1

It Governance Risk Compliance Jobs (NOW HIRING)

Manager, IT Risk Operations

Palo Alto, CA · On-site

$147K - $198K/yr

This high-impact position in the Governance, Risk & Compliance function sits at the center of the ... Strengthen IT Governance & Controls * Lead the development of executive-level reporting on IT risk, ...

next page

Showing results 1-20

It Governance Risk Compliance information

See salary details

$35K

$112K

$178K

How much do it governance risk compliance jobs pay per year?

As of Jun 17, 2026, the average yearly pay for it governance risk compliance in the United States is $111,975.00, according to ZipRecruiter salary data. Most workers in this role earn between $86,500.00 and $132,500.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as an IT Governance, Risk, and Compliance (GRC) professional, and why are they important?

To thrive as an IT Governance, Risk, and Compliance (GRC) professional, you need a strong understanding of risk management, regulatory frameworks (such as SOX, GDPR, or HIPAA), and IT security principles, often supported by a relevant degree or certifications like CISA, CRISC, or CISSP. Proficiency with GRC platforms (such as RSA Archer, ServiceNow GRC), audit tools, and compliance management systems is essential. Outstanding analytical thinking, attention to detail, and effective communication skills help you assess risks and collaborate across departments. These skills and qualities are crucial for maintaining regulatory compliance, mitigating organizational risks, and ensuring robust IT governance.

What are the most common challenges faced by IT Governance, Risk, and Compliance professionals, and how can they be addressed?

Professionals in IT Governance, Risk, and Compliance (GRC) often encounter challenges such as keeping up with rapidly evolving regulations, ensuring company-wide policy adherence, and effectively communicating risks to non-technical stakeholders. Staying current with regulatory changes requires ongoing education and strong networks within the industry. Building relationships across departments and using clear, accessible language helps ensure GRC initiatives are understood and supported. Additionally, leveraging automation tools can streamline compliance tracking and reporting, making it easier to manage complex requirements.

What are governance risk and compliance jobs?

Governance, Risk, and Compliance (GRC) jobs involve managing an organization’s policies, procedures, and controls to ensure legal and regulatory adherence, mitigate risks, and support strategic objectives. Roles often include risk analysts, compliance officers, and GRC managers who use tools like audit frameworks and security standards to protect organizational assets and ensure regulatory compliance.

What is the salary of governance risk compliance?

The salary for governance, risk, and compliance (GRC) professionals varies based on experience, location, and industry, but typically ranges from $70,000 to $130,000 annually. Senior roles or those with certifications like CISSP or CISA can earn higher salaries, often exceeding $150,000.

What is IT Governance, Risk, and Compliance (GRC)?

IT Governance, Risk, and Compliance (GRC) refers to a framework that helps organizations align their IT strategies with business goals, manage risks, and ensure compliance with relevant laws and regulations. IT GRC professionals establish policies, processes, and controls to protect information assets, assess and mitigate risks, and maintain regulatory compliance. Effective IT GRC ensures that technology supports organizational objectives while minimizing legal, financial, and security risks.

What is the difference between It Governance Risk Compliance vs IT Auditor?

AspectIT Governance Risk ComplianceIT Auditor
Primary FocusEstablishing and maintaining IT policies, risk management, compliance frameworksEvaluating and testing IT controls, ensuring compliance through audits
CertificationsCISA, CRISC, CISSPCISA, CISSP, CISM
Work EnvironmentPolicy development, risk assessments, compliance monitoringAudit planning, testing, reporting
Industry UsageUsed across organizations to ensure regulatory compliance and risk mitigationUsed to verify controls and compliance during audits

While both roles involve IT compliance, IT Governance Risk Compliance focuses on creating policies and managing risks proactively, whereas IT Auditors evaluate controls through audits to ensure compliance and effectiveness.

Is governance risk and compliance a good career?

Governance, Risk, and Compliance (GRC) is a growing field within IT, focusing on managing organizational risks, ensuring regulatory adherence, and establishing policies. Careers in GRC often require knowledge of frameworks like ISO, COBIT, or NIST, and certifications such as CISA or CISSP can enhance job prospects. It offers opportunities in various industries with a focus on security, audit, and policy development.

Is GRC certification worth IT?

For IT Governance, Risk, and Compliance (GRC) professionals, obtaining GRC certification can enhance credibility, demonstrate expertise, and improve job prospects in risk management, compliance, and security roles. It often complements technical skills and knowledge of frameworks like ISO, COBIT, or NIST, making candidates more competitive in the field.
More about It Governance Risk Compliance jobs
What cities are hiring for It Governance Risk Compliance jobs? Cities with the most It Governance Risk Compliance job openings:
What are the most commonly searched types of It Governance Risk Compliance jobs? The most popular types of It Governance Risk Compliance jobs are:
What states have the most It Governance Risk Compliance jobs? States with the most job openings for It Governance Risk Compliance jobs include:
What job categories do people searching It Governance Risk Compliance jobs look for? The top searched job categories for It Governance Risk Compliance jobs are:
Infographic showing various It Governance Risk Compliance job openings in the United States as of June 2026, with employment types broken down into 1% As Needed, 91% Full Time, 2% Part Time, and 6% Contract. Highlights an 81% Physical, 8% Hybrid, and 11% Remote job distribution, with an average salary of $111,975 per year, or $53.8 per hour.
Director of Cybersecurity, Governance, Risk and Compliance

Director of Cybersecurity, Governance, Risk and Compliance

Gross, Mendelsohn & Associates, P.A.

