1

Grc Risk Analyst Jobs in Philadelphia, PA (NOW HIRING)

Coordinate with IT GRC, APEX (AI risk), ECO/Legal, Global Privacy Office, BIRO/ITRMS, Procurement ... analytics and insights activities. * Partner with Procurement to verify onboarding and due ...

Coordinate with IT GRC, APEX (AI risk), ECO/Legal, Global Privacy Office, BIRO/ITRMS, Procurement ... for analytics and insights activities.Partner with Procurement to verify onboarding and due ...

... risk mitigation across on-premises, cloud, and hybrid environments. The Lead Analyst, Threat ... The role partners closely with the SOC, Cloud Services, Infrastructure, Engineering, GRC, Legal ...

Deputy IT SOX Compliance Lead

Philadelphia, PA · On-site

$89K - $90K/yr

Champion a risk-aware culture by promoting awareness of SOX compliance requirements and best ... Analyze control results, identify improvement opportunities, and develop actionable remediation ...

... Risk and Compliance (GRC) - Utilizing SAP BW/4HANA for data analytics and reporting - Developing compliance programs and governance frameworks - Implementing strategic questioning to enhance client ...

Champion a risk-aware culture by promoting awareness of SOX compliance requirements and best ... Analyze control results, identify improvement opportunities, and develop actionable remediation ...

SAP GTS Sr Associate

Philadelphia, PA · On-site

$77K - $202K/yr

... Risk and Compliance (GRC) - Utilizing SAP BW/4HANA for data analytics and reporting - Implementing compliance programs and regulatory guidelines - Developing policies and guidelines for corporate ...

Senior Systems Engineer - IAM

Wilmington, DE · On-site

$101K - $138K/yr

Strong analytical skills, excellent communication abilities, and professional experience are ... Governance, Risk, and Compliance (GRC): Develop and implement GRC strategies to ensure IAM ...

Showing results 41-60

Grc Risk Analyst information

See Philadelphia, PA salary details

$15

$40

$66

How much do grc risk analyst jobs pay per hour?

As of Aug 18, 2026, the average hourly pay for grc risk analyst in Philadelphia, PA is $40.85, according to ZipRecruiter salary data. Most workers in this role earn between $30.10 and $49.71 per hour, depending on experience, location, and employer.

What is a GRC Risk Analyst?

GRC Risk Analysts are professionals who specialize in Governance, Risk, and Compliance (GRC) within an organization. They assess and manage risks related to business operations, ensure compliance with relevant laws and regulations, and help implement policies and controls to mitigate potential threats. These analysts work closely with management to identify vulnerabilities, develop risk management strategies, and monitor the effectiveness of compliance programs. Their goal is to protect the organization from financial, legal, and reputational harm while supporting business objectives.

What are the key skills and qualifications needed to thrive as a GRC Risk Analyst?

To thrive as a GRC (Governance, Risk, and Compliance) Risk Analyst, you need a solid understanding of risk management principles, regulatory requirements, and compliance frameworks, often supported by a degree in information security, business, or a related field. Familiarity with GRC platforms (such as RSA Archer or MetricStream), risk assessment methodologies, and certifications like CRISC or CISA is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and convey findings to stakeholders. These skills are critical for ensuring organizational compliance, minimizing risk exposure, and supporting informed decision-making.

What are some common challenges a GRC Risk Analyst might face when implementing new risk management frameworks within an organization?

A GRC Risk Analyst often encounters challenges such as resistance to change from stakeholders, integrating new frameworks with existing processes, and ensuring consistent understanding across departments. Aligning risk management practices with organizational goals while adhering to regulatory requirements can also be complex. Success in this role requires strong communication skills, adaptability, and the ability to educate and collaborate with team members from diverse backgrounds.

What is the difference between Grc Risk Analyst vs Compliance Analyst?

AspectGrc Risk AnalystCompliance Analyst
CertificationsISO 31000, FRM, CRISCISO 19600, CCEP, CISA
Work EnvironmentRisk management teams, corporate officesRegulatory departments, corporate offices
Industry UsageFinance, banking, insurance, corporate riskFinancial services, healthcare, manufacturing
Job FocusIdentifying, assessing, and mitigating risks across enterpriseEnsuring compliance with laws and regulations

While both roles involve regulatory and risk considerations, a Grc Risk Analyst focuses on enterprise-wide risk management strategies, whereas a Compliance Analyst concentrates on adherence to specific laws and regulations. Both roles require similar certifications and often work in overlapping industries, but their core responsibilities differ in scope and focus.

