1

Grc Security Analyst Jobs (NOW HIRING)

$70K - $92K/yr

The Senior Security Analyst, GRC supports the bank's enterprise security governance program, ensuring alignment with regulatory expectations, enterprise risk management, and industry frameworks. This ...

Security Analyst

Lansing, MI · On-site

$45 - $55/hr

Security Analyst Public Sector Client Location: Lansing, MI - Hybrid on site Monday and Tuesday ... Experience with Keylight or similar GRC/security authorization platforms. * Experience working with ...

... the security models for all SAP SaaS platforms - including SAP Ariba, SAP Analytics Cloud (SAC ... The GRC Lead acts as the primary point of accountability for SoD risk mitigation, access ...

... the security models for all SAP SaaS platforms - including SAP Ariba, SAP Analytics Cloud (SAC ... The GRC Lead acts as the primary point of accountability for SoD risk mitigation, access ...

SAP Security Analyst Location: White Plains, NY Duration: 12 Months Job Functions ... Ensure Secure integration with other on-premise and cloud applications, such as the GRC tool.

Showing results 21-40

Grc Security Analyst information

See salary details

$39.5K

$107.3K

$141K

How much do grc security analyst jobs pay per year?

As of Sep 10, 2026, the average yearly pay for grc security analyst in the United States is $107,334.00, according to ZipRecruiter salary data. Most workers in this role earn between $91,500.00 and $130,000.00 per year, depending on experience, location, and employer.

What is the difference between Grc Security Analyst vs Security Compliance Analyst?

AspectGrc Security AnalystSecurity Compliance Analyst
CertificationsISO 27001, CISSP, CISAISO 27001, CISSP, CISA
Work EnvironmentRisk management, policy development, governanceAudits, compliance assessments, policy enforcement
Industry UsageIT, finance, healthcare, governmentIT, finance, healthcare, government

Grc Security Analysts focus on managing overall governance, risk, and compliance frameworks, ensuring organizations meet security standards. Security Compliance Analysts primarily conduct audits and enforce policies to ensure regulatory adherence. While both roles require similar certifications and work in comparable environments, Grc Security Analysts have a broader scope in risk management, whereas Compliance Analysts focus on specific regulatory requirements.

Are GRC Security Analysts in demand?

GRC Security Analysts are in high demand due to increasing cybersecurity threats and regulatory compliance requirements. Organizations seek professionals with skills in risk management, policy development, and familiarity with tools like GRC software, making this a growing field with strong job prospects.

What does a GRC security analyst do?

A GRC (Governance, Risk, and Compliance) security analyst is responsible for developing and implementing security policies, assessing risks, and ensuring compliance with industry standards and regulations. They analyze security controls, conduct audits, and use tools like risk management frameworks to protect organizational information assets.

What cities are hiring for Grc Security Analyst jobs?

Cities with the most Grc Security Analyst job openings:

What states have the most Grc Security Analyst jobs?

States with the most job openings for Grc Security Analyst jobs include:

What are popular job titles related to Grc Security Analyst jobs?

For Grc Security Analyst jobs, the most frequently searched job titles are:

Senior Security Analyst, GRC

On-site

GreatAmerica Financial Services Corporation
Finance and Insurance • 501 - 1,000 employees

