1

Grc Analyst Jobs (NOW HIRING)

Senior GRC Analyst

Pittsburgh, PA · On-site

$114K - $163K/yr

Senior GRC Analyst Department: Compliance & Fraud Employment Type: Full Time Location: Pittsburgh Onsite Compensation: $114,000 - $163,000 / year Description Role Summary Wolfe is a Pittsburgh-based ...

New

Sr. GRC Analyst About Subsplash Subsplash is an exciting award-winning team of 280+ mission-driven people who are committed to our core values of humility, innovation, and excellence. Founded in 2005 ...

Sr. GRC Analyst

Knoxville, TN · On-site

$95K - $105K/yr

Sr. GRC Analyst About Subsplash Subsplash is an exciting award-winning team of 280+ mission-driven people who are committed to our core values of humility, innovation, and excellence. Founded in 2005 ...

Sr. GRC Analyst About Subsplash Subsplash is an exciting award-winning team of 280+ mission-driven people who are committed to our core values of humility, innovation, and excellence. Founded in 2005 ...

Who you are Metropolis is seeking a Governance, Risk, and Compliance (GRC) Analyst to join our expanding Security team. Reporting to the Senior Manager, GRC, you will mature information security ...

GRC Analyst

Los Angeles, CA · On-site

$100K - $135K/yr

Who you are Metropolis is seeking a Governance, Risk, and Compliance (GRC) Analyst to join our expanding Security team. Reporting to the Senior Manager, GRC, you will mature information security ...

We are seeking an experienced Cybersecurity GRC Analyst for a 6-month engagement to support our ongoing security compliance and governance initiatives. The ideal candidate will have strong hands-on ...

We are seeking an experienced Cybersecurity GRC Analyst for a 6-month engagement to support our ongoing security compliance and governance initiatives. The ideal candidate will have strong hands-on ...

Associate GRC Analyst

Richmond, VA · On-site

$76K - $102K/yr

Associate GRC Analyst Overview CoStar Group (NASDAQ: CSGP) is a leading global provider of commercial and residential real estate information, analytics, and online marketplaces. Included in the S&P ...

Sr. GRC Analyst

Charlotte, NC · On-site

$95K - $105K/yr

Sr. GRC Analyst About Subsplash Subsplash is an exciting award-winning team of 280+ mission-driven people who are committed to our core values of humility, innovation, and excellence. Founded in 2005 ...

Sr. GRC Analyst

Indianapolis, IN · On-site

$95K - $105K/yr

Sr. GRC Analyst About Subsplash Subsplash is an exciting award-winning team of 280+ mission-driven people who are committed to our core values of humility, innovation, and excellence. Founded in 2005 ...

Sr. GRC Analyst

Albuquerque, NM · On-site

$95K - $105K/yr

Sr. GRC Analyst About Subsplash Subsplash is an exciting award-winning team of 280+ mission-driven people who are committed to our core values of humility, innovation, and excellence. Founded in 2005 ...

Sr. GRC Analyst

Louisville, KY · On-site

$95K - $105K/yr

Sr. GRC Analyst About Subsplash Subsplash is an exciting award-winning team of 280+ mission-driven people who are committed to our core values of humility, innovation, and excellence. Founded in 2005 ...

SaaS - GRC Location: Phoenix, Arizona (3 days a week). Duration: Contract Position Key ... Analyze shared responsibility models and identify security gaps. * Review controls across IAM ...

We are seeking an experienced Cybersecurity GRC Analyst for a 6-month engagement to support our ongoing security compliance and governance initiatives. The ideal candidate will have strong hands-on ...

The IT GRC Analyst II assess, tests, documents, and monitors the SECU technology ecosystem to ensure the IT control environment effectively mitigates risks associated with an everchanging threat ...

New

GRC Analyst - Remote

$80K - $137K/yr

Overview The GRC Analyst will play a critical role in strengthening the security posture of our growing organization by designing, implementing, and managing control and risk workflows, as well as ...

The Opportunity We are hiring a Security GRC & Risk Analyst to own the governance, risk, and compliance execution layer across a holding company and portfolio of businesses. This is a build-oriented ...

