1

Grc Risk Analyst Jobs in Pittsburgh, PA (NOW HIRING)

Senior GRC Analyst

Pittsburgh, PA ยท On-site

$114K - $163K/yr

Senior GRC Analyst Department: Compliance & Fraud Employment Type: Full Time Location: Pittsburgh ... Execute third-party risk assessments across our vendor portfolio, including security questionnaire ...

An excellent career opportunity is currently available for an entry level Risk & Compliance Analyst ... GRC's privacy and compliance initiatives Required Qualifications: * High School diploma/GED ...

An excellent career opportunity is currently available for an entry level Risk & Compliance Analyst ... GRC's privacy and compliance initiatives Required Qualifications: * High School diploma/GED ...

An excellent career opportunity is currently available for an entry level Risk & Compliance Analyst ... GRC's privacy and compliance initiatives Required Qualifications: * High School diploma/GED ...

next page

Showing results 1-20

Grc Risk Analyst information

See Pittsburgh, PA salary details

$14

$39

$63

How much do grc risk analyst jobs pay per hour?

As of Sep 7, 2026, the average hourly pay for grc risk analyst in Pittsburgh, PA is $39.30, according to ZipRecruiter salary data. Most workers in this role earn between $28.94 and $47.84 per hour, depending on experience, location, and employer.

What is a GRC Risk Analyst?

GRC Risk Analysts are professionals who specialize in Governance, Risk, and Compliance (GRC) within an organization. They assess and manage risks related to business operations, ensure compliance with relevant laws and regulations, and help implement policies and controls to mitigate potential threats. These analysts work closely with management to identify vulnerabilities, develop risk management strategies, and monitor the effectiveness of compliance programs. Their goal is to protect the organization from financial, legal, and reputational harm while supporting business objectives.

What are the key skills and qualifications needed to thrive as a GRC Risk Analyst?

To thrive as a GRC (Governance, Risk, and Compliance) Risk Analyst, you need a solid understanding of risk management principles, regulatory requirements, and compliance frameworks, often supported by a degree in information security, business, or a related field. Familiarity with GRC platforms (such as RSA Archer or MetricStream), risk assessment methodologies, and certifications like CRISC or CISA is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and convey findings to stakeholders. These skills are critical for ensuring organizational compliance, minimizing risk exposure, and supporting informed decision-making.

What are some common challenges a GRC Risk Analyst might face when implementing new risk management frameworks within an organization?

A GRC Risk Analyst often encounters challenges such as resistance to change from stakeholders, integrating new frameworks with existing processes, and ensuring consistent understanding across departments. Aligning risk management practices with organizational goals while adhering to regulatory requirements can also be complex. Success in this role requires strong communication skills, adaptability, and the ability to educate and collaborate with team members from diverse backgrounds.

What is the difference between Grc Risk Analyst vs Compliance Analyst?

AspectGrc Risk AnalystCompliance Analyst
CertificationsISO 31000, FRM, CRISCISO 19600, CCEP, CISA
Work EnvironmentRisk management teams, corporate officesRegulatory departments, corporate offices
Industry UsageFinance, banking, insurance, corporate riskFinancial services, healthcare, manufacturing
Job FocusIdentifying, assessing, and mitigating risks across enterpriseEnsuring compliance with laws and regulations

While both roles involve regulatory and risk considerations, a Grc Risk Analyst focuses on enterprise-wide risk management strategies, whereas a Compliance Analyst concentrates on adherence to specific laws and regulations. Both roles require similar certifications and often work in overlapping industries, but their core responsibilities differ in scope and focus.

What job categories do people searching Grc Risk Analyst jobs in Pittsburgh, PA look for?

The top searched job categories for Grc Risk Analyst jobs in Pittsburgh, PA are:

What cities near Pittsburgh, PA are hiring for Grc Risk Analyst jobs?

Cities near Pittsburgh, PA with the most Grc Risk Analyst job openings:

Infographic showing various Grc Risk Analyst job openings in Pittsburgh, PA as of August 2026, with employment types broken down into 1% As Needed, 86% Full Time, 10% Part Time, and 3% Contract. Highlights an 89% Physical, 4% Hybrid, and 7% Remote job distribution, with an average salary of $81,752 per year, or $39.3 per hour.

