1

Grc Risk Analyst Jobs in Minnesota (NOW HIRING)

Job Title - Information Security Analyst Duration - 3 Months (with a possibility of an extension ... 27000, risk assessment methodologies, Shared Assessments, ITIL practices, and GRC Demonstrate ...

... data analytics, and continuity skills where needed. Our ERAS practice is a group of highly ... Basic Understanding of SAP security and GRC (governance,riskand compliance) * Proven experience ...

Job Title - Information Security Analyst Duration - 3 Months (with a possibility of an extension ... 27000, risk assessment methodologies, Shared Assessments, ITIL practices, and GRC Demonstrate ...

IT Internal Audit Senior

Saint Paul, MN · On-site

$95.10K - $124.90K/yr

Draft IT audit reports with clear findings, root cause analysis, risk ratings, and practical ... Proficiency with audit/GRC tools (e.g., AuditBoard) and Microsoft Office Suite. * Strong analytical ...

next page

Showing results 1-20

Grc Risk Analyst information

What are the key skills and qualifications needed to thrive as a GRC Risk Analyst, and why are they important?

To thrive as a GRC (Governance, Risk, and Compliance) Risk Analyst, you need a solid understanding of risk management principles, regulatory requirements, and compliance frameworks, often supported by a degree in information security, business, or a related field. Familiarity with GRC platforms (such as RSA Archer or MetricStream), risk assessment methodologies, and certifications like CRISC or CISA is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and convey findings to stakeholders. These skills are critical for ensuring organizational compliance, minimizing risk exposure, and supporting informed decision-making.

What are some common challenges a GRC Risk Analyst might face when implementing new risk management frameworks within an organization?

A GRC Risk Analyst often encounters challenges such as resistance to change from stakeholders, integrating new frameworks with existing processes, and ensuring consistent understanding across departments. Aligning risk management practices with organizational goals while adhering to regulatory requirements can also be complex. Success in this role requires strong communication skills, adaptability, and the ability to educate and collaborate with team members from diverse backgrounds.

What are GRC Risk Analysts?

GRC Risk Analysts are professionals who specialize in Governance, Risk, and Compliance (GRC) within an organization. They assess and manage risks related to business operations, ensure compliance with relevant laws and regulations, and help implement policies and controls to mitigate potential threats. These analysts work closely with management to identify vulnerabilities, develop risk management strategies, and monitor the effectiveness of compliance programs. Their goal is to protect the organization from financial, legal, and reputational harm while supporting business objectives.

What is the difference between Grc Risk Analyst vs Compliance Analyst?

AspectGrc Risk AnalystCompliance Analyst
CertificationsISO 31000, FRM, CRISCISO 19600, CCEP, CISA
Work EnvironmentRisk management teams, corporate officesRegulatory departments, corporate offices
Industry UsageFinance, banking, insurance, corporate riskFinancial services, healthcare, manufacturing
Job FocusIdentifying, assessing, and mitigating risks across enterpriseEnsuring compliance with laws and regulations

While both roles involve regulatory and risk considerations, a Grc Risk Analyst focuses on enterprise-wide risk management strategies, whereas a Compliance Analyst concentrates on adherence to specific laws and regulations. Both roles require similar certifications and often work in overlapping industries, but their core responsibilities differ in scope and focus.

What cities in Minnesota are hiring for Grc Risk Analyst jobs? Cities in Minnesota with the most Grc Risk Analyst job openings:
Infographic showing various Grc Risk Analyst job openings in Minnesota as of May 2026, with employment types broken down into 1% Internship, 3% As Needed, 69% Full Time, and 27% Part Time. Highlights an 76% Physical, and 24% Remote job distribution.

Security Manager - IT Risk & PCI

Pattersoncompanies

Saint Paul, MN • On-site

Full-time

Medical, Dental, Vision, Retirement, PTO

Posted 11 days ago


Job description

Patterson isn't just a place to work, it's a partner that cares about your success.

One of the distinguishing marks of our company is the talented people who embrace the people-first, always advancing, and results-driven culture. Professional growth abounds in this motivating environment. We value the diverse talents and experiences our employees bring to Patterson and believe that they build a stronger and successful organization.

