1

Grc Risk Analyst Jobs in Worcester, MA (NOW HIRING)

Senior Security Analyst

Woonsocket, RI · On-site

$92K - $120K/yr

Facilitate discussions between compliance, risk, technical, and business teams to keep remediation ... A desire to move into a GRC-focused career path. Everforth Apex is a world-class IT services ...

Grc Risk Analyst information

See Worcester, MA salary details

$15

$40

$65

How much do grc risk analyst jobs pay per hour?

As of Aug 16, 2026, the average hourly pay for grc risk analyst in Worcester, MA is $40.40, according to ZipRecruiter salary data. Most workers in this role earn between $29.76 and $49.18 per hour, depending on experience, location, and employer.

What is the difference between Grc Risk Analyst vs Compliance Analyst?

AspectGrc Risk AnalystCompliance Analyst
CertificationsISO 31000, FRM, CRISCISO 19600, CCEP, CISA
Work EnvironmentRisk management teams, corporate officesRegulatory departments, corporate offices
Industry UsageFinance, banking, insurance, corporate riskFinancial services, healthcare, manufacturing
Job FocusIdentifying, assessing, and mitigating risks across enterpriseEnsuring compliance with laws and regulations

While both roles involve regulatory and risk considerations, a Grc Risk Analyst focuses on enterprise-wide risk management strategies, whereas a Compliance Analyst concentrates on adherence to specific laws and regulations. Both roles require similar certifications and often work in overlapping industries, but their core responsibilities differ in scope and focus.

What is a GRC Risk Analyst?

GRC Risk Analysts are professionals who specialize in Governance, Risk, and Compliance (GRC) within an organization. They assess and manage risks related to business operations, ensure compliance with relevant laws and regulations, and help implement policies and controls to mitigate potential threats. These analysts work closely with management to identify vulnerabilities, develop risk management strategies, and monitor the effectiveness of compliance programs. Their goal is to protect the organization from financial, legal, and reputational harm while supporting business objectives.

What are the key skills and qualifications needed to thrive as a GRC Risk Analyst?

To thrive as a GRC (Governance, Risk, and Compliance) Risk Analyst, you need a solid understanding of risk management principles, regulatory requirements, and compliance frameworks, often supported by a degree in information security, business, or a related field. Familiarity with GRC platforms (such as RSA Archer or MetricStream), risk assessment methodologies, and certifications like CRISC or CISA is highly valuable. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and convey findings to stakeholders. These skills are critical for ensuring organizational compliance, minimizing risk exposure, and supporting informed decision-making.

What are some common challenges a GRC Risk Analyst might face when implementing new risk management frameworks within an organization?

A GRC Risk Analyst often encounters challenges such as resistance to change from stakeholders, integrating new frameworks with existing processes, and ensuring consistent understanding across departments. Aligning risk management practices with organizational goals while adhering to regulatory requirements can also be complex. Success in this role requires strong communication skills, adaptability, and the ability to educate and collaborate with team members from diverse backgrounds.

What are popular job titles related to Grc Risk Analyst jobs in Worcester, MA?

For Grc Risk Analyst jobs in Worcester, MA, the most frequently searched job titles are:

What job categories do people searching Grc Risk Analyst jobs in Worcester, MA look for?

The top searched job categories for Grc Risk Analyst jobs in Worcester, MA are:

What cities near Worcester, MA are hiring for Grc Risk Analyst jobs?

Cities near Worcester, MA with the most Grc Risk Analyst job openings:

Infographic showing various Grc Risk Analyst job openings in Worcester, MA as of August 2026, with employment types broken down into 1% As Needed, 86% Full Time, 11% Part Time, and 2% Contract. Highlights an 87% Physical, 5% Hybrid, and 8% Remote job distribution, with an average salary of $84,026 per year, or $40.4 per hour.

Principal Technology Risk Analyst - Program & Regulatory Assurance

Fidelity Investments

Smithfield, RI

Full-time

Re-posted 10 days ago


Fidelity Investments rating

8.7

Company rating: 8.7 out of 10

Based on 271 frontline employees who took The Breakroom Quiz

15th of 150 rated financial services


Job description

Job Description:

Title: Principal Technology Risk Analyst

Note: Fidelity will not provide immigration sponsorship for this position.

The Role

The Enterprise Technology Risk group is seeking a passionate, driven and experienced professional to contribute to the Technology Risk Program and Regulatory Assurance CoE team.This role is responsible for performing regulatory and program management responsibilities, including designing and maintaining technology controls to support program and regulatory requirements. This role will require networking and relationship management skills to collaborate with the Controls Testing team, and various business units and risk teams across the enterprise. You will be working on:

  • Ensuring risk and control taxonomy aligns with enterprise standards
  • Developing and monitoring technology controls for security and compliance
  • Providing technical support and acting as liaison for technology risk management
  • Managing control updates, annual mapping, and testing requirements
  • Design, document, and maintain Risk and Control Matrices (RCMs/RACMs) across business and IT processes
  • Continuously improve and standardize control documentation and governance practices
  • Overseeing control certification process
  • Partnering with Control Testing team to track progress and remediation
  • Representing ETRA in enterprise control initiatives and special projects
  • Supporting regulatory activities, risk assessments, and examinations
  • Leading and supporting SOX 404 compliance, including control documentation
  • Reviewing SOC reports, assessing CUECs, and communicating control gaps

The Team

The Technology Risk Program and Regulatory Assurance team is responsible for managing controls to support program requirements, monitoring the results of control testing to meet program requirements, and ensuring a consistent risk and control taxonomy is leveraged in accordance with enterprise best practices. Additionally, this team supports regulatory activities such as maintaining application, server, and database inventories by entity.Technology Risk is part of the broader Legal, Risk and Compliance group and partners with Corporate Audit, Enterprise Compliance, and Security to protect the interests of our customers, our employees, and Fidelity's brand. You will also work closely with the Enterprise Technology Risk teams as well as Fidelity technology and business owners, and Operational Risk teams.

The Expertise and Skills You Bring

  • 5 -7 years' experience in information technology risk, controls, or audit roles
  • Bachelor's degree in computer science, technology, or a related field of study preferred
  • Professional technology and associated risk certifications (CISSP, CISA, CRISC, CISM), Certified risk/fraud examiners (CRE, CFE), and/or Cloud Certification(s) (CCSP, CCSK, AWS) preferred
  • Experience documenting controls for large scale financial service organizations (cloud, distributed, vendor solutions, mainframe, network environments, and AI)
  • Demonstrated technical abilities in multiple areas (e.g., technology infrastructure and application controls, cyber security, access management, network and cloud, resiliency, etc.)
  • Working knowledge of Cloud security and controls and cloud technology environments (AWS/Azure, SaaS, PaaS)
  • You have a strong knowledge of information technology processes and controls, and a comprehensive understanding of risk, quality control and assurance functions
  • Your love of solving complex problems, and comfort with ambiguous situations, and your ability to help solution innovative ways to mitigate risk using your advanced analytical and critical thinking skills
  • Your ability to build and maintain collaborative working relationships with Information Technology and Business personnel to design effective controls
  • Your process orientation and understanding of operations and technology enabling you to provide support in the analysis, development, and monitoring of controls
  • Knowledge of Industry standards, regulations, frameworks and best practices, such as NIST SP 800-53, COBIT, AICPA Trust Principles, ISO27001, SWIFT, HITRUST, and SOX404 is preferred
  • ISO9001 and/or ISO27001 certification preferred, with responsibility to support and participate in ISO peer audit reviews.
  • Knowledge of Governance, Risk, and Compliance (GRC) tools, such as Archer is preferred
  • Your excellent verbal and written communication skills enabling you to prepare and present recommendations to senior management

Note: Fidelity will not provide immigration sponsorship for this position.

Fidelity's Onsite Working Model
Fidelity is transitioning to a full-time onsite working model through a phased rollout across regions and roles. Currently, some roles and locations require 100% onsite presence, while others require less. Onsite expectations are likely to evolve as the rollout continues. This transition does not apply to fully remote roles.

Certifications:Category:Information Technology

Please be advised that Fidelity's business is governed by the provisions of the Securities Exchange Act of 1934, the Investment Advisers Act of 1940, the Investment Company Act of 1940, ERISA, numerous state laws governing securities, investment and retirement-related financial activities and the rules and regulations of numerous self-regulatory organizations, including FINRA, among others. Those laws and regulations may restrict Fidelity from hiring and/or associating with individuals with certain Criminal Histories.


What Fidelity Investments employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom