1

It Governance Risk Compliance Jobs (NOW HIRING)

IT Controls & Compliance Analyst

Denver, CO · On-site

$96K - $97K/yr

Manages and optimizes Governance, Risk & Compliance (GRC) processes, workflows, tooling, reporting ... Reviews and maintains IT security policies, standards, and governance documentation to align with ...

IT Controls & Compliance Analyst

Denver, CO · On-site

$96K - $97K/yr

Manages and optimizes Governance, Risk & Compliance (GRC) processes, workflows, tooling, reporting ... Reviews and maintains IT security policies, standards, and governance documentation to align with ...

IT Governance Senior Manager

Farmington Hills, MI · On-site

$128K - $129K/yr

This role provides executive oversight for IT risk management, controls oversight, policy governance, audit coordination, and remediation management to ensure a strong and compliant operational ...

IT Governance Senior Manager

Farmington Hills, MI · On-site

$128K - $129K/yr

This role provides executive oversight for IT risk management, controls oversight, policy governance, audit coordination, and remediation management to ensure a strong and compliant operational ...

next page

Showing results 1-20

It Governance Risk Compliance information

See salary details

$35K

$112K

$178K

How much do it governance risk compliance jobs pay per year?

As of Jun 17, 2026, the average yearly pay for it governance risk compliance in the United States is $111,975.00, according to ZipRecruiter salary data. Most workers in this role earn between $86,500.00 and $132,500.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as an IT Governance, Risk, and Compliance (GRC) professional, and why are they important?

To thrive as an IT Governance, Risk, and Compliance (GRC) professional, you need a strong understanding of risk management, regulatory frameworks (such as SOX, GDPR, or HIPAA), and IT security principles, often supported by a relevant degree or certifications like CISA, CRISC, or CISSP. Proficiency with GRC platforms (such as RSA Archer, ServiceNow GRC), audit tools, and compliance management systems is essential. Outstanding analytical thinking, attention to detail, and effective communication skills help you assess risks and collaborate across departments. These skills and qualities are crucial for maintaining regulatory compliance, mitigating organizational risks, and ensuring robust IT governance.

What are the most common challenges faced by IT Governance, Risk, and Compliance professionals, and how can they be addressed?

Professionals in IT Governance, Risk, and Compliance (GRC) often encounter challenges such as keeping up with rapidly evolving regulations, ensuring company-wide policy adherence, and effectively communicating risks to non-technical stakeholders. Staying current with regulatory changes requires ongoing education and strong networks within the industry. Building relationships across departments and using clear, accessible language helps ensure GRC initiatives are understood and supported. Additionally, leveraging automation tools can streamline compliance tracking and reporting, making it easier to manage complex requirements.

What are governance risk and compliance jobs?

Governance, Risk, and Compliance (GRC) jobs involve managing an organization’s policies, procedures, and controls to ensure legal and regulatory adherence, mitigate risks, and support strategic objectives. Roles often include risk analysts, compliance officers, and GRC managers who use tools like audit frameworks and security standards to protect organizational assets and ensure regulatory compliance.

What is the salary of governance risk compliance?

The salary for governance, risk, and compliance (GRC) professionals varies based on experience, location, and industry, but typically ranges from $70,000 to $130,000 annually. Senior roles or those with certifications like CISSP or CISA can earn higher salaries, often exceeding $150,000.

What is IT Governance, Risk, and Compliance (GRC)?

IT Governance, Risk, and Compliance (GRC) refers to a framework that helps organizations align their IT strategies with business goals, manage risks, and ensure compliance with relevant laws and regulations. IT GRC professionals establish policies, processes, and controls to protect information assets, assess and mitigate risks, and maintain regulatory compliance. Effective IT GRC ensures that technology supports organizational objectives while minimizing legal, financial, and security risks.

What is the difference between It Governance Risk Compliance vs IT Auditor?

AspectIT Governance Risk ComplianceIT Auditor
Primary FocusEstablishing and maintaining IT policies, risk management, compliance frameworksEvaluating and testing IT controls, ensuring compliance through audits
CertificationsCISA, CRISC, CISSPCISA, CISSP, CISM
Work EnvironmentPolicy development, risk assessments, compliance monitoringAudit planning, testing, reporting
Industry UsageUsed across organizations to ensure regulatory compliance and risk mitigationUsed to verify controls and compliance during audits

While both roles involve IT compliance, IT Governance Risk Compliance focuses on creating policies and managing risks proactively, whereas IT Auditors evaluate controls through audits to ensure compliance and effectiveness.

Is governance risk and compliance a good career?

Governance, Risk, and Compliance (GRC) is a growing field within IT, focusing on managing organizational risks, ensuring regulatory adherence, and establishing policies. Careers in GRC often require knowledge of frameworks like ISO, COBIT, or NIST, and certifications such as CISA or CISSP can enhance job prospects. It offers opportunities in various industries with a focus on security, audit, and policy development.

Is GRC certification worth IT?