$70K - $92K/yr

Other

Medical, Dental, Vision, Life, Retirement, PTO

Posted 23 days ago


Job description

## Senior Security Analyst, GRCApplylocations: REMOTEtime type: Full timeposted on: Posted Yesterdayjob requisition id: JR1195GreatAmerica Financial Services is a highly successful entrepreneurial company providing equipment financing to businesses across the United States. Our exemplary customer service, our principle-centered business philosophy and our team-based operating approach are key to our success and growth.**We are looking to add a Key Member to our Enterprise Security Team!**The Senior Security Analyst, GRC supports the bank’s enterprise security governance program, ensuring alignment with regulatory expectations, enterprise risk management, and industry frameworks. This role oversees security policies, standards, risk governance, partners with third-party security oversight, and provides support for regulatory engagement. The Senior Analyst partners with technology, risk, compliance, and audit teams to strengthen the bank’s Enterprise Security Governance framework and ensures effective operation of the three lines of defense by independently reviewing control effectiveness designed by first-line security engineering and IT operations.*GreatAmerica welcomes applications from candidates residing the following states, where we currently support employment and payroll operations: Arizona, Florida, Georgia, Iowa, Kansas, Michigan, Missouri, Nebraska, South Dakota, Tennessee, Texas, and Wisconsin.***As a Senior Security Analyst, GRC, you will:**Security Governance & Policy* Support the development and maintenance of the bank’s information security governance framework.* Track the lifecycle of security policies and standards, reporting non-compliance to the policy owners.* Ensure alignment with regulatory guidance from the Federal Financial Institutions Examination Council and banking regulators.* Maintain governance artifacts including policy exception processes and control documentation.* Independently review first-line procedures for alignment with approved policies and standards.Risk & Compliance Oversight (Second Line)* Support enterprise risk management by coordinating information security risk assessments.* Track and manage the security risk register.* Monitor and independently validate remediation of identified risks and control gaps.* Independently assess controls built and operated by first-line security engineering and IT operations teams and formally challenge control design, ownership, and evidence sufficiency through the second-line issue and escalation process.Regulatory & Audit Management* Act as the primary security governance liaison for regulators and auditors.* Support exams and reviews conducted by applicable agencies.* Coordinate and support responses to regulatory findings, internal audit issues, and external requests from customers.Security Metrics & Reporting* Develop and maintain security governance reporting for executive leadership.* Produce dashboards for: + Risk posture + Policy compliance + Control effectiveness + Incident trends* Support the presentation of quarterly updates to risk committees and senior management.Framework Alignment & Continuous Improvement* Maintain governance alignment with industry frameworks – NIST CSF, NIST RMF, CIS, ITGC* Recommend and support improvements to governance processes and tooling (Optro/Auditboard)* Collaborate across legal, compliance, risk, and technology functions**To be successful in the role, you will need:*** Bachelor’s degree or equivalent preferred.* Minimum of 5 years of work experience in information security, risk, security governance or audit* Strong knowledge of information security governance, risk management, regulatory compliance, and control frameworks, preferably within banking or regulated financial services.* Working knowledge of banking regulatory expectations, FFIEC guidance, and recognized security frameworks such as NIST CSF, NIST RMF, CIS, and ITGC.* Experience supporting regulatory exams, audit reviews, external customer requests, findings, issue management, and remediation tracking**Skills and Abilities*** Ability to maintain security policies, standards, governance artifacts, risk registers, control documentation, and policy exception processes.* Ability to independently assess control design, ownership, evidence sufficiency, remediation status, and operating effectiveness within a second-line risk oversight model.* Strong analytical and reporting skills, including the ability to develop dashboards and communicate risk posture, policy compliance, control effectiveness, and incident trends.* Ability to partner effectively across security, technology, risk, compliance, audit, legal, and business teams while maintaining appropriate independence and challenge.* Strong written and verbal communication skills, including the ability to document complex topics clearly and support updates to senior leaders, risk committees, auditors, and regulators.* Strong organizational, project coordination, follow-through, and judgment skills, with the ability to manage competing priorities and respond effectively to time-sensitive work.**Preferred Certifications*** ISACA CISA* ISACA CRISC* ISC2 CGRC* ISC2 CISSPISACA CISM **Other Requirements*** Exceptional organizational, analytical, and follow-through skills.* Excellent verbal and written communication skills.* Role will likely include periodic large project-oriented demands with tight deadlines requiring more than standard work hours and the need to respond quickly.* Must demonstrate sound business judgment.Sharing rewards is an integral part of our culture. We believe in the value of hard work and reward our employees beyond the paycheck. Our total rewards package is based on eligibility and includes:**Financial Benefits*** Competitive Compensation* Monthly Bonuses for Eligible Employees* 401(k) and Company Match* Annual Profit Sharing* Paid Time Off**Health, Wellbeing, and Family Planning Benefits*** Paid Vacation - starting at 80 hours annually for employees in their first year of service.* Paid Sick Days - Ten (10) per year with a conversion option for unused time.* Ten (10) Paid Holidays per year* Gym Reimbursement* Health Insurance* Dental Insurance* Vision Insurance* Short-Term and Long Term Disability* Company Paid Life Insurance* Flexible Spending Accounts (FSA)* Health Savings Accounts (HSA)* Employee Assistance Program* Parental Leave**Education and Career Planning Benefits*** Tuition Assistance* Networking Opportunities* Leadership Development Opportunities**Perks*** Paid Parking* Service Awards* Hybrid work arrangements* Business casual environment* A strong organizational culture focused on our greatest asset: **you**!*If your experience aligns closely, please apply. We value diverse backgrounds and adding new perspectives. We encourage you to apply if you can make a strong impact in this role at www.greatamerica.com/careers.* #J-18808-Ljbffr