1

Grc Risk Analyst Jobs in New York (NOW HIRING)

Perform and document risk and control assessments for systems, applications, vendors, projects, and business processes. * Identify control gaps, document findings, and support risk treatment planning ...

Helping design automated key risk indicator (KRI) and key performance indicator (KPI) reporting to ... Strong problem-solving and analytical skills to proactively identify repeatable day-to-day ...

Helping design automated key risk indicator (KRI) and key performance indicator (KPI) reporting to ... Strong problem-solving and analytical skills to proactively identify repeatable day-to-day ...

Helping design automated key risk indicator (KRI) and key performance indicator (KPI) reporting to ... Strong problem-solving and analytical skills to proactively identify repeatable day-to-day ...

GRC Analyst

New York, NY · On-site

$150K - $200K/yr

The Role Rogo is hiring a GRC Analyst to support our customer trust, security assurance, and ... Experience working with security questionnaires, audits, or third-party risk assessments.

Support risk and control assessments by providing technical analysis, control evidence and ... Familiarity with GRC platforms, compliance automation tools, ticketing systems or control ...

GRC Lead

New York, NY · On-site

$232K - $273K/yr

Your peer, the AI GRC Engineer, builds the platform underneath - the evidence pipelines and agents ... Chain Risk Lead. * Own the BCDR program: business impact analysis, recovery objectives with ...

Partnering with program owners, cyber/risk stakeholders, legal/compliance teams, and platform ... Mentor engineers and analysts through architecture standards, implementation playbooks, and design ...

Showing results 41-60

Grc Risk Analyst information

What is the difference between Grc Risk Analyst vs Compliance Analyst?

AspectGrc Risk AnalystCompliance Analyst
CertificationsISO 31000, FRM, CRISCISO 19600, CCEP, CISA
Work EnvironmentRisk management teams, corporate officesRegulatory departments, corporate offices
Industry UsageFinance, banking, insurance, corporate riskFinancial services, healthcare, manufacturing
Job FocusIdentifying, assessing, and mitigating risks across enterpriseEnsuring compliance with laws and regulations

While both roles involve regulatory and risk considerations, a Grc Risk Analyst focuses on enterprise-wide risk management strategies, whereas a Compliance Analyst concentrates on adherence to specific laws and regulations. Both roles require similar certifications and often work in overlapping industries, but their core responsibilities differ in scope and focus.

What is a GRC Risk Analyst?

GRC Risk Analysts are professionals who specialize in Governance, Risk, and Compliance (GRC) within an organization. They assess and manage risks related to business operations, ensure compliance with relevant laws and regulations, and help implement policies and controls to mitigate potential threats. These analysts work closely with management to identify vulnerabilities, develop risk management strategies, and monitor the effectiveness of compliance programs. Their goal is to protect the organization from financial, legal, and reputational harm while supporting business objectives.

What are the key skills and qualifications needed to thrive as a GRC Risk Analyst?

To thrive as a GRC (Governance, Risk, and Compliance) Risk Analyst, you need a solid understanding of risk management principles, regulatory requirements, and compliance frameworks, often supported by a degree in information security, business, or a related field. Familiarity with GRC platforms (such as RSA Archer or MetricStream), risk assessment methodologies, and certifications like CRISC or CISA is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and convey findings to stakeholders. These skills are critical for ensuring organizational compliance, minimizing risk exposure, and supporting informed decision-making.

What are some common challenges a GRC Risk Analyst might face when implementing new risk management frameworks within an organization?

A GRC Risk Analyst often encounters challenges such as resistance to change from stakeholders, integrating new frameworks with existing processes, and ensuring consistent understanding across departments. Aligning risk management practices with organizational goals while adhering to regulatory requirements can also be complex. Success in this role requires strong communication skills, adaptability, and the ability to educate and collaborate with team members from diverse backgrounds.
What job categories do people searching Grc Risk Analyst jobs in New York look for? The top searched job categories for Grc Risk Analyst jobs in New York are:
Infographic showing various Grc Risk Analyst job openings in New York as of August 2026, with employment types broken down into 67% Full Time, and 33% Contract. Highlights an 67% In-person, and 33% Hybrid job distribution.

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Re-posted 9 days ago


Job description

Requisition: 82464
PSEG Company: PSEG Long Island
Salary Range: $ 93,600 - $ 148,200
Work Location Category: Hybrid Fixed
We're one of the country's largest energy companies, with a vision of powering a future where people use energy more efficiently and it's safer and delivered more reliably than ever. We're also deeply connected to the communities we serve, with more than 13,000 employees working together to support our customers and make a difference every day.
Here, you'll have the stability and exciting opportunities that come with being a Fortune 500 company - along with a supportive, friendly work environment where your contributions are valued. We know life isn't one-size-fits-all, and neither is work. That's why we offer flexible work options depending on the role.
In support of this model, roles have been categorized into one of three work location categories:
1. Onsite - roles where employees are expected to be onsite daily.
2. Hybrid fixed - roles that are a mix of remote work and onsite work fixed days each week.
3. Hybrid flexible - roles that are a mix of remote work and onsite work, but the onsite requirements have greater flexibility. (i.e. 5-8 days a month vs. set days each week).
As an employee, if you are regularly scheduled to work 20 or more hours per week, you will have access to a wide range of comprehensive benefits designed to support your total well-being: medical, dental, vision, paternal leave and family leave programs, behavioral health programs, 401(k) with company match, life insurance, tuition reimbursement, and generous paid time off.
More than 13,000 people already call PSEG their work home, taking pride in providing safe, reliable service to millions of customers. If you're looking for a place where you can build a meaningful career and help power and support our communities, we'd love to welcome you to the team.
PSEG is not offering visa sponsorship for this position.
Job Summary
This position supports the organization's cybersecurity governance, risk, and compliance program through governance oversight, policy lifecycle management, standards alignment, risk and control assessments, audit coordination, compliance validation, issue remediation tracking, third-party risk review, and executive reporting and documentation.
The Cybersecurity GRC Analyst works closely with IT, Internal Audit, Compliance, Procurement, and business stakeholders to help ensure cybersecurity requirements are defined, documented, assessed, and monitored across the enterprise. This role is responsible for supporting the maintenance of cybersecurity policies and standards, conducting and documenting risk assessments, evaluating control effectiveness, coordinating audit and compliance activities, tracking remediation efforts, and preparing clear reporting for management and leadership.
Job Responsibilities
  • Support governance oversight activities for the cybersecurity program across the enterprise.
  • Maintain and support policy lifecycle management, including the review, update, and communication of cybersecurity policies, standards, procedures, and related documentation.
  • Assist with standards alignment to applicable requirements, contractual obligations, and recognized cybersecurity frameworks.
  • Perform and document risk and control assessments for systems, applications, vendors, projects, and business processes.
  • Identify control gaps, document findings, and support risk treatment planning with business and technical stakeholders.
  • Assist with control documentation and control testing to evaluate design and operating effectiveness.
  • Provide audit coordination support for internal audits, external audits, and regulatory assessments, including evidence gathering, response tracking, and issue follow-up.
  • Support compliance validation activities to confirm required controls, processes, and documentation are in place and operating as intended.
  • Support third-party risk review activities, including security questionnaires, documentation review, assessment follow-up, and findings management.
  • Maintain risk registers, issue logs, exception records, remediation plans, and supporting documentation.
  • Perform issue remediation tracking and follow up with stakeholders to support timely closure of findings, gaps, and action items.
  • Prepare executive reporting and documentation related to risk posture, compliance status, audit results, remediation progress, control maturity, and key metrics.
  • Support governance committees, risk discussions, and management reporting through accurate and organized documentation.
  • Contribute to continuous improvement of GRC processes, templates, reporting, and governance practices.

Job Specific Qualifications
  • Bachelors degree in Cybersecurity, Information Systems, Computer Science, Business, Risk Management or related discipline.
  • With four (4) or more years of experience in cybersecurity governance, risk, compliance, IT audit, internal controls, or related field.
  • Candidates without a degree who have 8 years of experience in cyber security governance risk and compliance will be considered.
  • Proficiency with Cyber GRC technologies (such as ServiceNow, Archer, RSAM, etc.)
  • Background supporting governance oversight, policy lifecycle management, and standards alignment activities.
  • Track record performing risk and control assessments and documenting findings, recommendations, and remediation actions.
  • History of supporting control testing, audit coordination, and compliance validation activities.
  • Direct involvement with third-party risk review, vendor assessment support, or related due diligence functions.
  • Familiarity with issue remediation tracking, exception management, and reporting processes.
  • Advanced analytical, organizational, reporting, and documentation skills.
  • Excellent written and verbal communication skills with the ability to work effectively with technical and non-technical stakeholders.
  • Ability to manage multiple priorities, maintain detailed records, and work independently with limited supervision.
  • Department of Energy's regulation 10 CFR 810 is required

Desired
  • Working knowledge of cybersecurity frameworks and control standards such as NIST CSF, NIST SP 800-53, ISO 27001, and CIS Controls.
  • Cybersecurity certification such as Security+, CISSP, CISA

Please Note the Following:
  • This position falls under the North American Electric Reliability Corporation (NERC) Critical Infrastructure Protection (CIP) and requires NERC CIP background investigation prior to start.

Some positions at PSEG require access to information covered by the Department of Energy's regulation 10 CFR 810 (Part 810). If applicable, the successful applicant must prove they are: (1) a citizen or national of the USA; OR (2) a lawful permanent resident of the United States (Non-Conditional Permanent I-551 / Green Card / Permanent Resident Card holder); OR (3) a citizen, national, or permanent resident of a "Generally Authorized" destination on the attached list and not also a citizen, national, permanent resident of any country not listed; OR (4) a "Protected Individual" under the Immigration and Naturalization Act (8 U.S.C 1324b(a)(3)).
As an employee of PSEG Long Island, you should be aware that during storm/outage restoration efforts, you may be required to perform functions different from normal operations and work extended hours beyond your regular work schedule. You may also be required to work on premise or in an alternate location as directed by the company.
For all roles, PSEGLI's drug and alcohol testing program includes pre-employment testing, testing for cause, and post-incident/accident testing.
Employees who are hired or transfer into a federally regulated role (including positions covered by USDOT, PHMSA, or NRC regulations) are subject to random drug and alcohol testing, inclusive of marijuana. Although numerous states throughout the country have legalized marijuana/cannabis products recreationally and medically, the use of these products are prohibited for employees in federally regulated roles. Please note that the use of CBD products may result in a positive drug test for THC/Marijuana and such use is not a legitimate medical explanation for a positive result.
If you are a current PSEG employee and offered an opportunity with PSEG Long Island, you will be treated as a new hire. Please note that as a new hire to the Long Island subsidiary, your benefits will change and generally will be consistent with other similarly situated PSEG Long Island new hires. Similarly, for PSEG Long Island employees who accept job opportunities with PSEG or any of its subsidiaries (other than PSEG Long Island), their benefits will change and generally be consistent with other similarly situated new hires of that company.
PSEGLI is an equal opportunity employer, dedicated to a policy of non-discrimination in employment, including the hiring process, based on any legally protected characteristic. Legally protected characteristics include race, color, religion, national origin, sex, age, marital status, sexual orientation, disability or veteran status or any other characteristic protected by federal, state, or local law in locations where PSEG employs individuals.
PSEGLI is committed to providing reasonable accommodations to individuals with disabilities. If you have a disability and need assistance applying for a position, please call 973-430-3845 or email accommodations@pseg.com.
If you need to request a reasonable accommodation to perform the essential functions of the job, email accommodations@pseg.com. Any information provided regarding a disability will be kept strictly confidential and will not be shared with anyone involved in making a hiring decision.
ADDITIONAL EEO INFORMATION (Click link below)
Know your Rights: Workplace Discrimination is Illegal