1

Grc Risk Analyst Jobs in Seattle, WA (NOW HIRING)

Showing results 41-52

Grc Risk Analyst information

See Seattle, WA salary details

$17

$46

$74

How much do grc risk analyst jobs pay per hour?

As of Aug 10, 2026, the average hourly pay for grc risk analyst in Seattle, WA is $46.07, according to ZipRecruiter salary data. Most workers in this role earn between $33.94 and $56.06 per hour, depending on experience, location, and employer.

What is the difference between Grc Risk Analyst vs Compliance Analyst?

AspectGrc Risk AnalystCompliance Analyst
CertificationsISO 31000, FRM, CRISCISO 19600, CCEP, CISA
Work EnvironmentRisk management teams, corporate officesRegulatory departments, corporate offices
Industry UsageFinance, banking, insurance, corporate riskFinancial services, healthcare, manufacturing
Job FocusIdentifying, assessing, and mitigating risks across enterpriseEnsuring compliance with laws and regulations

While both roles involve regulatory and risk considerations, a Grc Risk Analyst focuses on enterprise-wide risk management strategies, whereas a Compliance Analyst concentrates on adherence to specific laws and regulations. Both roles require similar certifications and often work in overlapping industries, but their core responsibilities differ in scope and focus.

What is a GRC Risk Analyst?

GRC Risk Analysts are professionals who specialize in Governance, Risk, and Compliance (GRC) within an organization. They assess and manage risks related to business operations, ensure compliance with relevant laws and regulations, and help implement policies and controls to mitigate potential threats. These analysts work closely with management to identify vulnerabilities, develop risk management strategies, and monitor the effectiveness of compliance programs. Their goal is to protect the organization from financial, legal, and reputational harm while supporting business objectives.

What are the key skills and qualifications needed to thrive as a GRC Risk Analyst?

To thrive as a GRC (Governance, Risk, and Compliance) Risk Analyst, you need a solid understanding of risk management principles, regulatory requirements, and compliance frameworks, often supported by a degree in information security, business, or a related field. Familiarity with GRC platforms (such as RSA Archer or MetricStream), risk assessment methodologies, and certifications like CRISC or CISA is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and convey findings to stakeholders. These skills are critical for ensuring organizational compliance, minimizing risk exposure, and supporting informed decision-making.

What are some common challenges a GRC Risk Analyst might face when implementing new risk management frameworks within an organization?

A GRC Risk Analyst often encounters challenges such as resistance to change from stakeholders, integrating new frameworks with existing processes, and ensuring consistent understanding across departments. Aligning risk management practices with organizational goals while adhering to regulatory requirements can also be complex. Success in this role requires strong communication skills, adaptability, and the ability to educate and collaborate with team members from diverse backgrounds.
What job categories do people searching Grc Risk Analyst jobs in Seattle, WA look for? The top searched job categories for Grc Risk Analyst jobs in Seattle, WA are:

Data Governance Specialist III

Fred Hutchinson Cancer Center

Seattle, WA • On-site

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Re-posted yesterday


Job description

Overview
Fred Hutchinson Cancer Center is an independent, nonprofit organization providing adult cancer treatment and groundbreaking research focused on cancer and infectious diseases. Based in Seattle, Fred Hutch is the only National Cancer Institute-designated cancer center in Washington.
With a track record of global leadership in bone marrow transplantation, HIV/AIDS prevention, immunotherapy and COVID-19 vaccines, Fred Hutch has earned a reputation as one of the world's leading cancer, infectious disease and biomedical research centers. Fred Hutch operates eight clinical care sites that provide medical oncology, infusion, radiation, proton therapy and related services, and network affiliations with hospitals in five states. Together, our fully integrated research and clinical care teams seek to discover new cures to the world's deadliest diseases and make life beyond cancer a reality.
At Fred Hutch we value collaboration, compassion, determination, excellence, innovation, integrity and respect. Our mission is directly tied to the humanity, dignity and inherent value of each employee, patient, community member and supporter. Our commitment to learning across our differences and similarities make us stronger. We seek employees who bring different and innovative ways of seeing the world and solving problems.
The Data Governance Specialist III designs, implements, and operates the enterprise data governance program within Fred Hutch's Information Security function. The role centers on protecting sensitive clinical, research, and operational data - ensuring it is properly classified, controlled, and used in compliance with applicable regulations and institutional policy.
This role works closely with the Office of the Chief Data Officer (OCDO), GRC, Privacy, Legal, and research and clinical business units to put data governance into practice and brings both technical depth and policy fluency to one of the organization's most critical compliance functions.
Most Fred Hutch jobs require some on-campus work. However, there may be flexibility for certain positions. Please check with the recruiter if you are an out-of-state applicant interested only in working outside of the Seattle area.
Responsibilities
Data Governance Program
  • Own and maintain the enterprise data classification and handling program, including policies, standards, and data inventories.
  • Develop and operate processes for data lifecycle management - covering data ownership/stewardship, data lineage, retention, de-identification, and secondary use in research and clinical contexts.
  • Partner with OCDO, Privacy, and Legal to ensure data governance policies are consistently applied across systems, cloud services, and research platforms.
  • Provide governance guidance on projects involving data collection, integration, analytics, and AI/ML use cases, including IRB-adjacent data use considerations.

