1

Grc Risk Analyst Jobs in Boston, MA (NOW HIRING)

The Team The Analyst Governance, Risk, and Compliance, a member of the Information Security - Governance, Risk and Compliance (GRC) team, focuses on implementing and maintaining governance frameworks ...

IT Risk & Compliance Analyst

Andover, MA · On-site +1

$95K - $95K/yr

Scope of Position The IT Risk & Compliance Analyst, as part of the Information Security ... Experience utilizing GRC, audit management, risk management, ticketing, or evidence management ...

Lead Security Engineer, GRC

Boston, MA · On-site

$111K - $146K/yr

ABOUT THE TEAM Anduril's Security Engineering team is looking for a Governance, Risk, and ... analysis * Surface control drift and route findings to system owners with clear remediation and ...

... Security - Governance, Risk and Compliance (GRC) Team. The Information Security- GRC team is ... As a Data Protection Sr. Analyst, you will partner cross-functionally to design, implement, and ...

Showing results 21-40

Grc Risk Analyst information

See Boston, MA salary details

$16

$43

$71

How much do grc risk analyst jobs pay per hour?

As of Sep 7, 2026, the average hourly pay for grc risk analyst in Boston, MA is $43.98, according to ZipRecruiter salary data. Most workers in this role earn between $32.40 and $53.56 per hour, depending on experience, location, and employer.

What is a GRC Risk Analyst?

GRC Risk Analysts are professionals who specialize in Governance, Risk, and Compliance (GRC) within an organization. They assess and manage risks related to business operations, ensure compliance with relevant laws and regulations, and help implement policies and controls to mitigate potential threats. These analysts work closely with management to identify vulnerabilities, develop risk management strategies, and monitor the effectiveness of compliance programs. Their goal is to protect the organization from financial, legal, and reputational harm while supporting business objectives.

What are the key skills and qualifications needed to thrive as a GRC Risk Analyst?

To thrive as a GRC (Governance, Risk, and Compliance) Risk Analyst, you need a solid understanding of risk management principles, regulatory requirements, and compliance frameworks, often supported by a degree in information security, business, or a related field. Familiarity with GRC platforms (such as RSA Archer or MetricStream), risk assessment methodologies, and certifications like CRISC or CISA is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and convey findings to stakeholders. These skills are critical for ensuring organizational compliance, minimizing risk exposure, and supporting informed decision-making.

What are some common challenges a GRC Risk Analyst might face when implementing new risk management frameworks within an organization?

A GRC Risk Analyst often encounters challenges such as resistance to change from stakeholders, integrating new frameworks with existing processes, and ensuring consistent understanding across departments. Aligning risk management practices with organizational goals while adhering to regulatory requirements can also be complex. Success in this role requires strong communication skills, adaptability, and the ability to educate and collaborate with team members from diverse backgrounds.

What is the difference between Grc Risk Analyst vs Compliance Analyst?

AspectGrc Risk AnalystCompliance Analyst
CertificationsISO 31000, FRM, CRISCISO 19600, CCEP, CISA
Work EnvironmentRisk management teams, corporate officesRegulatory departments, corporate offices
Industry UsageFinance, banking, insurance, corporate riskFinancial services, healthcare, manufacturing
Job FocusIdentifying, assessing, and mitigating risks across enterpriseEnsuring compliance with laws and regulations

While both roles involve regulatory and risk considerations, a Grc Risk Analyst focuses on enterprise-wide risk management strategies, whereas a Compliance Analyst concentrates on adherence to specific laws and regulations. Both roles require similar certifications and often work in overlapping industries, but their core responsibilities differ in scope and focus.

What job categories do people searching Grc Risk Analyst jobs in Boston, MA look for?

The top searched job categories for Grc Risk Analyst jobs in Boston, MA are:

What cities near Boston, MA are hiring for Grc Risk Analyst jobs?

Cities near Boston, MA with the most Grc Risk Analyst job openings:

Full-time

Medical, Retirement, PTO

Posted 27 days ago


American Tower rating

7.4

Company rating: 7.4 out of 10

Based on 8 frontline employees who took The Breakroom Quiz

54th of 101 rated telecommunications companies


Job description

The Team

The Analyst Governance, Risk, and Compliance, a member of the Information Security - Governance, Risk and Compliance (GRC) team, focuses on implementing and maintaining governance frameworks, managing risk remediation activities, and ensuring adherence to regulatory and internal security standards. The incumbent oversees requirements gathering and documentation for the Identity and Access Management (IAM) implementation. The incumbent administers GRC related inquiries from cross-functional business teams. The incumbent assists in the oversight and maintenance of policy and standards.

American Tower is a global digital infrastructure company serving customers through tower sites and other real estate solutions that support connectivity and opportunity, focused on achieving our vision of Building a More Connected World. Our success is rooted in the potential of our people and the power of local teams at our offices and sites across 25 countries.
We are one of the largest global Real Estate Investment Trusts (REITs) and a publicly traded (NYSE:AMT), Fortune 500 Company headquartered in Boston, Massachusetts. The next decade will be an exciting time as we evolve our infrastructure to meet tomorrow's needs and position our people to elevate their impact, their potential, and our shared success. Come grow your career with us!
For more information about how American Tower is building a more connected world, visit americantower.com 
American Tower is proud to be an equal opportunity employer and will not discriminate against an applicant or employee based on age, sex, sexual orientation, gender identity, race, color, creed, religion, national origin or ancestry, citizenship, marital status, familial status, disability, military or veteran status, genetic information, pregnancy, reproductive decisions, or any other characteristic protected under applicable law.

American Tower is committed to fair and equitable compensation practices. Placement within the salary range is based on a variety of factors, including relevant experience, skills, certifications, job level, and location. For U.S.-based candidates only, please see the base salary range for this position listed below. This position is also eligible for annual bonus, and annual equity award and participation in the Employee Stock Purchase Plan (ESPP).  For candidates outside of the U.S., salary and benefits are based upon local market practice.

American Tower also offers a comprehensive benefits package, which includes healthcare coverage, a 401(k) savings plan, paid time off, company holidays, sick leave, parental leave, and access to an Employee Assistance Program focused on mental and financial wellness, please click here to learn more.

What You Need to Succeed

  • Bachelor's degree in Information Security, Cybersecurity, Risk Management, or equivalent work experience preferred.
  • Minimum 2 years of experience in Governance, Risk, and Compliance (GRC) or Information Security required.
  • Experience conducting requirements gathering sessions and documentation, including data analysis preferred.
  • Experience developing, documenting and maintaining access and security policies, processes, procedures, and standards preferred.
  • Strong organization, planning, and project management skills; ability to prioritize tasks for self and team to meet requirements and deadlines.
  • Ability to work with different functional groups and levels of employees to effectively and professionally achieve results.
  • Excellent written and verbal communication skills and ability to interact well with internal and external parties
  • Ability to work individually and in team settings with cross-functional teams
  • Strong computer skills, including Microsoft Office suite and Oracle.
  • Knowledge of access, security, and risk assessment methods and technologies
  • Knowledge of Information Security Standards (ISO 27001/27002, ITIL, etc.)
  • Knowledge of Data Privacy and Compliance Regulations (MA CMR 201, HIPPA, Red Flag, etc.)

What You Can Offer Us

  • Act as a liaison between IT and business units to support the development and implementation of governance policies, standards, frameworks, and tools that align with organizational objectives.    
  • Supports requirements gathering and documentation for InfoSec projects and programs, including proactively setting up and leading meetings to work through unclear requirements, workflows, and drive toward identification of solutions.     
  • Manages GRC ticket maintenance and provides guidance to stakeholders on GRC topics.    
  • Monitor and maintain risk remediation activities, ensuring compliance issues are addressed, risks are documented, and exceptions are tracked in accordance with established frameworks and standards.    
  • Provide guidance and training to stakeholders on governance, risk, and compliance topics to enhance awareness and improve adherence to processes.    
  • Engage constructively with business partners to address information security governance and compliance concerns, offering actionable recommendations for improvement.    
  • Assist with the development of security architecture and security policies, principles and standards    
  • Proactively research and stay up to date on the latest access security issues    
  • Other duties as assigned.    

What American Tower employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom