1

It Governance Risk Compliance Analyst Jobs (NOW HIRING)

The Governance, Risk, and Compliance (GRC) team helps ensure technology and cybersecurity risks are ... Bachelor's degree in Information Security, Computer Science, Business Risk, Compliance, or a ...

Showing results 21-40

It Governance Risk Compliance Analyst information

See salary details

$46K

$93K

$104.5K

How much do it governance risk compliance analyst jobs pay per year?

As of Sep 12, 2026, the average yearly pay for it governance risk compliance analyst in the United States is $93,017.00, according to ZipRecruiter salary data. Most workers in this role earn between $94,000.00 and $94,500.00 per year, depending on experience, location, and employer.

What does an IT Governance Risk Compliance Analyst do?

An IT Governance, Risk, and Compliance (GRC) Analyst is responsible for ensuring that an organization's information technology systems comply with regulatory requirements and internal policies. They assess and manage IT risks, implement governance frameworks, and monitor compliance with relevant laws and standards such as GDPR, SOX, or ISO 27001. The role involves conducting audits, preparing reports, and working with various departments to mitigate risks and improve security. Their work helps protect the organization from data breaches, legal penalties, and reputational damage.

What are the key skills and qualifications needed to thrive as an IT Governance Risk Compliance Analyst?

To thrive as an IT Governance Risk Compliance Analyst, you need a solid understanding of information security frameworks, risk management principles, and relevant regulatory standards, usually supported by a degree in information technology or related field. Familiarity with GRC platforms (such as RSA Archer or ServiceNow), risk assessment tools, and certifications like CISA, CRISC, or CISSP are highly valued. Strong analytical thinking, attention to detail, and effective communication skills help you collaborate across departments and articulate complex compliance issues. These competencies are crucial for ensuring organizational compliance, minimizing risk exposure, and supporting robust IT governance.

What are some common challenges IT Governance Risk Compliance Analysts face when working with different departments?

IT Governance Risk Compliance Analysts often encounter challenges when aligning compliance standards and risk mitigation strategies across various departments. Each department may have unique processes and priorities, leading to inconsistencies in policy adoption and risk awareness. Effective communication, adaptability, and strong relationship-building skills are crucial for ensuring all teams understand and adhere to governance requirements. Analysts frequently collaborate with IT, legal, and business units to facilitate audits, implement controls, and foster a culture of compliance throughout the organization.

What is the difference between It Governance Risk Compliance Analyst vs IT Security Analyst?

AspectIt Governance Risk Compliance AnalystIT Security Analyst
CertificationsISO 27001 Lead Auditor, CISSP, CISACISSP, CompTIA Security+
Work EnvironmentPolicy development, compliance audits, risk assessmentsNetwork monitoring, threat analysis, incident response
Employer & Industry UsageFinancial, healthcare, government sectorsTech companies, cybersecurity firms, enterprises

While both roles focus on information security, the It Governance Risk Compliance Analyst emphasizes ensuring organizational compliance, managing risks, and developing governance frameworks. In contrast, the IT Security Analyst concentrates on protecting systems from threats and responding to security incidents. Both roles often collaborate but serve distinct functions within cybersecurity and compliance strategies.

Is IT governance risk compliance a good career?

IT Governance Risk Compliance analysts play a key role in ensuring organizations adhere to regulatory standards and manage technology risks effectively. The field offers strong job growth, competitive salaries, and opportunities for certification such as CISA or CISSP, making it a stable and rewarding career path for those interested in cybersecurity, compliance, and risk management.

Is an IT Governance Risk Compliance Analyst a good entry level job?

An IT Governance Risk Compliance Analyst can be a suitable entry-level position for individuals interested in cybersecurity, risk management, and compliance frameworks like ISO or NIST. It often requires foundational knowledge of IT systems, security principles, and relevant certifications such as CompTIA Security+ or CISA. The role provides opportunities to develop skills in assessing controls, managing risks, and understanding regulatory requirements, making it a solid starting point in the cybersecurity and IT governance fields.

