1

Grc Engineer Jobs in Raleigh, NC (NOW HIRING)

About Us ACA Group is the leading governance, risk, and compliance (GRC) advisor in financial ... Whether you're an early-career developer or a seasoned architect, you'll help shape a next ...

We work closely with security engineering, security operations, product security, GRC, identity and access management, infrastructure, product management, and customer trust teams across a global ...

We work closely with security engineering, security operations, product security, GRC, identity and access management, infrastructure, product management, and customer trust teams across a global ...

... Engineering, or a related discipline. Experience • 5+ years of experience in compliance, audit, governance, risk and compliance (GRC), or related program management roles. • Direct experience ...

... Engineering, or a related discipline. Experience 5+ years of experience in compliance, audit, governance, risk and compliance (GRC), or related program management roles. Direct experience supporting ...

1-20-Sr. SAP Developer

Raleigh, NC · Remote

$75 - $100/hr

... Manager, GRC, NWCE, PI, BTP and OpenText document management. This position plays a key role in ... Engineers and Enterprise Architects. Description (including, but not limited to): Required Skills:

Showing results 21-40

Grc Engineer information

See Raleigh, NC salary details

$57.8K

$108.5K

$197.3K

How much do grc engineer jobs pay per year?

As of Sep 9, 2026, the average yearly pay for grc engineer in Raleigh, NC is $108,515.00, according to ZipRecruiter salary data. Most workers in this role earn between $78,300.00 and $128,800.00 per year, depending on experience, location, and employer.

What is a GRC engineer?

GRC Engineers are professionals who specialize in Governance, Risk, and Compliance (GRC) within an organization’s information security and IT frameworks. They help ensure that a company’s policies and procedures meet regulatory requirements, manage risks, and align with business objectives. GRC Engineers often implement and maintain tools, conduct risk assessments, and ensure compliance through audits and reporting. Their role is critical in minimizing risks and protecting organizational assets from security threats.

What are the key skills and qualifications needed to thrive as a GRC engineer?

To thrive as a GRC Engineer, you need a solid understanding of governance, risk management, and compliance frameworks, often supported by a degree in information security or a related field. Familiarity with GRC platforms (such as RSA Archer or ServiceNow GRC), risk assessment tools, and certifications like CISA or CISSP are highly valued. Strong analytical skills, attention to detail, and effective communication are crucial soft skills for collaborating across departments and translating complex requirements. These competencies ensure that organizations can effectively manage risk, maintain regulatory compliance, and safeguard critical information assets.

What are some common challenges faced by GRC engineers when implementing new compliance frameworks?

GRC Engineers often encounter challenges such as integrating new compliance requirements with existing IT systems, ensuring consistent documentation, and keeping up with evolving regulatory standards. Collaboration with various departments—like IT, legal, and operations—is essential to map processes accurately and address potential gaps. Proactive communication and a strong understanding of both technical and regulatory aspects help GRC Engineers overcome these hurdles and support organizational compliance effectively.

What is the difference between Grc Engineer vs Security Analyst?

AspectGrc EngineerSecurity Analyst
CertificationsISO 27001, CISSP, CISACISSP, CompTIA Security+
Work EnvironmentPolicy development, compliance, risk managementMonitoring, incident response, threat analysis
Industry UsageCorporate governance, compliance teamsSecurity operations centers, IT departments

Grc Engineers focus on establishing and maintaining governance, risk, and compliance frameworks, ensuring organizations meet regulatory standards. Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. While both roles require security certifications and work within the cybersecurity industry, Grc Engineers emphasize policy and compliance, whereas Security Analysts focus on threat detection and response.

Are GRC engineer jobs hard to get?

GRC (Governance, Risk, and Compliance) engineer jobs can be competitive, especially for entry-level positions, but having relevant skills in cybersecurity, risk management, and certifications like CISSP or CISA can improve chances. The difficulty of securing a GRC engineer role depends on experience, education, and the demand within the industry or organization. Strong knowledge of compliance frameworks and tools is often required to stand out.

How much do GRC engineers make?

GRC (Governance, Risk, and Compliance) engineers typically earn between $80,000 and $130,000 annually, depending on experience, certifications, and location. Senior roles or those with specialized skills in cybersecurity tools and frameworks can earn higher salaries, often exceeding $150,000.

Is GRC engineer an entry-level job?

A GRC (Governance, Risk, and Compliance) engineer is typically an intermediate to senior role that requires relevant experience and knowledge of security frameworks, compliance standards, and risk management tools. Entry-level positions may be available but often require foundational skills, certifications, or internships in cybersecurity or IT governance.

What are popular job titles related to Grc Engineer jobs in Raleigh, NC?

For Grc Engineer jobs in Raleigh, NC, the most frequently searched job titles are:

What cities near Raleigh, NC are hiring for Grc Engineer jobs?

Cities near Raleigh, NC with the most Grc Engineer job openings:

Infographic showing various Grc Engineer job openings in Raleigh, NC as of August 2026, with employment types broken down into 100% Contract. Highlights an 100% In-person job distribution, with an average salary of $108,515 per year, or $52.2 per hour.

