1

Grc Contract Jobs (NOW HIRING)

Senior GRC Analyst

Pittsburgh, PA ยท On-site

$114K - $163K/yr

As Senior GRC Analyst, you will be the hands-on owner of the control and evidence work behind our ... review, contract security and PCI terms review, and ongoing monitoring of critical vendors.

Cybersecurity GRC Manager (Hybrid)

Houston, TX ยท On-site

$106K - $143K/yr

Your Job Koch Engineered Solutions (KES) is looking for a Cybersecurity GRC Manager to join our ... Experience supporting customer cybersecurity questionnaires, contract security reviews, evidence ...

This is a unique opportunity to build and scale a global cybersecurity GRC program in a complex ... Experience supporting customer cybersecurity questionnaires, contract security reviews, evidence ...

New

Manager, IT Security, GRC

Burlington, NJ ยท On-site

$150K - $175K/yr

The Manager of GRC helps shape the enterprise's risk posture while mentoring a high-performing team ... Embed incident response obligations into contracts and procurement. Audit and Compliance: * Oversee ...

This is a fully remote position open to Contract or Full-Time candidates. Key Responsibilities ... Hands-on experience with GRC platforms such as Archer, ServiceNow GRC, or OneTrust * Familiarity ...

Contract Analyst (Hybrid)

Raleigh, NC ยท Hybrid

$67K - $81K/yr

Contract Management - Manages queue of contracts coming up for renewal/expiration. Reviews and ... Experience with Archer governance, risk, and compliance (GRC) platform Benefits are an integral ...

Contract Analyst (Hybrid)

Raleigh, NC ยท Hybrid

$67K - $81K/yr

Contract Management - Manages queue of contracts coming up for renewal/expiration. Reviews and ... Experience with Archer governance, risk, and compliance (GRC) platform Benefits are an integral ...

GRC Analyst

Phoenix, AZ ยท On-site

SaaS - GRC Location: Phoenix, Arizona (3 days a week ... Duration: Contract Position Key Responsibilities * Perform security assessments of SaaS and ...

Experienced or Senior GRC Analyst

Fort Worth, TX ยท On-site +1

$84K - $111K/yr

This is a full-time, remote, contract-to-hire position. Top performers move into permanent roles within 6 months. What You Will Do As an Experienced or Senior GRC Analyst at Hotman Group you will ...

Showing results 41-60

Grc Contract information

See salary details

$48

$69

$81

How much do grc contract jobs pay per hour?

As of Aug 21, 2026, the average hourly pay for grc contract in the United States is $69.97, according to ZipRecruiter salary data. Most workers in this role earn between $67.31 and $76.92 per hour, depending on experience, location, and employer.

What is a GRC contract?

GRC contracts refer to agreements that govern the implementation and management of Governance, Risk, and Compliance (GRC) frameworks within an organization. These contracts outline responsibilities, standards, and procedures to ensure that a company adheres to regulatory requirements, manages risks effectively, and maintains robust internal controls. GRC contracts are often used with third-party vendors, consultants, or software providers to clarify expectations and protect the organization from legal or compliance issues. They play a critical role in helping businesses navigate complex regulatory environments and minimize potential liabilities.

What are the typical challenges faced by professionals working in GRC contract roles, and how can they effectively manage these challenges?

Professionals in GRC (Governance, Risk, and Compliance) contract roles often face challenges such as quickly adapting to new organizational cultures, understanding unique regulatory requirements, and managing tight deadlines for audits or compliance projects. Since contract roles may require rapid onboarding, it's important to proactively communicate with key stakeholders, leverage available documentation, and prioritize tasks based on risk and compliance impact. Building strong relationships with internal teams and maintaining up-to-date knowledge of relevant regulations can help contract professionals deliver value efficiently and mitigate potential compliance gaps.

What are the key skills and qualifications needed to thrive as a GRC contract specialist, and why are they important?

To thrive as a GRC Contract Specialist, you need a solid understanding of risk management, regulatory compliance, and contract law, often supported by a relevant degree or certification like CCEP or CRISC. Familiarity with GRC platforms (such as RSA Archer or ServiceNow), contract management systems, and regulatory databases is typically required. Exceptional attention to detail, analytical thinking, and strong negotiation and communication skills help you excel in this role. These capabilities ensure that organizations effectively manage risks, remain compliant with regulations, and protect their interests in contractual agreements.

What is the difference between Grc Contract vs Grc Analyst?

AspectGrc ContractGrc Analyst
Required CredentialsCertifications like CISA, CISSP, or CRISC often preferredSame certifications, often with additional compliance or audit training
Work EnvironmentContract-based, project-specific, often in consulting firms or client sitesFull-time or contract, typically within organizations' security or compliance teams
Employer & Industry UsageUsed by consulting firms, security vendors, and organizations for specific projectsCommon within organizations' risk management, compliance, or security departments

Grc Contract roles focus on providing specialized GRC services on a temporary basis, often for specific projects, while Grc Analysts typically work within organizations to monitor, analyze, and ensure compliance continuously. Both roles require similar certifications but differ mainly in employment type and scope of work.

More about Grc Contract jobs

What cities are hiring for Grc Contract jobs?

Cities with the most Grc Contract job openings:

What are the most commonly searched types of Grc jobs?

