1

Grc Risk Analyst Jobs in Norman, OK (NOW HIRING)

CACI is seeking an experienced and relationshipfocused Cyber Risk and IT Compliance professional to ... Experience using ServiceNow IRM or other GRC/compliance management platforms. - What You Can Expect:

Grc Risk Analyst information

See Norman, OK salary details

$13

$35

$57

How much do grc risk analyst jobs pay per hour?

As of Sep 7, 2026, the average hourly pay for grc risk analyst in Norman, OK is $35.37, according to ZipRecruiter salary data. Most workers in this role earn between $26.06 and $43.03 per hour, depending on experience, location, and employer.

What is a GRC Risk Analyst?

GRC Risk Analysts are professionals who specialize in Governance, Risk, and Compliance (GRC) within an organization. They assess and manage risks related to business operations, ensure compliance with relevant laws and regulations, and help implement policies and controls to mitigate potential threats. These analysts work closely with management to identify vulnerabilities, develop risk management strategies, and monitor the effectiveness of compliance programs. Their goal is to protect the organization from financial, legal, and reputational harm while supporting business objectives.

What are the key skills and qualifications needed to thrive as a GRC Risk Analyst?

To thrive as a GRC (Governance, Risk, and Compliance) Risk Analyst, you need a solid understanding of risk management principles, regulatory requirements, and compliance frameworks, often supported by a degree in information security, business, or a related field. Familiarity with GRC platforms (such as RSA Archer or MetricStream), risk assessment methodologies, and certifications like CRISC or CISA is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and convey findings to stakeholders. These skills are critical for ensuring organizational compliance, minimizing risk exposure, and supporting informed decision-making.

What are some common challenges a GRC Risk Analyst might face when implementing new risk management frameworks within an organization?

A GRC Risk Analyst often encounters challenges such as resistance to change from stakeholders, integrating new frameworks with existing processes, and ensuring consistent understanding across departments. Aligning risk management practices with organizational goals while adhering to regulatory requirements can also be complex. Success in this role requires strong communication skills, adaptability, and the ability to educate and collaborate with team members from diverse backgrounds.

What is the difference between Grc Risk Analyst vs Compliance Analyst?

AspectGrc Risk AnalystCompliance Analyst
CertificationsISO 31000, FRM, CRISCISO 19600, CCEP, CISA
Work EnvironmentRisk management teams, corporate officesRegulatory departments, corporate offices
Industry UsageFinance, banking, insurance, corporate riskFinancial services, healthcare, manufacturing
Job FocusIdentifying, assessing, and mitigating risks across enterpriseEnsuring compliance with laws and regulations

While both roles involve regulatory and risk considerations, a Grc Risk Analyst focuses on enterprise-wide risk management strategies, whereas a Compliance Analyst concentrates on adherence to specific laws and regulations. Both roles require similar certifications and often work in overlapping industries, but their core responsibilities differ in scope and focus.

What are popular job titles related to Grc Risk Analyst jobs in Norman, OK?

For Grc Risk Analyst jobs in Norman, OK, the most frequently searched job titles are:

What job categories do people searching Grc Risk Analyst jobs in Norman, OK look for?

The top searched job categories for Grc Risk Analyst jobs in Norman, OK are:

Infographic showing various Grc Risk Analyst job openings in Norman, OK as of June 2026, with employment types broken down into 1% As Needed, 88% Full Time, 9% Part Time, 1% Temporary, and 1% Contract. Highlights an 76% Physical, 7% Hybrid, and 17% Remote job distribution, with an average salary of $73,564 per year, or $35.4 per hour.

IT Assurance and Compliance Analyst

CACI

Oklahoma City, OK

$87K - $87K/yr

Full-time

Medical, Retirement, PTO

Posted 9 days ago


Job description

Job Title: IT Assurance and Compliance Analyst Job Category: Information Technology Time Type: Full time Minimum Clearance Required to Start: None Employee Type: Regular Percentage of Travel Required: Up to 10% Type of Travel: Continental US * * * The Opportunity: CACI is seeking an experienced and relationshipfocused Cyber Risk and IT Compliance professional to join our Governance, Risk & Compliance organization. As an Information Assurance and Compliance Analyst, you will help shape and maintain the organization's IT control environment by assessing internal controls, coordinating SOX IT audits, validating compliance with key regulatory frameworks, and partnering with IT and business owners to drive remediation activities. The analyst partners closely with cybersecurity, infrastructure, applications, and leadership teams to ensure that technology processes meet both internal and external standards.

