1

It Governance Risk Jobs (NOW HIRING)

IT Governance Analyst

Palo Alto, CA · On-site

$150K - $160K/yr

Adapt IT governance frameworks ( COBIT 2019, NIST CSF, CIS ) to fit both on-premise/co-located ... Present formal risk posture and compliance updates monthly to the executive team and risk ...

Technology Governance Manager

Midvale, UT · On-site

$89K - $109K/yr

The Technology Governance Manager plays a key role in developing, executing, and implementing ... Strong knowledge of information security standards, risk analysis, and regulatory requirements.

Position: IT Governance Analyst 1 Location: Lansing, MI 48933 REQ ID: 509124 Duration: 8 + Months ... Ensures issues are evaluated and resolved, escalates risk and directs corrective actions in any ...

Showing results 41-60

IT Governance Risk information

What is IT governance risk?

IT Governance Risk refers to the potential threats and vulnerabilities that can affect an organization's information technology systems, processes, and data. It involves identifying, assessing, and managing risks related to IT operations, compliance, security, and strategic alignment with business objectives. Effective IT governance risk management helps organizations ensure regulatory compliance, protect sensitive information, and support business continuity. Professionals in this field develop policies, procedures, and controls to mitigate risks and enable informed decision-making.

How does an IT governance risk professional typically collaborate with other departments within an organization?

IT Governance Risk professionals frequently work cross-functionally, partnering with departments such as IT, legal, compliance, and business units to ensure that risk management practices align with organizational objectives and regulatory requirements. This collaboration often involves facilitating risk assessments, developing and implementing policies, and providing guidance on risk mitigation strategies. Clear communication and strong relationship-building skills are key, as the role requires translating technical risks into business impacts and gaining buy-in from stakeholders across the company.

What are the key skills and qualifications needed to thrive as an IT governance, risk, and compliance (GRC) professional, and why are they important?

To thrive as an IT GRC professional, you need a solid understanding of information security principles, risk management frameworks, and relevant regulatory standards, often supported by a degree in IT or cybersecurity and certifications like CISA or CISSP. Familiarity with GRC tools such as RSA Archer, ServiceNow GRC, and risk assessment methodologies is typically required. Strong analytical thinking, attention to detail, and effective communication skills help you interpret complex regulations and collaborate with stakeholders. These competencies ensure effective risk mitigation, regulatory compliance, and alignment between IT and business objectives.

What is the difference between It Governance Risk vs It Security Analyst?

AspectIt Governance RiskIt Security Analyst
CertificationsCISA, CRISCCISSP, Security+
Work EnvironmentPolicy development, risk assessment, complianceMonitoring security systems, incident response
Industry UsageGovernance, risk management, compliance teamsSecurity operations teams, IT departments

It Governance Risk focuses on establishing policies, managing IT risks, and ensuring compliance across the organization. In contrast, an It Security Analyst primarily monitors security systems, investigates incidents, and implements security measures. While both roles require understanding of IT frameworks and certifications like CISA or CISSP, their core responsibilities differ: governance versus security operations.

Is IT governance risk and compliance a good career?

IT Governance Risk and Compliance is a growing field that involves managing an organization’s IT policies, security, and regulatory requirements. It requires knowledge of frameworks like ISO 27001 or COBIT and often benefits from certifications such as CISA or CISSP. The role offers opportunities in various industries with a focus on risk management, security, and compliance strategies.

What are the roles of IT governance risk?

IT governance risk involves identifying, assessing, and managing risks related to information technology to ensure alignment with organizational goals and compliance requirements. IT governance risk professionals develop policies, implement controls, and monitor systems to mitigate threats such as data breaches, cyberattacks, and operational failures, often using frameworks like COBIT or ISO 27001. Strong risk management helps organizations maintain security, improve decision-making, and ensure regulatory compliance.
More about IT Governance Risk jobs

What cities are hiring for It Governance Risk jobs?

Cities with the most It Governance Risk job openings:

Infographic showing various It Governance Risk job openings in the United States as of September 2026, with employment types broken down into 1% As Needed, 90% Full Time, 7% Part Time, and 2% Contract. Highlights an 82% Physical, 5% Hybrid, and 13% Remote job distribution.

IT Governance Analyst

Palo Alto, CA • On-site

TabaPay
Finance and Insurance • 11 - 50 employees

$150K - $160K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 24 days ago


Key responsibilities

  • Lead the development, implementation, and enforcement of IT governance frameworks across a hybrid computing environment.

  • Ensure all IT functions are audit-ready and maintain compliance with US regulatory standards such as PCI-DSS, FFIEC, SOC, and GLBA.