Compliance & Risk
  • Assess data-related risks across systems, applications, third-party vendors, and cloud environments; track and drive remediation.
  • Support external audits and assessments involving data (HIPAA, HITRUST, research compliance), including evidence preparation and response coordination.
  • Collaborate with Privacy and Legal to interpret and operationalize current and emerging regulations: HIPAA/HITECH (including the 2025 Security Rule updates), GDPR, the Common Rule, and FDA 21 CFR Part 11.
  • Maintain data protection impact assessments, handling standards, and records of processing activities and policy exceptions.

Operations & Tooling
  • Recommend and oversee data protection technologies including DLP, CASB, DSPM, and data discovery/classification tools.
  • Maintain enterprise data flow documentation: systems of record, data transfers, cross-border flows, and third-party obligations.
  • Work with Security Operations monitoring for data-related threats (exfiltration, misuse); support incident response scoping and regulatory notification requirements.
  • Define and report metrics on data governance program effectiveness for executive and regulatory audiences.

Training & Collaboration
  • Deliver targeted awareness training on data handling, classification, and secure use of cloud and collaboration platforms.
  • Mentor team members and contribute to maturing data governance practices across the organization.

Qualifications
MINIMUM QUALIFICATIONS:
  • Bachelor's degree in information technology, computer science, business analytics, statistics, data science, public health, or other scientific or health-related field.
  • Minimum 9 years of experience in data analytics, data management, governance, privacy, security or related disciplines (a Master's degree can substitute for two years of professional experience).
  • Strong evidence of excellent cross-discipline communication via written and verbal communication with ability to present complex technical information in a clear and concise manner to a variety of audiences, including executives and non-technical leaders.
  • Demonstrated expertise in managing enterprise-wide governance initiatives across data domains.
  • Demonstrated ability to scale and sustain external and internal initiatives and partnerships around data governance functions.

PREFERRED QUALIFICATIONS:
  • Hands-on experience with data protection and governance tools (DLP, DSPM, data classification/discovery tools, data catalogs, or equivalent).
  • Working knowledge of healthcare and research regulatory frameworks: HIPAA/HITECH, the Common Rule, FDA 21 CFR Part 11, and related state privacy laws.
  • Familiarity with security and risk frameworks: NIST 800-53, NIST CSF, HITRUST CSF, and NIST AI RMF.
  • Proven ability to translate complex regulatory and policy requirements into practical controls and operational processes.
  • Strong written and verbal communication skills; comfortable presenting data risk topics to executive and non-technical audiences.
  • High integrity and sound judgment when handling sensitive, confidential information.
  • Experience in a research or academic medical center environment, including familiarity with research data sharing agreements, data use agreements (DUAs), and IRB processes.
  • Experience integrating GRC platforms with data governance and security tooling for control monitoring and evidence collection.
  • Proficiency with cloud data platforms (Azure, AWS) and modern data architectures (data lakes, pipelines, analytics platforms).
  • Experience evaluating AI/ML pipelines and data sets for compliance, privacy, and ethical use requirements.
  • Ability to script or automate governance processes (Python, PowerShell, or API integrations).
  • Relevant certifications: CDMP, CIPT, CIPP/US, HCISPP, CISSP, CISM, CRISC, or HITRUST CCSFP.

The annual base salary range for this position is from $115,170 to $182,021, and pay offered will be based on experience and qualifications.
Most Fred Hutch jobs require some on-campus work. However, there may be flexibility for certain positions. Please check with the recruiter if you are an out-of-state applicant interested only in working outside of the Seattle area. This position may be eligible for a sign-on bonus.
Although Fred Hutch is not sponsoring most H-1B visas at this time, candidates who already hold an H-1B sponsored by another organization and are currently in the U.S. may be eligible for this position.
Fred Hutchinson Cancer Center offers employees a comprehensive benefits package designed to enhance health, well-being, and financial security. Benefits include medical/vision, dental, flexible spending accounts, life, disability, retirement, family life support, employee assistance program, onsite health clinic, tuition reimbursement, paid vacation (12-22 days per year), paid sick leave (12-25 days per year), paid holidays (13 days per year), and paid parental leave (up to 4 weeks).
Additional Information
We are proud to be an Equal Employment Opportunity (EEO) and Vietnam Era Veterans Readjustment Assistance Act (VEVRAA) Employer. We do not discriminate on the basis of race, color, religion, creed, ancestry, national origin, sex, age, disability (physical or mental), marital or veteran status, genetic information, sexual orientation, gender identity, political ideology, or membership in any other legally protected class. We desire priority referrals of protected veterans. If due to a disability you need assistance/and or a reasonable accommodation during the application or recruiting process, please send a request to Human Resources at hrops@fredhutch.org or by calling 206-667-4700.