1

It Governance Risk Compliance Jobs (NOW HIRING)

... technology teams aligned under the Chief Information Officer. This role executes governance, risk, and compliance activities aligned with regulatory frameworks and internal policies. Core ...

AVP, IT & AI Governance

New York, NY · On-site

$171K - $215K/yr

The AVP will oversee IT governance, AI governance, model risk alignment, technology risk management, and regulatory compliance across the organization. This role serves as a key control function ...

IT Security and Governance Analyst

Louisville, KY · On-site

$43.25 - $57.50/hr

Brown-Forman is a premium spirits company that offers a dynamic opportunity for an experienced IT Governance/Risk/Compliance Analyst. In this role, you will identify and mitigate IT risks, ensure ...

$41.75 - $55.75/hr

The IT Governance/Risk/Compliance Analyst position offers a dynamic opportunity for an experienced analyst to help shape the future of our governance, risk, and compliance initiatives. In this role ...

next page

Showing results 1-20

It Governance Risk Compliance information

What is IT Governance, Risk, and Compliance (GRC)?

IT Governance, Risk, and Compliance (GRC) refers to a framework that helps organizations align their IT strategies with business goals, manage risks, and ensure compliance with relevant laws and regulations. IT GRC professionals establish policies, processes, and controls to protect information assets, assess and mitigate risks, and maintain regulatory compliance. Effective IT GRC ensures that technology supports organizational objectives while minimizing legal, financial, and security risks.

What are the key skills and qualifications needed to thrive as an IT Governance, Risk, and Compliance (GRC) professional?

To thrive as an IT Governance, Risk, and Compliance (GRC) professional, you need a strong understanding of risk management, regulatory frameworks (such as SOX, GDPR, or HIPAA), and IT security principles, often supported by a relevant degree or certifications like CISA, CRISC, or CISSP. Proficiency with GRC platforms (such as RSA Archer, ServiceNow GRC), audit tools, and compliance management systems is essential. Outstanding analytical thinking, attention to detail, and effective communication skills help you assess risks and collaborate across departments. These skills and qualities are crucial for maintaining regulatory compliance, mitigating organizational risks, and ensuring robust IT governance.

What are the most common challenges faced by IT Governance, Risk, and Compliance professionals, and how can they be addressed?

Professionals in IT Governance, Risk, and Compliance (GRC) often encounter challenges such as keeping up with rapidly evolving regulations, ensuring company-wide policy adherence, and effectively communicating risks to non-technical stakeholders. Staying current with regulatory changes requires ongoing education and strong networks within the industry. Building relationships across departments and using clear, accessible language helps ensure GRC initiatives are understood and supported. Additionally, leveraging automation tools can streamline compliance tracking and reporting, making it easier to manage complex requirements.

What is the difference between It Governance Risk Compliance vs IT Auditor?

AspectIT Governance Risk ComplianceIT Auditor
Primary FocusEstablishing and maintaining IT policies, risk management, compliance frameworksEvaluating and testing IT controls, ensuring compliance through audits
CertificationsCISA, CRISC, CISSPCISA, CISSP, CISM
Work EnvironmentPolicy development, risk assessments, compliance monitoringAudit planning, testing, reporting
Industry UsageUsed across organizations to ensure regulatory compliance and risk mitigationUsed to verify controls and compliance during audits

While both roles involve IT compliance, IT Governance Risk Compliance focuses on creating policies and managing risks proactively, whereas IT Auditors evaluate controls through audits to ensure compliance and effectiveness.

How to get into IT Governance Risk Compliance?

To enter IT Governance Risk Compliance, candidates typically need a bachelor's degree in information technology, cybersecurity, or a related field. Gaining certifications such as CISSP, CISA, or CRISC can enhance job prospects, along with developing skills in risk management, compliance frameworks, and security policies. Relevant experience in IT or cybersecurity roles also helps in advancing into this field.

Is IT Governance Risk Compliance an entry level job?

IT Governance Risk Compliance roles can be entry-level or require some experience, depending on the organization. Entry-level positions often focus on supporting compliance activities, documentation, and basic risk assessments, while more advanced roles may require certifications like CISA or CISSP and prior experience in IT or security. The job level varies based on the specific responsibilities and company requirements.

