1

Grc Risk Analyst Jobs in Minnesota (NOW HIRING)

... GRC platforms) * Experience designing dashboards and developing self-service reporting using ... Strong analytical, problem-solving, and judgment skills in complex risk scenarios * Clear ...

... GRC platforms) * Experience designing dashboards and developing self-service reporting using ... Strong analytical, problem-solving, and judgment skills in complex risk scenarios * Clear ...

Job Title - Information Security Analyst Duration - 3 Months (with a possibility of an extension ... 27000, risk assessment methodologies, Shared Assessments, ITIL practices, and GRC Demonstrate ...

... data analytics, and continuity skills where needed. Our ERAS practice is a group of highly ... Basic Understanding of SAP security and GRC (governance,riskand compliance) * Proven experience ...

Job Title - Information Security Analyst Duration - 3 Months (with a possibility of an extension ... 27000, risk assessment methodologies, Shared Assessments, ITIL practices, and GRC Demonstrate ...

... Governance, Risk and Compliance (GRC) space of Client cyber security team as part of the ... Experience analyzing business requirements and translate them into technical solutions. * Ideal ...

next page

Showing results 1-20

Grc Risk Analyst information

What is the difference between Grc Risk Analyst vs Compliance Analyst?

AspectGrc Risk AnalystCompliance Analyst
CertificationsISO 31000, FRM, CRISCISO 19600, CCEP, CISA
Work EnvironmentRisk management teams, corporate officesRegulatory departments, corporate offices
Industry UsageFinance, banking, insurance, corporate riskFinancial services, healthcare, manufacturing
Job FocusIdentifying, assessing, and mitigating risks across enterpriseEnsuring compliance with laws and regulations

While both roles involve regulatory and risk considerations, a Grc Risk Analyst focuses on enterprise-wide risk management strategies, whereas a Compliance Analyst concentrates on adherence to specific laws and regulations. Both roles require similar certifications and often work in overlapping industries, but their core responsibilities differ in scope and focus.

What are GRC Risk Analysts?

GRC Risk Analysts are professionals who specialize in Governance, Risk, and Compliance (GRC) within an organization. They assess and manage risks related to business operations, ensure compliance with relevant laws and regulations, and help implement policies and controls to mitigate potential threats. These analysts work closely with management to identify vulnerabilities, develop risk management strategies, and monitor the effectiveness of compliance programs. Their goal is to protect the organization from financial, legal, and reputational harm while supporting business objectives.

What are the key skills and qualifications needed to thrive as a GRC Risk Analyst, and why are they important?

To thrive as a GRC (Governance, Risk, and Compliance) Risk Analyst, you need a solid understanding of risk management principles, regulatory requirements, and compliance frameworks, often supported by a degree in information security, business, or a related field. Familiarity with GRC platforms (such as RSA Archer or MetricStream), risk assessment methodologies, and certifications like CRISC or CISA is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and convey findings to stakeholders. These skills are critical for ensuring organizational compliance, minimizing risk exposure, and supporting informed decision-making.

What are some common challenges a GRC Risk Analyst might face when implementing new risk management frameworks within an organization?

A GRC Risk Analyst often encounters challenges such as resistance to change from stakeholders, integrating new frameworks with existing processes, and ensuring consistent understanding across departments. Aligning risk management practices with organizational goals while adhering to regulatory requirements can also be complex. Success in this role requires strong communication skills, adaptability, and the ability to educate and collaborate with team members from diverse backgrounds.
Infographic showing various Grc Risk Analyst job openings in Minnesota as of June 2026, with employment types broken down into 1% As Needed, 89% Full Time, 9% Part Time, and 1% Contract. Highlights an 76% Physical, 9% Hybrid, and 15% Remote job distribution.
Cyber - SAP Security and GRC Access & Process Control Consultant / Security Engineer II

Cyber - SAP Security and GRC Access & Process Control Consultant / Security Engineer II

Deloitte

Minneapolis, MN • On-site

Other

Posted 4 days ago


Deloitte rating

8.1

Company rating: 8.1 out of 10

Based on 86 frontline employees who took The Breakroom Quiz

58th of 139 rated financial services


Job description

SAP Security and GRC Access & Process Control Consultant / Security Engineer II

Our Deloitte Cyber team helps organizations address cybersecurity challenges while enabling business growth and resilience. As part of this team, you will support clients in navigating an evolving threat landscape through practical, scalable security solutions. In this role, you will focus on SAP security and access governance capabilities that help clients strengthen controls, manage risk, and support secure transformation.

Recruiting for this role ends on 12/31/2026.

Work you'll do

As a Security Engineer II on the Enterprise Security team, you will be responsible for supporting SAP security and GRC access control implementations, assessments, and optimization efforts.

  • Deliver SAP ECC and SAP S/4HANA security implementations and assessments across client environments.
  • Design, build, test, and deploy end-user and IT support roles for SAP S/4HANA, SAP Fiori, and SAP Business Technology Platform environments.
  • Configure and support SAP Governance, Risk, and Compliance Access Control capabilities, including Access Risk Analysis, Access Request Management, Emergency Access Management, and Business Role Management.
  • Analyze segregation of duties risks, support ruleset updates, and perform user- and role-level risk assessments in SAP GRC 12.0.
  • Develop security solutions for custom transactions, tables, programs, reporting, and analytics tools across complex, multi-country rollout programs.

