1

Grc Risk Analyst Jobs in Madison, WI (NOW HIRING)

This role assists with risk assessments, maintenance of the risk register, control evaluations ... The GRC Analyst I also supports emerging AI Governance initiatives by assisting with the ...

This role assists with risk assessments, maintenance of the risk register, control evaluations ... The GRC Analyst I also supports emerging AI Governance initiatives by assisting with the ...

Lead, AI Governance - Enablement

Madison, WI ยท On-site

$120 - $180/hr

... risk management, compliance, analytics, or relevant experience required. * Experience leading or mentoring others in a team or cross-functional setting required. * Experience working with GRC ...

New

Senior IT Security Analyst

Madison, WI ยท On-site

$90 - $115/hr

This Senior Analyst combines deep knowledge of cybersecurity frameworks with handsโ€‘on experience in governance, risk, and compliance (GRC) operations, and excels at clear communication and high ...

Posted today

Senior IT Security Analyst

Madison, WI ยท On-site +1

$90K - $115K/yr

This Senior Analyst combines deep knowledge of cybersecurity frameworks with hands-on experience in governance, risk, and compliance (GRC) operations, and excels at clear communication and high ...

Grc Risk Analyst information

See Madison, WI salary details

$15

$40

$66

How much do grc risk analyst jobs pay per hour?

As of Aug 21, 2026, the average hourly pay for grc risk analyst in Madison, WI is $40.79, according to ZipRecruiter salary data. Most workers in this role earn between $30.05 and $49.66 per hour, depending on experience, location, and employer.

What is a GRC Risk Analyst?

GRC Risk Analysts are professionals who specialize in Governance, Risk, and Compliance (GRC) within an organization. They assess and manage risks related to business operations, ensure compliance with relevant laws and regulations, and help implement policies and controls to mitigate potential threats. These analysts work closely with management to identify vulnerabilities, develop risk management strategies, and monitor the effectiveness of compliance programs. Their goal is to protect the organization from financial, legal, and reputational harm while supporting business objectives.

What are the key skills and qualifications needed to thrive as a GRC Risk Analyst?

To thrive as a GRC (Governance, Risk, and Compliance) Risk Analyst, you need a solid understanding of risk management principles, regulatory requirements, and compliance frameworks, often supported by a degree in information security, business, or a related field. Familiarity with GRC platforms (such as RSA Archer or MetricStream), risk assessment methodologies, and certifications like CRISC or CISA is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and convey findings to stakeholders. These skills are critical for ensuring organizational compliance, minimizing risk exposure, and supporting informed decision-making.

What are some common challenges a GRC Risk Analyst might face when implementing new risk management frameworks within an organization?

A GRC Risk Analyst often encounters challenges such as resistance to change from stakeholders, integrating new frameworks with existing processes, and ensuring consistent understanding across departments. Aligning risk management practices with organizational goals while adhering to regulatory requirements can also be complex. Success in this role requires strong communication skills, adaptability, and the ability to educate and collaborate with team members from diverse backgrounds.

What is the difference between Grc Risk Analyst vs Compliance Analyst?

AspectGrc Risk AnalystCompliance Analyst
CertificationsISO 31000, FRM, CRISCISO 19600, CCEP, CISA
Work EnvironmentRisk management teams, corporate officesRegulatory departments, corporate offices
Industry UsageFinance, banking, insurance, corporate riskFinancial services, healthcare, manufacturing
Job FocusIdentifying, assessing, and mitigating risks across enterpriseEnsuring compliance with laws and regulations

While both roles involve regulatory and risk considerations, a Grc Risk Analyst focuses on enterprise-wide risk management strategies, whereas a Compliance Analyst concentrates on adherence to specific laws and regulations. Both roles require similar certifications and often work in overlapping industries, but their core responsibilities differ in scope and focus.

What job categories do people searching Grc Risk Analyst jobs in Madison, WI look for?

The top searched job categories for Grc Risk Analyst jobs in Madison, WI are:

Infographic showing various Grc Risk Analyst job openings in Madison, WI as of August 2026, with employment types broken down into 1% As Needed, 83% Full Time, 12% Part Time, and 4% Contract. Highlights an 86% Physical, 5% Hybrid, and 9% Remote job distribution, with an average salary of $84,852 per year, or $40.8 per hour.

Full-time

Medical, Dental, Vision, Retirement, PTO

Posted 14 days ago


Job description

Job Overview

The GRC Analyst I is responsible for supporting the organization's Governance, Risk, and Compliance (GRC) program through risk management, policy governance, compliance monitoring, reporting, and continuous improvement activities. This role assists with risk assessments, maintenance of the risk register, control evaluations, mitigation tracking, policy management, and compliance-related activities that help protect the organization and enable business objectives.

The GRC Analyst I also supports emerging AI Governance initiatives by assisting with the identification, assessment, monitoring, and reporting of risks associated with artificial intelligence technologies. Working closely with IT Security, Legal, Business Continuity, Data Governance, and business stakeholders, this position helps promote responsible technology use, organizational resilience, and a risk-aware culture that enables the business to move faster with greater confidence.

This is a full-time position based at Sub-Zero Group's headquarters in Fitchburg, Wisconsin, just outside Madison.

Job Responsibilities

Responsibilities include, but are not limited to:

Governance:

  • Assist with policy governance activities, including the development, maintenance, review, and administration of policies, standards, procedures, and related governance documentation, while providing guidance to employees and business units on their application.
  • Support the organization's AI Governance program through documentation, inventories, risk assessments, stakeholder coordination, and monitoring activities that promote the responsible, secure, and compliant use of AI technologies.
  • Help maintain alignment with governance frameworks and industry standards, including NIST CSF, NIST AI RMF, and ISO standards, while assessing governance implications of new technologies, AI initiatives, business process changes, and emerging regulatory requirements.

Risk Management:

  • Support risk assessment activities by gathering information, documenting risks, facilitating stakeholder discussions, evaluating inherent and residual risk, and tracking follow-up actions and remediation activities.
  • Maintain the risk register, including risk documentation, ownership assignments, risk scoring, review cadences, mitigation plans, control effectiveness evaluations, and reporting activities.
  • Partner with risk owners to evaluate risk events, root causes, business impacts, existing controls, and risk response strategies while developing dashboards, metrics, KPIs, and executive reporting that communicate organizational risk exposure and program maturity.

Compliance:

  • Monitor compliance with internal policies, regulatory requirements, contractual obligations, and applicable industry standards while supporting assessments against relevant governance and compliance frameworks.
  • Assist with compliance reviews, internal audits, and audit readiness activities by collecting evidence, validating controls, documenting findings, maintaining records, and tracking remediation activities through resolution.
  • Track and report compliance metrics, audit findings, governance performance indicators, corrective actions, and overall program effectiveness and maturity.

Additional Opportunities

The GRC Analyst I may have opportunities to contribute to additional initiatives based on business needs, program priorities, and individual career interests.

  • Business Continuity & Resilience: Participate in business continuity, IT disaster recovery, crisis management, resilience planning, business impact analyses, exercises, and improvement activities in support of organizational resilience efforts.
  • Third-Party Risk Management: Assist with vendor due diligence, third-party governance activities, and ongoing monitoring efforts as the organization's third-party risk management capabilities evolve and mature.
  • Awareness, Training & Risk Culture: Contribute to governance, risk, compliance, cybersecurity, and responsible AI awareness initiatives through the development of training materials, communications, workshops, and other educational opportunities that promote a culture of accountability and risk-informed decision-making.

Required Qualifications

  • Associateโ€™s or Bachelorโ€™s degree in enterprise risk management, information technology, cybersecurity, business administration, finance, accounting, or related field.
  • 0-3 years of relevant experience in risk management, governance, compliance, auditing, or related disciplines.
  • Strong analytical, organizational, and communication skills.

Preferred Qualifications

  • Experience supporting risk assessments, maintaining risk registers, or tracking remediation activities.
  • Experience supporting policy management, compliance reviews, control assessments, or audit activities.
  • Familiarity with NIST CSF, NIST AI RMF, ISO 27001, ISO 31000, ISO 22301, or similar frameworks.
  • Familiarity with regulations and standards such as CCPA/CPRA, GDPR, PCI DSS, or similar requirements.
  • Relevant certifications or progress toward certification, such as ISC2 CC, Security+, CISA, CRISC, CGRC, or similar credentials.

Why Join Sub-Zero Group?

Join a growing Governance, Risk, and Compliance program that is helping embed governance, risk management, compliance, and resilience into the fabric of the organization. This role offers a unique opportunity to help shape and mature a developing GRC program while gaining hands-on experience across technology risk management, cybersecurity governance, compliance, policy management, internal audit, and business continuity. Working closely with organizational leaders, you will have a direct impact on strengthening the company's ability to reliably achieve its objectives, address uncertainty, build resilience, and act with integrity.

We value our employees by providing:

  • Competitive compensation based on skills
  • Industry leading health, dental, and vision plans
  • Generous 401(k) savings and profit sharing
  • 10 Paid Holidays
  • Paid Time Off (PTO)
  • Parental Leave
  • On-site UW Health clinic, fitness center, and walking paths
  • Education assistance and internal training programs
  • Employee discount program
  • Employee Assistance Program (EAP)
  • Electric vehicle charging
  • Department & Company-wide social events

Interested in learning more about our robust benefits package? Click here!

This position requires a pre-employment drug/alcohol test and background check, which will be administered after a conditional job offer is extended. A negative drug/alcohol test result is required for employment. Refusal to take the test or a positive result may disqualify a candidate from further consideration.ย  All drug testing will be conducted in accordance with federal and state laws.