What You Will Do As an Entry Level GRC Analyst at Hotman Group you will work side by side with senior team members and partners to help our clients strengthen their cybersecurity and compliance ...

Showing results 21-40

Grc Analyst information

See salary details

$36.5K

$97.7K

$228.5K

How much do grc analyst jobs pay per year?

As of Aug 14, 2026, the average yearly pay for grc analyst in the United States is $97,659.00, according to ZipRecruiter salary data. Most workers in this role earn between $55,000.00 and $111,000.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a GRC analyst?

To thrive as a GRC Analyst, you need a solid understanding of governance, risk management, and compliance frameworks, often complemented by a degree in information security, business, or a related field. Experience with GRC platforms (like RSA Archer, ServiceNow, or LogicManager), and certifications such as CISA, CRISC, or CISSP are highly valued. Strong analytical thinking, attention to detail, effective communication, and collaboration skills set outstanding GRC Analysts apart. These capabilities are vital for ensuring organizations meet regulatory requirements, identify and mitigate risks, and foster a culture of compliance.

Is GRC analyst an entry level job?

A GRC analyst role can be entry-level or require some experience, depending on the organization. Entry-level positions typically focus on basic compliance, risk management, and using tools like GRC software, often requiring relevant certifications or a related degree. More advanced roles may demand several years of experience and specialized knowledge.

Is GRC analyst in high demand?

GRC analysts are in high demand due to increasing focus on cybersecurity, regulatory compliance, and risk management across industries. Organizations seek professionals with skills in risk assessment, policy development, and familiarity with tools like GRC software, making this a growing field for qualified candidates.

What does a GRC analyst do?

GRC Analysts are responsible for monitoring and assessing organizational policies, procedures, and controls to ensure compliance with internal and external regulations. Their daily tasks often include performing risk assessments, maintaining documentation, supporting audits, analyzing data for potential security gaps, and preparing reports for management. They regularly collaborate with IT, legal, and business teams to remediate vulnerabilities and strengthen compliance programs. This dynamic role requires both independent research and cross-departmental communication to help organizations proactively manage risk and regulatory obligations.

What is a GRC analyst?

A GRC (Governance, Risk, and Compliance) Analyst is responsible for ensuring that an organization adheres to regulatory requirements, industry standards, and internal policies. They assess risks, implement compliance programs, and monitor security controls to protect data and systems. Their role often involves working with various departments to identify vulnerabilities, develop risk mitigation strategies, and prepare reports for audits. GRC Analysts play a key role in maintaining regulatory compliance and enhancing an organization's overall security posture.

What cities are hiring for Grc Analyst jobs?

Cities with the most Grc Analyst job openings:

What are the most commonly searched types of Grc Analyst jobs?

The most popular types of Grc Analyst jobs are:

What states have the most Grc Analyst jobs?

States with the most job openings for Grc Analyst jobs include:

What job categories do people searching Grc Analyst jobs look for?

The top searched job categories for Grc Analyst jobs are:

Infographic showing various Grc Analyst job openings in the United States as of August 2026, with employment types broken down into 1% Internship, 86% Full Time, 6% Part Time, and 7% Contract. Highlights an 81% Physical, 9% Hybrid, and 10% Remote job distribution, with an average salary of $97,659 per year, or $47 per hour.

Senior GRC Analyst

Wolfe, LLC

Pittsburgh, PA • On-site

$114K - $163K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 3 days ago

New


Job description

Senior GRC Analyst
Department: Compliance & Fraud
Employment Type: Full Time
Location: Pittsburgh Onsite
Compensation: $114,000 - $163,000 / year
Description
Role SummaryWolfe is a Pittsburgh-based FinTech company operating consumer gifting and payments brands, and we are actively embedding AI across our products, our internal processes, and the way our teams work day-to-day. As Senior GRC Analyst, you will be the hands-on owner of the control and evidence work behind our PCI DSS Level 1 service provider obligations, our SOC 2 Type II readiness, our IT general controls, our NIST CSF 2.0 maturity program, and our third-party risk assessments. This is a deliberately senior individual contributor role - you will operate with minimal oversight, work directly with our QSA and external auditors, and serve as the compliance advisor engineering, fraud, and product teams come to before they build. You will also help us define how governance keeps pace with AI adoption, including the controls and review process for AI use across the company. This is a 5-day onsite role in Pittsburgh, PA.
Responsibilities
  • Run our annual PCI DSS v4.0.1 Level 1 service provider assessment and SOC 2 Type II examination end to end - scope validation, evidence collection, QSA and auditor coordination, gap remediation tracking, and support for sponsor bank and processor due diligence requests.
  • Own IT general control readiness across change management, logical access, SDLC, and backup and job scheduling - documenting control narratives, walking auditors through the environment, and performing internal design and operating-effectiveness testing so that external testing produces no surprises.
  • Own the issues management lifecycle under our Issues Management Policy - intake, risk rating, remediation tracking, closure evidence, and recurring reporting to leadership and the Audit Committee.
  • Execute third-party risk assessments across our vendor portfolio, including security questionnaire review, contract security and PCI terms review, and ongoing monitoring of critical vendors.
  • Administer our GRC platform - control library and cross-framework mappings across PCI, SOC 2, and ITGC, automated evidence collection, control owner workflows, and compliance dashboards.

Impact StatementFor more clarity on the role, below are the success metrics and measurements for this role in the first 90 to 120 days.:
  • Take over evidence collection for the current PCI DSS v4.0.1 assessment cycle and deliver a QSA-accepted evidence package for your assigned requirement families, with an aging report showing zero overdue evidence requests at the 120-day mark.
  • Deliver a SOC 2 Type II readiness assessment covering the full ITGC population - change management, logical access, SDLC, and backup and recovery - including written control narratives, identified design gaps, and a remediation plan sized to close before the audit period opens.
  • Complete a refreshed assessment of the governance function and deliver a prioritized remediation plan covering the lowest-scoring subcategories, with owners, target dates, and a defined scoring path from current to target maturity.
  • Migrate all open compliance and audit findings into a single issues register in the GRC platform - each item risk-rated, owner-assigned, and due-dated - and publish the first monthly issues report to the IT Steering Committee.

Qualifications
  • 7+ years in GRC, IT audit, or information security compliance, including at least 3 years directly supporting PCI DSS in a Level 1 service provider or equivalent payment card environment; CISA, CRISC, CISSP, PCIP, or ISA certification preferred but not required.
  • Demonstrated experience preparing for and supporting SOC 2 Type II examinations, including designing, documenting, and testing IT general controls across change management, logical access, and the software development lifecycle.
  • Working depth in IT governance, with proven ability to translate control requirements into testable evidence that an external assessor accepts without rework.
  • Hands-on experience administering a GRC platform (Vanta, Drata, Secureframe, ServiceNow IRM, AuditBoard, or similar) - control mapping, automated evidence collection, and reporting.
  • Track record running third-party risk assessments end to end, including reviewing security and compliance terms in vendor contracts.
  • Experience in a regulated financial services environment answering to external parties - sponsor banks, processors, regulators, or internal audit - and producing deliverables for executive and board audiences.

Compensation, Benefits, and Perks
Wolfe is committed to providing a comprehensive benefits package to support your well-being, along with competitive compensation. Our benefits and perks include but not limited to:
  • Restricted Stock Units (RSUs)
  • Profit Share
  • Medical, Prescription, Vision, and Dental insurance for employees and dependents (Wolfe pays 80% of premium)
  • Short-Term Disability Insurance (Wolfe pays 100% of premium)
  • Voluntary Long-Term Disability Insurance, Life Insurance, Critical Illness Insurance, Accident Insurance, and Hospital Indemnity coverage
  • PTO (vacation and sick time)
  • Corporate Holidays and Floating Holidays
  • 401(k)
  • Employee recognition program
  • Charitable Donation to a charity of your choice yearly
  • Employee Referral Bonus
  • Tuition Reimbursement
  • Internal Training and Information sessions
  • Family Picnic, Holiday Party, and other outings
  • Internal Culture Club