Is IT governance risk compliance a good career?

IT Governance, Risk, and Compliance (GRC) is a growing field that involves managing IT policies, security risks, and regulatory requirements. It offers opportunities for advancement, certifications like CISSP or CISA, and a stable job market due to increasing cybersecurity concerns. Success in this career requires strong analytical skills, understanding of IT frameworks, and continuous learning.
More about It Governance Risk Compliance jobs

What cities are hiring for It Governance Risk Compliance jobs?

Cities with the most It Governance Risk Compliance job openings:

What are the most commonly searched types of It Governance Risk Compliance jobs?

The most popular types of It Governance Risk Compliance jobs are:

What states have the most It Governance Risk Compliance jobs?

States with the most job openings for It Governance Risk Compliance jobs include:

Infographic showing various It Governance Risk Compliance job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 84% Full Time, 11% Part Time, and 4% Contract. Highlights an 92% Physical, 3% Hybrid, and 5% Remote job distribution.

Director, IT Governance, Risk, Compliance & AI

General Dynamics Mission Systems, Inc

Scottsdale, AZ • On-site

$201K - $218K/yr

Full-time

Posted 9 days ago


General Dynamics Mission Systems rating

8.1

Company rating: 8.1 out of 10

Based on 31 frontline employees who took The Breakroom Quiz

114th of 246 rated software companies


Job description

Basic Qualifications
Master's degree + minimum 13 years of demonstrated leadership experience; or Bachelor's degree in a related specialized area or equivalent combination of education and relevant work experience + minimum 15 years of demonstrated leadership experience.
CLEARANCE REQUIREMENTS:
Department of Defense Secret security clearance is preferred at time of hire. Applicants selected will be subject to a U.S. Government security investigation and must meet eligibility requirements for access to classified information. Due to the nature of work performed within our facilities, U.S. citizenship is required.
Responsibilities for this Position
General Dynamics Mission Systems is seeking a Director, IT Governance, Risk, Compliance & AI to lead the enterprise governance function across information technology, cybersecurity, privacy, data, financial systems, and artificial intelligence. Reporting to the Chief Data & AI Officer (CDAIO), who has assumed the broader enterprise technology, data, AI, and governance portfolio, this director will establish and operate an integrated, risk-based governance model that protects the company, enables disciplined innovation, and improves the speed and quality of decision-making.
The director will partner across Business Operations, Cybersecurity, Finance, Legal, Privacy, Internal Audit, Contracts, Engineering, Supply Chain, programs, and business leadership. The successful candidate will translate complex regulatory, contractual, technical, and business requirements into clear policies, practical controls, measurable accountability, and sustainable operating practices. They will bring bold ideas and deep expertise while building upon and advancing an established vision. Success in this role requires both strong individual contribution and the ability to collaborate across CDAIO teams and enterprise partners, harness collective capabilities, and strengthen the organization's overall effectiveness.
Key Responsibilities
  • Lead the enterprise IT governance, risk, and compliance strategy and operating model, ensuring alignment with business objectives, mission needs, regulatory obligations, and the enterprise technology, data, and AI strategy.
  • Direct and develop a multidisciplinary governance organization; establish priorities, performance expectations, succession capability, and a culture of accountability, continuous improvement, and customer focus.
  • Own the development, maintenance, communication, and enforcement of IT governance policies, standards, procedures, control frameworks, exception processes, and accountability mechanisms.
  • Lead governance and assurance for IT general controls, application controls, access management, change management, configuration management, vulnerability management, secure development, third-party services, and other technology risks.
  • Oversee SOX-related IT controls and partner with Finance, Internal Audit, external auditors, and system owners on control design, testing, evidence, deficiencies, remediation, and closure.
  • Partner with the CISO and cybersecurity organization to govern security risk, policy, exceptions, risk acceptance, compliance assessments, remediation, and executive reporting without duplicating operational security ownership.
  • Drive compliance readiness for applicable frameworks and contractual requirements, including NIST, CMMC, DFARS, privacy, controlled unclassified information, export-controlled information, and customer obligations.
  • Establish AI governance within the enterprise GRC model, including risk tiering, acceptable use, use-case intake, data and privacy safeguards, third-party AI risk, human oversight, documentation, monitoring, and lifecycle controls.
  • Partner with AI strategy, delivery, data, engineering, and cybersecurity leaders to make the responsible path for AI adoption clear, efficient, and proportionate to risk; identify opportunities to use AI to improve governance operations and control monitoring.
  • Lead internal and external audit coordination across IT, cybersecurity, privacy, data, and AI; ensure evidence is audit-ready, findings have accountable owners and due dates, and corrective actions are validated to closure.
  • Develop executive-level governance, risk, compliance, and AI reporting, including meaningful metrics, risk trends, control health, audit posture, remediation progress, and investment priorities.
  • Govern IT programs and projects at defined decision points to assess strategic alignment, risk, controls, compliance, resource use, and expected business value.
  • Plan and manage the department budget; identify opportunities to simplify, standardize, automate, and continuously improve governance processes and service delivery.
  • Build trusted relationships across geographically dispersed teams and influence senior stakeholders through clear communication, sound judgment, and practical risk recommendations.

