1

Grc Analyst Jobs (NOW HIRING)

What You Will Do As an Entry Level GRC Analyst at Hotman Group you will work side by side with senior team members and partners to help our clients strengthen their cybersecurity and compliance ...

Senior GRC Analyst

Seattle, WA · On-site

$140K - $165K/yr

We're looking for a Senior GRC Analyst to serve as the primary architect for our expanding ISO ecosystem. As a Senior GRC Analyst at DigitalOcean, you will lead the strategic maturation of ...

The Role We Want You For Under the direction of and in collaboration with the GRC Manager, the Sr. GRC Analyst, Risk Management is the primary owner and operational steward of the Enterprise Risk ...

The Role We Want You For Under the direction of and in collaboration with the GRC Manager, the Sr. GRC Analyst, Risk Management is the primary owner and operational steward of the Enterprise Risk ...

The Sr. GRC Analyst will support enterprise risk assessments, evaluate control effectiveness, identify risk exposures and control gaps, track remediation efforts, and support cross-functional teams ...

GRC Analyst

Milwaukee, WI · On-site +1

As a GRC Analyst, you will manage compliance frameworks, assess organizational risk, and help Zywave maintain the trust of the customers it serves. This role partners closely with IT, Legal, and R&D ...

New

We are looking for a Senior GRC Analyst, HIPAA to help mature and operate HIPAA-related security and compliance programs across DoorDash. This role will support multiple ongoing HIPAA workstreams ...

GRC Analyst

$134K - $202K/yr

We are looking for a GRC Analyst to join our Governance, Risk & Compliance (GRC) team. You will have the opportunity to manage and maintain ongoing compliance with security and privacy frameworks ...

What You Will Do As an Entry Level GRC Analyst at Hotman Group you will work side by side with senior team members and partners to help our clients strengthen their cybersecurity and compliance ...

Overview The Sr. Analyst, Governance, Risk, and Compliance (GRC) plays an important role in the GRC delivery framework, ensuring Black & Veatch's compliance with contractual and regulatory ...

The Role We Want You For Under the direction of and in collaboration with the GRC Manager, the Sr. GRC Analyst, Risk Management is the primary owner and operational steward of the Enterprise Risk ...

Overview The Sr. Analyst, Governance, Risk, and Compliance (GRC) plays an important role in the GRC delivery framework, ensuring Black & Veatch's compliance with contractual and regulatory ...

The Role We Want You For Under the direction of and in collaboration with the GRC Manager, the Sr. GRC Analyst, Risk Management is the primary owner and operational steward of the Enterprise Risk ...

Senior GRC Analyst

Westerville, OH · On-site

$92K - $121K/yr

We are looking for a Security Governance, Risk, and Compliance (GRC) Analyst to support and mature our security and compliance programs across a large construction organization. This role focuses on ...

GRC Analyst

San Francisco, CA · On-site

$95K - $150K/yr

As a GRC Analyst at Zip, you'll be a key driver for ensuring the success of compliance programs at a fast-growing company. Your contributions will be pivotal to the overall growth and competitive ...

New

The Role We Want You For Under the direction of and in collaboration with the GRC Manager, the Sr. GRC Analyst, Risk Management is the primary owner and operational steward of the Enterprise Risk ...

The Role We Want You For Under the direction of and in collaboration with the GRC Manager, the Sr. GRC Analyst, Risk Management is the primary owner and operational steward of the Enterprise Risk ...

The Role We Want You For Under the direction of and in collaboration with the GRC Manager, the Sr. GRC Analyst, Risk Management is the primary owner and operational steward of the Enterprise Risk ...

The Role We Want You For Under the direction of and in collaboration with the GRC Manager, the Sr. GRC Analyst, Risk Management is the primary owner and operational steward of the Enterprise Risk ...

Showing results 41-60

Grc Analyst information

See salary details

$36.5K

$97.7K

$228.5K

How much do grc analyst jobs pay per year?

As of Jul 25, 2026, the average yearly pay for grc analyst in the United States is $97,659.00, according to ZipRecruiter salary data. Most workers in this role earn between $55,000.00 and $111,000.00 per year, depending on experience, location, and employer.

Is GRC a good career?

A GRC (Governance, Risk, and Compliance) analyst plays a key role in managing an organization’s security policies, risk assessments, and regulatory compliance. It is a growing field with demand for professionals skilled in frameworks like ISO, NIST, and tools such as audit management software. The role often requires certifications like CISA or CISSP and offers opportunities for career advancement in cybersecurity and risk management.

Is GRC an entry level job?

GRC Analyst roles can be entry-level or require some experience, depending on the organization. Entry-level positions typically focus on basic compliance, risk management, and security controls, often requiring foundational knowledge of cybersecurity or IT. More advanced roles may demand certifications like CISSP or CISA and prior experience in security or audit functions.

What are the key skills and qualifications needed to thrive in the Grc Analyst position, and why are they important?

To thrive as a GRC Analyst, you need a solid understanding of governance, risk management, and compliance frameworks, often complemented by a degree in information security, business, or a related field. Experience with GRC platforms (like RSA Archer, ServiceNow, or LogicManager), and certifications such as CISA, CRISC, or CISSP are highly valued. Strong analytical thinking, attention to detail, effective communication, and collaboration skills set outstanding GRC Analysts apart. These capabilities are vital for ensuring organizations meet regulatory requirements, identify and mitigate risks, and foster a culture of compliance.

What does a GRC analyst do?

A GRC analyst (Governance, Risk, and Compliance analyst) is responsible for managing an organization’s compliance with regulations, assessing and mitigating risks, and developing governance frameworks. They often use tools like risk management software and require knowledge of industry standards such as ISO or NIST. The role involves analyzing policies, conducting audits, and ensuring security controls are effective.