As the Security Manager - IT Risk & PCI Compliance you will lead a team and provide hands-on leadership and strategic execution across the organization's information security compliance and risk programs. This essential role is responsible for driving consistent, scalable execution of regulatory and assurance activities with a primary focus on PCI DSS, merchant and payment product security, policy and control governance, and audit readiness.

This position partners closely with the Security Program Director, broader security team, Technology, Finance, Legal, Regulatory Compliance, Internal Audit, and business stakeholders to translate regulatory and controls requirements into operational processes that support the business while protecting sensitive information. The Manager plays a critical role in ensuring compliance programs are sustainable, well-documented, and integrated into day-to-day operations.

Essential Functions

To perform this job successfully, an employee must be able to perform each essential function satisfactorily, with or without reasonable accommodation. To request a reasonable accommodation, notify Human Resources or the manager who oversees the position.

  • Manage and lead execution of the PCI DSS compliance program, including annual scoping, assessments, remediation tracking, and ongoing compliance for Patterson business entities and payment environments.

  • Perform PCI security reviews for Patterson products and merchant-facing solutions, ensuring required controls are designed, implemented, and operating effectively (e.g. payment service providers, payment platforms and solutions, merchant services).

  • Serve as the primary point of coordination with external assessors, auditors, and payment stakeholders, including support for merchant auditing and payment-related compliance activities.

  • Own and maintain security policies, standards, and procedures, ensuring alignment with PCI DSS, NIST CSF, ISO, SOX ITGC, and applicable regulatory requirements.

  • Translate regulatory, audit, and product security requirements into operational controls and workflows, partnering with Technology and business teams to embed compliance into system design and operations.

  • Ensure audit readiness and evidence integrity by maintaining clear documentation, control ownership, and tracking within GRC tooling (e.g., Vanta, ServiceNow), and driving remediation through closure.

  • Accountable for setting goals, performance development, source developmental opportunities and provide long-term career guidance to team members

  • Support hiring, onboarding, and development of team members as the program scales, including delegation of execution-focused work.

Additional functions

In addition to the essential functions listed above, the incumbent may perform the following additional functions.

  • Provide day-to-day leadership, guidance, and mentoring to analysts and contract resources supporting compliance and audit activities.

  • Contribute to cross-functional risk management activities, including issue tracking, risk acceptance support, and alignment with enterprise risk processes.

  • Support third-party security and vendor risk activities related to PCI-relevant vendors and payment partners.

  • Develop and deliver compliance metrics, status reporting, and audit-readiness views for leadership and executive stakeholders.

Required Qualifications

  • Bachelor'sor Master'sDegree with an emphasis in security, technology, or engineering or equivalent work experience

  • At least6yearswork experience in information technology, cyber security, or information security

  • At least3years of experience coaching, mentoring, and developing a team of people as a manager of people

  • Demonstrated experience owning information security compliance programs including supporting policies, standards, and procedures, to execute, maintain, and align controls to organizational needs and frameworks

  • Demonstrated continuous improvement mindset, with experience designing and evolving security, compliance, and audit workflows, including leveraging GRC platforms (e.g., Vanta) to build and maintain scalable controls

Preferred Qualifications

  • PCI Internal Security Assessor (ISA) (strongly preferred)

  • CISSP (preferred)

What's In It For You:

We provide competitive benefits, unique incentive programs and rewards for our eligible employees:

  • Full Medical, Dental, and Vision benefits and an integrated Wellness Program

  • 401(k) Match Retirement Savings Plan

  • Paid Time Off (PTO)

  • Holiday Pay & Floating Holidays

  • Volunteer Time Off (VTO)

  • Educational Assistance Program

  • Full Paid Parental and Adoption Leave

  • LifeWorks (Employee Assistance Program)

  • Patterson Perks Program

The potential compensation range for this role is below. The final offer amount could exceed this range, based on various factors such as candidate location (geographical labor market), experience, and skills.

$109,100.00 - $145,433.33EEO Statement

Patterson provides equal employment opportunities to applicants and employees without regard to race; color; sex; gender identity; sexual orientation; religious practices and observances; national origin; pregnancy, childbirth, or other related medical conditions; status as a protected veteran or spouse/family member of a protected veteran; or disability.