The most popular types of Grc jobs are:

What states have the most Grc Contract jobs?

States with the most job openings for Grc Contract jobs include:

What job categories do people searching Grc Contract jobs look for?

The top searched job categories for Grc Contract jobs are:

Infographic showing various Grc Contract job openings in the United States as of August 2026, with employment types broken down into 52% Full Time, and 48% Contract. Highlights an 70% In-person, 11% Hybrid, and 19% Remote job distribution, with an average salary of $145,541 per year, or $70 per hour.

Senior GRC Analyst

Wolfe, LLC

Pittsburgh, PA โ€ข On-site

$114K - $163K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 9 days ago


Job description

Description
Role Summary
Wolfe is a Pittsburgh-based FinTech company operating consumer gifting and payments brands, and we are actively embedding AI across our products, our internal processes, and the way our teams work day-to-day. As Senior GRC Analyst, you will be the hands-on owner of the control and evidence work behind our PCI DSS Level 1 service provider obligations, our SOC 2 Type II readiness, our IT general controls, our NIST CSF 2.0 maturity program, and our third-party risk assessments. This is a deliberately senior individual contributor role — you will operate with minimal oversight, work directly with our QSA and external auditors, and serve as the compliance advisor engineering, fraud, and product teams come to before they build. You will also help us define how governance keeps pace with AI adoption, including the controls and review process for AI use across the company. This is a 5-day onsite role in Pittsburgh, PA. 

Responsibilities
  • Run our annual PCI DSS v4.0.1 Level 1 service provider assessment and SOC 2 Type II examination end to end — scope validation, evidence collection, QSA and auditor coordination, gap remediation tracking, and support for sponsor bank and processor due diligence requests. 
  • Own IT general control readiness across change management, logical access, SDLC, and backup and job scheduling — documenting control narratives, walking auditors through the environment, and performing internal design and operating-effectiveness testing so that external testing produces no surprises. 
  • Own the issues management lifecycle under our Issues Management Policy — intake, risk rating, remediation tracking, closure evidence, and recurring reporting to leadership and the Audit Committee. 
  • Execute third-party risk assessments across our vendor portfolio, including security questionnaire review, contract security and PCI terms review, and ongoing monitoring of critical vendors. 
  • Administer our GRC platform — control library and cross-framework mappings across PCI, SOC 2, and ITGC, automated evidence collection, control owner workflows, and compliance dashboards. 

Impact Statement
For more clarity on the role, below are the success metrics and measurements for this role in the first 90 to 120 days.: 
  • Take over evidence collection for the current PCI DSS v4.0.1 assessment cycle and deliver a QSA-accepted evidence package for your assigned requirement families, with an aging report showing zero overdue evidence requests at the 120-day mark. 
  • Deliver a SOC 2 Type II readiness assessment covering the full ITGC population — change management, logical access, SDLC, and backup and recovery — including written control narratives, identified design gaps, and a remediation plan sized to close before the audit period opens. 
  • Complete a refreshed assessment of the governance function and deliver a prioritized remediation plan covering the lowest-scoring subcategories, with owners, target dates, and a defined scoring path from current to target maturity. 
  • Migrate all open compliance and audit findings into a single issues register in the GRC platform — each item risk-rated, owner-assigned, and due-dated — and publish the first monthly issues report to the IT Steering Committee. 

Qualifications
  • 7+ years in GRC, IT audit, or information security compliance, including at least 3 years directly supporting PCI DSS in a Level 1 service provider or equivalent payment card environment; CISA, CRISC, CISSP, PCIP, or ISA certification preferred but not required. 
  • Demonstrated experience preparing for and supporting SOC 2 Type II examinations, including designing, documenting, and testing IT general controls across change management, logical access, and the software development lifecycle. 
  • Working depth in IT governance, with proven ability to translate control requirements into testable evidence that an external assessor accepts without rework. 
  • Hands-on experience administering a GRC platform (Vanta, Drata, Secureframe, ServiceNow IRM, AuditBoard, or similar) — control mapping, automated evidence collection, and reporting. 
  • Track record running third-party risk assessments end to end, including reviewing security and compliance terms in vendor contracts. 
  • Experience in a regulated financial services environment answering to external parties — sponsor banks, processors, regulators, or internal audit — and producing deliverables for executive and board audiences. 

Compensation, Benefits, and Perks
Wolfe is committed to providing a comprehensive benefits package to support your well-being, along with competitive compensation. Our benefits and perks include but not limited to:
  • Restricted Stock Units (RSUs)
  • Profit Share 
  • Medical, Prescription, Vision, and Dental insurance for employees and dependents (Wolfe pays 80% of premium)
  • Short-Term Disability Insurance (Wolfe pays 100% of premium)
  • Voluntary Long-Term Disability Insurance, Life Insurance, Critical Illness Insurance, Accident Insurance, and Hospital Indemnity coverage
  • PTO (vacation and sick time)
  • Corporate Holidays and Floating Holidays
  • 401(k)
  • Employee recognition program
  • Charitable Donation to a charity of your choice yearly
  • Employee Referral Bonus
  • Tuition Reimbursement
  • Internal Training and Information sessions
  • Family Picnic, Holiday Party, and other outings
  • Internal Culture Club