1

Grc Auditor Jobs (NOW HIRING)

IT GRC Auditor Consultant ONSITE - CORAL GABLES, MIAMI, FLORIDA www.elevateconsult.com Are you passionate about working in a complex IT environment where security and data privacy are a primary focus ...

The candidate will act as the primary security lead , coordinating across business stakeholders, auditors, SAP functional teams, and offshore delivery resources. Key Responsibilities SAP GRC ...

Title: SAP GRC Security Business Analyst (Governance & Advisory) Location: Connecticut Hybrid ... This individual will work closely with business leaders, internal security teams, auditors, and SAP ...

GRC Engineer

Foster City, CA · On-site

$210K - $320K/yr

We are looking for a GRC Engineer to serve as a key technical contributor for our compliance and ... Auditor Relationships: Own and cultivate the primary relationship with external auditors. You will ...

You will be responsible for reviewing and validating control evidence within our GRC platform ... Who You Are * 2-5 years of experience in internal auditing, compliance, or GRC roles * Familiarity ...

GRC Officer - Federal Compliance PenLink is a technology company bringing clarity to complex data ... Coordinating with internal teams, external auditors, consultants, and 3PAO assessors during ...

next page

Showing results 1-20

Grc Auditor information

See salary details

$41.5K

$78.2K

$125K

How much do grc auditor jobs pay per year?

As of Jun 11, 2026, the average yearly pay for grc auditor in the United States is $78,163.00, according to ZipRecruiter salary data. Most workers in this role earn between $58,500.00 and $89,500.00 per year, depending on experience, location, and employer.

What does a GRC auditor do?

A GRC (Governance, Risk, and Compliance) auditor assesses an organization's adherence to regulatory requirements, internal policies, and industry standards related to governance, risk management, and compliance. They review controls, perform audits, and recommend improvements, often using tools like audit software and frameworks such as ISO or COBIT. Strong analytical skills and knowledge of compliance regulations are essential for this role.

What is a GRC Auditor?

A GRC Auditor is a professional responsible for evaluating an organization's Governance, Risk Management, and Compliance (GRC) processes. They assess whether the organization is following relevant laws, regulations, and internal policies, and help identify areas of risk or non-compliance. GRC Auditors often conduct audits, review documentation, and provide recommendations to improve controls and ensure the organization meets its regulatory and operational requirements.

What is the difference between Grc Auditor vs Compliance Analyst?

AspectGrc AuditorCompliance Analyst
CertificationsISO 27001 Lead Auditor, CISA, CISMCertified Compliance & Ethics Professional (CCEP), CCEP-I
Work EnvironmentAudit firms, corporate compliance departmentsCorporate compliance teams, regulatory agencies
Industry UsageRisk management, IT, financeRegulatory adherence, policy enforcement

Grc Auditors focus on evaluating an organization’s governance, risk, and compliance frameworks through audits, often requiring certifications like CISA. Compliance Analysts primarily monitor and ensure adherence to regulations and policies, with certifications like CCEP. While both roles operate within compliance, Grc Auditors typically conduct formal audits, whereas Compliance Analysts focus on ongoing compliance monitoring.

Is GRC an entry level job?

GRC Auditor roles are often considered mid-level positions that require some experience in governance, risk management, or compliance, along with relevant certifications like CISA or CISSP. Entry-level positions in GRC may be available but typically involve supporting roles or internships, with more advanced responsibilities assigned to those with prior experience. Skills in auditing, understanding of regulations, and familiarity with GRC tools are important for progression in this field.

What are the main challenges GRC Auditors face when ensuring compliance across multiple departments?

GRC Auditors often encounter challenges in standardizing compliance processes across diverse departments, each with their own workflows and risk profiles. Coordinating with various teams to gather accurate data and evidence can be time-consuming, especially when systems are not integrated. Communication and collaboration are crucial, as auditors must often explain regulatory requirements and best practices to non-technical staff. Proactively building strong relationships and clear processes helps overcome these hurdles and ensures smoother audits.

Is GRC high paying?

GRC Auditor roles are generally considered well-paying within the cybersecurity and compliance fields, with salaries often reflecting experience, certifications, and industry demand. Professionals with skills in risk management, audit processes, and familiarity with frameworks like ISO or NIST tend to earn higher salaries. Entry-level positions may start lower, but experienced GRC auditors can earn competitive compensation.

What are the key skills and qualifications needed to thrive as a GRC Auditor, and why are they important?