Senior GRC Analyst

Wolfe, LLC

Pittsburgh, PA โ€ข On-site

$114K - $163K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 27 days ago


Job description

Senior GRC Analyst
Department: Compliance & Fraud
Employment Type: Full Time
Location: Pittsburgh Onsite
Compensation: $114,000 - $163,000 / year
Description
Role SummaryWolfe is a Pittsburgh-based FinTech company operating consumer gifting and payments brands, and we are actively embedding AI across our products, our internal processes, and the way our teams work day-to-day. As Senior GRC Analyst, you will be the hands-on owner of the control and evidence work behind our PCI DSS Level 1 service provider obligations, our SOC 2 Type II readiness, our IT general controls, our NIST CSF 2.0 maturity program, and our third-party risk assessments. This is a deliberately senior individual contributor role - you will operate with minimal oversight, work directly with our QSA and external auditors, and serve as the compliance advisor engineering, fraud, and product teams come to before they build. You will also help us define how governance keeps pace with AI adoption, including the controls and review process for AI use across the company. This is a 5-day onsite role in Pittsburgh, PA.
Responsibilities
  • Run our annual PCI DSS v4.0.1 Level 1 service provider assessment and SOC 2 Type II examination end to end - scope validation, evidence collection, QSA and auditor coordination, gap remediation tracking, and support for sponsor bank and processor due diligence requests.
  • Own IT general control readiness across change management, logical access, SDLC, and backup and job scheduling - documenting control narratives, walking auditors through the environment, and performing internal design and operating-effectiveness testing so that external testing produces no surprises.
  • Own the issues management lifecycle under our Issues Management Policy - intake, risk rating, remediation tracking, closure evidence, and recurring reporting to leadership and the Audit Committee.
  • Execute third-party risk assessments across our vendor portfolio, including security questionnaire review, contract security and PCI terms review, and ongoing monitoring of critical vendors.
  • Administer our GRC platform - control library and cross-framework mappings across PCI, SOC 2, and ITGC, automated evidence collection, control owner workflows, and compliance dashboards.

Impact StatementFor more clarity on the role, below are the success metrics and measurements for this role in the first 90 to 120 days.:
  • Take over evidence collection for the current PCI DSS v4.0.1 assessment cycle and deliver a QSA-accepted evidence package for your assigned requirement families, with an aging report showing zero overdue evidence requests at the 120-day mark.
  • Deliver a SOC 2 Type II readiness assessment covering the full ITGC population - change management, logical access, SDLC, and backup and recovery - including written control narratives, identified design gaps, and a remediation plan sized to close before the audit period opens.
  • Complete a refreshed assessment of the governance function and deliver a prioritized remediation plan covering the lowest-scoring subcategories, with owners, target dates, and a defined scoring path from current to target maturity.
  • Migrate all open compliance and audit findings into a single issues register in the GRC platform - each item risk-rated, owner-assigned, and due-dated - and publish the first monthly issues report to the IT Steering Committee.

Qualifications
  • 7+ years in GRC, IT audit, or information security compliance, including at least 3 years directly supporting PCI DSS in a Level 1 service provider or equivalent payment card environment; CISA, CRISC, CISSP, PCIP, or ISA certification preferred but not required.
  • Demonstrated experience preparing for and supporting SOC 2 Type II examinations, including designing, documenting, and testing IT general controls across change management, logical access, and the software development lifecycle.
  • Working depth in IT governance, with proven ability to translate control requirements into testable evidence that an external assessor accepts without rework.
  • Hands-on experience administering a GRC platform (Vanta, Drata, Secureframe, ServiceNow IRM, AuditBoard, or similar) - control mapping, automated evidence collection, and reporting.
  • Track record running third-party risk assessments end to end, including reviewing security and compliance terms in vendor contracts.
  • Experience in a regulated financial services environment answering to external parties - sponsor banks, processors, regulators, or internal audit - and producing deliverables for executive and board audiences.

Compensation, Benefits, and Perks
Wolfe is committed to providing a comprehensive benefits package to support your well-being, along with competitive compensation. Our benefits and perks include but not limited to:
  • Restricted Stock Units (RSUs)
  • Profit Share
  • Medical, Prescription, Vision, and Dental insurance for employees and dependents (Wolfe pays 80% of premium)
  • Short-Term Disability Insurance (Wolfe pays 100% of premium)
  • Voluntary Long-Term Disability Insurance, Life Insurance, Critical Illness Insurance, Accident Insurance, and Hospital Indemnity coverage
  • PTO (vacation and sick time)
  • Corporate Holidays and Floating Holidays
  • 401(k)
  • Employee recognition program
  • Charitable Donation to a charity of your choice yearly
  • Employee Referral Bonus
  • Tuition Reimbursement
  • Internal Training and Information sessions
  • Family Picnic, Holiday Party, and other outings
  • Internal Culture Club