What are popular job titles related to Grc Risk Analyst jobs in Philadelphia, PA?

For Grc Risk Analyst jobs in Philadelphia, PA, the most frequently searched job titles are:

What job categories do people searching Grc Risk Analyst jobs in Philadelphia, PA look for?

The top searched job categories for Grc Risk Analyst jobs in Philadelphia, PA are:

What cities near Philadelphia, PA are hiring for Grc Risk Analyst jobs?

Cities near Philadelphia, PA with the most Grc Risk Analyst job openings:

Infographic showing various Grc Risk Analyst job openings in Philadelphia, PA as of August 2026, with employment types broken down into 1% As Needed, 86% Full Time, 10% Part Time, and 3% Contract. Highlights an 88% Physical, 5% Hybrid, and 7% Remote job distribution, with an average salary of $84,975 per year, or $40.9 per hour.

Dir , Data Governance

MSD

North Wales, PA

Full-time

Medical, Dental, Vision, Retirement, PTO

Posted 5 days ago


Job description

Job Description

The Director is accountable for setting and driving the Social, Web, Mobile, Primary market research, data, digital data product and Digital data solutions governance & enablement strategy for Digital Human Health (DHH), across markets and franchises. This leader is responsible for embedding scalable governance-by-design controls across the lifecycle of customer facing digital engagement, primary market research, data ingestion and enablement across the medallion architecture, creation of Digital data products and more broadly pharma analytics and creation/enablement of digital solutions.

This role is responsible for leading a team that turns corporate policy and enterprise governance, privacy, risk, and compliance requirements into practical playbooks, tools and DHH operating standards. Socializes through alignment and influence with DHH leadership and key stakeholders across Legal, Compliance, IT RMS, General Counsel, Medical, Human Health leadership and with DHH product, platform, analytics teams, and vendor ecosystems. The leader will also be responsible to train the broader DHH organization to understand the guidelines, rules and playbooks. He/She will also strategize, design and build the right checkpoints to ensure adoption and becomes a trusted partner for DHH leadership to enable compliance by design, in the day to day ways of working across DHH.

He/She, with their team, will manage risk and deviation processes, coordinate cross functional reviews (Privacy, Security, Legal, Ethics, Procurement, Pharmacovigilance, Audit), and provide an escalation path for material risks while leaving operational delivery decisions with business owners.

Success in this role requires deep understanding of data, data driven analytics, Primary market research methodologies, digital marketing and marketing enablement across social, web and mobile channels. It is essential that the individual has extensive knowledge and experience in the application of Privacy (GDPR, HIPPA CCPA etc.), Pharmacovigilance (EMA, FDA), Anti-Trust, FCPA regulations etc. and their application to data, data sciences and market research. Given the evolving technology landscape, this individual is also expected to have learning orientation to learn to leverage technology and AI to enable the required capability builds, SOP creation, governance practices, monitoring and compliance readiness. The Director partners with first-line delivery leaders to enable responsible innovation while maintaining regulatory defensibility, privacy by design, and risk transparency, with clear linkage to second-line oversight functions.

Organizational Scope

The Director will lead a multidisciplinary team across Social, Web, Mobile, Market Research, Digital and Data governance enablement and GRC specialists (direct and matrixed). Scope includes governance enablement for:

  • Primary market research

  • Web, mobile and digital channels (apps, sites, content ecosystems)

  • Social media (listening, influencer engagements, company owned handles/assets)

  • Commercial data analytics- Prescriptive analytics and advanced statistical modeling

  • Data governance and privacy integration - Sensitive data domains, including HCP and patient-level data (identified, de-identified, and pseudonymized), Commercial data ecosystems (1st/2nd/3rd party), data ingestion, linkage, and enrichment

  • Digital data product governance enablement - Digital data products, insights platforms, and Digital data solutions

  • Risk management, audit/inspection readiness, and governance capability building

Leadership Responsibilities

  • Set strategy, priorities, and operating model for DHH Digital, Social, Web, Mobile, Market Research, data, and digital data product governance enablement.

  • Align and influence DHH leadership and key stakeholders to embed governance-by-design into planning and delivery.

  • Build governance capability (frameworks, training, templates, tooling, and metrics) that accelerates delivery while protecting patients, customers, and the company.

  • Provide transparent risk reporting and timely escalation pathways to second-line oversight functions and enterprise governance forums.

  • Responsible for building a high performing team of GRC advisors. Responsible for coaching, mentoring, hiring, disciplining when required, and providing guidance to the team.

Education

  • B.S. or M.S. in Engineering, Sciences, Liberal arts, Law, Medicine, Pharmacy, Business, Analytics or related fields

  • Ph.D. is preferred

Data Governance & Privacy Integration

  • Partner with CD&AO, DHH teams, HH leaders, Global Privacy Office, BIRO/ITRMS, Ethics & Compliance, and Legal to ensure policy alignment and consistent execution.

  • Embed privacy-by-design and data governance controls into DHH Digital and data product workflows, including secondary use, linkage/enrichment, cross-domain integration, and retention requirements.

  • Translate policies into concise playbooks, standards, templates and delivery tools.

  • Ensure defensible documentation for de-identification/pseudonymization methods and periodic reassessment, with clear traceability to intended use.

Digital Data Product Governance Integration

  • Integrate governance checkpoints into SDLC and agile product ways of working, with clear review/approval triggers where required.

  • Ensure end-to-end traceability across data inputs, transformations, model integration (where applicable), outputs, and intended use.

  • Set documentation and quality standards for digital data products and vendor-provided solutions, including controls for data acquisition and fair market value (FMV) approvals.

Risk Enablement & Escalation

  • Maintain and mature the DHH risk register to cover data/digital data products, including consistent assessment criteria and mitigation tracking. Align with enterprise ERM, enforce standardized risk classification and escalation procedures; ensure timely logging, ownership, mitigation and closure.

  • Identify systemic control gaps and drive remediation plans with delivery leaders; monitor effectiveness through defined metrics.

  • Escalate material privacy, security, and cybersecurity risks to second-line functions and enterprise risk governance, with timely executive communication.

Enterprise Governance, Risk & Compliance Alignment

  • Translate enterprise governance requirements into practical, auditable operational controls for DHH.

  • Coordinate with IT GRC, APEX (AI risk), ECO/Legal, Global Privacy Office, BIRO/ITRMS, Procurement, and MCAAS to ensure alignment, clear ownership, and effective escalation.

  • Anticipate emerging regulatory expectations impacting Social, Web, mobile, Market research, Digital and data. Update DHH standards and guidance accordingly.

  • Ensure documentation and evidence expectations support inspection readiness and defensible decisions.

  • Coordinate Privacy, Security and Legal reviews, document decisions with audit trails, and define escalation paths for analytics and insights activities.

  • Partner with Procurement to verify onboarding and due diligence in Aravo, maintain approved vendor list, validate MSAs/compliance before go live, monitor vendor performance and escalate material vendor risks.

Audit & Inspection Readiness

  • Set standardized evidence and documentation expectations across domains to support audits and regulatory inspections.

  • Ensure all required artifacts are complete, traceable, and defensible for intended use and risk posture.

  • Coordinate audit responses across DHH data domains and maintain ongoing readiness.

Governance Culture, Capability and Advocacy

  • Training & culture: design and deliver role based GRC training, track competency and completion, sponsor governance stewards and run regular steward forums.

  • Drive governance adoption by aligning with and influencing DHH leaders and delivery teams; clarify accountabilities, escalation paths, and decision forums.

  • Build practical enablement (role-based training, playbooks, templates, and tooling) that increases consistency and reduces delivery friction.

  • Champion responsible stewardship, balancing innovation, patient/customer trust, and compliance obligations.

  • Own success metrics (adoption, training completion, auditability, time to escalation, risk closure, stakeholder satisfaction) and drive improvements from register insights.