Required Qualifications
  • Bachelor's degree in Computer Science, Information Systems, Cybersecurity, Risk Management, Business, or a related field, or an equivalent combination of education and relevant experience, plus at least 15 years of demonstrated leadership experience; or a master's degree plus at least 13 years of demonstrated leadership experience.
  • Substantial leadership experience in IT governance, risk, compliance, information security, audit, or related enterprise technology functions within a highly regulated environment.
  • Demonstrated experience leading complex, geographically dispersed technical organizations and developing leaders and technical professionals.
  • Strong knowledge of IT control frameworks and risk methodologies, including relevant NIST frameworks, COBIT, ITIL, ISO 27001, and/or comparable standards.
  • Demonstrated experience with IT SOX controls, audit coordination, control testing, remediation management, and executive reporting.
  • Working knowledge of defense-industry and government-contracting requirements relevant to technology governance, including CMMC, NIST SP 800-171/172, DFARS, CUI, and supplier or third-party risk, as applicable.
  • Knowledge of AI governance principles, including responsible AI, model and data risk, privacy, security, human oversight, third-party AI services, AI lifecycle controls, and the NIST AI Risk Management Framework or comparable practices.
  • Ability to assess risk pragmatically and translate legal, regulatory, contractual, and technical requirements into clear, executable business actions.
  • Excellent executive communication, presentation, relationship-building, organizational-change, and influence skills.

Preferred Qualifications
  • Professional certifications such as CISSP, CISM, CISA, CRISC, CIPP, PMP, CGEIT, or comparable credentials.
  • Experience implementing scalable governance workflows, continuous control monitoring, automated evidence collection, or governance tooling.
  • Experience governing AI-enabled business processes, generative AI, or agentic AI use cases in a regulated or mission-focused environment.
  • Experience with privacy-by-design, enterprise data governance, cloud governance, and third-party technology or supply-chain risk management.
  • Active security clearance or ability to obtain and maintain a clearance, as required by position access.

Salary Note
This estimate represents the typical salary range for this position based on experience and other factors (geographic location, etc.). Actual pay may vary. This job posting will remain open until the position is filled.
Combined Salary Range
USD $201,481.00 - USD $218,009.00 /Yr.
Company Overview
General Dynamics Mission Systems (GDMS) engineers a diverse portfolio of high technology solutions, products and services that enable customers to successfully execute missions across all domains of operation. With a global team of 12,000+ top professionals, we partner with the best in industry to expand the bounds of innovation in the defense and scientific arenas. Given the nature of our work and who we are, we value trust, honesty, alignment and transparency. We offer highly competitive benefits and pride ourselves in being a great place to work with a shared sense of purpose. You will also enjoy a flexible work environment where contributions are recognized and rewarded. If who we are and what we do resonates with you, we invite you to join our high-performance team!
Equal Opportunity Employer / Individuals with Disabilities / Protected Veterans

What General Dynamics Mission Systems employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom