$81 - $99/hr
You will run the security change management review process, conduct risk and vendor assessments ... Experience with GRC or compliance automation platforms such as ServiceNow GRC, Vanta, Drata ...
$81 - $99/hr
You will run the security change management review process, conduct risk and vendor assessments ... Experience with GRC or compliance automation platforms such as ServiceNow GRC, Vanta, Drata ...
$81 - $99/hr
You will run the security change management review process, conduct risk and vendor assessments ... Experience with GRC or compliance automation platforms such as ServiceNow GRC, Vanta, Drata ...
$140 - $190/hr
... GRC program ... This role will be responsible for the governance, risk management, compliance, and assurance ...
$140 - $190/hr
... GRC program ... This role will be responsible for the governance, risk management, compliance, and assurance ...
$75 - $95/hr
Support third‑party and vendor risk assessments and evidence requests. * Route completed responses to the GRC Lead and management for review before submission. Research & Program Support -- support ...
New
$75 - $95/hr
Support third‑party and vendor risk assessments and evidence requests. * Route completed responses to the GRC Lead and management for review before submission. Research & Program Support -- support ...
New
$120 - $160/hr
Manage and track remediation of audit findings, exceptions, and risk acceptances, and conduct ... Hands-on experience administering a GRC or compliance automation platform such as Vanta, Drata ...
$120 - $160/hr
Manage and track remediation of audit findings, exceptions, and risk acceptances, and conduct ... Hands-on experience administering a GRC or compliance automation platform such as Vanta, Drata ...
$95K - $105K/yr
About the Role The Senior GRC Analyst acts as a strategic lead to advance security and risk operations. In this role, you will integrate people, policy, and technology to drive operational excellence ...
$95K - $105K/yr
About the Role The Senior GRC Analyst acts as a strategic lead to advance security and risk operations. In this role, you will integrate people, policy, and technology to drive operational excellence ...
$150 - $190/hr
As a fast-growing startup, we specialize in a wide range of GRC (governance, risk, and compliance) services that support frameworks across SOC 2, ISO 27001, GDPR, CMMC, NIST 800-171, NIST 800-53, and ...
$150 - $190/hr
As a fast-growing startup, we specialize in a wide range of GRC (governance, risk, and compliance) services that support frameworks across SOC 2, ISO 27001, GDPR, CMMC, NIST 800-171, NIST 800-53, and ...
$98 - $146/hr
The Governance, Risk & Compliance (GRC) Consultant serves as a subject matter expert supporting Quality Management System (QMS), Information Security Management System (ISMS), risk management, and ...
$98 - $146/hr
The Governance, Risk & Compliance (GRC) Consultant serves as a subject matter expert supporting Quality Management System (QMS), Information Security Management System (ISMS), risk management, and ...
$109 - $185/hr
This role sits within Northern Trust's Cyber security Governance, Risk and Compliance (GRC) organization , an integral part o f the strategic evolution of cyber risk management capabilities across ...
$109 - $185/hr
This role sits within Northern Trust's Cyber security Governance, Risk and Compliance (GRC) organization , an integral part o f the strategic evolution of cyber risk management capabilities across ...
$184 - $230/hr
Build a new Risk Analysis capability for coordinating risk identification, assessment, and ... Advance the three-lines-of-defense model and the broader GRC strategy, aligning ERM activity ...
$184 - $230/hr
Build a new Risk Analysis capability for coordinating risk identification, assessment, and ... Advance the three-lines-of-defense model and the broader GRC strategy, aligning ERM activity ...
$104 - $166/hr
Peraton Labs is hiring a Senior GRC / Third-Party Risk / Data Protection Analyst to own the governance, risk, and compliance engine of the engagement -- policy, control testing, and POA&M management ...
$104 - $166/hr
Peraton Labs is hiring a Senior GRC / Third-Party Risk / Data Protection Analyst to own the governance, risk, and compliance engine of the engagement -- policy, control testing, and POA&M management ...
$134 - $202/hr
We are looking for a GRC Analyst to join our Governance, Risk & Compliance (GRC) team. You will have the opportunity to manage and maintain ongoing compliance with security and privacy frameworks ...
$134 - $202/hr
We are looking for a GRC Analyst to join our Governance, Risk & Compliance (GRC) team. You will have the opportunity to manage and maintain ongoing compliance with security and privacy frameworks ...
