1

Grc Analyst Jobs in Decatur, GA (NOW HIRING)

About the Role Merci Technologies is seeking a GRC Analyst to support the governance, risk, and compliance program for one of our enterprise clients. This role sits at the intersection of security ...

The Role We Want You For Under the direction of and in collaboration with the GRC Manager, the Sr. GRC Analyst, Risk Management is the primary owner and operational steward of the Enterprise Risk ...

The Role We Want You For Under the direction of and in collaboration with the GRC Manager, the Sr. GRC Analyst, Risk Management is the primary owner and operational steward of the Enterprise Risk ...

The Role We Want You For Under the direction of and in collaboration with the GRC Manager, the Sr. GRC Analyst, Risk Management is the primary owner and operational steward of the Enterprise Risk ...

The Role We Want You For Under the direction of and in collaboration with the GRC Manager, the Sr. GRC Analyst, Risk Management is the primary owner and operational steward of the Enterprise Risk ...

The Role We Want You For Under the direction of and in collaboration with the GRC Manager, the Sr. GRC Analyst, Risk Management is the primary owner and operational steward of the Enterprise Risk ...

PrizePicks is seeking an experienced and detail-oriented Senior GRC Analyst to join our expanding governance programs. This role will help drive the continued development and maturation of the ...

The Role We Want You For Under the direction of and in collaboration with the GRC Manager, the Sr. GRC Analyst, Risk Management is the primary owner and operational steward of the Enterprise Risk ...

The Role We Want You For Under the direction of and in collaboration with the GRC Manager, the Sr. GRC Analyst, Risk Management is the primary owner and operational steward of the Enterprise Risk ...

PrizePicks is seeking an experienced and detail-oriented Senior GRC Analyst to join our expanding governance programs. This role will help drive the continued development and maturation of the ...

Mentor and guide junior GRC analysts and contribute to team capability development * Stay current on emerging regulatory developments and industry best practices and translate them into actionable ...

next page

Showing results 1-20

Grc Analyst information

See Decatur, GA salary details

$35.6K

$95.3K

$223.1K

How much do grc analyst jobs pay per year?

As of Jul 27, 2026, the average yearly pay for grc analyst in Decatur, GA is $95,348.00, according to ZipRecruiter salary data. Most workers in this role earn between $53,700.00 and $108,400.00 per year, depending on experience, location, and employer.

Is GRC a good career?

A GRC (Governance, Risk, and Compliance) analyst plays a key role in managing an organization’s security policies, risk assessments, and regulatory compliance. It is a growing field with demand for professionals skilled in frameworks like ISO, NIST, and tools such as audit management software. The role often requires certifications like CISA or CISSP and offers opportunities for career advancement in cybersecurity and risk management.

Is GRC an entry level job?

GRC Analyst roles can be entry-level or require some experience, depending on the organization. Entry-level positions typically focus on basic compliance, risk management, and security controls, often requiring foundational knowledge of cybersecurity or IT. More advanced roles may demand certifications like CISSP or CISA and prior experience in security or audit functions.

What are the key skills and qualifications needed to thrive in the Grc Analyst position, and why are they important?

To thrive as a GRC Analyst, you need a solid understanding of governance, risk management, and compliance frameworks, often complemented by a degree in information security, business, or a related field. Experience with GRC platforms (like RSA Archer, ServiceNow, or LogicManager), and certifications such as CISA, CRISC, or CISSP are highly valued. Strong analytical thinking, attention to detail, effective communication, and collaboration skills set outstanding GRC Analysts apart. These capabilities are vital for ensuring organizations meet regulatory requirements, identify and mitigate risks, and foster a culture of compliance.

What does a GRC analyst do?

A GRC analyst (Governance, Risk, and Compliance analyst) is responsible for managing an organization’s compliance with regulations, assessing and mitigating risks, and developing governance frameworks. They often use tools like risk management software and require knowledge of industry standards such as ISO or NIST. The role involves analyzing policies, conducting audits, and ensuring security controls are effective.

Do GRC analysts work from home?

GRC analysts can often work remotely, especially if their employer supports telecommuting and the role involves tasks like risk assessment, policy development, and compliance monitoring that can be performed online. However, some positions may require on-site presence for meetings, audits, or access to secure systems.

What are the typical daily responsibilities of a GRC Analyst?

GRC Analysts are responsible for monitoring and assessing organizational policies, procedures, and controls to ensure compliance with internal and external regulations. Their daily tasks often include performing risk assessments, maintaining documentation, supporting audits, analyzing data for potential security gaps, and preparing reports for management. They regularly collaborate with IT, legal, and business teams to remediate vulnerabilities and strengthen compliance programs. This dynamic role requires both independent research and cross-departmental communication to help organizations proactively manage risk and regulatory obligations.

What is a GRC Analyst job?

A GRC (Governance, Risk, and Compliance) Analyst is responsible for ensuring that an organization adheres to regulatory requirements, industry standards, and internal policies. They assess risks, implement compliance programs, and monitor security controls to protect data and systems. Their role often involves working with various departments to identify vulnerabilities, develop risk mitigation strategies, and prepare reports for audits. GRC Analysts play a key role in maintaining regulatory compliance and enhancing an organization's overall security posture.

What are the most commonly searched types of Grc Analyst jobs in Decatur, GA? The most popular types of Grc Analyst jobs in Decatur, GA are:
What are popular job titles related to Grc Analyst jobs in Decatur, GA? For Grc Analyst jobs in Decatur, GA, the most frequently searched job titles are:
What job categories do people searching Grc Analyst jobs in Decatur, GA look for? The top searched job categories for Grc Analyst jobs in Decatur, GA are:
What cities near Decatur, GA are hiring for Grc Analyst jobs? Cities near Decatur, GA with the most Grc Analyst job openings:
Infographic showing various Grc Analyst job openings in Decatur, GA as of July 2026, with employment types broken down into 87% Full Time, 7% Part Time, 1% Temporary, and 5% Contract. Highlights an 85% Physical, 6% Hybrid, and 9% Remote job distribution, with an average salary of $95,348 per year, or $45.8 per hour.

GRC Analyst

Merci Technologies - Talent

Atlanta, GA • Remote

Full-time

Posted yesterday


Job description

About the Role
Merci Technologies is seeking a GRC Analyst to support the governance, risk, and compliance program for one of our enterprise clients. This role sits at the intersection of security, audit, and business operations, translating complex regulatory and framework requirements into practical controls that teams can actually implement and sustain. You will be the person who knows where the control gaps are, what the auditors are going to ask for, and how to keep the organization audit-ready year round rather than scrambling at assessment time.

The work is varied and visible. In a given month you might run a control assessment against NIST CSF, prepare evidence for a SOC 2 examination, complete a vendor risk review for a new SaaS purchase, and brief stakeholders on the status of open findings. You will maintain the policy library, track risk to closure, and act as a trusted advisor to engineering and business teams who need to understand what compliance requires of them. This is a strong fit for someone who is organized, detail-driven, and comfortable holding teams accountable to commitments. This is a fully remote position open to Contract or Full-Time candidates.

Key Responsibilities

  • Conduct control assessments and gap analyses against frameworks including NIST CSF, NIST 800-53, ISO 27001, SOC 2, and CMMC
  • Plan and support internal and third-party audits, including scoping, evidence collection, and walkthroughs
  • Track audit and assessment findings to remediation and closure, escalating risks where needed
  • Develop, maintain, and version-control security policies, standards, and procedures
  • Perform vendor and third-party risk assessments and document risk acceptance decisions
  • Build and maintain the risk register and report risk posture to leadership and stakeholders
  • Support regulatory, customer, and compliance reporting requests
  • Help operationalize new framework or regulatory requirements as they emerge

Required Qualifications

  • 3 to 5 years of experience in governance, risk, and compliance, IT audit, or information security
  • Working knowledge of one or more frameworks: NIST CSF, NIST 800-53, ISO 27001, SOC 2, or CMMC
  • Demonstrated experience supporting audit cycles and risk assessments end to end
  • Ability to read a control requirement and translate it into clear, actionable guidance
  • Strong documentation, organization, and stakeholder communication skills

Preferred Qualifications

  • CISA, CRISC, ISO 27001 Lead Auditor, or CISSP certification
  • Hands-on experience with GRC platforms such as Archer, ServiceNow GRC, or OneTrust
  • Familiarity with defense, healthcare, or financial-services compliance requirements
  • Experience with CMMC readiness and assessment preparation

What You Will Bring
You are the kind of person who reads the fine print and keeps the spreadsheet honest. You can push a remediation owner for an update without burning the relationship, and you can explain to a busy engineer why a control matters in language they care about. You treat compliance as a way to make the organization genuinely more secure, not just to pass an audit.