1

It Governance Risk Compliance Analyst Jobs (NOW HIRING)

IT Governance Analyst

Palo Alto, CA · On-site

$150K - $160K/yr

Adapt IT governance frameworks ( COBIT 2019, NIST CSF, CIS ) to fit both on-premise/co-located ... Present formal risk posture and compliance updates monthly to the executive team and risk ...

Great Waters Federal is seeking to hire an IT Governance Analyst for the National Capital Region or ... risk and maintaining compliance standards. Roles and Responsibilities include, but are not limited ...

IT Governance Consultant

MD · On-site

$90K - $150K/yr

Certified in Governance, Risk and Compliance (CGRC), (GRC Professional), FISMA, SOC, PCI DSS * 8+ ... Dashboard reporting, analytics, or data governance * Background in IT audit, IT operations ...

... governance by administering policy and compliance processes, automating control activities, and ... Collaborate with Information Security, Risk, Compliance, Legal, Audit, IT, and business ...

The IT Governance practice at VDOT is focused on process improvement, standardization, reporting and risk minimization. It's responsible for ensuring compliance. The Analyst will review processes ...

... governance, risk, and compliance across the organization ... This position partners closely with QA, IT, Information Security, Legal, Product, and other ...

New

Showing results 41-60

It Governance Risk Compliance Analyst information

See salary details

$46K

$93K

$104.5K

How much do it governance risk compliance analyst jobs pay per year?

As of Sep 13, 2026, the average yearly pay for it governance risk compliance analyst in the United States is $93,017.00, according to ZipRecruiter salary data. Most workers in this role earn between $94,000.00 and $94,500.00 per year, depending on experience, location, and employer.

What does an IT Governance Risk Compliance Analyst do?

An IT Governance, Risk, and Compliance (GRC) Analyst is responsible for ensuring that an organization's information technology systems comply with regulatory requirements and internal policies. They assess and manage IT risks, implement governance frameworks, and monitor compliance with relevant laws and standards such as GDPR, SOX, or ISO 27001. The role involves conducting audits, preparing reports, and working with various departments to mitigate risks and improve security. Their work helps protect the organization from data breaches, legal penalties, and reputational damage.

What are the key skills and qualifications needed to thrive as an IT Governance Risk Compliance Analyst?

To thrive as an IT Governance Risk Compliance Analyst, you need a solid understanding of information security frameworks, risk management principles, and relevant regulatory standards, usually supported by a degree in information technology or related field. Familiarity with GRC platforms (such as RSA Archer or ServiceNow), risk assessment tools, and certifications like CISA, CRISC, or CISSP are highly valued. Strong analytical thinking, attention to detail, and effective communication skills help you collaborate across departments and articulate complex compliance issues. These competencies are crucial for ensuring organizational compliance, minimizing risk exposure, and supporting robust IT governance.

What are some common challenges IT Governance Risk Compliance Analysts face when working with different departments?

IT Governance Risk Compliance Analysts often encounter challenges when aligning compliance standards and risk mitigation strategies across various departments. Each department may have unique processes and priorities, leading to inconsistencies in policy adoption and risk awareness. Effective communication, adaptability, and strong relationship-building skills are crucial for ensuring all teams understand and adhere to governance requirements. Analysts frequently collaborate with IT, legal, and business units to facilitate audits, implement controls, and foster a culture of compliance throughout the organization.

What is the difference between It Governance Risk Compliance Analyst vs IT Security Analyst?

AspectIt Governance Risk Compliance AnalystIT Security Analyst
CertificationsISO 27001 Lead Auditor, CISSP, CISACISSP, CompTIA Security+
Work EnvironmentPolicy development, compliance audits, risk assessmentsNetwork monitoring, threat analysis, incident response
Employer & Industry UsageFinancial, healthcare, government sectorsTech companies, cybersecurity firms, enterprises

While both roles focus on information security, the It Governance Risk Compliance Analyst emphasizes ensuring organizational compliance, managing risks, and developing governance frameworks. In contrast, the IT Security Analyst concentrates on protecting systems from threats and responding to security incidents. Both roles often collaborate but serve distinct functions within cybersecurity and compliance strategies.

Is IT governance risk compliance a good career?

IT Governance Risk Compliance analysts play a key role in ensuring organizations adhere to regulatory standards and manage technology risks effectively. The field offers strong job growth, competitive salaries, and opportunities for certification such as CISA or CISSP, making it a stable and rewarding career path for those interested in cybersecurity, compliance, and risk management.

Is an IT Governance Risk Compliance Analyst a good entry level job?

An IT Governance Risk Compliance Analyst can be a suitable entry-level position for individuals interested in cybersecurity, risk management, and compliance frameworks like ISO or NIST. It often requires foundational knowledge of IT systems, security principles, and relevant certifications such as CompTIA Security+ or CISA. The role provides opportunities to develop skills in assessing controls, managing risks, and understanding regulatory requirements, making it a solid starting point in the cybersecurity and IT governance fields.

What cities are hiring for It Governance Risk Compliance Analyst jobs?

Cities with the most It Governance Risk Compliance Analyst job openings:

What states have the most It Governance Risk Compliance Analyst jobs?

States with the most job openings for It Governance Risk Compliance Analyst jobs include:

What are popular job titles related to It Governance Risk Compliance Analyst jobs?

For It Governance Risk Compliance Analyst jobs, the most frequently searched job titles are:

Infographic showing various It Governance Risk Compliance Analyst job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 84% Full Time, 11% Part Time, and 4% Contract. Highlights an 94% Physical, 2% Hybrid, and 4% Remote job distribution, with an average salary of $93,017 per year, or $44.7 per hour.

Senior Analyst, Cybersecurity Governance, Risk and Compliance

New York, NY • On-site

Next Step Systems
IT Services • 11 - 50 employees

Full-time

Medical, Dental, Vision, Retirement, PTO

Re-posted 8 days ago


Key responsibilities

  • Administer the completion of compliance-related client requests to assess security policies and procedures.

  • Respond to inquiries on security controls policies, processes, and procedures for managed systems and applications.

  • Support vendor due diligence, compliance assessments, and broader GRC efforts by coordinating with external assessors and internal stakeholders.


Job description

Senior Analyst, Cybersecurity Governance, Risk and Compliance, New York, NY
The Senior Analyst, Cybersecurity Governance Risk & Compliance will administer the completion of compliance-related client requests to assess security policies and procedures. The Senior Analyst will respond to inquiries on the security controls policy, processes, and procedures implemented for managed systems and applications, as well as support Third Party Risk Management (TPRM) and Governance and Risk functions in conducting vendor due diligence (initial, reassessments and ongoing monitoring) and supporting broader GRC efforts. This position is 100% Onsite and not open for Remote.
Senior Analyst, Cybersecurity Governance, Risk and Compliance Responsibilities:
- Review and understand current IT Risk Management (ITRM) program framework and associated policies, standards, procedures, and processes.
- Prepare and respond to related compliance requests and web-shares including referencing evidentiary artifacts or other documentation.
- Complete external information security assessments, remediation efforts and support status tracking of assessment queues.
- Coordinate with external assessors and internal subject matter experts to address compliance inquiries and web-shares of security artifacts.
- Assist in further defining the process for completing information security control assessments.
- Support metrics and reporting of the Information Security Program through the collection and analysis of effectiveness security control measures.
- Develop understanding of control structure to support the creating or revising standard narratives/responses for client questionnaires (e.g., SIG).
- Work with the CISO, senior managers, managers and other internal stakeholders to report existing information security programs and ongoing security projects that address information security risks and compliance requirements.
- Manage competing deadlines and multiple external inquiries using effective organizational skills and attention to detail as demonstrated by prior work experience.
- Contribute to the creation of GRC related processes and procedures and relevant documents.
- Collaborate with InfoSec, Privacy and GRC management and internal subject matter experts to support coordination, tracking, and reporting of GRC team strategy and goals; and complete other tasks as assigned.
- Participate in efforts to evolve and streamline GRC solutions, processes and procedures.
- Develop and maintain the status tracking related to findings from information security assessments, Governance, Risk and Compliance, and TPRM due diligence/reassessment assessments and associated remediations.
Senior Analyst, Cybersecurity Governance, Risk and Compliance Qualifications:
- Bachelor's degree (required) and at least 5 years of combined information technology and information security experience.
- Strong understanding of multiple risk management concepts, frameworks, and standards (CSC, NIST, ISO, COBIT).
- Strong understanding of information security concepts and technologies.
- Strong understanding of due diligence and compliance documents (e.g. SOC 2 Type 2, ISO 27001 Certification, SIG Questionnaires, Certificates of Insurance, Pen Test, etc.).
- Strong communication skills with the ability to interact with various teams.
- Demonstrated experience with the NIST Cybersecurity Framework and auditing security controls identified in NIST SP800-171 and NIST SP800-53A.
- Experience in the analysis of IT and Security control requirements and understanding of associated technology processes.
- Experience working with internal and external auditing firms.
- Fundamental knowledge of MS Outlook, Word, Excel, Visio, and PowerPoint.
Benefits include medical insurance, retirement plan, Dental, Vision, PTO, etc.
Keywords: New York NY Jobs, Senior Analyst, Cybersecurity Governance Risk and Compliance, Information Security, Risk Management, CSC, NIST, ISO, COBIT, NIST Cybersecurity Framework, NIST SP800-171, NIST SP800-53A, SOC 2 Type 2, ISO 27001 Certification, SIG Questionnaires, Certificates of Insurance, Pen Test, New York Recruiters, Information Technology Jobs, IT Jobs, New York Recruiting
Looking to hire for similar positions in New York, NY or in other cities? Our IT recruiting agencies and staffing companies can help.
We help companies that are looking to hire Senior Analysts, Cybersecurity Governance Risk and Compliance for jobs in New York, New York and in other cities too. Please contact our IT recruiting agencies and IT staffing companies today! Phone 630-428-0600 ext. 11 or email us at jobs@nextstepsystems.com. Click here to submit your resume for this job and others.
Atlanta Georgia IT Recruiters, Austin TX IT Recruiters, Baltimore Executive Staffing, Boston IT Recruiters, Charlotte IT Recruiters, Chicago Recruiting Agency, Cincinnati Executive Search Firms, Cleveland Executive Tech Recruiting, Columbus Technical Recruiters, Dallas Recruiters for IT, Denver Technology Headhunters, Detroit IT Headhunters, Fort Lauderdale Information Technology Recruiters, Houston IT Recruiters, Indianapolis IT Recruiters, Jacksonville IT Recruiters, Kansas City IT Recruiters, Los Angeles IT Recruiters, Miami IT Recruiters, Minneapolis IT Recruiters, Nashville IT Recruiters, New Jersey Tech Recruiters, New York IT Recruiters, Phoenix IT Recruiters, Raleigh IT Recruiters, Salt Lake City IT Recruitment, San Antonio Information Technology Recruiters, San Diego Executive Staffing, San Francisco Executive Search Firms, San Jose Executive Tech Recruiting, Seattle Technical Recruiters, Silicon Valley Tech Recruiters, St. Louis Technology Headhunters, Tampa Technology Headhunters, Washington DC IT Recruiters
Home"Senior Analyst, Cybersecurity Governance, Risk and Compliance