GRC platform, risk, compliance, audit, or related professional certifications. * Experience working with large or complex organizations and cross-functional stakeholder groups. * Strong client ...
New
GRC platform, risk, compliance, audit, or related professional certifications. * Experience working with large or complex organizations and cross-functional stakeholder groups. * Strong client ...
New
$120 - $150/hr
The Senior Security Analyst, GRC supports the bank's enterprise security governance program ... This role oversees security policies, standards, risk governance, partners with third-party ...
$120 - $150/hr
The Senior Security Analyst, GRC supports the bank's enterprise security governance program ... This role oversees security policies, standards, risk governance, partners with third-party ...
GRC platform, risk, compliance, audit, or related professional certifications. * Experience working with large or complex organizations and cross-functional stakeholder groups. * Strong client ...
New
GRC platform, risk, compliance, audit, or related professional certifications. * Experience working with large or complex organizations and cross-functional stakeholder groups. * Strong client ...
New
$225 - $350/hr
About the Role We're looking for a GRC Lead who personally drives our certifications (SOC 2, ISO ... Day to day, you'll be managing audits, controls, and risk assessments. Alongside that, you'll be ...
New
$225 - $350/hr
About the Role We're looking for a GRC Lead who personally drives our certifications (SOC 2, ISO ... Day to day, you'll be managing audits, controls, and risk assessments. Alongside that, you'll be ...
New
$150 - $210/hr
As a fast-growing startup, we specialize in a wide range of GRC (governance, risk, and compliance) services that support frameworks across SOC 2, ISO 27001, GDPR, CMMC, NIST 800-171, NIST 800-53, and ...
$150 - $210/hr
As a fast-growing startup, we specialize in a wide range of GRC (governance, risk, and compliance) services that support frameworks across SOC 2, ISO 27001, GDPR, CMMC, NIST 800-171, NIST 800-53, and ...
$134 - $202/hr
About the role We are looking for a GRC Analyst to join our Governance, Risk & Compliance (GRC) team. You will have the opportunity to manage and maintain ongoing compliance with security and privacy ...
$134 - $202/hr
About the role We are looking for a GRC Analyst to join our Governance, Risk & Compliance (GRC) team. You will have the opportunity to manage and maintain ongoing compliance with security and privacy ...
$115 - $125/hr
Thrive Global is seeking a detail-oriented GRC (Governance, Risk, and Compliance) and Privacy Analyst to strengthen our security, compliance, and data privacy posture. In this role, you will own and ...
New
$115 - $125/hr
Thrive Global is seeking a detail-oriented GRC (Governance, Risk, and Compliance) and Privacy Analyst to strengthen our security, compliance, and data privacy posture. In this role, you will own and ...
New
$115 - $125/hr
Thrive Global is seeking a detail-oriented GRC (Governance, Risk, and Compliance) and Privacy Analyst to strengthen our security, compliance, and data privacy posture. In this role, you will own and ...
$115 - $125/hr
Thrive Global is seeking a detail-oriented GRC (Governance, Risk, and Compliance) and Privacy Analyst to strengthen our security, compliance, and data privacy posture. In this role, you will own and ...
GRC Consultant-CyberSecurity, Compliance Job Location: Erlanger, KY Job Type: Contract to Hire ... Conduct risk assessment on Applications Network Systems according to Client policies applicable ...
Quick apply
GRC Consultant-CyberSecurity, Compliance Job Location: Erlanger, KY Job Type: Contract to Hire ... Conduct risk assessment on Applications Network Systems according to Client policies applicable ...
| Aspect | Grc Risk | Grc Analyst |
|---|---|---|
| Certifications | ISO 31000, CRISC, COSO | CISA, CRISC, CISSP |
| Work Environment | Risk management teams, compliance departments | IT, audit, compliance teams |
| Industry Usage | Financial, healthcare, corporate sectors | IT, finance, consulting firms |
| Primary Focus | Identifying and managing enterprise risks | Analyzing controls, assessing risks in systems |
Grc Risk professionals focus on enterprise-wide risk management strategies, while Grc Analysts typically analyze specific controls and systems to identify vulnerabilities. Both roles require similar certifications and often work within the same industries, but Grc Risk has a broader scope in risk oversight, whereas Grc Analysts concentrate on detailed control assessments.