  • Support and oversee documentation of technical risks, disaster recovery, and business continuity strategies related to high-volume US payment systems.


Job description

Who We Are
The world is moving towards instant digital payments and TabaPay is leading the way. We help thousands of Fintechs in the US and Canada instantly move money in and out of accounts and we are actively expanding into other countries. Our customers represent the hottest verticals in the financial service industry such as neobanks, challenger brokers, gaming and wallets. TabaPay is a highly profitable rocketship that processes billions of dollars each year. To learn more visit www.tabapay.com.
What You'll Do
Lead the development, implementation, and enforcement of IT governance frameworks across a hybrid computing environment. Balance fast-paced fintech software deployments with the rigid security and compliance rules required for high-volume US payment systems. Ensure that all IT functions of organization are continuously audit-ready with regard to US financial institution (FFIEC) audit requirements as well as Payment Card Industry (PCI) DSS requirements and System and Organization Controls (SOC) audit expectations.
Core Responsibilities
US Regulatory Compliance & Audit Readiness
  • Maintain continuous compliance with PCI-DSS v4.0 (Level 1), FFIEC guidelines, SOC 1/2, and GLBA.
  • Act as the lead technical liaison for US regulatory exams (e.g., OCC, Federal Reserve, FDIC, state banking/money transmission regulators).
  • Support regular internal audits and mock exams to identify and patch compliance gaps before official audits.

Hybrid Environment Policy & Architecture Governance
  • Adapt IT governance frameworks (COBIT 2019, NIST CSF, CIS) to fit both on-premise/co-located servers and AWS or other cloud environments.
  • Govern strict data residency and sovereignty policies to keep sensitive US financial data isolated and compliant.
  • Enforce unified change management and secure software development lifecycle (SDLC) rules across both cloud and on-prem assets.

High-Volume Transaction Environment Documentation
  • Identify and document technical risks or other concerns unique to high-throughput US payment rails (e.g., FedNow, ACH, Fedwire, and Real-Time Payments/RTP).
  • Establish separate but integrated disaster recovery (DR) and business continuity (BCP) strategies for cloud systems and physical data centers.
  • Facilitate vendor management processes for critical third-party IT-related vendors.

Metrics, Reporting & Accountability
  • Design and track Key Performance Indicators (KPIs) and Key Risk Indicators (KRIs) for hybrid operational stability.
  • Present formal risk posture and compliance updates monthly to the executive team and risk committees.
  • Chair the hybrid change advisory board (CAB) to safely approve complex cross-environment code deployments.

Key Requirements
Experience & Education
  • Education: Bachelor's degree in Management Information Systems (MIS), Cybersecurity, Finance, or Computer Science.
  • Fintech/Banking Experience: 5 to 7 years in IT governance, risk, or compliance (GRC) inside a US financial institution, regulated payment processor, or equivalent.
  • Payment Domain Knowledge: At least 3 years of experience in an environment that processes high-volume US payment rails and card networks.

Required Certifications (At least two preferred)
  • CGEIT (Certified in the Governance of Enterprise IT)
  • CRISC (Certified in Risk and Information Systems Control)
  • CISA (Certified Information Systems Auditor)
  • CISSP (Certified Information Systems Security Professional)

Technical & Soft Skills
  • Regulatory Expertise: Expert-level mastery of FFIEC handbooks, PCI-DSS, and US federal banking privacy laws.
  • Hybrid Tech Literacy: Strong understanding of hybrid models (e.g., connecting on-prem database architecture with containerized cloud microservices).
  • Communication: Ability to confidently bridge the gap between fast-moving DevOps engineers and conservative corporate bank attorneys.

Performance Success Metrics
  • Flawless US Regulatory Audits: Zero material or critical findings from the FFIEC, OCC, or external accounting auditors.
  • Unified Environment Controls: Successful deployment of governance policies that apply equally well to cloud infrastructure and physical servers.
  • Safe Velocity: Maintenance of high-throughput payment uptimes without blocking the engineering department's agile sprint schedule.

The compensation for this position is $150,000 - $160,000. However, base pay offered may vary depending on job-related knowledge, skills, and experience. In addition to a full range of medical, financial, and/or other benefits, dependent on the position offered.
Benefits
TabaPay offers the following benefits:
  • 100% employer-paid health care insurance including medical, dental, vision, and life insurance (for employee only)
  • Employer 401K Matching
  • Generous and Flexible PTO

EEO Employer: TabaPay is an equal opportunity employer; all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, Veteran status, or any other protected classification.