For IT Governance, Risk, and Compliance (GRC) professionals, obtaining GRC certification can enhance credibility, demonstrate expertise, and improve job prospects in risk management, compliance, and security roles. It often complements technical skills and knowledge of frameworks like ISO, COBIT, or NIST, making candidates more competitive in the field.
More about It Governance Risk Compliance jobs
What cities are hiring for It Governance Risk Compliance jobs? Cities with the most It Governance Risk Compliance job openings:
What are the most commonly searched types of It Governance Risk Compliance jobs? The most popular types of It Governance Risk Compliance jobs are:
What states have the most It Governance Risk Compliance jobs? States with the most job openings for It Governance Risk Compliance jobs include:
What job categories do people searching It Governance Risk Compliance jobs look for? The top searched job categories for It Governance Risk Compliance jobs are:
Infographic showing various It Governance Risk Compliance job openings in the United States as of June 2026, with employment types broken down into 1% As Needed, 91% Full Time, 2% Part Time, and 6% Contract. Highlights an 81% Physical, 8% Hybrid, and 11% Remote job distribution, with an average salary of $111,975 per year, or $53.8 per hour.
IT Manager II - IT Governance, Risk and Controls

IT Manager II - IT Governance, Risk and Controls

Western Alliance Bank

Columbus, OH • On-site

$91K - $112K/yr

Full-time

Medical, Dental, Retirement

Posted 16 days ago


Job description

Job Title:

IT Manager II - IT Governance, Risk and Controls

Location:

Block 23

What you'll do:

The IT Manager II - IT Governance, Risk and Controls role is a first line of defense risk professional within the IT Governance team. The position is responsible for supporting and executing IT risk management activities aligned with the Company's Risk Appetite and Corporate Strategy. You will partner with IT leadership, other Risk Teams and business stakeholders to identify, assess, and manage technology risks, ensuring compliance with regulatory expectations and internal standards.
  • Oversee the development, tracking, and reporting of IT KRIs within GRC and Workfront platforms to provide timely insights into emerging risks and trends.
  • Coordinate and help lead reviews of Service Organization Control (SOC) reports to validate IT control effectiveness and identify potential gaps impacting risk posture.
  • Ensure the accuracy and completeness of the IT risk control inventory, including updates for new controls, retirements, and alignment with regulatory and internal standards.
  • Develop and deliver high-quality materials for governance forums, ensuring clarity on risk issues, mitigation strategies, and decision-making support.
  • Serve as a trusted advisor to IT stakeholders by offering guidance on risk identification, exception management, mitigation strategies, and compliance with enterprise risk frameworks.
  • Aggregate and analyze data for issue owners to monitor remediation progress and escalate delays or concerns to leadership.
  • Organize and execute mock regulatory exams and remediation exercises to strengthen preparedness for supervisory reviews and internal assessments.
  • Prepare and present risk and control updates for key governance bodies, ensuring transparency and actionable insights.
  • Create reports and presentations that communicate IT risk posture, trends, and strategic initiatives to senior leadership.
  • Implement safety procedures and data recovery plans. Develop user manuals, as well as policies, procedures, and safety protocols.
  • Work with IT Leadership in employee development, retention, resource planning, talent management, performance management, and achieve a diverse and engaged workforce as well as recruit, train, and evaluate staff members' work.
  • Analyze a variety of data and summarize findings in applicable reports or other communication mediums. Utilize data to identify areas of improvement and opportunities for growth by collaborating with business and tech leads.

What you'll need:

  • 5+ years of IT risk management or related experience in areas such as IT Governance, Risk & Compliance, IT Controls, Audit coordination, or similar functions.
  • Bachelor's degree in Information Technology, Cybersecurity, Risk Management, or a related field required; Advanced degree or certifications (e.g., CRISC, CISA, CISSP) preferred.
  • Proven leadership experience with the ability to manage and develop teams, drive accountability, and foster collaboration across IT and business units.
  • Intermediate knowledge of general Financial Services or Banking operations and their associated technology risk landscape is preferred.
  • Intermediate knowledge of regulatory and compliance frameworks (e.g., FFIEC, SOX, GLBA) and industry standards (e.g., NIST, ISO).
  • Experience managing IT risk programs and governance processes, including KRIs, control inventories, audit coordination, and regulatory deliverables.
  • Proficiency in risk management tools and platforms and familiarity with IT control frameworks.
  • Intermediate to advanced experience in managing mid-sized technology team within multiple functional areas while ensuring highest quality delivery of complex products or services.
  • Intermediate to advanced experience with the execution KPIs and meeting timelines.
  • Advanced speaking and writing communication skills.
  • May require up to 25% travel.

Benefits you'll love:
We offer all the important things you'd want - like competitive salaries, an ownership stake in the company, medical and dental insurance, time off, a great 401k matching program, tuition assistance program, an employee volunteer program, and a wellness program. In addition, you'll have the opportunity to bolster your business knowledge, learning the ins and outs of how successful companies operate and manage their finances, giving you invaluable hands-on experience to help grow your career!

About the company:

Western Alliance Bank, Member FDIC, is a wholly owned subsidiary of Western Alliance Bancorporation. Serving clients nationwide, Western Alliance Bank includes six legacy bank brands - Alliance Association Bank, Alliance Bank of Arizona, Bank of Nevada, Bridge Bank, First Independent Bank and Torrey Pines Bank - that remain part of the company's heritage, as well as AmeriHome Mortgage, a Western Alliance Bank Company.

Western Alliance Bancorporation is committed to equal employment and will consider all qualified applicants without regard to race, sex, color, religion, age, nation origin, marital status, disability, protected veteran status, sexual orientation, gender identity or genetic information. Western Alliance Bancorporation is committed to working with and providing reasonable accommodations for individuals with disabilities. If you are an individual with a disability and require a reasonable accommodation to complete any part of the application process and/or need an alternative method of applying, please email HR@westernalliancebank.com or call 602-386-2488. When contacting us, please provide your contact information and state the nature of your accessibility issue. We will only respond to inquiries concerning requests that involve a reasonable accommodation in the application process.

Western Alliance Bancorporation