Do GRC analysts work from home?

GRC analysts can often work remotely, especially if their employer supports telecommuting and the role involves tasks like risk assessment, policy development, and compliance monitoring that can be performed online. However, some positions may require on-site presence for meetings, audits, or access to secure systems.

What are the typical daily responsibilities of a GRC Analyst?

GRC Analysts are responsible for monitoring and assessing organizational policies, procedures, and controls to ensure compliance with internal and external regulations. Their daily tasks often include performing risk assessments, maintaining documentation, supporting audits, analyzing data for potential security gaps, and preparing reports for management. They regularly collaborate with IT, legal, and business teams to remediate vulnerabilities and strengthen compliance programs. This dynamic role requires both independent research and cross-departmental communication to help organizations proactively manage risk and regulatory obligations.

What is a GRC Analyst job?

A GRC (Governance, Risk, and Compliance) Analyst is responsible for ensuring that an organization adheres to regulatory requirements, industry standards, and internal policies. They assess risks, implement compliance programs, and monitor security controls to protect data and systems. Their role often involves working with various departments to identify vulnerabilities, develop risk mitigation strategies, and prepare reports for audits. GRC Analysts play a key role in maintaining regulatory compliance and enhancing an organization's overall security posture.

What cities are hiring for Grc Analyst jobs? Cities with the most Grc Analyst job openings:
What are the most commonly searched types of Grc Analyst jobs? The most popular types of Grc Analyst jobs are:
What states have the most Grc Analyst jobs? States with the most job openings for Grc Analyst jobs include:
Infographic showing various Grc Analyst job openings in the United States as of July 2026, with employment types broken down into 89% Full Time, 6% Part Time, 1% Temporary, and 4% Contract. Highlights an 83% Physical, 7% Hybrid, and 10% Remote job distribution, with an average salary of $97,659 per year, or $47 per hour.
Entry Level GRC Analyst

Entry Level GRC Analyst

Hotman Group

Fort Worth, TX

Contractor

Posted 16 days ago


Job description

About the Role

Hotman Group is a boutique cybersecurity and GRC consulting firm doing meaningful work for clients who need GRC done right ranging from Fortune 1000 companies to high-growth startups. We are looking for a driven, detail-obsessed early-career professional who is ready to apply your professional foundation to real GRC consulting work and contribute to real client work from day one.

This is a full-time, remote, contract-to-hire position. Top performers move into permanent roles within 6 months.

What You Will Do

As an Entry Level GRC Analyst at Hotman Group you will work side by side with senior team members and partners to help our clients strengthen their cybersecurity and compliance programs. You will:

  • Assess and improve client security and IT controls
  • Develop policies, processes, and risk assessments aligned to top frameworks including NIST, ISO 27001, and SOC 2
  • Crosswalk and harmonize controls across multiple compliance frameworks
  • Document security requirements, support control implementation, and help track remediation progress
  • Build risk registers, support assessments, and monitor remediation progress
  • Work hands-on with GRC tools and contribute to solutions for complex client challenges
  • Translate technical and regulatory requirements into clear, actionable steps for our clients
  • Participate in peer review of deliverables before they go to clients - your work will be reviewed and you will review others

You will touch every aspect of cybersecurity and GRC work across multiple industries. Every engagement brings new challenges and new opportunities to grow.

What You Bring

  • A Bachelor's or Graduate degree in Cybersecurity, Information Systems, or a related field
  • 1 to 2 years of professional work experience -- this does not need to be in GRC or cybersecurity specifically, but it does need to be in a professional office or corporate environment. We are looking for candidates who have demonstrated reliability, communication, and accountability in a workplace setting
  • Solid understanding of fundamental security and IT concepts including access controls, data retention, and change management
  • Familiarity with major security and privacy frameworks including ISO, NIST, SOC 2, and HIPAA
  • Strong critical thinking, organization, and communication skills
  • Ability to balance multiple projects and deadlines with exceptional follow-through
  • Technical aptitude -- you are curious, you learn fast, and you do not shy away from new tools
  • A genuine interest in cybersecurity and a commitment to helping organizations build stronger, safer programs
  • A solutions-first attitude -- you show up with curiosity and energy and you are not afraid to dive into the work
  • The ability to think critically and execute with precision in a fast-paced, high-trust, low-ego environment
  • A high level of ownership and accountability -- you communicate proactively and follow through without being managed closely
  • A default toward communication - you keep the team informed, you acknowledge quickly, and you do not go dark on a deliverable or a client

Active pursuit of a relevant certification (Security+, CC, SSCP) is strongly preferred. If you are not currently studying for one, be prepared to explain why.

Requirements

  • Located in the USA with permanent work authorization (no sponsorship of any kind now or in the future)
  • Able to pass a background check
  • A private, dedicated workspace with a door - client calls and confidential work require it

Our Hiring Process

Our process is designed to be straightforward but thorough. In addition to a written questionnaire and video responses, finalists will complete a practical skills assessment before advancing to a panel interview with our delivery team. The assessment is designed to reflect real GRC work. If you are serious about building a career in this field, it is your opportunity to show us what you can do.

Why Hotman Group

At Hotman Group we are not just another consulting firm. You will work alongside people who care about the craft and push each other to do better. No politics, no silos, no hierarchy between you and the people making decisions.

You will touch more GRC frameworks, more industries, and more client situations in one year here than most practitioners see in five. You will grow because the work demands it.

The clients you serve will actually notice your work. You are not a number on a headcount. Your name is on the deliverable.

If you want to do real GRC work, get better at it every day, and work with a team that holds itself to a high standard - this is the place.

No phone calls or emails please.

Employment Type: CONTRACTOR