1

Grc Risk Analyst Jobs in Tucson, AZ (NOW HIRING)

IT GRC Specialist

Tucson, AZ · On-site

$95 - $140/hr

Perform risk assessments, control effectiveness testing, and compliance evaluations. * Support ... Strong analytical skills with the ability to identify risks and develop practical remediation ...

Perform risk assessments, control effectiveness testing, and compliance evaluations. * Support ... Strong analytical skills with the ability to identify risks and develop practical remediation ...

Perform risk assessments, control effectiveness testing, and compliance evaluations. * Support ... Strong analytical skills with the ability to identify risks and develop practical remediation ...

Perform risk assessments, control effectiveness testing, and compliance evaluations. * Support ... Strong analytical skills with the ability to identify risks and develop practical remediation ...

Grc Risk Analyst information

See Tucson, AZ salary details

$14

$38

$62

How much do grc risk analyst jobs pay per hour?

As of Aug 29, 2026, the average hourly pay for grc risk analyst in Tucson, AZ is $38.28, according to ZipRecruiter salary data. Most workers in this role earn between $28.17 and $46.59 per hour, depending on experience, location, and employer.

What is a GRC Risk Analyst?

GRC Risk Analysts are professionals who specialize in Governance, Risk, and Compliance (GRC) within an organization. They assess and manage risks related to business operations, ensure compliance with relevant laws and regulations, and help implement policies and controls to mitigate potential threats. These analysts work closely with management to identify vulnerabilities, develop risk management strategies, and monitor the effectiveness of compliance programs. Their goal is to protect the organization from financial, legal, and reputational harm while supporting business objectives.

What are the key skills and qualifications needed to thrive as a GRC Risk Analyst?

To thrive as a GRC (Governance, Risk, and Compliance) Risk Analyst, you need a solid understanding of risk management principles, regulatory requirements, and compliance frameworks, often supported by a degree in information security, business, or a related field. Familiarity with GRC platforms (such as RSA Archer or MetricStream), risk assessment methodologies, and certifications like CRISC or CISA is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and convey findings to stakeholders. These skills are critical for ensuring organizational compliance, minimizing risk exposure, and supporting informed decision-making.

What are some common challenges a GRC Risk Analyst might face when implementing new risk management frameworks within an organization?

A GRC Risk Analyst often encounters challenges such as resistance to change from stakeholders, integrating new frameworks with existing processes, and ensuring consistent understanding across departments. Aligning risk management practices with organizational goals while adhering to regulatory requirements can also be complex. Success in this role requires strong communication skills, adaptability, and the ability to educate and collaborate with team members from diverse backgrounds.

What is the difference between Grc Risk Analyst vs Compliance Analyst?

AspectGrc Risk AnalystCompliance Analyst
CertificationsISO 31000, FRM, CRISCISO 19600, CCEP, CISA
Work EnvironmentRisk management teams, corporate officesRegulatory departments, corporate offices
Industry UsageFinance, banking, insurance, corporate riskFinancial services, healthcare, manufacturing
Job FocusIdentifying, assessing, and mitigating risks across enterpriseEnsuring compliance with laws and regulations

While both roles involve regulatory and risk considerations, a Grc Risk Analyst focuses on enterprise-wide risk management strategies, whereas a Compliance Analyst concentrates on adherence to specific laws and regulations. Both roles require similar certifications and often work in overlapping industries, but their core responsibilities differ in scope and focus.

What job categories do people searching Grc Risk Analyst jobs in Tucson, AZ look for?

The top searched job categories for Grc Risk Analyst jobs in Tucson, AZ are:

What cities near Tucson, AZ are hiring for Grc Risk Analyst jobs?

Cities near Tucson, AZ with the most Grc Risk Analyst job openings:

IT GRC Specialist

NovAtel Inc.

Tucson, AZ • On-site

$95 - $140/hr

Other

Posted 6 days ago


Job description

Overview

Hexagon’s Autonomous Solutions division is looking for an IT GRC Specialist to join our team in Tucson, AZ. Reporting to the appropriate IT leadership team, this role will support Hexagon Autonomous Solutions’ governance, risk, and compliance capability by ensuring IT systems, controls, and processes align with regulatory requirements, internal policies, and business-adopted standards while helping strengthen the security, integrity, and compliance posture of the organization.

The Location:This position is based in Tucson, AZ in a hybrid capacity.

The Company: Hexagon is a global leader in digital reality solutions, combining sensor, software, and autonomous technologies. We are putting data to work to boost efficiency, productivity, quality, and safety across industrial, manufacturing, infrastructure, public sector, and mobility applications.

Our technologies are shaping the production and people-related ecosystems to become increasingly connected and autonomous, ensuring a scalable, sustainable future.

Responsibilities

AsIT GRC Specialistyou will be responsible for these activities:

  • Support the implementation and maintenance of security controls aligned with industry-standard frameworks including ISO 27001, COBIT, SOX, and NIST.
  • Conduct regular reviews of corporate policies and procedures while serving as a key liaison for internal and external IT audits.
  • Perform gap assessments against business-adopted standards, regulatory requirements, and compliance frameworks while supporting remediation planning and execution.
  • Establish and maintain reporting on compliance health, risk status, and governance activities for assigned projects and initiatives.
  • Administer and enhance GRC platforms and associated IT governance processes.
  • Serve as the primary point of contact for IT compliance, governance, and audit-related activities.
  • Develop and maintain IT policies, standards, procedures, and process documentation.
  • Lead IT risk assessment activities and support broader information security risk management initiatives.
  • Perform risk assessments, control effectiveness testing, and compliance evaluations.
  • Support third-party risk management activities through risk assessments and vendor review processes.
  • Develop and maintain security awareness training programs for new employees and annual compliance training initiatives.
  • Collect, evaluate, and organize evidence supporting audits, investigations, customer requests, and compliance inquiries.
  • Assist with the completion of customer security and compliance questionnaires.
Qualifications

Must Have:

  • Bachelor’s degree in Computer Science, Computer Engineering, Management Information Systems, Information Technology, or a related field. Equivalent combinations of education, certifications, and experience will be considered.
  • 10+ years of experience working within large, complex IT environments.
  • Knowledge of information security standards and compliance requirements including ISO 27001, NIS2, NIST 800-171, CMMC, TISAX, and GDPR.
  • Experience with IT and information security technologies and controls including cybersecurity, networks, infrastructure, applications, cloud services, and enterprise platforms.
  • Proven experience in IT governance, risk management, and compliance.
  • Strong communication and interpersonal skills with the ability to work effectively with cross-functional stakeholders.

Nice To Have:

  • Professional certifications such as CISSP, CISA, CRISC, CGEIT, ISO 27001 Lead Implementer, or similar.
  • Experience supporting global manufacturing, industrial technology, or multinational organizations.
  • Experience with GRC platforms, audit management tools, and compliance automation solutions.

Key Success Factors:

  • Strong understanding of governance, risk, compliance, and information security principles.
  • Ability to build trusted relationships across IT, Information Security, Legal, Finance, Procurement, and business teams.
  • Strong analytical skills with the ability to identify risks and develop practical remediation strategies.
  • Excellent organizational skills with the ability to manage multiple audits, assessments, and compliance initiatives simultaneously.
  • Commitment to continuous improvement and operational excellence.
  • Ability to communicate complex compliance and risk concepts clearly to both technical and non-technical audiences.

At Hexagon, we are committed to a diverse and inclusive work environment.

#J-18808-Ljbffr