To thrive as a GRC Auditor, you need a strong understanding of governance, risk management, compliance frameworks, and auditing principles, often supported by a degree in accounting, finance, or a related field. Familiarity with audit management tools, GRC platforms (such as RSA Archer or MetricStream), and certifications like CISA, CRISC, or CISSP are commonly required. Strong analytical thinking, attention to detail, and effective communication are essential soft skills to excel in this role. These competencies ensure comprehensive risk assessments, regulatory compliance, and effective reporting, which are critical for organizational integrity and security.

What type of auditor gets paid the most?

Among auditors, financial auditors and internal auditors with specialized skills or certifications such as CPA or CIA tend to earn the highest salaries. GRC (Governance, Risk, and Compliance) auditors with expertise in regulatory frameworks and risk management also command higher pay, especially with experience and advanced certifications. Salary levels depend on industry, location, and level of experience.
More about Grc Auditor jobs
What cities are hiring for Grc Auditor jobs? Cities with the most Grc Auditor job openings:
What states have the most Grc Auditor jobs? States with the most job openings for Grc Auditor jobs include:
Infographic showing various Grc Auditor job openings in the United States as of June 2026, with employment types broken down into 99% Full Time, and 1% Contract. Highlights an 77% Physical, 9% Hybrid, and 14% Remote job distribution, with an average salary of $78,163 per year, or $37.6 per hour.
Manager, Governance, Risk Management & Compliance (GRC) Auditor

Manager, Governance, Risk Management & Compliance (GRC) Auditor

Otsuka Pharmaceutical Co., Ltd.

Princeton, NJ • On-site

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 5 days ago


Job description

Following the implementation of the Governance, Risk Management, and Compliance (GRC) program and Enterprise Risk Management (ERM) Assessment in the U.S., this role will support the U.S. Ethics & Compliance (E&C) operational audit program and risk management activities.
The Manager, GRC Auditor will conduct planning, execution, and reporting of operational audits, tabletop assessments, and other ad-hoc reviews on behalf of Otsuka America Pharmaceutical, Inc. (OAPI) and Otsuka Pharmaceutical Development & Commercialization, Inc. (OPDC), collectively Otsuka. This will support effective risk management and compliance by providing assurance services through independent audits and reviews of Otsuka's enterprise and US compliance risks and business activities. This role supports U.S. E&C's GRC function and the Vice President & U.S. Chief Compliance Officer in executing an effective compliance program.
Job Description
The Manager, GRC Auditor will be responsible to:
  • Execute a U.S. Compliance audit program that provides assurance over Otsuka's enterprise and U.S. compliance risks and helps to detect and prevent fraud.
  • Update the audit universe based on engagement with stakeholders to ensure it is focused on the highest-risk activities and remains fit-for-purpose.
  • Conduct audits and other independent assessments of Otsuka's enterprise and compliance risks, by assessing the design and operating effectiveness of internal controls (through detailed transaction testing) to identify control gaps or risks.
  • Support development and execution of audit process steps, including drafting announcement memos, designing audit testing procedures, interviewing stakeholders, reviewing and testing internal controls, executing sampling methodology, reviewing supporting documentation, and documenting testing procedures, findings, and observations.
  • Validate audit findings and observations with management and communicate final audit results to management, through presentations and written reports that address findings, risks, root cause analysis, and recommended actions.
  • Draft formal written audit reports or other Compliance reports for the U.S. business that are clear, concise, and drive meaningful action to strengthen controls and mitigate risks.
  • Support management of third-party consultants and actively oversee audits conducted by third-parties on Otsuka's behalf, ensuring audit quality and on-time delivery.
  • Track and follow-up on management action plans to ensure they are completed timely and effectively.
  • Partner with U.S. Compliance Counsel and other functional areas to recommend pragmatic risk mitigation or remediation actions.
  • Establish and maintain effective relationships with internal stakeholders and collaborate with internal partners.
  • Provide feedback and/or drafts sections of reports and documents intended for submission to various organizational committees.
  • Maintain a working knowledge of relevant trends, laws and regulations pertaining to healthcare law, regulatory compliance, and auditing. Assists in developing or improving processes and procedures that promote compliance with healthcare laws, regulations and guidance.
  • Identify opportunities and supports further development of the COMPLi system, Otsuka's U.S. E&C data analytics platform.
  • Conduct other risk management activities or duties to support the U.S. E&C GRC and Healthcare Law Auditing and Monitoring teams.