A successful candidate would possess these skills:

  • Ability to work independently and collaborate as part of a team
  • Effective written and verbal communication skills
  • Meticulous attention to detail and quality of work product
  • Ability to build and sustain professional relationships
  • Ability to lead projects or workstreams
  • Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
  • Strong interpersonal skills and professional demeanor
  • Ability to meet deadlines
  • Ability to provide clear guidance to others

The team

Our Enterprise Security Offering helps embed security across digital transformation initiatives by securing the technical backbone of the organization while enabling business change. The team supports capabilities across security architecture, secure development and deployment, cyber cloud, application security, and security for emerging technologies and connected products.

Qualifications

Required:

  • Bachelor's degree
  • 3+ years of experience with SAP S/4HANA Security and SAP Governance, Risk, and Compliance Access Control
  • 3+ years of experience implementing security for SAP S/4HANA, SAP Fiori, and SAP Business Technology Platform, including requirements gathering, security design, and deployment
  • Experience delivering at least 2 full-cycle SAP S/4HANA security implementations
  • 2+ years of experience configuring and implementing SAP Governance, Risk, and Compliance Access Risk Analysis, Access Request Management, Emergency Access Management, and Business Role Management
  • 2+ years of experience building and updating segregation of duties rulesets and performing user- and role-level risk analysis in SAP Governance, Risk, and Compliance 12.0
  • Ability to travel 50%, on average, based on the work you do and the clients and industries/sectors you serve.
  • Limited immigration sponsorship may be available.

Preferred:

  • Experience in consulting or Big 4 environments
  • Professional certifications such as Certified Information Systems Security Professional, Certified Information Security Manager, or Certified Information Systems Auditor
  • Experience with SAP Identity and Access Governance
  • Experience with cloud security and cloud migration projects
  • Experience executing vulnerability management tools such as Onapsis
  • Experience preparing written deliverables and presenting information to stakeholders

The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $82,600 to $162,800.

You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.

Qualifications:

SAP Security and GRC Access & Process Control Consultant / Security Engineer II

Our Deloitte Cyber team helps organizations address cybersecurity challenges while enabling business growth and resilience. As part of this team, you will support clients in navigating an evolving threat landscape through practical, scalable security solutions. In this role, you will focus on SAP security and access governance capabilities that help clients strengthen controls, manage risk, and support secure transformation.

Recruiting for this role ends on 12/31/2026.

Work you'll do

As a Security Engineer II on the Enterprise Security team, you will be responsible for supporting SAP security and GRC access control implementations, assessments, and optimization efforts.

  • Deliver SAP ECC and SAP S/4HANA security implementations and assessments across client environments.
  • Design, build, test, and deploy end-user and IT support roles for SAP S/4HANA, SAP Fiori, and SAP Business Technology Platform environments.
  • Configure and support SAP Governance, Risk, and Compliance Access Control capabilities, including Access Risk Analysis, Access Request Management, Emergency Access Management, and Business Role Management.
  • Analyze segregation of duties risks, support ruleset updates, and perform user- and role-level risk assessments in SAP GRC 12.0.
  • Develop security solutions for custom transactions, tables, programs, reporting, and analytics tools across complex, multi-country rollout programs.

A successful candidate would possess these skills:

  • Ability to work independently and collaborate as part of a team
  • Effective written and verbal communication skills
  • Meticulous attention to detail and quality of work product
  • Ability to build and sustain professional relationships
  • Ability to lead projects or workstreams
  • Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
  • Strong interpersonal skills and professional demeanor
  • Ability to meet deadlines
  • Ability to provide clear guidance to others

The team

Our Enterprise Security Offering helps embed security across digital transformation initiatives by securing the technical backbone of the organization while enabling business change. The team supports capabilities across security architecture, secure development and deployment, cyber cloud, application security, and security for emerging technologies and connected products.

Qualifications

Required:

  • Bachelor's degree
  • 3+ years of experience with SAP S/4HANA Security and SAP Governance, Risk, and Compliance Access Control
  • 3+ years of experience implementing security for SAP S/4HANA, SAP Fiori, and SAP Business Technology Platform, including requirements gathering, security design, and deployment
  • Experience delivering at least 2 full-cycle SAP S/4HANA security implementations
  • 2+ years of experience configuring and implementing SAP Governance, Risk, and Compliance Access Risk Analysis, Access Request Management, Emergency Access Management, and Business Role Management
  • 2+ years of experience building and updating segregation of duties rulesets and performing user- and role-level risk analysis in SAP Governance, Risk, and Compliance 12.0
  • Ability to travel 50%, on average, based on the work you do and the clients and industries/sectors you serve.
  • Limited immigration sponsorship may be available.

Preferred:

  • Experience in consulting or Big 4 environments
  • Professional certifications such as Certified Information Systems Security Professional, Certified Information Security Manager, or Certified Information Systems Auditor
  • Experience with SAP Identity and Access Governance
  • Experience with cloud security and cloud migration projects
  • Experience executing vulnerability management tools such as Onapsis
  • Experience preparing written deliverables and presenting information to stakeholders

The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $82,600 to $162,800.

You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.

Education:Bachelor's DegreeEmployment Type:

What Deloitte employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom