1

Grc Risk Analyst Jobs in Boston, MA (NOW HIRING)

We are seeking a Senior Security Compliance Analyst with expertise in Governance, Risk, and Compliance (GRC) to support and enhance our security and compliance programs within the healthcare industry.

Lead Security Engineer, GRC

Boston, MA · On-site

$166K - $253K/yr

Experience with continuous control monitoring or GRC platforms (Vanta, Drata, Hyperproof, OneTrust ... This third-party service provider provides risk-intelligence services that may include analysis of ...

... GRC) platforms, preferably Archer. * Understanding of business process mapping, risk identification, control documentation, and issue management. * Strong analytical and problem-solving capabilities ...

Damco Solutions is seeking a Cyber Security Analyst to join their team in Woburn, MA. The role ... GRC (Governance Risk Compliance) tools • Working knowledge of security controls on server ...

... Risk and Compliance (GRC) Team. The Information Security- GRC team is responsible for oversight and ... As a Data Protection Sr. Analyst, you will partner cross-functionally to design, implement, and ...

VMCA Analyst

Boston, MA · On-site

$57 - $62/hr

Ability to analyze large datasets to identify trends, anomalies, and risk concentrations, and to ... as SIEM, GRC, and ticketing systems to support governance and operational workflows.

Cyber Product Analyst

Quincy, MA · On-site

$120K - $202K/yr

The position requires collaboration with risk, compliance, and technology teams to deliver secure ... GRC * Exceptional communication, strategic thinking, and change management skills. * Preferred ...

Support preparation of compliance metrics and reporting for the Governance, Risk, and Compliance (GRC) Committee and senior leadership. * Utilize analytics and reporting tools to identify trends ...

... GRC Access Control for SoD analysis, simulation, remediation, and reporting. • Strong understanding of SoD rule design and risk mitigation strategies during ECC to S/4HANA transitions. • 10+ ...

... data analytics, and continuity skills where needed. Our ERAS practice is a group of highly ... Basic Understanding of SAP security and GRC (governance,riskand compliance) * Proven experience ...

Showing results 41-60

Grc Risk Analyst information

See Boston, MA salary details

$16

$43

$71

How much do grc risk analyst jobs pay per hour?

As of Sep 7, 2026, the average hourly pay for grc risk analyst in Boston, MA is $43.98, according to ZipRecruiter salary data. Most workers in this role earn between $32.40 and $53.56 per hour, depending on experience, location, and employer.

What is a GRC Risk Analyst?

GRC Risk Analysts are professionals who specialize in Governance, Risk, and Compliance (GRC) within an organization. They assess and manage risks related to business operations, ensure compliance with relevant laws and regulations, and help implement policies and controls to mitigate potential threats. These analysts work closely with management to identify vulnerabilities, develop risk management strategies, and monitor the effectiveness of compliance programs. Their goal is to protect the organization from financial, legal, and reputational harm while supporting business objectives.

What are the key skills and qualifications needed to thrive as a GRC Risk Analyst?

To thrive as a GRC (Governance, Risk, and Compliance) Risk Analyst, you need a solid understanding of risk management principles, regulatory requirements, and compliance frameworks, often supported by a degree in information security, business, or a related field. Familiarity with GRC platforms (such as RSA Archer or MetricStream), risk assessment methodologies, and certifications like CRISC or CISA is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and convey findings to stakeholders. These skills are critical for ensuring organizational compliance, minimizing risk exposure, and supporting informed decision-making.

What are some common challenges a GRC Risk Analyst might face when implementing new risk management frameworks within an organization?

A GRC Risk Analyst often encounters challenges such as resistance to change from stakeholders, integrating new frameworks with existing processes, and ensuring consistent understanding across departments. Aligning risk management practices with organizational goals while adhering to regulatory requirements can also be complex. Success in this role requires strong communication skills, adaptability, and the ability to educate and collaborate with team members from diverse backgrounds.

What is the difference between Grc Risk Analyst vs Compliance Analyst?

AspectGrc Risk AnalystCompliance Analyst
CertificationsISO 31000, FRM, CRISCISO 19600, CCEP, CISA
Work EnvironmentRisk management teams, corporate officesRegulatory departments, corporate offices
Industry UsageFinance, banking, insurance, corporate riskFinancial services, healthcare, manufacturing
Job FocusIdentifying, assessing, and mitigating risks across enterpriseEnsuring compliance with laws and regulations

While both roles involve regulatory and risk considerations, a Grc Risk Analyst focuses on enterprise-wide risk management strategies, whereas a Compliance Analyst concentrates on adherence to specific laws and regulations. Both roles require similar certifications and often work in overlapping industries, but their core responsibilities differ in scope and focus.

What job categories do people searching Grc Risk Analyst jobs in Boston, MA look for?

The top searched job categories for Grc Risk Analyst jobs in Boston, MA are:

What cities near Boston, MA are hiring for Grc Risk Analyst jobs?

Cities near Boston, MA with the most Grc Risk Analyst job openings:

Information Security Analyst (GRC & Microsoft 365 Security)

Samsung HME America Inc

Danvers, MA • On-site

$100K - $125K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 9 days ago


Job description

Information Security Analyst (GRC & Microsoft 365 Security)

  • Location:  On-site in Danvers, MA

Who We Are

Samsung HME America (Healthcare and Medical Equipment) is Samsung’s U.S. medical imaging organization, delivering advanced diagnostic solutions across Ultrasound, Digital Radiography, and Computed Tomography. We lead nationwide sales, marketing, service, and distribution of Samsung’s imaging technologies, partnering with healthcare providers to strengthen diagnostic capabilities, streamline clinical workflows, and support better patient care. Samsung HME America also serves as the global manufacturing center for Samsung’s mobile Computed Tomography (mCT) business, leading the development of advanced CT systems used by healthcare providers worldwide.

Backed by Samsung Electronics’ global technology leadership, our teams work closely with clinicians to translate real-world challenges into innovative imaging solutions. Our culture combines a sense of urgency, customer focus, and clinical collaboration to advance the future of medical imaging.

Role Description

We are seeking a junior-to-mid level Information Security Analyst to support and own key elements of our information security and compliance program, with a strong emphasis on ISO 27001 and CMMC frameworks. This role focuses on policy creation, documentation, and audit readiness while supporting operational security across Microsoft 365, DLP, and incident response.
 
 The analyst will work closely with IT and Compliance to maintain a strong security posture and will play a key role in driving compliance initiatives, managing documentation, and coordinating security processes. This role requires a hands-on approach, including participation in help desk support and day-to-day IT security operations.

Key duties and responsibilities, other duties may be assigned:


Compliance Ownership & Governance (ISO 27001 / CMMC):
  • Own and maintain ISO 27001 and CMMC compliance programs
  • Manage evidence, remediation tracking, and audit readiness
  • Perform gap assessments and risk analyses

Policy Development & Documentation

  • Develop and maintain security policies, procedures, and runbooks
  • Ensure documentation is audit-ready and version controlled

DLP & Microsoft 365 Security

  • Configure and manage DLP policies across Microsoft 365
  • Support Microsoft Purview and identity security controls

Security Operations & SIEM:

  • Monitor alerts using SIEM tools
  • Support incident response and tabletop exercises 

AI Policy & Usage:

  • Support the development and maintenance of an Acceptable AI Usage Policy
  • Evaluate AI models and use cases to determine appropriate application across organizational roles
  • Support tracking, logging, and governance methodologies for AI usage

Disaster Recovery:

  • Support disaster recovery planning, documentation, and testing activities
  • Assist with tabletop exercises and post-test remediation tracking

IT Support:

    • Provide help desk support and security guidance to end users
    • Assist with day-to-day IT security operations and user education

Qualifications and Requirements: To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions.


Skills & Experience

  • 2–5 years of experience in IT or information security
  • Experience with ISO 27001 and/or CMMC
  • Strong documentation and policy writing skills
  • Familiarity with Microsoft 365 security
  • Understanding of DLP, incident response, and DR
  • Understanding of AI models and their use within an organization
  • Willingness to support help desk operations

Preferred Qualifications

  • Experience supporting ISO or CMMC audits
  • Familiarity with Microsoft Purview
  • Experience with SIEM tools (e.g., Microsoft Sentinel, Splunk)
  • Knowledge of NIST frameworks
  • Relevant certifications (Security+, SC-900, etc.)

Competencies

  • Strong documentation skills
  • Ownership and accountability
  • Attention to detail
  • Collaboration
  • Problem-solving
  • Customer service mindset

Physical Requirements

  • Occasionally lift and /or move up to 25 pounds
  • Frequently required to sit; use hands to finger, handle, or feel; reach with hands; and talk or hear
  • Must be able to sit for long periods of time 

Benefits

We offer a comprehensive benefit package which includes:

  • Medical (Blue Benefit Administrators): 5 PPO Plans (with up to 95% employer contribution)
  • Dental (Blue Cross Blue Shield): 2 PPO Plans (with up to 80% employer contribution)
  • Vision (Blue Cross Blue Shield): 100% company paid
  • Short/Long Term Disability, Life & AD&D (The Standard): 100% company paid
  • 401k Retirement (Fidelity): 100% company match up to 5%
  • Tax Deferred Health Care Savings Programs
  • Accident Insurance, Critical Illness, Hospital Indemnity, Pet, Legal, ID Theft 
  • Generous paid time off, tuition reimbursement, and more!

Inclusion and Diversity Statement: We are an Equal Opportunity Employer and value diversity at all levels of the organization. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, protected veteran status, or any other characteristic protected by applicable law. We are committed to providing reasonable accommodation to individuals with disabilities throughout the application and employment process. If you require assistance or accommodation, please contact Human Resources.