1

Grc Risk Analyst Jobs in Raleigh, NC (NOW HIRING)

At Abrigo, we provide market-leading compliance, credit risk and lending software solutions that ... financial institution, or GRC at a technology company * Hands-on experience managing or ...

At Abrigo, we provide market-leading compliance, credit risk and lending software solutions that ... financial institution, or GRC at a technology company * Hands-on experience managing or ...

ACA Group is the leading governance, risk, and compliance (GRC) advisor in financial services. We empower our clients to reimagine GRC and protect and grow their business. Our innovative approach ...

Senior Security Engineer II

Raleigh, NC ยท On-site

$95K - $158K/yr

... Risk, and Compliance (GRC) foundation across our cloud-based environment. This role will focus on ... We're one of the largest information and analytics companies on the planet. We design solutions ...

Senior Security Engineer II

Raleigh, NC ยท On-site

$95K - $158K/yr

... Risk, and Compliance (GRC) foundation across our cloud-based environment. This role will focus on ... We're one of the largest information and analytics companies on the planet. We design solutions ...

Senior Security Engineer II

Raleigh, NC ยท Hybrid

$95K - $158K/yr

... Risk, and Compliance (GRC) foundation across our cloud-based environment. This role will focus on ... We're one of the largest information and analytics companies on the planet. We design solutions ...

Senior Security Engineer II

Raleigh, NC ยท Hybrid

$95K - $158K/yr

... Risk, and Compliance (GRC) foundation across our cloud-based environment. This role will focus on ... We're one of the largest information and analytics companies on the planet. We design solutions ...

... Security Analytics, Enterprise GRC Solutions, Automated External Application Scanning, and ... A Security and Risk professional developing and delivering solutions that protect enterprise ...

New

AI Operations Engineer

Durham, NC ยท Hybrid

$67K - $90K/yr

The ideal candidate is detail-oriented, analytical, and excited about working hands-on with modern ... ACA Group is the leading governance, risk, and compliance (GRC) advisor in financial services. We ...

AI Operations Engineer

Durham, NC ยท On-site

$67K - $90K/yr

The ideal candidate is detail-oriented, analytical, and excited about working hands-on with modern ... ACA Group is the leading governance, risk, and compliance (GRC) advisor in financial services. We ...

Analyze client issues and develop approaches to remediate them. * Act as the main RegTech POC ... We are the leading governance, risk, and compliance (GRC) advisor in financial services. When you ...

Senior Angular Engineer

Durham, NC ยท On-site

$125K - $156K/yr

Who Are We ACA Group ("ACA") is the leading governance, risk, and compliance (GRC) advisor in ... analytics to help risk and compliance officers simplify and streamline their regulatory and ...

next page

Showing results 1-20

Grc Risk Analyst information

See Raleigh, NC salary details

$14

$39

$64

How much do grc risk analyst jobs pay per hour?

As of Jun 19, 2026, the average hourly pay for grc risk analyst in Raleigh, NC is $39.36, according to ZipRecruiter salary data. Most workers in this role earn between $28.99 and $47.88 per hour, depending on experience, location, and employer.

What is the difference between Grc Risk Analyst vs Compliance Analyst?

AspectGrc Risk AnalystCompliance Analyst
CertificationsISO 31000, FRM, CRISCISO 19600, CCEP, CISA
Work EnvironmentRisk management teams, corporate officesRegulatory departments, corporate offices
Industry UsageFinance, banking, insurance, corporate riskFinancial services, healthcare, manufacturing
Job FocusIdentifying, assessing, and mitigating risks across enterpriseEnsuring compliance with laws and regulations

While both roles involve regulatory and risk considerations, a Grc Risk Analyst focuses on enterprise-wide risk management strategies, whereas a Compliance Analyst concentrates on adherence to specific laws and regulations. Both roles require similar certifications and often work in overlapping industries, but their core responsibilities differ in scope and focus.

What are GRC Risk Analysts?

GRC Risk Analysts are professionals who specialize in Governance, Risk, and Compliance (GRC) within an organization. They assess and manage risks related to business operations, ensure compliance with relevant laws and regulations, and help implement policies and controls to mitigate potential threats. These analysts work closely with management to identify vulnerabilities, develop risk management strategies, and monitor the effectiveness of compliance programs. Their goal is to protect the organization from financial, legal, and reputational harm while supporting business objectives.

What are the key skills and qualifications needed to thrive as a GRC Risk Analyst, and why are they important?

To thrive as a GRC (Governance, Risk, and Compliance) Risk Analyst, you need a solid understanding of risk management principles, regulatory requirements, and compliance frameworks, often supported by a degree in information security, business, or a related field. Familiarity with GRC platforms (such as RSA Archer or MetricStream), risk assessment methodologies, and certifications like CRISC or CISA is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and convey findings to stakeholders. These skills are critical for ensuring organizational compliance, minimizing risk exposure, and supporting informed decision-making.

What are some common challenges a GRC Risk Analyst might face when implementing new risk management frameworks within an organization?

A GRC Risk Analyst often encounters challenges such as resistance to change from stakeholders, integrating new frameworks with existing processes, and ensuring consistent understanding across departments. Aligning risk management practices with organizational goals while adhering to regulatory requirements can also be complex. Success in this role requires strong communication skills, adaptability, and the ability to educate and collaborate with team members from diverse backgrounds.
What cities near Raleigh, NC are hiring for Grc Risk Analyst jobs? Cities near Raleigh, NC with the most Grc Risk Analyst job openings:
Sr. Manager, Information Security

Sr. Manager, Information Security

Advance Auto Parts

Raleigh, NC โ€ข Hybrid

Full-time

Posted 29 days ago


Job description

Job Description

Role Summary

The Cybersecurity Compliance Manager is responsible for designing, operating, and continuously improving the company's cybersecurity compliance program within a largescale retail environment. This role leads the daytoday execution of compliance activities using the OneTrust GRC platform, with a strong focus on automation, controls monitoring, and auditready evidence generation.

The role ensures enterprise alignment with NIST Cybersecurity Framework (CSF) and regulatory requirements including PCI DSS, HIPAA, and U.S. state privacy regulations (CCPA/CPRA).

This role is hybrid and based in our corporate headquarters in Raleigh, NC.

Key Responsibilities

Cybersecurity Compliance Program Execution

  • Operate and mature the enterprise cybersecurity compliance program aligned to NIST CSF and applicable regulatory frameworks (PCI DSS, HIPAA, CCPA/CPRA).
  • Translate regulatory and framework requirements into clear, monitored internal controls mapped to business systems and processes.
  • Serve as a subject matter expert for cybersecurity control compliance across IT, cloud, retail, ecommerce, and corporate environments.
  • Lead daytoday use of the OneTrust GRC compliance modules, including:
    • Control libraries and framework mappings
    • Automated evidence collection and surveys
    • Workflowdriven control testing and remediation tracking
    • Compliance reporting and dashboards
  • Implement and enhance automation to reduce manual effort and eliminate pointintime compliance gaps.
  • Partner with IT, Audit and Security teams to integrate OneTrust with upstream systems where feasible (e.g., vulnerability management, asset inventories).

Controls Monitoring & Assurance

  • Establish and operate a continuous controls monitoring (CCM) model in dynamic retail and cloud environments.
  • Monitor control performance, SLA adherence, and exception trends across inscope systems (e.g., PCI environments, customer data platforms).
  • Track control effectiveness metrics and produce regular compliance reporting for leadership.
  • Coordinate and support internal and external audits and assessments, including:
    • PCI DSS attestations
    • HIPAA risk and compliance reviews
    • Privacy regulatory inquiries and assessments
  • Maintain auditready evidence within OneTrust and drive timely remediation of findings.
  • Partner with IT, Internal Audit, Legal, and Privacy to ensure consistent interpretation and execution of control requirements.
  • Work closely with system owners, IT leaders, cybersecurity team, and business partners to ensure controls are properly implemented and operated.
  • Assign control ownership, track accountability, and facilitate risk acceptance where appropriate.
  • Provide guidance and training to control owners on compliance expectations, evidence requirements, and remediation processes.

Required Qualifications

  • 6+ years of experience in cybersecurity compliance, GRC, or IT risk management, preferably in a retail or consumerfacing enterprise.
  • Strong working knowledge of:
    • NIST Cybersecurity Framework (CSF)
    • PCI DSS
    • HIPAA Security Rule
    • CCPA/CPRA and U.S. privacy obligations
  • Experience supporting audits and regulatory assessments in complex, distributed environments.

Preferred Qualifications

  • Handson experience with OneTrust GRC (or comparable GRC platforms) including compliance automation and evidence workflows.
  • Experience implementing continuous controls monitoring (CCM) or security metrics programs.
  • Retail industry experience supporting pointofsale (POS), ecommerce, or cardholder data environments (CDE).
  • Familiarity with thirdparty risk and vendor compliance monitoring.
  • Relevant certifications (preferred, not required):
    • CISA, CISSP, CRISC, PCI ISA, or similar.

Key Competencies

  • Strong analytical and riskbased thinking
  • Ability to translate regulatory language into practical, businessaligned controls
  • Excellent stakeholder communication and influence skills
  • Detailoriented with a strong audit and evidence mindset
  • Comfortable operating in fastmoving, matrixed retail organizations
We are an Equal Opportunity Employer and do not discriminate against any employee or applicant for employment because of race, color, sex, age national origin, religion, sexual orientation, gender identity, status as a veteran and basis of disability or any other federal, state or local protected class. We comply with all applicable federal, state, and local laws.

California Residents click below for Privacy Notice:

https://jobs.advanceautoparts.com/us/en/disclosures

Advance Auto Parts logo

About Advance Auto Parts

Sourced by ZipRecruiter

At Advance Auto Parts we have a passion for YES. Each day we are motivated by a passion to help our Customers. We have a commitment to advance the lives of our fellow Team Members, Customers, and the Communities where we live and work.

Industry

Motor vehicle and motor vehicle parts wholesalers, retail, internet and it and elementary and secondary schools

Company size

10,000+ Employees

Headquarters location

Raleigh, NC, US