1

Grc Risk Analyst Jobs in Colorado (NOW HIRING)

Sr. Principal, GRC

Boulder, CO · On-site

$196K - $287K/yr

Conduct strategic analysis of Workday's control and technical landscape to identify automation ... risk models and controls related to these services; 7 years (84 months) of experience in legal ...

Crypto Risk Senior Specialist

Denver, CO · On-site

$101K/yr

Prepare risk reporting and analysis for governance forums, including committee materials and ... Experience with governance, risk, and compliance (GRC) tools such as LogicGate or similar platforms ...

Senior IT Compliance Analyst

Centennial, CO · On-site

$68K - $116K/yr

Summary In this role, you will serve as a trusted expert in Governance, Risk, and Compliance (GRC ... Analyze findings, document and report program gaps, and recommend mitigation strategies to ...

New

Senior IT Compliance Analyst

Englewood, CO · On-site

$68K - $116K/yr

Summary In this role, you will serve as a trusted expert in Governance, Risk, and Compliance (GRC ... Analyze findings, document and report program gaps, and recommend mitigation strategies to ...

New

... Risk, and Compliance (GRC) Specialist, IT Risk Manager, Threat Assessment Analyst, Systems Compliance Auditor, Cyber Risk Analyst, etc. DEGREE (Level Desired) Bachelor's Degree DEGREE (Focus ...

... analyses, and remediation plans. * Lead third-party cyber risk management across inherent risk ... GRC and TPRM platforms; trust centers and questionnaire automation; privacy regimes (GDPR, CCPA ...

... Risk, and Compliance (GRC) Specialist, IT Risk Manager, Threat Assessment Analyst, Systems Compliance Auditor, Cyber Risk Analyst, etc. DEGREE (Level Desired) Bachelor's Degree DEGREE (Focus ...

Growth Leader, Risk Services

Denver, CO · On-site

$156K - $195K/yr

The role requires analytical skills, a can-do attitude to decision-making and problem solving, and ... Knowledge of GRC/IT Assurance services. * Proficiency with HubSpot or a comparable marketing ...

Showing results 21-40

Grc Risk Analyst information

What is the difference between Grc Risk Analyst vs Compliance Analyst?

AspectGrc Risk AnalystCompliance Analyst
CertificationsISO 31000, FRM, CRISCISO 19600, CCEP, CISA
Work EnvironmentRisk management teams, corporate officesRegulatory departments, corporate offices
Industry UsageFinance, banking, insurance, corporate riskFinancial services, healthcare, manufacturing
Job FocusIdentifying, assessing, and mitigating risks across enterpriseEnsuring compliance with laws and regulations

While both roles involve regulatory and risk considerations, a Grc Risk Analyst focuses on enterprise-wide risk management strategies, whereas a Compliance Analyst concentrates on adherence to specific laws and regulations. Both roles require similar certifications and often work in overlapping industries, but their core responsibilities differ in scope and focus.

What is a GRC Risk Analyst?

GRC Risk Analysts are professionals who specialize in Governance, Risk, and Compliance (GRC) within an organization. They assess and manage risks related to business operations, ensure compliance with relevant laws and regulations, and help implement policies and controls to mitigate potential threats. These analysts work closely with management to identify vulnerabilities, develop risk management strategies, and monitor the effectiveness of compliance programs. Their goal is to protect the organization from financial, legal, and reputational harm while supporting business objectives.

What are the key skills and qualifications needed to thrive as a GRC Risk Analyst?

To thrive as a GRC (Governance, Risk, and Compliance) Risk Analyst, you need a solid understanding of risk management principles, regulatory requirements, and compliance frameworks, often supported by a degree in information security, business, or a related field. Familiarity with GRC platforms (such as RSA Archer or MetricStream), risk assessment methodologies, and certifications like CRISC or CISA is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and convey findings to stakeholders. These skills are critical for ensuring organizational compliance, minimizing risk exposure, and supporting informed decision-making.

What are some common challenges a GRC Risk Analyst might face when implementing new risk management frameworks within an organization?

A GRC Risk Analyst often encounters challenges such as resistance to change from stakeholders, integrating new frameworks with existing processes, and ensuring consistent understanding across departments. Aligning risk management practices with organizational goals while adhering to regulatory requirements can also be complex. Success in this role requires strong communication skills, adaptability, and the ability to educate and collaborate with team members from diverse backgrounds.
What job categories do people searching Grc Risk Analyst jobs in Colorado look for? The top searched job categories for Grc Risk Analyst jobs in Colorado are:
Infographic showing various Grc Risk Analyst job openings in Colorado as of August 2026, with employment types broken down into 1% As Needed, 87% Full Time, 10% Part Time, and 2% Contract. Highlights an 87% Physical, 5% Hybrid, and 8% Remote job distribution.

Full-time

Medical, Dental, Vision, Retirement

Posted 28 days ago


Job description

Voyager is an innovative space, defense, and national security technology company committed to advancing and delivering transformative, mission-critical solutions. We tackle the most complex challenges to unlock new frontiers for human progress, fortify national security, and protect critical assets to lead in the race for technological and operational superiority from ground to space. 

Forge the Future: Join Voyager Technologies 

The future belongs to those who build it. At Voyager Technologies, we're building technologies that protect lives, expand frontiers and prepare us for what's next. And we're doing that with people who are wired to solve, build, adapt and lead. These roles are not for the faint of heart. 

You'll help lay the foundation for humanity's future. Join a culture where innovation thrives, curiosity is rewarded, and impact is real. We're a company of doers, thinkers and builders, united by purpose and grounded in reality. 

If you want to put your skills to work where the stakes are real and the mission is bigger than any one person,forge the future with Voyager. 

Job Summary

The Cybersecurity Analyst is a hands-on role responsible for analyzing security events, supporting vulnerability and risk remediation, maintaining cybersecurity evidence, and helping Voyager protect corporate, engineering, and regulated-program environments.

This role is being reframed from a compliance-led position into a cyber analysis role that still understands governance, risk, and compliance. The successful candidate will connect practical security analysis with audit-ready documentation so Voyager can protect systems, support CMMC/NIST obligations, and move quickly in a regulated aerospace, defense, and space technology environment.

This is a strong fit for a motivated analyst who can learn fast, work across IT and engineering teams, and turn security data, control requirements, and operational findings into clear action.

ResponsibilitiesSecurity Monitoring & Cyber Analysis
  • Monitor and analyze security alerts, endpoint events, identity events, email-security findings, and other signals from Voyager's security tooling.
  • Investigate suspicious activity, document findings, recommend remediation, and escalate incidents through defined response paths.
  • Support threat-hunting, log review, and detection-improvement efforts in partnership with cybersecurity leadership and managed security providers.
  • Prepare concise summaries of risks, trends, incidents, and open actions for technical and non-technical stakeholders.
Vulnerability & Risk Analysis
  • Analyze vulnerability scan results, endpoint posture, configuration gaps, and control weaknesses across corporate and regulated environments.
  • Partner with IT operations, networking, cloud, and system owners to prioritize remediation and track closure.
  • Maintain risk findings, exception requests, mitigation plans, and remediation status in a structured, auditable manner.
  • Support impact analysis for new systems, tools, integrations, and program requirements.
Compliance Evidence & Control Support
  • Support cybersecurity evidence collection for NIST SP 800-171, CMMC, DFARS 252.204-7012, ITAR/EAR, NASA, DoD, and prime contractor requirements.
  • Maintain assigned sections of system security plans, POA&Ms, control evidence, procedures, and security documentation.
  • Assist with internal readiness reviews, mock audits, control testing, and formal assessment preparation.
  • Help translate control requirements into practical tasks for IT, engineering, program, legal, and contracts teams.
Data Protection & User Enablement
  • Support secure handling of CUI, export-controlled technical data, and sensitive government information.
  • Contribute to data classification, marking, secure collaboration, and user-awareness efforts.
  • Help document security procedures and train users on secure workflows, phishing awareness, and compliance practices.
  • Participate in tabletop exercises, response drills, and process-improvement activities.

If your experience aligns with our basic qualifications and you are inspired by our mission, we'd like to connect. If you don't see the right role right now, Join Our Talent Community and stay connected as we continue to build what's next. 

Required Qualifications
  • High school diploma or equivalent.
  • 3-7+ years of experience in cybersecurity, cyber analysis, IT security, vulnerability management, security operations, IT compliance, GRC, or closely related roles.
  • Working knowledge of security operations concepts, endpoint security, identity security, vulnerability management, incident response, and risk analysis.
  • Familiarity with cybersecurity frameworks and requirements such as NIST SP 800-171, CMMC, NIST 800-53, DFARS, ITAR/EAR, CUI, or similar regulated-environment controls.
  • Experience creating or maintaining security documentation such as findings, evidence, POA&Ms, procedures, control narratives, risk registers, or remediation trackers.
  • Prior DoD, federal, aerospace, defense, or government-contractor experience.
  • Strong analytical, writing, communication, and cross-functional collaboration skills.
  • Ability to obtain and maintain a U.S. security clearance.
Preferred Qualifications
  • Active Secret clearance or 
  • Experience with SIEM, EDR, vulnerability scanning, GRC, ticketing, or cloud-security tools such as Microsoft Defender, Sentinel, Splunk, Tenable, Rapid7, ServiceNow GRC, Archer, Drata, or similar platforms.
  • Experience supporting Microsoft GCC High, Azure Government, FedRAMP, GovCloud, or secure collaboration environments.
  • Certifications such as Security+, CySA+, GSEC, CISA, CISM, CRISC, CMMC RP, or similar.
  • Demonstrated ability to progress quickly, learn new security domains, and operate with high ownership in a fast-moving environment.
Travel, Physical and/or Government-Mandated Requirements
  • Travel may be required to Voyager facilities, operational sites, and partner locations.
  • Participation in security exercises, incident response, or time-sensitive remediation activities may occasionally be required outside normal business hours.
  • This position requires access to information governed by U.S. export-control laws and may require access to government-controlled systems or data.

The good faith base salary range for this role is $95,000 - $125,000 at the time of this posting. Where you fall within the range depends on your experience, skills, and location. This range reflects base salary only and does not include benefits or bonus/incentive. This range may be adjusted in the future.

Voyager offers a highly competitive total compensation package designed to support the well-being, growth, and success of our employees. Employees benefit from a flexible and comprehensive rewards program that supports both professional and personal well-being.  

  • Flexible Time Off (FTO), empowering employees to take the time they need to recharge and maintain a healthy work-life balance
  • Comprehensive medical, dental, and vision coverage for employees and their families, with a significant portion of premiums covered by the company and many benefits paid at 100% for employees
  • Flexible, affordable gym memberships with 12,700+ options nationwide, including 24 Hour Fitness, EoS Fitness, Crunch Fitness, Anytime Fitness, Blink Fitness, Chuze Fitness, and more! No long-term contracts and FREE on-demand workout videos before you enroll
  • 401(k) retirement plan with a 50% company match on contributions up to 8%, supporting long-term financial security
  • Company wellness programs that support physical and mental well-being
  • Additional voluntary benefits and employee support resources
  • The opportunity to work alongside a highly talented team in an innovative, mission-driven environment

Voyager is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, national or ethnic origin, sex, sexual orientation, gender identity or expression, age, disability, protected veteran status, or other characteristics protected by law. 

To conform to U.S. Government export regulations, including the International Traffic in Arms Regulations (ITAR) (22 CFR Parts 120-130) and the Export Administration Regulations (EAR) (15 CFR Parts 730-774), applicants for this position must be a U.S. Person: a US Citizen, a lawful permanent resident of the U.S., or a protected individual as defined by 8 U.S.C. 1324b(a)(3). Applicants must be eligible to obtain any required export authorizations from the U.S. Department of State or the U.S. Department of Commerce. 

Minority/Female/Disabled/Veteran 

The statements contained in this job description are intended to describe the general content and requirements for performance of this job. It is not intended to be an exhaustive list of all job duties, responsibilities, and requirements. This job description is not an employment agreement or contract. Management has the exclusive right to alter the scope of work within the framework of this job description at any time without prior notice.Â