1

Grc Compliance Jobs (NOW HIRING)

THE POSITION NMCยฒ is looking for a detail-oriented GRC Compliance Auditor to join the Information Security team, reporting to the GRC & Privacy Manager and based at our Dallas, TX offices at Victory ...

THE POSITION NMC is looking for a detail-oriented GRC Compliance Auditor to join the Information Security team, reporting to the GRC & Privacy Manager and based at our Dallas, TX offices at Victory ...

Director, Product, GRC/Compliance

San Jose, CA ยท On-site

$272K - $285K/yr

Director Of Product, GRC/Compliance We are seeking a visionary and results-driven Director of Product, GRC/compliance, to lead our core product strategy, roadmap, and execution. This leader will be ...

$98K - $132K/yr

Your Day to Day As a Senior GRC Compliance Analyst you would be working on : * Serve as a senior level GRC engineering contributor, combining practical compliance knowledge with hands-on systems ...

Serve as the definitive GRC/Compliance deep domain expert across the organization, translating complex regulatory frameworks, risk assessment workflows, and audit practices into seamless, intuitive ...

Serve as the definitive GRC/Compliance deep domain expert across the organization, translating complex regulatory frameworks, risk assessment workflows, and audit practices into seamless, intuitive ...

Director, Product, GRC/Compliance

San Jose, CA ยท On-site

$188K - $282K/yr

Serve as the definitive GRC/Compliance deep domain expert across the organization, translating complex regulatory frameworks, risk assessment workflows, and audit practices into seamless, intuitive ...

Serve as the definitive GRC/Compliance deep domain expert across the organization, translating complex regulatory frameworks, risk assessment workflows, and audit practices into seamless, intuitive ...

next page

Showing results 1-20

Grc Compliance information

See salary details

$31.5K

$98.9K

$207.5K

How much do grc compliance jobs pay per year?

As of Jul 27, 2026, the average yearly pay for grc compliance in the United States is $98,949.00, according to ZipRecruiter salary data. Most workers in this role earn between $61,500.00 and $115,000.00 per year, depending on experience, location, and employer.

What is the salary of governance risk compliance?

The salary for a GRC (Governance, Risk, and Compliance) professional typically ranges from $70,000 to $130,000 annually, depending on experience, certifications, and location. Entry-level roles may start lower, while senior positions with certifications like CISA or CISSP tend to earn higher salaries. The role often requires knowledge of compliance frameworks and risk management tools.

What are the key skills and qualifications needed to thrive as a GRC Compliance professional, and why are they important?

To thrive as a GRC Compliance professional, you need a solid understanding of governance, risk management, and compliance frameworks, often supported by degrees in business, law, or information security. Familiarity with tools like GRC platforms (e.g., RSA Archer, ServiceNow), risk assessment methodologies, and relevant certifications such as CISA or CRISC is highly valuable. Attention to detail, analytical thinking, and strong communication skills help in interpreting regulations and collaborating across departments. These competencies are crucial for ensuring organizations meet legal requirements, manage risks, and maintain robust internal controls.

What is GRC compliance?

GRC compliance refers to the integration of Governance, Risk Management, and Compliance processes within an organization. It ensures that a company adheres to legal, regulatory, and internal policies while effectively managing risks and aligning business objectives. GRC compliance helps organizations streamline operations, prevent fraud, and maintain a strong reputation by proactively addressing potential issues. Adopting GRC frameworks often involves using specialized software, regular audits, and employee training.

What are some common challenges faced by professionals in GRC Compliance roles, and how can they be addressed?

Professionals in GRC (Governance, Risk, and Compliance) Compliance roles often navigate the complexities of evolving regulations, balancing business objectives with compliance requirements. One common challenge is staying updated with regulatory changes and ensuring timely implementation across the organization. Additionally, GRC professionals must foster strong communication and collaboration among multiple departments, such as IT, legal, and operations, to build a cohesive compliance culture. Addressing these challenges involves continuous learning, proactive stakeholder engagement, and leveraging compliance management tools to streamline processes and reporting.

Is GRC an entry level job?

GRC (Governance, Risk, and Compliance) roles can be entry-level or require experience depending on the specific position. Entry-level GRC jobs typically focus on supporting compliance activities and may require basic knowledge of regulations and tools like audit software, while more advanced roles involve managing risk frameworks and require relevant certifications or experience.

Is compliance a dead-end job?

GRC (Governance, Risk, and Compliance) compliance roles are typically stable and offer opportunities for career advancement as organizations prioritize regulatory adherence and risk management. Professionals in this field often develop specialized skills, certifications, and experience that can lead to higher-level positions or related roles in cybersecurity, audit, or legal compliance.

Is GRC a good career?

GRC (Governance, Risk, and Compliance) is a growing field that offers opportunities in cybersecurity, regulatory compliance, and risk management. Professionals in GRC roles often require knowledge of industry standards, certifications like CISA or CISSP, and strong analytical skills. It can be a stable career with increasing demand across various industries.

What is the difference between Grc Compliance vs Risk Analyst?

AspectGrc ComplianceRisk Analyst
Required CertificationsISO 27001 Lead Auditor, CISA, CISMFRM, CRM, CIA
Work EnvironmentCorporate, compliance departments, consulting firmsFinancial institutions, consulting, corporate risk teams
Industry UsageFinance, healthcare, technology, governmentBanking, insurance, investment firms

Grc Compliance professionals focus on establishing and maintaining compliance frameworks, policies, and controls to meet regulatory standards. Risk Analysts evaluate and quantify potential risks to the organization, often using data analysis to inform decision-making. While both roles require understanding of industry regulations, Grc Compliance emphasizes adherence and policy implementation, whereas Risk Analysts concentrate on risk assessment and mitigation strategies.

More about Grc Compliance jobs
What cities are hiring for Grc Compliance jobs? Cities with the most Grc Compliance job openings:
What are the most commonly searched types of Grc Compliance jobs? The most popular types of Grc Compliance jobs are:
What states have the most Grc Compliance jobs? States with the most job openings for Grc Compliance jobs include:
Infographic showing various Grc Compliance job openings in the United States as of July 2026, with employment types broken down into 1% As Needed, 83% Full Time, 12% Part Time, and 4% Contract. Highlights an 94% Physical, 2% Hybrid, and 4% Remote job distribution, with an average salary of $98,949 per year, or $47.6 per hour.

GRC Compliance Auditor

NorthMark Strategies

Dallas, TX โ€ข On-site

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 5 days ago


Job description

THE COMPANY
NorthMark Compute & Cloud (NMCยฒ) is backed by dedicated leadership and investment, with a clear mission as it operates at the bleeding edge of technology. Its goal is to scale and enhance the high-performance computing (HPC) and cloud infrastructure that supports its clients' research, production, and delivery, enabling breakthroughs that shape the industries of tomorrow. Its engineers build critical infrastructure to eliminate friction in scientific research, simulations, analysis, and decision-making, accelerating discovery and driving faster innovation.
THE POSITION
NMCยฒ is looking for a detail-oriented GRC Compliance Auditor to join the Information Security team, reporting to the GRC & Privacy Manager and based at our Dallas, TX offices at Victory Commons. This role owns the day-to-day execution of NMCยฒ's SOC 2 Type II and ISO 27001 compliance programmes - from readiness assessments and control mapping through to evidence collection and external audit coordination.
You will serve as the primary administrator of our GRC platform, maintaining the control framework library, driving automated evidence collection, and producing compliance posture reporting for leadership. You will work closely with control owners across Engineering, IT, HR, Legal, and Operations - translating regulatory requirements into practical controls and embedding audit readiness into how teams operate day to day.
The right candidate brings deep hands-on experience with SOC 2 and ISO 27001, a sharp eye for control gaps, and the communication skills to guide both technical and non-technical stakeholders through audit processes without disrupting the business.
RESPONSIBILITIES
  • Lead internal audit cycles for SOC 2 Type II and ISO 27001, assessing the design and operating effectiveness of controls and identifying deficiencies for remediation.
  • Coordinate external audits end-to-end - scheduling walkthroughs, preparing evidence packages, managing auditor requests, and tracking findings through to validated closure.
  • Conduct readiness assessments and gap analyses across compliance frameworks, recommending remediation actions prioritized by risk and business impact.
  • Develop and maintain a cross-framework control library mapping SOC 2 TSC, ISO 27001 Annex A, NIST CSF, and other applicable standards to NMCยฒ's operational controls.
  • Serve as the primary administrator of the GRC and compliance automation platform - configuring control frameworks, evidence integrations, risk registers, and compliance dashboards.
  • Drive adoption of automated evidence collection via integrations with IdP, IGA, HR, and infrastructure systems to reduce manual audit overhead across the business.
  • Produce executive-ready compliance posture reports, control health metrics, and audit-readiness scorecards for leadership and board-level stakeholders.
  • Manage and track remediation of audit findings, exceptions, and risk acceptances, and conduct vendor and third-party risk assessments against SOC 2 and ISO 27001 requirements.
  • Develop audit readiness training, control owner guides, and playbooks to embed compliance awareness into day-to-day operations across Engineering, Product, and Operations teams.
  • Respond to customer security questionnaires and due diligence requests relating to audit certifications and NMCยฒ's compliance posture.