Baltimore, MD • On-site

Full-time

Posted 15 days ago


Job description

Gross Mendelsohn, one of the Mid-Atlantic’s leading independent CPA and advisory firms, is seeking a strategic and technically strong Director of Cybersecurity Governance, Risk & Compliance (GRC) to build and lead our cybersecurity and IT risk advisory capabilities.

This is a visible, high-impact leadership role responsible for designing, implementing, and overseeing enterprise cybersecurity and IT compliance programs for both clients and the firm, particularly government contractors and organizations operating in regulated environments.

As cybersecurity requirements continue to intensify, this role will sit at the intersection of IT architecture, regulatory compliance, risk advisory, and executive leadership. The Director will help position Gross Mendelsohn as a trusted advisor in cybersecurity governance, CUI compliance, and federal regulatory readiness.

Recognized with nine Top Workplace awards, Gross Mendelsohn is committed to professional excellence, collaboration, and long-term growth. This opportunity offers leadership visibility, strategic influence, and the ability to build and expand a critical service line within a respected independent firm.

Key Responsibilities

Cybersecurity & IT Governance Leadership

  • Serve as the firm’s senior leader for cybersecurity governance, risk, and compliance advisory services

  • Design and oversee enterprise cybersecurity frameworks aligned with NIST CSF, NIST SP 800-171, NIST SP 800-53, ISO 27001, and related standards

  • Lead end-to-end CUI and federal compliance programs, including development and maintenance of System Security Plans (SSP) and Plans of Action & Milestones (POA&M)

  • Conduct NIST SP 800-171 gap assessments and develop prioritized remediation roadmaps

  • Support clients with DFARS 252.204-7012 compliance, SPRS scoring, and CMMC readiness initiatives

  • Prepare clients for audits, mock assessments, and government inquiries

IT Infrastructure & Security Oversight

  • Oversee implementation and validation of technical cybersecurity controls, including:

  • Multi-factor authentication

  • Encryption (data at rest and in transit)

  • Endpoint protection

  • Logging, SIEM, and continuous monitoring

  • Network segmentation

  • Secure configuration and hardening standards

  • Provide advisory oversight of secure cloud environments, including Microsoft GCC High, Azure Government, and AWS GovCloud

  • Establish identity and access management frameworks and privileged access controls

  • Evaluate backup, disaster recovery, and business continuity processes

  • Direct incident response strategy and regulatory reporting obligations

Supply Chain & Flow-Down Advisory

  • Advise prime contractors on subcontractor cybersecurity flow-down requirements

  • Assess subcontractor readiness and compliance risk exposure

  • Support documentation required for federal scrutiny

Training & Continuous Improvement

  • Develop and deliver CUI-specific and role-based cybersecurity training

  • Implement measurable security awareness initiatives, including phishing simulations

  • Lead annual program reviews and continuous improvement initiatives

  • Maintain compliance posture during infrastructure changes, acquisitions, or system transitions

Executive Advisory & Reporting

  • Prepare executive-level cybersecurity risk reports and board-ready briefings

  • Translate complex technical risk into actionable business guidance

  • Collaborate with firm leadership to expand cybersecurity service offerings

  • Bachelor’s degree in Cybersecurity, Information Systems, Computer Science, Engineering, or related field

  • 7–12+ years of progressive experience in cybersecurity, IT risk, compliance, or security architecture

  • Demonstrated experience leading CUI, DFARS, and NIST 800-171 compliance initiatives

  • Experience working within a government contractor or regulated environments strongly preferred

  • Experience with secure federal cloud platforms such as GCC High or GovCloud preferred

  • Professional certifications preferred: CISSP, CISM, CISA, ISO 27001 Lead Implementer, Security+, or equivalent

Required Skills and Competencies

      Technical Expertise

  • Deep understanding of modern IT infrastructure, cloud security, and cybersecurity architecture

  • Strong working knowledge of NIST frameworks and federal cybersecurity regulations

  • Experience leading risk assessments and remediation programs

  • Strong documentation, audit-readiness, and control validation capabilities

Analytical Strength

  • Exceptional risk analysis and problem-solving skills

  • Ability to align cybersecurity controls with business processes

  • Strong systems thinking and governance design capability

Interpersonal & Professional Skills

  • Strong executive presence and communication skills

  • Ability to present complex cybersecurity risks clearly to non-technical audiences

  • Collaborative leadership style with the ability to build cross-functional relationships

  • Growth-oriented mindset with interest in expanding advisory capabilities

Additional Requirements

  • U.S. Citizenship required

  • Ability to travel up to 30% to client sites as needed

  • Proficiency in Microsoft Office and cybersecurity reporting tools

Why Join Gross Mendelsohn?

  • Lead and grow a high-impact cybersecurity advisory capability

  • Work directly with firm leadership in a visible strategic role

  • Contribute to modernization initiatives within a respected independent firm

  • Collaborative, growth-oriented culture

  • Competitive compensation and comprehensive benefits

  • Free parking at our Locust Point/McHenry Row office

  • Hybrid flexibility is available with approval

Work Environment

This role offers flexibility to work hybrid or fully remote; however, the Director of Cybersecurity will be expected to be present at client sites or in the office as business needs require, particularly for client delivery, team leadership, and strategic initiatives.

Physical Requirements

Ability to sit for extended periods, lift up to 20 pounds, and manage physical files and documentation as needed.

Join Us

If you are a strategic and execution-driven cybersecurity leader who thrives in a collaborative, growth-oriented professional services firm and is energized by building, scaling, and protecting a high-impact practice, we encourage you to apply.

Gross Mendelsohn is an equal opportunity employer

committed to fostering a respectful and inclusive workplace.