For Grc Risk jobs in Kentucky, the most frequently searched job titles are:
The top searched job categories for Grc Risk jobs in Kentucky are:

$81 - $99/hr
Other
Posted 9 days ago
NorthMark Compute & Cloud (NMC²) is backed by dedicated leadership and investment, with a clear mission as it operates at the bleeding edge of technology. Its goal is to scale and enhance the high-performance computing (HPC) and cloud infrastructure that supports its clients' research, production, and delivery, enabling breakthroughs that shape the industries of tomorrow. Its engineers build critical infrastructure to eliminate friction in scientific research, simulations, analysis, and decision-making, accelerating discovery and driving faster innovation.
THE POSITIONNMC² is hiring a GRC Analyst to join the Information Security team, reporting to the GRC & Privacy Manager and based at our Dallas, TX offices at Victory Commons. This role is the operational engine of NMC²'s security governance program - responsible for the processes, documentation, and cross-functional coordination that keep our compliance posture current and our risk exposure understood.
You will run the security change management review process, conduct risk and vendor assessments, maintain the enterprise risk register, and own the lifecycle of NMC²'s security policy library. Day-to-day, you will work closely with Engineering, Product, Legal, and Operations - acting as the connective tissue between technical teams and the governance structures that protect the business.
The right person for this role is equally at home authoring a policy document, running a risk workshop with a product team, and producing a clean risk summary for the CISO. You bring strong judgment about where governance adds real value, and you know how to design processes that people actually follow.
RESPONSIBILITIESOwn and operate the security change management review process - triaging incoming IT and infrastructure change requests, engaging Engineering and IT stakeholders, and documenting findings, approvals, and escalations.
Iterate on change management processes, runbooks, and risk criteria to reduce friction for low-risk changes while preserving appropriate rigor for high-risk ones.
Conduct security reviews for new products, features, third-party integrations, and vendor onboarding, applying a consistent risk-based assessment methodology and tracking remediation of identified gaps.
Facilitate threat identification workshops and risk discussions with Engineering, Product, and Operations for major initiatives or architectural changes.
Maintain and continuously improve the enterprise Information Security risk register, ensuring risks are clearly articulated, owned, prioritized, and tracked through to mitigation or acceptance.
Develop risk reporting dashboards and narrative summaries for the CISO and executive leadership; monitor the regulatory and threat landscape for emerging risks that warrant program attention.
Author, revise, and manage the organization's information security policy library - policies, standards, procedures, and guidelines - aligned to applicable frameworks including ISO 27001, SOC 2, and NIST CSF.
Manage the security exception process: collect requests, facilitate risk-based approvals with the GRC Manager, and track expiry and renewal.
Monitor adherence to governance processes across the business (change management, access reviews, training, exception management) and produce compliance metrics for security leadership.
Serve as a day-to-day point of contact for Engineering, Product, Legal, HR, and Operations on security governance questions, and represent the Information Security team in cross-functional forums such as the Change Advisory Board and Risk Committee.
REQUIREMENTSBachelor's degree in Information Systems, Computer Science, Business Administration, or a related field - or equivalent experience.
4-8 years of experience in GRC, information security governance, compliance, or risk management.
Hands-on experience owning or significantly contributing to security change management, risk assessment, or policy management processes.
Working knowledge of at least two major security frameworks or standards - ISO 27001, SOC 2 TSC, NIST CSF, NIST SP 800-53, or CIS Controls.
Experience developing, reviewing, and publishing information security policies, standards, and procedures.
Familiarity with risk register management: identifying, rating, tracking, and reporting on information security risks.
Experience with GRC or compliance automation platforms such as ServiceNow GRC, Vanta, Drata, Hyperproof, or Archer.
Proficiency with project and workflow tools (Jira, Confluence, or similar) for change tracking, risk registers, and policy workflows.
Strong written communication skills with the ability to translate technical security requirements into clear, accessible policy language for a non-technical audience.
Collaborative working style with demonstrated experience engaging stakeholders across Engineering, Legal, HR, and Operations.
One or more relevant certifications preferred: CISM, CRISC, CISA, CISSP, ISO 27001 Lead Implementer or Lead Auditor, or CompTIA Security+.