What cities are hiring for It Governance Risk Compliance Analyst jobs?

Cities with the most It Governance Risk Compliance Analyst job openings:

What states have the most It Governance Risk Compliance Analyst jobs?

States with the most job openings for It Governance Risk Compliance Analyst jobs include:

What are popular job titles related to It Governance Risk Compliance Analyst jobs?

For It Governance Risk Compliance Analyst jobs, the most frequently searched job titles are:

Infographic showing various It Governance Risk Compliance Analyst job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 84% Full Time, 11% Part Time, and 4% Contract. Highlights an 94% Physical, 2% Hybrid, and 4% Remote job distribution, with an average salary of $93,017 per year, or $44.7 per hour.

Junior Governance, Risk & Compliance Analyst

Davenport, IA β€’ On-site

$60K - $80K/yr

Full-time, Part-time

Re-posted 9 days ago


Job description

Lee Enterprises is seeking a motivated Junior GRC Analyst to join our growing Governance, Risk & Compliance (GRC) team. This part-time, developmental position offers an opportunity to gain direct exposure to enterprise risk management, compliance, and governance initiatives in a fast-paced, collaborative environment.

This role serves as a launchpad β€” after a successful 90-day performance review, the position may transition into a full-time GRC Analyst role with expanded responsibilities and a competitive annual salary ($60K–$80K, commensurate with experience and performance).

The ideal candidate is curious, detail-oriented, and eager to learn. You’ll work closely with senior members of the GRC team and cross-functional partners in Legal, Finance, IT, and Operations to strengthen our risk-aware culture and governance practices.

KEY RESPONSIBILITIES

Risk Identification & Monitoring

  • Assist in identifying, assessing, and tracking risks across IT and enterprise functions.
  • Support maintenance of the enterprise risk register and dashboards used by leadership.

Governance & Compliance Support

  • Help draft, organize, and maintain policies, standards, and procedures.
  • Support compliance awareness campaigns and training that promote a culture of risk accountability.

Framework Alignment

  • Learn and assist in mapping controls to frameworks such as NIST CSF, COBIT 2019, and ISO 27001.
  • Support tracking and validation of control effectiveness through GRC tools or reports.

Collaboration & Reporting

  • Partner with GRC leadership to prepare reports, metrics, and presentations for management.
  • Contribute to meetings with stakeholders across Legal, Finance, IT, and Operations.

Operational Support & Learning

  • Provide day-to-day administrative and research assistance to the GRC team.
  • Demonstrate initiative, curiosity, and a commitment to learning risk and compliance fundamentals.

QUALIFICATIONS

Must Have:

  • Strong organizational and written communication skills.
  • Detail-oriented with an analytical mindset and ability to problem-solve.
  • Interest in learning frameworks such as NIST, COBIT, ISO 27001, or SOC 2.
  • Desire to learn, hunger to achieve, and persistence to accomplish.

Nice to Have:

  • Internship experience in governance, risk, compliance, audit, or related disciplines (internships and academic experience welcome).
  • Bachelor’s degree (completed or in progress) in Information Security, Risk Management, Business Administration, or a related field β€” or equivalent experience.
  • Experience supporting policy writing, audits, or risk assessments.
  • Exposure to GRC tools or risk management platforms.
  • Familiarity with cybersecurity, data protection, or IT operations concepts.
  • Relevant certifications (e.g., Security+, CISA, CISM, CGRC) are a plus.

Why Join the GRC Team?

  • Opportunity to develop real-world GRC experience in a supportive environment.
  • Work directly with senior GRC leadership and cross-functional teams.
  • Build the skills needed to progress into a full-time GRC Analyst role.
  • Gain enterprise-wide exposure to risk management, compliance, and governance functions.
  • Be part of a team driving a risk-first culture across the organization.