Responsibilities: Coordinate, facilitate, and support IT SOX compliance activities as the primary focus of the role, including walkthroughs, evidence collection, ITGC testing support, remediation tracking, and audit readiness. Support internal and external IT SOX audits, ISO 27001 internal assessments, and special audits, as well as thirdparty compliance assessments for ITrelevant services (e.g., NIST SP 800 171, CMMC) as needed. Monitor remediation and corrective action plans across Corporate and program enclaves, ensuring timely and complete resolution of SOX findings and broader compliance issues

Develop, maintain, and improve compliance documentation and guidance, including system security plans, policies, procedures, and control libraries. Communicate and collaborate with IT teams to strengthen SOX control performance, improve security compliance, and support a consistent, wellgoverned control environment. Build and maintain strong working relationships across IT, cybersecurity, infrastructure, and business stakeholders at all organizational levels.

Assist with IT compliance and assurance special projects as required, including process maturity initiatives and control automation efforts. Research and stay current on evolving IT regulatory requirements-particularly SOX and SEC requirements-while gaining exposure to cybersecurity frameworks (NIST 800X), DFARS, and CMMC regulations. Maintain a continuous learning mindset as technologies, regulations, and compliance frameworks evolve.

Qualifications: Required: Bachelor's degree in MIS, Information Assurance, Cybersecurity, Auditing, or a related discipline. 2+ years of experience in IT auditing, ITGC testing, IT consulting, or IT compliance. Experience leading meetings and communicating effectively with technical and nontechnical stakeholders.

Working knowledge of SOX, COSO, COBIT, ISO 27001, DFARS 252.2047012, and NIST SP 800171. Experience evaluating IT processes, controls, policies, and governance frameworks. Ability to identify control gaps, assess risk, recommend solutions, and clearly communicate findings

Exceptional written and verbal communication skills, with the ability to simplify complex issues. Strong interpersonal skills and the ability to collaborate effectively with external auditors and internal teams. Strong organizational skills with the ability to handle multiple workstreams and deadlines independently.

Demonstrated ability to operate with minimal supervision in a complex IT environment. Desired: Professional certifications such as CISA, CIA, CRISC, or ISO 27001 Lead/Implementer. Experience in a regulated industry (e.g., government contracting, defense, finance)

Handson experience supporting endtoend IT SOX programs (walkthroughs, testing coordination, evidence requests, remediation validation). Experience using ServiceNow IRM or other GRC/compliance management platforms. - What You Can Expect: A culture of integrity.

At CACI, we place character and innovation at the center of everything we do. As a valued team member, you'll be part of a high-performing group dedicated to our customer's missions and driven by a higher purpose - to ensure the safety of our nation. An environment of trust.

CACI values the unique contributions that every employee brings to our company and our customers - every day. You'll have the autonomy to take the time you need through a unique flexible time off benefit and have access to robust learning resources to make your ambitions a reality. A focus on continuous growth.

Together, we will advance our nation's most critical missions, build on our lengthy track record of business success, and find opportunities to break new ground - in your career and in our legacy. Pay Range: There are a host of factors that can influence final salary including, but not limited to, geographic location, Federal Government contract labor categories and contract wage rates, relevant prior work experience, specific skills and competencies, education, and certifications. Our employees value the flexibility at CACI that allows them to balance quality work and their personal lives.

We offer competitive compensation, benefits and learning and development opportunities. Our broad and competitive mix of benefits options is designed to support and protect employees and their families. At CACI, you will receive comprehensive benefits such as; healthcare, wellness, financial, retirement, family support, continuing education, and time off benefits.

The proposed salary range for this position is: $67,800 - $142,200 CACI is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, pregnancy, sexual orientation, age, national origin, disability, status as a protected veteran, or any other protected characteristic.