1

Grc Analyst Jobs in Indiana (NOW HIRING)

Sr. GRC Analyst About Subsplash Subsplash is an exciting award-winning team of 280+ mission-driven people who are committed to our core values of humility, innovation, and excellence. Founded in 2005 ...

$80K - $165K/yr

Perform formal risk analysis and self-assessments for technology processes, leveraging industry ... ServiceNow IRM/GRC experience to design/optimize workflow, reporting and implementing new features

Senior GRC Risk Analyst

Carmel, IN · On-site

$105K - $130K/yr

Join MISO as a Senior GRC Risk Analyst , where you will play a key role in safeguarding the power grid by identifying, assessing, and mitigating cybersecurity risks. In this role, you'll be central ...

Job Title: IT Auditor I (GRC Analyst I) FLSA Status: Exempt Job Family: Information Technology Department: IT - Information Security Location: Corporate Office (Fort Wayne IN) JOB SUMMARY Assist in ...

Job Title: IT Auditor I (GRC Analyst I) FLSA Status: Exempt Job Family: Information Technology Department: IT - Information Security Location: Corporate Office (Fort Wayne IN) JOB SUMMARY Assist in ...

Cybersecurity Risk Analyst

Evansville, IN · On-site

$36.93 - $55.40/hr

Analyze security incidents, vulnerabilities, and emerging threats to determine potential business ... Four or more years of experience in cybersecurity, governance, risk and compliance (GRC), or a ...

Manager, Cyber Security

Indianapolis, IN · On-site

$150K - $165K/yr

Review and triage escalated alerts; serve as a hands-on analyst when needed * Maintain and improve ... Familiarity with GRC platforms (e.g., ServiceNow GRC, Archer, OneTrust) * Experience with PAM ...

Manager, Cyber Security

Indianapolis, IN · Hybrid

$150K - $165K/yr

Review and triage escalated alerts; serve as a hands-on analyst when needed * Maintain and improve ... Familiarity with GRC platforms (e.g., ServiceNow GRC, Archer, OneTrust) * Experience with PAM ...

Manager, Cyber Security

Indianapolis, IN · On-site

$150K - $165K/yr

Review and triage escalated alerts; serve as a hands-on analyst when needed * Maintain and improve ... Familiarity with GRC platforms (e.g., ServiceNow GRC, Archer, OneTrust) * Experience with PAM ...

This role is ideal for someone who has strong analytical capabilities, experience with global ... Demonstrate familiarity with Governance, Risk, and Compliance (GRC) software-preferably ServiceNow ...

This role is ideal for someone who has strong analytical capabilities, experience with global ... Demonstrate familiarity with Governance, Risk, and Compliance (GRC) software-preferably ServiceNow ...

Internal Audit Manager

Indianapolis, IN · Hybrid

$96K - $128K/yr

Leverage data analytics, automation, AI-enabled tools, and GRC platforms, where appropriate, to improve audit efficiency, insight generation, reporting quality, and overall value delivery, while ...

Internal Audit Manager

Indianapolis, IN · Hybrid

$96K - $128K/yr

Leverage data analytics, automation, AI-enabled tools, and GRC platforms, where appropriate, to improve audit efficiency, insight generation, reporting quality, and overall value delivery, while ...

next page

Showing results 1-20

Grc Analyst information

See Indiana salary details

$34.7K

$92.9K

$217.4K

How much do grc analyst jobs pay per year?

As of Jul 26, 2026, the average yearly pay for grc analyst in Indiana is $92,929.00, according to ZipRecruiter salary data. Most workers in this role earn between $52,300.00 and $105,600.00 per year, depending on experience, location, and employer.

Is GRC a good career?

A GRC (Governance, Risk, and Compliance) analyst plays a key role in managing an organization’s security policies, risk assessments, and regulatory compliance. It is a growing field with demand for professionals skilled in frameworks like ISO, NIST, and tools such as audit management software. The role often requires certifications like CISA or CISSP and offers opportunities for career advancement in cybersecurity and risk management.

Is GRC an entry level job?

GRC Analyst roles can be entry-level or require some experience, depending on the organization. Entry-level positions typically focus on basic compliance, risk management, and security controls, often requiring foundational knowledge of cybersecurity or IT. More advanced roles may demand certifications like CISSP or CISA and prior experience in security or audit functions.

What are the key skills and qualifications needed to thrive in the Grc Analyst position, and why are they important?

To thrive as a GRC Analyst, you need a solid understanding of governance, risk management, and compliance frameworks, often complemented by a degree in information security, business, or a related field. Experience with GRC platforms (like RSA Archer, ServiceNow, or LogicManager), and certifications such as CISA, CRISC, or CISSP are highly valued. Strong analytical thinking, attention to detail, effective communication, and collaboration skills set outstanding GRC Analysts apart. These capabilities are vital for ensuring organizations meet regulatory requirements, identify and mitigate risks, and foster a culture of compliance.

What does a GRC analyst do?

A GRC analyst (Governance, Risk, and Compliance analyst) is responsible for managing an organization’s compliance with regulations, assessing and mitigating risks, and developing governance frameworks. They often use tools like risk management software and require knowledge of industry standards such as ISO or NIST. The role involves analyzing policies, conducting audits, and ensuring security controls are effective.

Do GRC analysts work from home?

GRC analysts can often work remotely, especially if their employer supports telecommuting and the role involves tasks like risk assessment, policy development, and compliance monitoring that can be performed online. However, some positions may require on-site presence for meetings, audits, or access to secure systems.

What are the typical daily responsibilities of a GRC Analyst?

GRC Analysts are responsible for monitoring and assessing organizational policies, procedures, and controls to ensure compliance with internal and external regulations. Their daily tasks often include performing risk assessments, maintaining documentation, supporting audits, analyzing data for potential security gaps, and preparing reports for management. They regularly collaborate with IT, legal, and business teams to remediate vulnerabilities and strengthen compliance programs. This dynamic role requires both independent research and cross-departmental communication to help organizations proactively manage risk and regulatory obligations.

What is a GRC Analyst job?

A GRC (Governance, Risk, and Compliance) Analyst is responsible for ensuring that an organization adheres to regulatory requirements, industry standards, and internal policies. They assess risks, implement compliance programs, and monitor security controls to protect data and systems. Their role often involves working with various departments to identify vulnerabilities, develop risk mitigation strategies, and prepare reports for audits. GRC Analysts play a key role in maintaining regulatory compliance and enhancing an organization's overall security posture.

What are the most commonly searched types of Grc Analyst jobs in Indiana? The most popular types of Grc Analyst jobs in Indiana are:
What job categories do people searching Grc Analyst jobs in Indiana look for? The top searched job categories for Grc Analyst jobs in Indiana are:
What cities in Indiana are hiring for Grc Analyst jobs? Cities in Indiana with the most Grc Analyst job openings:
Infographic showing various Grc Analyst job openings in Indiana as of July 2026, with employment types broken down into 86% Full Time, 9% Part Time, 1% Temporary, and 4% Contract. Highlights an 85% Physical, 6% Hybrid, and 9% Remote job distribution, with an average salary of $92,929 per year, or $44.7 per hour.
Sr. GRC Analyst

Sr. GRC Analyst

Subsplash

Indianapolis, IN

$95K - $105K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 12 days ago


Job description

Sr. GRC Analyst
About Subsplash

Subsplash is an exciting award-winning team of 280+ mission-driven people who are committed to our core values of humility, innovation, and excellence. Founded in 2005, we've remained family owned and operated while pioneering the market with the first ever church mobile app. Since then, we've been working together to build The Ultimate Engagement Platform™ for churches, Christian ministries, non-profits, and businesses around the world. We find excitement in serving our 14,000+ clients, creating impactful products, and delighting the millions of people who use our platform every day. Subsplash has won awards for best mobile experience, been voted top 100 Washington's Best Workplaces by the Puget Sound Business Journal, created some of the most downloaded apps of all time, and built enterprise software for world-class brands like XBOX, Microsoft, Samsung, Expedia, and Cisco; yet, at the end of the day, we love making a lasting impact and a difference in our world.

Working at Subsplash is more than just a job; we are a team of people who are courageous, inventive, and passionate about doing meaningful work every day. Don't take our word for it—head to Glassdoor and see for yourself!

About the Team

The IT Team at Subsplash is the foundation that maintains all the activities and services that are required to support business functions as well as ensuring proper security across all IT systems. We are passionately focused on delivering delightful support to our internal customers. We achieve this by providing robust day-to-day technical support that empowers our fellow Subsplash employees to perform their best work most often. Beyond daily technical support, our team handles crucial functions such as access management, user provisioning and deprovisioning, new hardware and software setup, and diligently works to keep our dues and subscription spend under budget.

About the Role

The Senior GRC Analyst acts as a strategic lead to advance security and risk operations. In this role, you will integrate people, policy, and technology to drive operational excellence and framework maturity. You will be responsible for identifying security gaps, implementing best practices, and maturing our control environment to ensure we stay ahead of evolving regulatory and threat landscapes. We are building an AI-first compliance function, and this role is expected to lead from the front in identifying and deploying AI tools that scale our GRC program.

Compensation
  • The total compensation for this position is between $95,000-$105,000/yr depending on experience level.
Essential Functions of This Role:Compliance Program Management & Audit Leadership
  • Audit Execution: Act as the primary point of contact for external auditors; lead the end-to-end execution of PCI DSS audits and support internal audit on IT SOX controls.
  • Data Mapping Maintenance: Develop and maintain a comprehensive data inventory and data flow diagrams. Track how sensitive data (PII, PCI) moves through our systems to ensure compliance with privacy regulations and security boundaries.
  • Framework Maturation: Map and implement controls across multiple frameworks (PCI DSS, NIST CSF) to eliminate redundancies and improve the organization's security posture.
  • GRC Reporting: Track and report on GRC program health across compliance posture, risk register status, audit readiness, and control effectiveness. Present metrics and trends to leadership on a regular cadence.
2. Access Governance & Identity Management
  • User Access Reviews (UAR): Orchestrate and lead the quarterly and semi-annual user access review process across all critical systems (SaaS, Cloud Infrastructure, and Internal Tools).
  • Joiner/Mover/Leaver Oversight: Monitor and validate that provisioning and deprovisioning processes are executed accurately and on time across critical systems. Flag exceptions, track remediation, and maintain documentation to support access control audits.
3. Security Awareness & Phishing Program
  • Program Ownership: Execute and maintain a comprehensive, year-round Security Awareness Training (SAT) program that meets PCI DSS requirements while driving actual behavioral change.
  • Phishing Simulations: Execute monthly or quarterly phishing simulations; analyze "fail rates" and provide targeted follow-up training to high-risk groups.
  • Content Curation: Select and deploy engaging security content, newsletters, and "security moments" to keep cybersecurity top-of-mind for all employees.
  • Reporting: Present program health metrics (completion rates, simulation trends, and reporting speed) to the Leadership team.
4. Risk and Vendor Management
  • Vendor & Risk Execution: Execute the TPRM program—conducting vendor security reviews, tracking remediation to completion, and escalating high-risk findings to leadership.
  • Risk Register Ownership: Maintain and update the corporate risk register, ensuring remediation efforts are tracked, validated, and communicated to leadership.
Desired Qualifications:
  • Experience: 3–5 years of dedicated experience in GRC, Information Security, or Audit (FinTech or Financial Services industry experience is highly preferred).
  • Technical Mastery: Deep practical knowledge of PCI DSS requirements and controls.
  • Data Governance: Experience performing Data Mapping exercises and maintaining Records of Processing Activities (RoPA).
  • SAT Strategy: Proven experience managing phishing platforms (e.g., KnowBe4, Mimecast, or Vanta-integrated tools) and developing security training curricula.
  • IAM Expertise: Proven experience managing formal access review cycles and identity governance processes.
  • Systems: Proven experience administering a GRC platform, including automated evidence collection, control monitoring, and access review workflows. Direct experience with Vanta is a significant advantage.
  • SOX IT Controls: Experience with SOX IT General Controls (ITGCs), including change management, logical access, computer operations controls, and segregation of duties (SoD). This role will work directly with internal audit to support IT SOX control testing and evidence collection.
  • AI Tooling: Demonstrated experience using AI tools to improve GRC workflows, automate reporting, or accelerate evidence collection and analysis.
Core Competencies
  • Critical Thinker: You have a drive for distinguishing clear priorities and conclusions from ambiguous data.
  • Velocity: You bring urgency and momentum to compliance work—prioritizing ruthlessly, moving quickly through ambiguity, and consistently pushing the program further than the baseline requires.
  • Detail Oriented: You notice the small gaps in access logs, data maps, or training reports that others might miss.
  • AI-Forward: You treat AI as a force multiplier for GRC work—using it to compress audit prep cycles, automate evidence gathering, and free up capacity for higher-value risk analysis.
  • Collaborative: You work effectively across IT and Engineering to surface control gaps, translate technical risks into compliance language, and ensure cross-functional ownership of remediation.
Your First 90 Days
  • Own the PCI DSS evidence pipeline. Get fully oriented on the current ASV scanning cadence, open findings, and SAQ scoping in Vanta. By day 60, be actively supporting evidence collection. By day 90, have a clear understanding of the program state and a plan for taking it over fully.
  • Get oriented on the SOX SoD review cycle. The conflict detection framework and SoD procedure are built. Within 90 days, develop a working understanding of the quarterly review rhythm, the supporting Confluence documentation, and the compensating controls tracking process — with the goal of owning it independently shortly after.
  • Complete a full UAR cycle. Execute a complete user access review across all critical systems, coordinating with IT and system owners, documenting exceptions, and tracking remediation to closure. This is a tangible, auditable deliverable that demonstrates cross-functional coordination and Vanta proficiency.

â—Ź Deliver a first GRC metrics report to leadership. Produce a polished metrics report covering compliance posture, risk register status, PCI standing, and SOX control health. This establishes the reporting cadence and introduces the role to leadership on their terms.

Location

Subsplash currently has operations in 27 states across the US! As much as we would love to have employees in as many states and countries as we have clients, we are currently limiting hiring to the states we already operate in. As a result of that, this role is only available as a 100% remote position if you reside in one of the following states:

AL, AR, AZ, CO, FL, GA, ID, IA, IN, KS, KY, MO, MI, MN, NC, NM, OK, OH, OR, SC, SD, TN, TX, UT, VA, WA, WY.

We are not sponsoring relocation for this role so unfortunately, if you do not currently reside in one of these states, we are unable to consider your application.

Benefits

Generous Paid Time Off, Medical Coverage, Dental Coverage, Vision Coverage, short and long term disability and life insurance all free of charge, Competitive Compensation, 401k Matching, Professional Development, Top of the Line Equipment, Referral Program, Parental Leave, Family-Friendly Culture, and the chance to work side-by-side with thought leaders in emerging tech


Note: Employment with Subsplash is contingent upon satisfactory proof of employee's right to work in the U.S., as required by law and upon completion of a basic background check and; employment with Subsplash is considered "at will," meaning that either the company or the employee may terminate the employment relationship at any time without cause or notice.

Subsplash is an Equal Opportunity Employer. We value all human life as all people are created with equal dignity, value, and worth. We do not discriminate on the ground of race, color, religion, sex, age, disability or national origin, or genetic information in the hiring, retention, or promotion of employees; nor in determining their rank, or the compensation or fringe benefits paid them.

#LI-Remote #BI-Remote