1

Grc Risk Analyst Jobs in Washington (NOW HIRING)

The Principal Governance, Risk, & Compliance (GRC) Analyst is an Individual contributor (IC) role that reports to the Manager of GRC. This role is within the team responsible for implementing and ...

Sr GRC Analyst

Herndon, VA · Remote

$98.70K - $129.10K/yr

26-May-2026 Senior GRC Engineering Analyst US (Remote) 10880BR Company Summary Built on 40 years of ... Identify control gaps, assess technical risk and business impact, and drive remediation to closure ...

next page

Showing results 1-20

Grc Risk Analyst information

What are the key skills and qualifications needed to thrive as a GRC Risk Analyst, and why are they important?

To thrive as a GRC (Governance, Risk, and Compliance) Risk Analyst, you need a solid understanding of risk management principles, regulatory requirements, and compliance frameworks, often supported by a degree in information security, business, or a related field. Familiarity with GRC platforms (such as RSA Archer or MetricStream), risk assessment methodologies, and certifications like CRISC or CISA is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and convey findings to stakeholders. These skills are critical for ensuring organizational compliance, minimizing risk exposure, and supporting informed decision-making.

What are some common challenges a GRC Risk Analyst might face when implementing new risk management frameworks within an organization?

A GRC Risk Analyst often encounters challenges such as resistance to change from stakeholders, integrating new frameworks with existing processes, and ensuring consistent understanding across departments. Aligning risk management practices with organizational goals while adhering to regulatory requirements can also be complex. Success in this role requires strong communication skills, adaptability, and the ability to educate and collaborate with team members from diverse backgrounds.

What are GRC Risk Analysts?

GRC Risk Analysts are professionals who specialize in Governance, Risk, and Compliance (GRC) within an organization. They assess and manage risks related to business operations, ensure compliance with relevant laws and regulations, and help implement policies and controls to mitigate potential threats. These analysts work closely with management to identify vulnerabilities, develop risk management strategies, and monitor the effectiveness of compliance programs. Their goal is to protect the organization from financial, legal, and reputational harm while supporting business objectives.

What is the difference between Grc Risk Analyst vs Compliance Analyst?

AspectGrc Risk AnalystCompliance Analyst
CertificationsISO 31000, FRM, CRISCISO 19600, CCEP, CISA
Work EnvironmentRisk management teams, corporate officesRegulatory departments, corporate offices
Industry UsageFinance, banking, insurance, corporate riskFinancial services, healthcare, manufacturing
Job FocusIdentifying, assessing, and mitigating risks across enterpriseEnsuring compliance with laws and regulations

While both roles involve regulatory and risk considerations, a Grc Risk Analyst focuses on enterprise-wide risk management strategies, whereas a Compliance Analyst concentrates on adherence to specific laws and regulations. Both roles require similar certifications and often work in overlapping industries, but their core responsibilities differ in scope and focus.

What job categories do people searching Grc Risk Analyst jobs in Washington look for? The top searched job categories for Grc Risk Analyst jobs in Washington are:
What cities in Washington are hiring for Grc Risk Analyst jobs? Cities in Washington with the most Grc Risk Analyst job openings:
Infographic showing various Grc Risk Analyst job openings in Washington as of May 2026, with employment types broken down into 1% Internship, 3% As Needed, 68% Full Time, and 28% Part Time. Highlights an 76% Physical, and 24% Remote job distribution.
Governance, Risk, and Compliance (GRC) Analyst

Governance, Risk, and Compliance (GRC) Analyst

EdgeConneX

Herndon, VA

Other

Posted 4 days ago


Job description

We are seeking a highly motivated and experienced Governance, Risk, and Compliance (GRC) Analyst to join our team. The ideal candidate will have at least five years of experience in GRC or IT risk, a bachelor's degree or higher in a related field, and professional certifications in GRC or cybersecurity. As a GRC Analyst, you will play a pivotal role in ensuring our organization adheres to regulatory requirements, manage risks effectively, and maintain robust governance practices for industry standards, frameworks and international data protection law.

Responsibilities:

  • Develop, implement, and maintain governance, risk, and compliance frameworks, policies, standards and procedures.
  • Conduct risk assessments and analyze potential threats to the organization's information systems and business operations.
  • Monitor compliance with internal policies and external regulatory requirements (e.g., NIS2, DORA, ISO27001, AICPA Trust Principles, NIST, CIS, GDPR, SOX, HIPAA).
  • Track changes to regional data protection law in the regions where EdgeConneX operates (APAC, EU, North America and South America)
  • Collaborate with cross-functional teams to identify, assess, and mitigate risks across the organization.
  • Maintain risk registers, compliance metrics, and reporting dashboards
  • Support third-party risk management and vendor security assessments
  • Prepare and present regular reports on risk management activities, compliance status, and remediation efforts to management.
  • Support internal and external audits, including gathering documentation and facilitating audit processes.
  • Stay up to date with changes in relevant laws, regulations, and industry best practices.
  • Assist in the development and delivery of training programs related to governance, risk, and compliance topics.
  • Contribute to continuous improvement of GRC processes and tooling

Required education & experience:

  • Bachelor's degree or higher in Information Security, Computer Science, Business Administration, or a related field.
  • Minimum of 5 years of professional experience in governance, risk, and compliance or a related discipline.
  • Professional certifications such as CISA, CRISC, CISSP, CISM, ISO27001LA or similar are required.
  • Strong understanding of regulatory requirements and frameworks (e.g., ISO 27001, NIST, PCI DSS).
  • Risk assessment methodologies and control testing
  • Excellent analytical and problem-solving skills.
  • Strong communication and interpersonal skills, with the ability to work collaboratively across departments.
  • Experience with:
    • Policy development and lifecycle management
    • Third-party/vendor risk assessments
    • GRC tools and risk management platforms (e.g., DRATA, VANTA, Archer, OneTrust)
  • Detail-oriented and highly organized, with a proactive approach to identifying and managing risks.

Preferred experience:

  • Experience with GRC software platforms and tools.
  • Project management experience or certification.
  • Experience in a regulated industry (e.g., datacenter, finance, technology).
  • Ability to train and mentor junior staff.