Qualifications
Required
  • At least 4 - 7 years of experience performing auditing or monitoring activities and strong understanding of enterprise risk management frameworks, internal controls, and risk assessment and audit methodologies
  • Excellent communication skills (verbal and written)
  • Experience with regulators, external auditors, and/or independent review organizations
  • Bachelor's degree in Accounting, Risk Management, or a related field
    Certified Public Accountant (CPA), Certified Internal Auditor (CIA), Certified Information Systems Auditor (CISA) or other certification or professional designation in accounting, compliance, or auditing

Preferred
  • Pharmaceutical industry experience

Competencies
Accountability for Results - Stay focused on key strategic objectives, be accountable for high standards of performance, and take an active role in leading change.
Strategic Thinking & Problem Solving - Make decisions considering the long-term impact to customers, patients, employees, and the business.
Patient & Customer Centricity - Maintain an ongoing focus on the needs of our customers and/or key stakeholders.
Impactful Communication - Communicate with logic, clarity, and respect. Influence at all levels to achieve the best results for Otsuka.
Respectful Collaboration - Seek and value others' perspectives and strive for diverse partnerships to enhance work toward common goals.
Empowered Development - Play an active role in professional development as a business imperative.
Minimum $121,103.00 - Maximum $181,125.00, plus incentive opportunity: The range shown represents a typical pay range or starting pay for individuals who are hired in the role to perform in the United States. Other elements may be used to determine actual pay such as the candidate's job experience, specific skills, and comparison to internal incumbents currently in role. Typically, actual pay will be positioned within the established range, rather than at its minimum or maximum. This information is provided to applicants in accordance with states and local laws.
Application Deadline: This will be posted for a minimum of 5 business days.
Company benefits: Comprehensive medical, dental, vision, prescription drug coverage, company provided basic life, accidental death & dismemberment, short-term and long-term disability insurance, tuition reimbursement, student loan assistance, a generous 401(k) match, flexible time off, paid holidays, and paid leave programs as well as other company provided benefits.
Come discover more about Otsuka and our benefit offerings; https://www.otsuka-us.com/careers-join-otsuka.
Disclaimer:
This job description is intended to describe the general nature and level of the work being performed by the people assigned to this position. It is not intended to include every job duty and responsibility specific to the position. Otsuka reserves the right to amend and change responsibilities to meet business and organizational needs as necessary.
Otsuka is an equal opportunity employer. All qualified applicants are encouraged to apply and will be given consideration for employment without regard to race, color, sex, gender identity or gender expression, sexual orientation, age, disability, religion, national origin, veteran status, marital status, or any other legally protected characteristic.
If you are a qualified individual with a disability or a disabled veteran, you may request a reasonable accommodation, if you are unable or limited in your ability to apply to this job opening as a result of your disability. You can request reasonable accommodations by contacting Accommodation Request.
Statement Regarding Job Recruiting Fraud Scams
At Otsuka we take security and protection of your personal information very seriously. Please be aware individuals may approach you and falsely present themselves as our employees or representatives. They may use this false pretense to try to gain access to your personal information or acquire money from you by offering fictitious employment opportunities purportedly on our behalf.
Please understand, Otsuka will never ask for financial information of any kind or for payment of money during the job application process. We do not require any financial, credit card or bank account information and/or any payment of any kind to be considered for employment. We will also not offer you money to buy equipment, software, or for any other purpose during the job application process. If you are being asked to pay or offered money for equipment fees or some other application processing fee, even if claimed you will be reimbursed, this is not Otsuka. These claims are fraudulent and you are strongly advised to exercise caution when you receive such an offer of employment.
Otsuka will also never ask you to download a third-party application in order to communicate about a legitimate job opportunity. Scammers may also send offers or claims from a fake email address or from Yahoo, Gmail, Hotmail, etc, and not from an official Otsuka email address. Please take extra caution while examining such an email address, as the scammers may misspell an official Otsuka email address and use a slightly modified version duplicating letters.
To ensure that you are communicating about a legitimate job opportunity at Otsuka, please only deal directly with Otsuka through its official Otsuka Career website https://vhr-otsuka.wd1.myworkdayjobs.com/en-US/External.
Otsuka will not be held liable or responsible for any claims, losses, damages or expenses resulting from job recruiting scams. If you suspect a position is fraudulent, please contact Otsuka's call center at: 800-363-5670. If you believe you are the victim of fraud resulting from a job recruiting scam, please contact the FBI through the Internet Crime Complaint Center at: https://www.ic3.gov, or your local authorities.
Otsuka America Pharmaceutical Inc., Otsuka Pharmaceutical Development & Commercialization, Inc., and Otsuka Precision Health, Inc. ("Otsuka") does not accept unsolicited assistance from search firms for employment opportunities. All CVs/resumes submitted by search firms to any Otsuka employee directly or through Otsuka's application portal without a valid written search agreement in place for the position will be considered Otsuka's sole property. No fee will be paid if a candidate is hired by Otsuka as a result of an agency referral where no pre-existing agreement is in place. Where agency agreements are in place, introductions are position specific. Please, no phone calls or emails.