1

Grc Analyst Jobs in Virginia (NOW HIRING)

Lead, mentor, and develop a GRC analyst, setting priorities, coaching for growth, and serving as the escalation point for complex risk and compliance matters. * Operate as a player-coach: remain ...

Lead, mentor, and develop a GRC analyst, setting priorities, coaching for growth, and serving as the escalation point for complex risk and compliance matters. * Operate as a player-coach: remain ...

Lead, mentor, and develop a GRC analyst, setting priorities, coaching for growth, and serving as the escalation point for complex risk and compliance matters. * Operate as a player-coach: remain ...

Lead, mentor, and develop a GRC analyst, setting priorities, coaching for growth, and serving as the escalation point for complex risk and compliance matters. * Operate as a player-coach: remain ...

next page

Showing results 1-20

Grc Analyst information

See Virginia salary details

$36.2K

$96.8K

$226.5K

How much do grc analyst jobs pay per year?

As of Aug 17, 2026, the average yearly pay for grc analyst in Virginia is $96,822.00, according to ZipRecruiter salary data. Most workers in this role earn between $54,500.00 and $110,000.00 per year, depending on experience, location, and employer.

What is a GRC analyst?

A GRC (Governance, Risk, and Compliance) Analyst is responsible for ensuring that an organization adheres to regulatory requirements, industry standards, and internal policies. They assess risks, implement compliance programs, and monitor security controls to protect data and systems. Their role often involves working with various departments to identify vulnerabilities, develop risk mitigation strategies, and prepare reports for audits. GRC Analysts play a key role in maintaining regulatory compliance and enhancing an organization's overall security posture.

What does a GRC analyst do?

GRC Analysts are responsible for monitoring and assessing organizational policies, procedures, and controls to ensure compliance with internal and external regulations. Their daily tasks often include performing risk assessments, maintaining documentation, supporting audits, analyzing data for potential security gaps, and preparing reports for management. They regularly collaborate with IT, legal, and business teams to remediate vulnerabilities and strengthen compliance programs. This dynamic role requires both independent research and cross-departmental communication to help organizations proactively manage risk and regulatory obligations.

What are the key skills and qualifications needed to thrive as a GRC analyst?

To thrive as a GRC Analyst, you need a solid understanding of governance, risk management, and compliance frameworks, often complemented by a degree in information security, business, or a related field. Experience with GRC platforms (like RSA Archer, ServiceNow, or LogicManager), and certifications such as CISA, CRISC, or CISSP are highly valued. Strong analytical thinking, attention to detail, effective communication, and collaboration skills set outstanding GRC Analysts apart. These capabilities are vital for ensuring organizations meet regulatory requirements, identify and mitigate risks, and foster a culture of compliance.

Is GRC analyst an entry level job?

A GRC analyst role can be entry-level or require some experience, depending on the organization. Entry-level positions typically focus on basic compliance, risk management, and using tools like GRC software, often requiring relevant certifications or a related degree. More advanced roles may demand several years of experience and specialized knowledge.

Is GRC analyst in high demand?

GRC analysts are in high demand due to increasing focus on cybersecurity, regulatory compliance, and risk management across industries. Organizations seek professionals with skills in risk assessment, policy development, and familiarity with tools like GRC software, making this a growing field for qualified candidates.

What are the most commonly searched types of Grc Analyst jobs in Virginia?

The most popular types of Grc Analyst jobs in Virginia are:

What are popular job titles related to Grc Analyst jobs in Virginia?

For Grc Analyst jobs in Virginia, the most frequently searched job titles are:

What job categories do people searching Grc Analyst jobs in Virginia look for?

The top searched job categories for Grc Analyst jobs in Virginia are:

What cities in Virginia are hiring for Grc Analyst jobs?

Cities in Virginia with the most Grc Analyst job openings:

Infographic showing various Grc Analyst job openings in Virginia as of August 2026, with employment types broken down into 1% Internship, 86% Full Time, 7% Part Time, and 6% Contract. Highlights an 81% Physical, 9% Hybrid, and 10% Remote job distribution, with an average salary of $96,822 per year, or $46.5 per hour.

Senior Information Security & GRC Analyst - 2 positions (Hybrid)

Virginia Jobs

Richmond, VA • On-site

$75K - $100K/yr

Other

Posted 3 days ago

New


Job description

Additional Detail
Senior Information Security & GRC Analyst - 2 positions
Anticipated Starting Salary Range: $75,000 - $100,000
Starting Salary Commensurate with Qualifications and Experience
The State Corporation Commission's (SCC) Health Benefit Exchange (HBE) division seeks two analysts interested in rewarding public service careers to join its Information Security team. One position is a Senior Information Security Analyst and one is a Senior Governance, Risk, and Compliance (GRC) Analyst. Both positions will work under the direction of the HBE Information Security Manager to safeguard the HBE's consumer data and information and ensure compliance with state and federal regulations. These positions offer a hybrid work schedule (some in-office and telework days each week) as well as a variety of professional development and training opportunities.
Essential Functions & Responsibilities of the Senior Information Security Analyst position include, but are not limited to:
  • Monitor, analyze, and report on security vulnerabilities and weaknesses.
  • Perform complex security impact assessments, analyze, and report on the impact of requested system and framework changes to security posture and applicable controls.
  • Remain informed of emerging threats, trends, and new security technologies and regularly present findings of impact to the Information Security team.
  • Lead continuous improvement efforts, developing and presenting security training to team and division personnel.
  • Mentor and train junior Security Analysts.
  • Perform complex risk and threat assessments.
  • Respond, coordinate, and monitor complex incident response activities.
  • Coordinate and support 3rd party assessments and penetration tests.
  • Assess system operations and security controls and make recommendations for improvements.
  • Communicate and collaborate with vendors, HBE staff, partners, and other SCC divisions on complex security issues, updates, controls, and additional ad hoc items.
  • Prepare reports on security findings, progress towards remediation of security related issues, and system trends.
  • Perform related work as required.

Essential Functions & Responsibilities of the Senior Governance, Risk, and Compliance (GRC) Analyst position include but are not limited to:
  • Coordinate with federal agencies, SCC internal teams, vendors, and 3rd parties to perform privacy and security assessments, audits, and other security and privacy compliances activities.
  • Conduct complex audits of HBE partners and vendors to evaluate compliance with privacy and security requirements.
  • Lead and participate in internal assessments to evaluate compliance with information security and privacy policies, procedures, regulations, and agreements.
  • Monitor regulatory changes, evaluate impacts, and prepare reports and recommendations on compliance for security and privacy policies for HBE senior leadership.
  • Review and update security and privacy control documentation to ensure it is accurate, up to date, and adheres to legal and regulatory requirements.
  • Develop and present compliance findings from audits and assessments to HBE senior leadership and prepare remediation reports.
  • Develop, update, and support implementation of data security and privacy protection policies and procedures.
  • Coordinate with vendors and monitor complex security and privacy incidents.
  • Contribute to continuous improvement efforts.
  • Perform related work as required.

Please Note: SCC only accepts applications received through its career center site. Applications submitted through Virginia Jobs site directly will not be considered.
For more information and to apply for this position directly on the SCC Career Center website, click the Additional Detail button on this page.
To view all current SCC job openings, visit the SCC Career Center website and click the Search button under Job Search.
Each agency within the Commonwealth of Virginia is dedicated to recruiting, supporting, and maintaining a competent and diverse work force. Equal Opportunity Employer