REQUIREMENTS
  • Bachelor's degree in Information Systems, Computer Science, Business Administration, or a related field - or equivalent experience.
  • 4-8 years of hands-on experience in GRC, IT audit, or information security compliance.
  • Demonstrated experience conducting or supporting SOC 2 Type II audits, including evidence collection, control testing, and auditor coordination.
  • Working knowledge of ISO 27001 / 27002 requirements, with experience supporting certification or surveillance audits.
  • Hands-on experience administering a GRC or compliance automation platform such as Vanta, Drata, Hyperproof, AuditBoard, or equivalent.
  • Ability to translate complex regulatory requirements into practical, implementable controls and evidence procedures.
  • Familiarity with identity and access management tooling (Entra ID, Okta, or equivalent) in the context of access reviews and compliance evidence.
  • Experience working with control owners across Engineering, IT, Legal, HR, and Operations to define and validate control procedures.
  • Strong written and verbal communication skills; comfortable presenting compliance findings to both technical and non-technical audiences.
  • One or more relevant certifications preferred: CISA, ISO 27001 Lead Auditor or Lead Implementer, CISM, CISSP, or CRISC.

It is impossible to list every requirement for, or responsibility of, any position. Similarly, we cannot identify all the skills a position may require since job responsibilities and the Company's needs may change over time. Therefore, the above job description is not comprehensive or exhaustive. The Company reserves the right to adjust, add to or eliminate any aspect of the above description. The Company also retains the right to require all employees to undertake additional or different job responsibilities when necessary to meet business needs.
Must be legally authorized to work in the United States without the need for employer sponsorship, now or at any time in the future.
Benefits & Perks:
  • Company-Paid Lunch Stipend: Lunch is provided via GrubHub
  • Company-Paid Benefits: 100% Employer-Paid Medical in our High Deductible Health Plan, Dental and Vision benefits for employees and their families, 16 weeks of Paid Parental Leave, Employee Assistance Program, Life insurance, Short-Term Disability and Long-Term Disability
  • 401(k): Company will match 100% of your contributions up to 6%
  • Optional Employee-Paid Benefits: Medical insurance in our PPO plan and a variety of other benefits such as Health Savings Accounts (with Company Contribution!), Flexible Spending Accounts, Supplemental Life Insurance, Wellhub and more.
  • Time Off: 25 days of Paid Time Off plus 12 company holidays

EQUAL OPPORTUNITY EMPLOYER
NORTHMARK STRATEGIES LLC IS AN EQUAL EMPLOYMENT OPPORTUNITY EMPLOYER. THE COMPANY'S POLICY IS NOT TO DISCRIMINATE AGAINST ANY APPLICANT OR EMPLOYEE BASED ON RACE, COLOR, RELIGION, NATIONAL ORIGIN, GENDER, AGE, SEXUAL ORIENTATION, GENDER IDENTITY OR EXPRESSION, MARITAL STATUS, MENTAL OR PHYSICAL DISABILITY, AND GENETIC INFORMATION, OR ANY OTHER BASIS PROTECTED BY APPLICABLE LAW. THE FIRM ALSO PROHIBITS HARASSMENT OF APPLICANTS OR EMPLOYEES BASED ON ANY OF THESE PROTECTED CATEGORIES.