuses on establishing policies, ensuring regulatory adherence, and managing enterprise-wide risks. Risk Analysts primarily assess specific financial or operational risks through data analysis. While both roles involve risk management, Governance Risk Compliance has a broader scope related to organizational compliance and governance frameworks, whereas Risk Analysts concentrate on analyzing and quantifying particular risks.

What are the key skills and qualifications needed to thrive as a Governance Risk Compliance (GRC) professional, and why are they important?

To thrive as a Governance Risk Compliance professional, you need a solid understanding of regulatory frameworks, risk management principles, and policy development, often supported by a degree in business, law, or information security. Familiarity with GRC software platforms, compliance management systems, and certifications like CISA, CRISC, or CISSP is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills set top performers apart in this field. These competencies are essential for ensuring organizational compliance, minimizing risks, and maintaining robust corporate governance.
What are the most commonly searched types of Governance Risk Compliance jobs in Tennessee? The most popular types of Governance Risk Compliance jobs in Tennessee are:
What are popular job titles related to Governance Risk Compliance jobs in Tennessee? For Governance Risk Compliance jobs in Tennessee, the most frequently searched job titles are:
What cities in Tennessee are hiring for Governance Risk Compliance jobs? Cities in Tennessee with the most Governance Risk Compliance job openings:
Infographic showing various Governance Risk Compliance job openings in Tennessee as of July 2026, with employment types broken down into 1% As Needed, 80% Full Time, 14% Part Time, and 5% Contract. Highlights an 94% Physical, 2% Hybrid, and 4% Remote job distribution, with an average salary of $62,382 per year, or $30 per hour.
Sr. Information Security Governance, Risk and Compliance Analyst

Sr. Information Security Governance, Risk and Compliance Analyst

BlueCross BlueShield of Tennessee

Chattanooga, TN • Remote

Full-time

Posted 14 days ago


Job description

We are hiring a Sr. Information Security Governance, Risk, and Compliance (GRC) Analyst at BlueCross BlueShield of Tennessee!
In this role, you will help strengthen and mature BCBST's information security governance program by leading risk management, compliance, and assurance initiatives across the enterprise. You will serve as a key contributor in developing and maintaining Systems Security Plans (SSPs), beginning with enterprise-level security plans and extending into application-specific security documentation. You'll partner with technology and business stakeholders to support audit readiness efforts, manage security controls, assess risk, and ensure alignment with industry frameworks and regulatory requirements. This role plays an important part in protecting organizational assets while helping BCBST maintain a strong security and compliance posture.
To be successful in this role, in addition to the core job requirements, you'll bring strong cybersecurity knowledge, exceptional technical writing skills, and experience translating complex security requirements into clear, actionable documentation. You will be a strong candidate for this role if you have experience developing Systems Security Plans (SSPs), supporting audit and compliance activities, working with security frameworks and control management programs, and collaborating across technical teams to manage risk. Professional certifications such as CISA, CISM, or CISSP are highly preferred and will help distinguish top candidates.
Note:
  • This is a remote, work-from-home position, but the final round of interviews will take place on-site in our Chattanooga, TN office.
  • Candidates must be able to work Eastern Time Zone business hours.
  • Participation in an on-call rotation is required for approximately two weeks every 30 weeks.
  • Sponsorship is not available for this role.

Job Responsibilities

  • Lead SOC 2 Audit Support - Coordinate audit activities including evidence collection, control validation, and auditor engagement.
  • Manage and Validate Control Frameworks - Maintain control documentation, mappings, and narratives while partnering with control owners to ensure effectiveness and alignment with Trust Services Criteria and NIST frameworks.
  • Track Audit & Remediation Activities - Oversee audit findings, remediation efforts, and timely closure of issues.
  • Develop & Maintain NIST SSPs - Create and update System Security Plans (SSPs), including control implementations, inheritance, and system boundaries.
  • Drive Security Awareness Programs - Design and manage training initiatives, including phishing simulations and targeted campaigns.
  • Manage Policies & Governance Documentation - Oversee the full lifecycle of security policies, standards, and procedures to ensure compliance and audit readiness.
  • Conduct Enterprise & Third-Party Risk Management - Perform risk assessments, maintain risk registers, execute vendor risk assessments, and monitor remediation.
  • Oversee Vulnerability Management - Track vulnerability remediation against SLAs and collaborate with teams to mitigate risks.
  • Support Customer Security Assurance - Respond to RFPs and security questionnaires, ensuring accurate, compliant, and consistent security representations.
  • Leadership - Leads by example, actively supporting initiatives across all GRC areas while fostering a culture of collaboration and shared accountability.

Job Qualifications
Education

  • Bachelor's degree in a relevant field or an equivalent of four years of experience is required.

Experience

  • 5 years - Professional experience in Information Security or related IT roles with security-related responsibilities, including at least 2 years focused on Governance, Risk, and Compliance (GRC) functions.
  • Experience leveraging AI-enabled tools to automate and enhance GRC processes, improving efficiency, consistency, and scalability of governance, risk, and compliance activities preferred.

Skills/Certifications

  • Preferred, one or more of the following certifications required: CISSP, CRISC, CISA, or CISM.
  • Ability to assess and document organizational risks, including identifying impacts and recommending mitigation strategies.
  • Ability to interpret and apply regulatory requirements and industry frameworks (e.g., NIST, SOC 2, HIPAA) to organizational controls.
  • Ability to analyze security, compliance, and risk metrics to identify trends and drive continuous improvement.
  • Ability to communicate complex risk and compliance concepts clearly to both technical and non-technical stakeholders.
  • Ability to collaborate effectively across cross-functional teams to integrate governance, risk, and compliance practices into business processes.
  • Exceptional time management skills.
  • Excellent oral and written communication skills.
  • Strong interpersonal skills and ability to cultivate relationships with internal and external stakeholders, promoting diversity of people, perspectives and ideas.
  • Ability to work with all levels of staff and management.

N/A

Number of Openings Available

1

Worker Type:

Employee

Company:

BCBST BlueCross BlueShield of Tennessee, Inc.

Applying for this job indicates your acknowledgement and understanding of the following statements:

BCBST will recruit, hire, train and promote individuals in all job classifications without regard to race, religion, color, age, sex, national origin, citizenship, pregnancy, veteran status, sexual orientation, physical or mental disability, gender identity, or any other characteristic protected by applicable law.

Further information regarding BCBST's EEO Policies/Notices may be found by reviewing the following page:

BCBST's EEO Policies/Notices

BlueCross BlueShield of Tennessee is not accepting unsolicited assistance from search firms for this employment opportunity. All resumes submitted by search firms to any employee at BlueCross BlueShield of Tennessee via-email, the Internet or any other method without a valid, written Direct Placement Agreement in place for this position from BlueCross BlueShield of Tennessee HR/Talent Acquisition will not be considered. No fee will be paid in the event the applicant is hired by BlueCross BlueShield of Tennessee as a result of the referral or through other means.