Decision Rights

The Director has authority to:

  • Define minimum governance controls for Social, Web, Mobile, Market research, Content, data, data products, digital data solutions within company policy and standards boundaries in close partnership with other teams that have a role in defining privacy, risk, compliance and governance standards for Human Health (HH).

  • Require minimum documentation and evidence prior to deployment and material change.

  • Escalate material risks for additional review, decisioning, and approval, as required.

  • Mandate remediation or mitigation plans for control gaps and monitor closure.

  • Business and product leaders retain ownership of delivery decisions and risk acceptance within company policy and standards; the Director provides governance enablement standards, oversight cadence, and escalation pathways to support consistent, defensible outcomes.

Qualifications

  • 10+ years of experience in Governance, risk and compliance, Marketing, Data strategy, Data Engineering, Product design & deployment, data science and AI enablement, digital channels and market research with at least 7+ years of experience in Governance, Privacy, Risk Assessment and Compliance enablement

  • Proven ability to translate policy into operational standards, playbooks and tooling

  • Experience managing cross functional reviews with Privacy, Security and Legal

  • Strong leadership of multi-disciplinary teams and vendor oversight

  • Familiarity with risk registers, deviation/CAPA processes and vendor due diligence platforms

  • Excellent stakeholder management and training program delivery skills

Required Skills:

Data Governance, Data Ingestion, Data Management, Digital Consumer Engagement, Digital Healthcare, Governance Management, Market Research, Operational Decisions, Pharmacovigilance, Privacy Compliance, Procurement, Quality Management, Risk Governance, Social Media, Social Media Management, Strategic Procurement, Technical Advice, Waterfall Model

Preferred Skills:

Current Employees apply HERE

Current Contingent Workers apply HERE

US and Puerto Rico Residents Only:

Our company is committed to inclusion, ensuring that candidates can engage in a hiring process that exhibits their true capabilities. Please click here if you need an accommodation during the application or hiring process.

As an Equal Employment Opportunity Employer, we provide equal opportunities to all employees and applicants for employment and prohibit discrimination on the basis of race, color, age, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, disability status, or other applicable legally protected characteristics.As a federal contractor, we comply with all affirmative action requirements for protected veterans and individuals with disabilities. For more information about personal rights under the U.S. Equal Opportunity Employment laws, visit:

EEOC Know Your Rights

EEOC GINA Supplement

We are proud to be a company that embraces the value of bringing together, talented, and committed people with diverse experiences, perspectives, skills and backgrounds. The fastest way to breakthrough innovation is when people with diverse ideas, broad experiences, backgrounds, and skills come together in an inclusive environment. We encourage our colleagues to respectfully challenge one another's thinking and approach problems collectively.

Learn more about your rights, including under California, Colorado and other US State Acts

The salary range for this role is

$173,200.00 - $272,600.00

This is the lowest to highest salary we in good faith believe we would pay for this role at the time of this posting. An employee's position within the salary range will be based on several factors including, but not limited to relevant education, qualifications, certifications, experience, skills, geographic location, government requirements, and business or organizational needs.

The successful candidate will be eligible for annual bonus and long-term incentive, if applicable.

We offer a comprehensive package of benefits. Available benefits include medical, dental, vision healthcare and other insurance benefits (for employee and family), retirement benefits, including 401(k), paid holidays, vacation, and compassionate and sick days. More information about benefits is available at https://jobs.merck.com/us/en/compensation-and-benefits.

You can apply for this role through https://jobs.merck.com/us/en (or via the Workday Jobs Hub if you are a current employee). The application deadline for this position is stated on this posting.

San Francisco Residents Only:We will consider qualified applicants with arrest and conviction records for employment in compliance with the San Francisco Fair Chance Ordinance

Los Angeles Residents Only:We will consider for employment all qualified applicants, including those with criminal histories, in a manner consistent with the requirements of applicable state and local laws, including the City of Los Angeles' Fair Chance Initiative for Hiring Ordinance

Search Firm Representatives Please Read Carefully
Merck & Co., Inc., Rahway, NJ, USA, also known as Merck Sharp & Dohme LLC, Rahway, NJ, USA, does not accept unsolicited assistance from search firms for employment opportunities. All CVs / resumes submitted by search firm...