1

Grc Risk Analyst Jobs in Manhattan, NY (NOW HIRING)

Deep experience in Information Security Third-Party Risk Management, Risk Management, GRC Compliance, or a related field * Strong analytical skills with the ability to identify, assess, and resolve ...

Senior GRC Analyst

New York, NY · On-site

$125K - $160K/yr

About the role We're hiring a Senior GRC Analyst to help scale Radar's security and compliance ... Own and evolve Radar's third-party risk program, including vendor security and compliance reviews ...

About the role We're hiring a Senior GRC Analyst to help scale Radar's security and compliance ... Own and evolve Radar's third-party risk program, including vendor security and compliance reviews ...

Required : • Deep experience in Information Security Third-Party Risk Management, Risk Management, GRC Compliance, or a related field • Strong analytical skills with the ability to identify ...

Collaborate cross-functionally with IT, Risk, Compliance, and business units to optimize GRC ... Utilize data analytics tools (Power BI, Tableau, advanced Excel) to analyze control effectiveness ...

The Role Rogo is hiring a GRC Analyst to support our customer trust, security assurance, and ... Experience working with security questionnaires, audits, or third-party risk assessments.

The Role Rogo is hiring a GRC Analyst to support our customer trust, security assurance, and ... Experience working with security questionnaires, audits, or third-party risk assessments.

next page

Showing results 1-20

Grc Risk Analyst information

See Manhattan, NY salary details

$16

$44

$72

How much do grc risk analyst jobs pay per hour?

As of May 28, 2026, the average hourly pay for grc risk analyst in Manhattan, NY is $44.68, according to ZipRecruiter salary data. Most workers in this role earn between $32.88 and $54.38 per hour, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a GRC Risk Analyst, and why are they important?

To thrive as a GRC (Governance, Risk, and Compliance) Risk Analyst, you need a solid understanding of risk management principles, regulatory requirements, and compliance frameworks, often supported by a degree in information security, business, or a related field. Familiarity with GRC platforms (such as RSA Archer or MetricStream), risk assessment methodologies, and certifications like CRISC or CISA is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and convey findings to stakeholders. These skills are critical for ensuring organizational compliance, minimizing risk exposure, and supporting informed decision-making.

What are some common challenges a GRC Risk Analyst might face when implementing new risk management frameworks within an organization?

A GRC Risk Analyst often encounters challenges such as resistance to change from stakeholders, integrating new frameworks with existing processes, and ensuring consistent understanding across departments. Aligning risk management practices with organizational goals while adhering to regulatory requirements can also be complex. Success in this role requires strong communication skills, adaptability, and the ability to educate and collaborate with team members from diverse backgrounds.

What are GRC Risk Analysts?

GRC Risk Analysts are professionals who specialize in Governance, Risk, and Compliance (GRC) within an organization. They assess and manage risks related to business operations, ensure compliance with relevant laws and regulations, and help implement policies and controls to mitigate potential threats. These analysts work closely with management to identify vulnerabilities, develop risk management strategies, and monitor the effectiveness of compliance programs. Their goal is to protect the organization from financial, legal, and reputational harm while supporting business objectives.

What is the difference between Grc Risk Analyst vs Compliance Analyst?

AspectGrc Risk AnalystCompliance Analyst
CertificationsISO 31000, FRM, CRISCISO 19600, CCEP, CISA
Work EnvironmentRisk management teams, corporate officesRegulatory departments, corporate offices
Industry UsageFinance, banking, insurance, corporate riskFinancial services, healthcare, manufacturing
Job FocusIdentifying, assessing, and mitigating risks across enterpriseEnsuring compliance with laws and regulations

While both roles involve regulatory and risk considerations, a Grc Risk Analyst focuses on enterprise-wide risk management strategies, whereas a Compliance Analyst concentrates on adherence to specific laws and regulations. Both roles require similar certifications and often work in overlapping industries, but their core responsibilities differ in scope and focus.

What job categories do people searching Grc Risk Analyst jobs in Manhattan, NY look for? The top searched job categories for Grc Risk Analyst jobs in Manhattan, NY are:
Infographic showing various Grc Risk Analyst job openings in Manhattan, NY as of May 2026, with employment types broken down into 1% Internship, 3% As Needed, 68% Full Time, and 28% Part Time. Highlights an 76% Physical, and 24% Remote job distribution, with an average salary of $92,936 per year, or $44.7 per hour.

TPRM Analyst, Info Sec

Fanatics Inc.

New York, NY • On-site

Full-time

Posted 18 days ago


Fanatics rating

7.4

Company rating: 7.4 out of 10

Based on 62 frontline employees who took The Breakroom Quiz

82nd of 710 rated retailers


Job description

About Us
Fanatics is building a leading global digital sports platform. We ignite the passions of global sports fans and maximize the presence and reach for our hundreds of sports partners globally by offering products and services across Fanatics Commerce, Fanatics Collectibles, and Fanatics Betting & Gaming, allowing sports fans to Buy, Collect, and Bet. Through the Fanatics platform, sports fans can buy licensed fan gear, jerseys, lifestyle and streetwear products, headwear, and hardgoods; collect physical and digital trading cards, sports memorabilia, and other digital assets; and bet as the company builds its Sportsbook and iGaming platform. Fanatics has an established database of over 100 million global sports fans; a global partner network with approximately 900 sports properties, including major national and international professional sports leagues, players associations, teams, colleges, college conferences and retail partners, 2,500 athletes and celebrities, and 200 exclusive athletes; and over 2,000 retail locations, including its Lids retail stores. Our more than 22,000 employees are committed to relentlessly enhancing the fan experience and delighting sports fans globally.
About the Role
We are seeking a detail-oriented, analytical, and highly motivated Senior/Staff Analyst to support and scale our Information Security Third-Party Risk Management (TPRM) program. This role will play a key part in assessing, monitoring, and mitigating risks associated with third-party vendors. You will use our new modern, AI-powered TPRM platform to assess risk, analyze vendor responses and artifacts, and drive practical informed recommendations. You will partner closely with cross-functional teams, including Legal, Procurement, Information Security, and business stakeholders to enable risk-informed decisions and strengthen our overall third-party risk posture.
Your Impact
  • Strengthen Resilience: Directly contribute to the security and resilience of the organization by developing and supporting a robust third-party risk management framework
  • Drive Compliance: Ensure third-party relationships adhere to company policies, regulatory requirements, and industry best practices
  • Enable the Business: Partner with business units to support risk-aware decision-making, enabling effective supplier engagement while safeguarding the organization

Key Responsibilities
Risk Assessment & Due Diligence
  • Perform thorough due diligence reviews with the assistance of our AI-powered platform, including risk questionnaires, documentation analysis, and standard supplier due diligence assessments
  • Ensure all third-party due diligence artifacts and supporting documentation are properly captured and maintained in the TPRM platform
  • Evaluate third-party controls and documentation (e.g., SOC reports, policies, certifications etc.)
  • Coordinate closely with other Information Security (e.g., security architecture / engineering, and subsidiary GRC) teams throughout the business to further assess third-party solutions as needed
  • Advise business and stakeholders on third-party risk

Monitoring, Remediation, and Offboarding
  • Continuously monitor third-party cyber posture, including ransomware susceptibility, breach likelihood, and other open-source intelligence signals using our modern cyber rating platform
  • Triage alerts and escalate early warnings as appropriate
  • Develop and manage corrective action plans and control documentation for identified risks and/or issues
  • Track and evaluate vendor remediation efforts to ensure timely and effective resolution, working with business owners to address underperformance or emerging concerns
  • Conduct periodic and event-driven reassessments of third parties based on risk and criticality
  • Ensure secure third-party offboarding, including data handling, access revocation, and closure of contractual and security obligations.

Collaboration & Process Improvement
  • Collaborate with business units, Legal, Information Security, and other risk subject matter experts to address and mitigate identified risks
  • Support internal, customer, and third-party audits related to supplier risk and compliance
  • Contribute to the development and enhancement of TPRM policies, standards, and procedures
  • Create and implement scalable solutions for supplier tracking, monitoring, and compliance
  • Stay current on industry trends, emerging risks, and regulatory changes impacting third-party relationships

What We're Looking For
  • Deep experience in Information Security Third-Party Risk Management, Risk Management, GRC Compliance, or a related field
  • Strong analytical skills with the ability to identify, assess, and resolve complex issues
  • Familiarity with risk management frameworks (e.g., NIST, ISO etc.) and vendor risk best practices
  • Excellent communication and interpersonal skills, with the ability to collaborate effectively across teams
  • High level of professionalism, integrity, and commitment to accuracy and thoroughness
  • A risk-focused, outcomes-focused mindset - you know how to balance thoroughness with speed, and you're comfortable prioritizing efforts to address most critical risks and moving quickly in a fast-paced business without compromising control integrity
  • Comfortable working with technology platforms and AI-assisted tooling (you don't need to be technical, but you should be curious and adaptable)

What Success Looks Like
  • Consistent, high-quality execution of vendor risk assessments and due diligence
  • Clear, actionable reporting that enhances leadership visibility into third-party risk
  • Strong cross-functional partnerships enabling risk-informed business decisions
  • Continuous improvement of TPRM processes, tools, and controls

Why Join Us
  • Opportunity to help build and mature a critical risk management function
  • High visibility role with cross-functional impact
  • Collaborative and fast-paced environment

The salary range represents base pay only and does not include short-term or long-term incentive compensation. When determining base pay as part of a final compensation package, we consider several factors such as location, experience, qualifications, and training. For information about our benefits, please visit https://benefitsatfanatics.com/
Salary Range
$155,000-$165,000 USD
By submitting your application, you agree to our terms of service and acknowledge you have read our Candidate Privacy Policy.

What Fanatics employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom