1

Grc Analyst Jobs in Boca Raton, FL (NOW HIRING)

AI Governance Analyst

Boca Raton, FL

$78K - $93K/yr

... Governance Analyst role sits within the Technology Risk & Compliance function and focuses on ... Experience using Onspring or a similar GRC tool * Ability to work independently and collaborate ...

AI Governance Analyst

Boca Raton, FL

$78K - $93K/yr

... Governance Analyst role sits within the Technology Risk & Compliance function and focuses on ... Experience using Onspring or a similar GRC tool * Ability to work independently and collaborate ...

This role is ideal for someone who has strong analytical capabilities, experience with global ... Demonstrate familiarity with Governance, Risk, and Compliance (GRC) software-preferably ServiceNow ...

Grc Analyst information

See Boca Raton, FL salary details

$34.6K

$92.7K

$216.8K

How much do grc analyst jobs pay per year?

As of Jul 26, 2026, the average yearly pay for grc analyst in Boca Raton, FL is $92,676.00, according to ZipRecruiter salary data. Most workers in this role earn between $52,200.00 and $105,300.00 per year, depending on experience, location, and employer.

Is GRC a good career?

A GRC (Governance, Risk, and Compliance) analyst plays a key role in managing an organization’s security policies, risk assessments, and regulatory compliance. It is a growing field with demand for professionals skilled in frameworks like ISO, NIST, and tools such as audit management software. The role often requires certifications like CISA or CISSP and offers opportunities for career advancement in cybersecurity and risk management.

Is GRC an entry level job?

GRC Analyst roles can be entry-level or require some experience, depending on the organization. Entry-level positions typically focus on basic compliance, risk management, and security controls, often requiring foundational knowledge of cybersecurity or IT. More advanced roles may demand certifications like CISSP or CISA and prior experience in security or audit functions.

What are the key skills and qualifications needed to thrive in the Grc Analyst position, and why are they important?

To thrive as a GRC Analyst, you need a solid understanding of governance, risk management, and compliance frameworks, often complemented by a degree in information security, business, or a related field. Experience with GRC platforms (like RSA Archer, ServiceNow, or LogicManager), and certifications such as CISA, CRISC, or CISSP are highly valued. Strong analytical thinking, attention to detail, effective communication, and collaboration skills set outstanding GRC Analysts apart. These capabilities are vital for ensuring organizations meet regulatory requirements, identify and mitigate risks, and foster a culture of compliance.

What does a GRC analyst do?

A GRC analyst (Governance, Risk, and Compliance analyst) is responsible for managing an organization’s compliance with regulations, assessing and mitigating risks, and developing governance frameworks. They often use tools like risk management software and require knowledge of industry standards such as ISO or NIST. The role involves analyzing policies, conducting audits, and ensuring security controls are effective.

Do GRC analysts work from home?

GRC analysts can often work remotely, especially if their employer supports telecommuting and the role involves tasks like risk assessment, policy development, and compliance monitoring that can be performed online. However, some positions may require on-site presence for meetings, audits, or access to secure systems.

What are the typical daily responsibilities of a GRC Analyst?

GRC Analysts are responsible for monitoring and assessing organizational policies, procedures, and controls to ensure compliance with internal and external regulations. Their daily tasks often include performing risk assessments, maintaining documentation, supporting audits, analyzing data for potential security gaps, and preparing reports for management. They regularly collaborate with IT, legal, and business teams to remediate vulnerabilities and strengthen compliance programs. This dynamic role requires both independent research and cross-departmental communication to help organizations proactively manage risk and regulatory obligations.

What is a GRC Analyst job?

A GRC (Governance, Risk, and Compliance) Analyst is responsible for ensuring that an organization adheres to regulatory requirements, industry standards, and internal policies. They assess risks, implement compliance programs, and monitor security controls to protect data and systems. Their role often involves working with various departments to identify vulnerabilities, develop risk mitigation strategies, and prepare reports for audits. GRC Analysts play a key role in maintaining regulatory compliance and enhancing an organization's overall security posture.

What are the most commonly searched types of Grc Analyst jobs in Boca Raton, FL? The most popular types of Grc Analyst jobs in Boca Raton, FL are:
What cities near Boca Raton, FL are hiring for Grc Analyst jobs? Cities near Boca Raton, FL with the most Grc Analyst job openings:
Infographic showing various Grc Analyst job openings in Boca Raton, FL as of July 2026, with employment types broken down into 87% Full Time, 8% Part Time, 1% Temporary, and 4% Contract. Highlights an 85% Physical, 6% Hybrid, and 9% Remote job distribution, with an average salary of $92,676 per year, or $44.6 per hour.
GRC Analyst - IT Security Risk and Audit Manager

GRC Analyst - IT Security Risk and Audit Manager

Apex Informatics

Boca Raton, FL • On-site

Other

Posted 6 days ago


Job description

Job Title: IT Security Risk and Audit Manager - Governance Risk Compliance (GRC) Analyst
Location: Tolls Data Center in Boca Raton, FL. This is an onsite position, not remote.
Job Summary: The IT Security Risk and Audit Manager at the Florida Turnpike Enterprise leads the IT security risk and audit program. This role involves managing, assessing, and mitigating risks as part of the information assurance and cybersecurity program, using standards such as NIST, ISO, PCI, and ISACA. The position entails developing and implementing strategies for IT security risk and audit, conducting risk assessments, and evaluating control effectiveness.
Key Responsibilities:
  • Perform reviews to ensure compliance with PCI, SOC2, ISO, and State of Florida cybersecurity controls.
  • Plan and assess IT security controls' effectiveness and manage remediation efforts.
  • Maintain IT security risk and compliance matrices and perform management reporting.
  • Oversee the Third-Party Risk Management Program (TPRM) and analyze SOC-2 and other reports, mapping to key security controls.
  • Manage IT security vulnerabilities in alignment with PCI and NIST standards.
  • Identify and rank the criticality of operations and assets to prioritize risk mitigation.
  • Estimate potential losses and recovery costs for critical assets if threats materialize.
  • Identify and implement cost-effective risk mitigation actions, including new policies and technical controls.
  • Coordinate and verify the remediation of audit findings.
  • Document results and develop action plans for risk mitigation.
  • Produce formal audit reports based on ISACA Audit Standards.
  • Promote compliance with regulatory requirements (e.g., PCI DSS) and IT best practices.

Skills and Requirements:
  • 7-10 years of IT Audit experience (CISA certification preferred).
  • 3 years of IT Risk Management lifecycle experience.
  • 3 years of hands-on technical experience (e.g., developer, system administrator).
  • Experience with NIST 800-30 Risk Assessment Standard.
  • Extensive experience with IT General Controls evaluation and design.
  • Advanced skills in business process mapping, documentation, and policy development.
  • Up-to-date knowledge of the current threat landscape in Information Security.
  • Solid understanding of PCI DSS standards.

Education and Certifications:
  • Bachelor's Degree in Computer Science, Information Systems, Business Administration, or a related field, or equivalent work experience.
  • Preferred certifications: CISA and CISSP.