Manager Security Compliance and Risk Management

Raleigh, NC • On-site

LexisNexis
IT Services • 10K+ employees

Full-time

Re-posted 24 days ago


LexisNexis rating

7.6

Company rating: 7.6 out of 10

Based on 17 frontline employees who took The Breakroom Quiz

195th of 501 rated business services


Job description

Manager, Security - Security Compliance & Risk Management

Core Responsibilities

Risk Management

  • Own andoperatethe enterprise technology and security risk management program, including risk identification, scoring, tracking, and maintenance of the risk register

  • Lead the risk exception and acceptance process, ensuring documentation, approvals, and periodic review are consistently enforced

  • Drivetimelyidentification, escalation, and resolution of cybersecurity risks and issues across the organization

  • Serve as a trusted advisor to business and technology stakeholders, providing pragmatic, risk-based guidance that unblocks decisions rather than just flagging concerns

People Leadership

  • Manage, coach, and develop a team of security engineers, including performance management, career growth planning, and hiring

  • Set clear priorities, delegate work effectively, andmaintainteam capacity across concurrent audit, compliance, andConMonactivities

  • Build a team culture where audit-readiness and evidence quality are treated as ongoing standards, not last-minute scrambles

Reporting & Communication

  • Produce metrics, KPIs, and dashboard-level reporting for senior leadership, including risk dashboards, compliance posture summaries, and control effectiveness metrics

  • Communicate risk and compliance posture clearly to technical and non-technical stakeholders, translating audit findings and control gaps into concrete next steps

  • Support the CISO in preparing board and executive committee materials on the state of the security and compliance program

Management Duties

  • Carry out management responsibilitiesin accordance withthe organization's policies, procedures, and applicable laws. Responsibilities include interviewing, hiring, and training employees; planning, assigning, and directing work; appraising performance; rewarding and disciplining employees; and addressing complaints and resolving problems.

  • Ensure all staffisprovided with training and resources needed to perform their jobs to the most outstanding degree possible. Ensure all staffisprovided with frequent feedback and coachingin order tomeet and exceed individual and team performance goals consistently.

  • Manage and encouragenew ideasfrom staff to foster improvements through innovations.

  • Empower the staff to be accountable and responsible for their own actions and decisions.

  • All other duties as assigned.

Qualifications

Required

  • 6-8 years of progressive experience in information security compliance, risk management, or IT audit, withdemonstratedownership of program-level responsibilities - not just participation

  • 2-3 years of people management or formal team leadership experience, including performance management and team development

  • Deep, hands-on knowledge of GRC disciplines across risk management, compliance, and control governance, with the ability to speak credibly to program design decisions, control gaps, and risk trade-offs in both technical and executive conversations

  • Demonstrated experienceowning an enterprise risk register and managing the full risk lifecycleand producing risk reporting for executive audiences

  • Deep working knowledge of control frameworks including NIST CSF and ISO 27001, with hands-on experience performing control mapping,identifyinggaps, and translating framework requirements into actionable compliance activities; SOC 2 experiencerequired

  • Experience with technology-sector regulatory obligations (e.g., SOC 2, GDPR, CCPA) and the ability to assess organizational impact of emerging compliance requirements

  • Experience with FedRAMP Continuous Monitoring programs and associated compliance obligations

  • Proven ability to manage audit engagements end-to-end and interface directly with internal and external auditors

  • Proven ability to design or mature a compliance program, driving continuous improvement across people, processes, and controls

  • Demonstrated ability to build relationships with both technical and executive stakeholders, influence decisions across organizational boundaries, and drive remediation at an organizational level

  • Strong written and verbal communication skills; ability to translate technical risk into clear business language and present risk and compliance posture to senior leadership and board-level audiences

  • Familiarity with cloud environments (e.g., AWS, GCP, or Azure) and their risk and compliance implications, including how cloud architecture decisions affect control design and evidence collection

  • Bachelor's degree in Information Security, Computer Science, Risk Management, or a related field - or equivalent practical experience

Preferred

  • CRISC or CISA strongly preferred; CISSP or CISM acceptable with demonstrated GRC focus - candidates without a relevant certification should be prepared todemonstrateequivalent depth through experience

  • Experience with GRC platforms such as ServiceNow GRC, Archer,OneTrust, orLogicGate

  • Familiarity with AI governance concepts and emerging frameworks (e.g., ISO 42001, NIST AI RMF)

  • Prior experience in a SaaS, cloud, or technology product company

U.S. National Base Pay Range: $118,300 - $219,800. Geographic differentials may apply in some locations to better reflect local market rates. This job is eligible for an annual incentive bonus.

We know your well-being and happiness are key to a long and successful career. We are delighted to offer country specific benefits. Click here to access benefits specific to your location.

We are committed to providing a fair and accessible hiring process. If you have a disability or other need that requires accommodation or adjustment, please let us know by completing our Applicant Request Support Formor please contact 1-855-833-5120.

Criminals may pose as recruiters asking for money or personal information. We never request money or banking details from job applicants. Learn more about spotting and avoiding scams here.

Please read our Candidate Privacy Policy.

We are an equal opportunity employer: qualified applicants are considered for and treated during employment without regard to race, color, creed, religion, sex, national origin, citizenship status, disability status, protected veteran status, age, marital status, sexual orientation, gender identity, genetic information, or any other characteristic protected by law.

USA Job Seekers:

EEO Know Your Rights.


What LexisNexis employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom