We are hiring a Sr. Information Security Governance, Risk, and Compliance (GRC) Analyst at BlueCross BlueShield of Tennessee! In this role, you will help strengthen and mature BCBST's information ...
We are hiring a Sr. Information Security Governance, Risk, and Compliance (GRC) Analyst at BlueCross BlueShield of Tennessee! In this role, you will help strengthen and mature BCBST's information ...
As a Senior Governance Risk and Compliance (GRC) Analyst at C2 Labs you will lead a team of security analysts and engineers to implement regulatory frameworks such as the Federal Information Security ...
Quick apply
As a Senior Governance Risk and Compliance (GRC) Analyst at C2 Labs you will lead a team of security analysts and engineers to implement regulatory frameworks such as the Federal Information Security ...
The Transportation, Risk, & Compliance team is looking for an experienced Sr. Risk Manager to own and advance Amazon's transportation risk management, governance strategy and policy lifecycle ...
The Transportation, Risk, & Compliance team is looking for an experienced Sr. Risk Manager to own and advance Amazon's transportation risk management, governance strategy and policy lifecycle ...
The Transportation, Risk, & Compliance team is looking for an experienced Sr. Risk Manager to own and advance Amazon's transportation risk management, governance strategy and policy lifecycle ...
The Transportation, Risk, & Compliance team is looking for an experienced Sr. Risk Manager to own and advance Amazon's transportation risk management, governance strategy and policy lifecycle ...
Developing AI-enabled capabilities that accelerate governance, risk, and compliance and cyber operations, including evidence summarization, control testing assist, policy question-and-answer ...
Developing AI-enabled capabilities that accelerate governance, risk, and compliance and cyber operations, including evidence summarization, control testing assist, policy question-and-answer ...
POSITION PURPOSE The Director of IT Governance, Risk and Compliance provides strategic leadership and oversight of the organization's IT risk posture, governance frameworks, and regulatory compliance ...
POSITION PURPOSE The Director of IT Governance, Risk and Compliance provides strategic leadership and oversight of the organization's IT risk posture, governance frameworks, and regulatory compliance ...
POSITION PURPOSE The Director of IT Governance, Risk and Compliance provides strategic leadership and oversight of the organization's IT risk posture, governance frameworks, and regulatory compliance ...
POSITION PURPOSE The Director of IT Governance, Risk and Compliance provides strategic leadership and oversight of the organization's IT risk posture, governance frameworks, and regulatory compliance ...
Developing AI-enabled capabilities that accelerate governance, risk, and compliance and cyber operations, including evidence summarization, control testing assist, policy question-and-answer ...
Developing AI-enabled capabilities that accelerate governance, risk, and compliance and cyber operations, including evidence summarization, control testing assist, policy question-and-answer ...
Developing AI-enabled capabilities that accelerate governance, risk, and compliance and cyber operations, including evidence summarization, control testing assist, policy question-and-answer ...
Developing AI-enabled capabilities that accelerate governance, risk, and compliance and cyber operations, including evidence summarization, control testing assist, policy question-and-answer ...
POSITION PURPOSE The Director of IT Governance, Risk and Compliance provides strategic leadership and oversight of the organization's IT risk posture, governance frameworks, and regulatory compliance ...
POSITION PURPOSE The Director of IT Governance, Risk and Compliance provides strategic leadership and oversight of the organization's IT risk posture, governance frameworks, and regulatory compliance ...
The Transportation, Risk, & Compliance team is looking for an experienced Sr. Risk Manager to own and advance Amazon's transportation risk management, governance strategy and policy lifecycle ...
The Transportation, Risk, & Compliance team is looking for an experienced Sr. Risk Manager to own and advance Amazon's transportation risk management, governance strategy and policy lifecycle ...
Support maintenance of the Regulatory Relations governance framework, procedures, playbooks, and communication standards. * Assist with enterprise compliance risk assessments and control evaluations ...
Support maintenance of the Regulatory Relations governance framework, procedures, playbooks, and communication standards. * Assist with enterprise compliance risk assessments and control evaluations ...
Support maintenance of the Regulatory Relations governance framework, procedures, playbooks, and communication standards. * Assist with enterprise compliance risk assessments and control evaluations ...
Support maintenance of the Regulatory Relations governance framework, procedures, playbooks, and communication standards. * Assist with enterprise compliance risk assessments and control evaluations ...
Research Analyst GRC
Nashville, TN · On-site
Contribute to the development and delivery of research and advisory services across governance, risk, compliance and cybersecurity technologies * Support Research Directors in conducting and ...
Quick apply
Research Analyst GRC
Nashville, TN · On-site
Contribute to the development and delivery of research and advisory services across governance, risk, compliance and cybersecurity technologies * Support Research Directors in conducting and ...
Research Analyst GRC
Nashville, TN · On-site
Contribute to the development and delivery of research and advisory services across governance, risk, compliance and cybersecurity technologies * Support Research Directors in conducting and ...
Research Analyst GRC
Nashville, TN · On-site
Contribute to the development and delivery of research and advisory services across governance, risk, compliance and cybersecurity technologies * Support Research Directors in conducting and ...
Research Analyst GRC
Nashville, TN · On-site
Contribute to the development and delivery of research and advisory services across governance, risk, compliance and cybersecurity technologies * Support Research Directors in conducting and ...
Research Analyst GRC
Nashville, TN · On-site
Contribute to the development and delivery of research and advisory services across governance, risk, compliance and cybersecurity technologies * Support Research Directors in conducting and ...
Director, Cybersecurity & Compliance
Brentwood, TN · On-site
$105K - $141K/yr
Governance, Risk & Compliance * Maintain security policies, standards, risk registers, and governance documentation. * Support SOC 2, HIPAA, CMMC, and other compliance initiatives. * Conduct access ...
Quick apply
Director, Cybersecurity & Compliance
Brentwood, TN · On-site
$105K - $141K/yr
Governance, Risk & Compliance * Maintain security policies, standards, risk registers, and governance documentation. * Support SOC 2, HIPAA, CMMC, and other compliance initiatives. * Conduct access ...
Governance, Risk & Compliance * Maintain security policies, standards, risk registers, and governance documentation. * Support SOC 2, HIPAA, CMMC, and other compliance initiatives. * Conduct access ...
Quick apply
Governance, Risk & Compliance * Maintain security policies, standards, risk registers, and governance documentation. * Support SOC 2, HIPAA, CMMC, and other compliance initiatives. * Conduct access ...
Director, Cybersecurity & Compliance
Brentwood, TN · On-site
$160K - $200K/yr
Governance, Risk & Compliance * Maintain security policies, standards, risk registers, and governance documentation. * Support SOC 2, HIPAA, CMMC, and other compliance initiatives. * Conduct access ...
Director, Cybersecurity & Compliance
Brentwood, TN · On-site
$160K - $200K/yr
Governance, Risk & Compliance * Maintain security policies, standards, risk registers, and governance documentation. * Support SOC 2, HIPAA, CMMC, and other compliance initiatives. * Conduct access ...
Director, Cybersecurity & Compliance
$105K - $141K/yr
Governance, Risk & Compliance * Maintain security policies, standards, risk registers, and governance documentation. * Support SOC 2, HIPAA, CMMC, and other compliance initiatives. * Conduct access ...
Director, Cybersecurity & Compliance
$105K - $141K/yr
Governance, Risk & Compliance * Maintain security policies, standards, risk registers, and governance documentation. * Support SOC 2, HIPAA, CMMC, and other compliance initiatives. * Conduct access ...
Governance Risk Compliance information
See Tennessee salary details
$28.6K - $35.2K
12% of jobs
$35.2K - $41.9K
7% of jobs
$44.2K is the 25th percentile. Wages below this are outliers.
$41.9K - $48.5K
17% of jobs
$48.5K - $55.2K
10% of jobs
The median wage is $56.9K / yr.
$55.2K - $61.8K
16% of jobs
$61.8K - $68.4K
9% of jobs
$72.7K is the 75th percentile. Wages above this are outliers.
$68.4K - $75.1K
7% of jobs
$75.1K - $81.7K
5% of jobs
$81.7K - $88.4K
7% of jobs
$88.4K - $95K
5% of jobs
$95K - $101.7K
4% of jobs
$28.6K
$62.4K
$101.7K
How much do governance risk compliance jobs pay per year?
Is GRC an entry level job?
Is governance risk and compliance a good career?
What is the work of governance risk and compliance?
What Are Jobs in Governance, Risk and Compliance?
Governance risk compliance (GRC) is a method for managing and strategizing an organization's regulations regarding governance, financial or physical risk, and regulatory compliance. It aligns the IT aspects with business objectives and works to improve the efficiency of a company. There are GRC consultants and GRC analysts who provide an assessment of a business’s GRC, identify risks, analyze the data, develop policies to benefit the workplace, and consult on the best choice of action. Your duties may involve optimizing GRC systems, implementing tactics to lower risk, providing internal audits, assisting with cybersecurity, creating routine reports, and ensuring regulatory compliance.
What is the salary of governance risk compliance?
What is Governance, Risk, and Compliance (GRC)?
How does a Governance, Risk, and Compliance (GRC) professional typically collaborate with other departments within an organization?
What is the difference between Governance Risk Compliance vs Risk Analyst?
| Aspect | Governance Risk Compliance | Risk Analyst |
|---|---|---|
| Certifications | CRISC, CISA, CISSP | CFA, FRM, CRISC |
| Work Environment | Corporate, regulated industries | Financial, consulting firms |
| Employer & Industry Usage | Financial institutions, healthcare, government | Banking, investment firms, insurance |
Governance Risk Compliance focuses on establishing policies, ensuring regulatory adherence, and managing enterprise-wide risks. Risk Analysts primarily assess specific financial or operational risks through data analysis. While both roles involve risk management, Governance Risk Compliance has a broader scope related to organizational compliance and governance frameworks, whereas Risk Analysts concentrate on analyzing and quantifying particular risks.
What are the key skills and qualifications needed to thrive as a Governance Risk Compliance (GRC) professional, and why are they important?
- What steps are key to getting into the field of Governance Risk Compliance?
- Is a Governanc Risk Compliance a good career?
- How Can I Get a Job in Governance, Risk and Compliance?
- What is the salary for a Governance Risk Compliance job?
- Governance Risk Compliance Jobs - What Are They and How to Get One
- Governance Risk Compliance Job Description Sample Template

Sr. Information Security Governance, Risk and Compliance Analyst
Chattanooga, TN • Remote
Full-time
Posted 15 days ago
Job description
- This is a remote, work-from-home position, but the final round of interviews will take place on-site in our Chattanooga, TN office.
- Candidates must be able to work Eastern Time Zone business hours.
- Participation in an on-call rotation is required for approximately two weeks every 30 weeks.
- Sponsorship is not available for this role.
Job Responsibilities
- Lead SOC 2 Audit Support - Coordinate audit activities including evidence collection, control validation, and auditor engagement.
- Manage and Validate Control Frameworks - Maintain control documentation, mappings, and narratives while partnering with control owners to ensure effectiveness and alignment with Trust Services Criteria and NIST frameworks.
- Track Audit & Remediation Activities - Oversee audit findings, remediation efforts, and timely closure of issues.
- Develop & Maintain NIST SSPs - Create and update System Security Plans (SSPs), including control implementations, inheritance, and system boundaries.
- Drive Security Awareness Programs - Design and manage training initiatives, including phishing simulations and targeted campaigns.
- Manage Policies & Governance Documentation - Oversee the full lifecycle of security policies, standards, and procedures to ensure compliance and audit readiness.
- Conduct Enterprise & Third-Party Risk Management - Perform risk assessments, maintain risk registers, execute vendor risk assessments, and monitor remediation.
- Oversee Vulnerability Management - Track vulnerability remediation against SLAs and collaborate with teams to mitigate risks.
- Support Customer Security Assurance - Respond to RFPs and security questionnaires, ensuring accurate, compliant, and consistent security representations.
- Leadership - Leads by example, actively supporting initiatives across all GRC areas while fostering a culture of collaboration and shared accountability.
Job Qualifications
Education
- Bachelor's degree in a relevant field or an equivalent of four years of experience is required.
Experience
- 5 years - Professional experience in Information Security or related IT roles with security-related responsibilities, including at least 2 years focused on Governance, Risk, and Compliance (GRC) functions.
- Experience leveraging AI-enabled tools to automate and enhance GRC processes, improving efficiency, consistency, and scalability of governance, risk, and compliance activities preferred.
Skills/Certifications
- Preferred, one or more of the following certifications required: CISSP, CRISC, CISA, or CISM.
- Ability to assess and document organizational risks, including identifying impacts and recommending mitigation strategies.
- Ability to interpret and apply regulatory requirements and industry frameworks (e.g., NIST, SOC 2, HIPAA) to organizational controls.
- Ability to analyze security, compliance, and risk metrics to identify trends and drive continuous improvement.
- Ability to communicate complex risk and compliance concepts clearly to both technical and non-technical stakeholders.
- Ability to collaborate effectively across cross-functional teams to integrate governance, risk, and compliance practices into business processes.
- Exceptional time management skills.
- Excellent oral and written communication skills.
- Strong interpersonal skills and ability to cultivate relationships with internal and external stakeholders, promoting diversity of people, perspectives and ideas.
- Ability to work with all levels of staff and management.
N/A
Number of Openings Available
1Worker Type:
EmployeeCompany:
BCBST BlueCross BlueShield of Tennessee, Inc.Applying for this job indicates your acknowledgement and understanding of the following statements:
BCBST will recruit, hire, train and promote individuals in all job classifications without regard to race, religion, color, age, sex, national origin, citizenship, pregnancy, veteran status, sexual orientation, physical or mental disability, gender identity, or any other characteristic protected by applicable law.
Further information regarding BCBST's EEO Policies/Notices may be found by reviewing the following page:
BCBST's EEO Policies/Notices
BlueCross BlueShield of Tennessee is not accepting unsolicited assistance from search firms for this employment opportunity. All resumes submitted by search firms to any employee at BlueCross BlueShield of Tennessee via-email, the Internet or any other method without a valid, written Direct Placement Agreement in place for this position from BlueCross BlueShield of Tennessee HR/Talent Acquisition will not be considered. No fee will be paid in the event the applicant is hired by BlueCross BlueShield of Tennessee as a result of the referral or through other means.
About BlueCross BlueShield of Tennessee
Sourced by ZipRecruiter
Industry
Insurance services
Company size
5,001 - 10,000 Employees
Headquarters location
Chattanooga, TN, US
Year founded
1945