1

It Grc Analyst Jobs (NOW HIRING)

The IT GRC Analyst is responsible for supporting Globalstar's information security governance, risk, and compliance programs. This role executes control oversight activities, maintains compliance ...

The IT GRC Analyst is responsible for supporting Globalstar's information security governance, risk, and compliance programs. This role executes control oversight activities, maintains compliance ...

The IT GRC Analyst II assess, tests, documents, and monitors the SECU technology ecosystem to ensure the IT control environment effectively mitigates risks associated with an everchanging threat ...

Overview The IT GRC Analyst operates within the enterprise Cybersecurity Operations function and supports the Information Technology, Information Systems, and other technology teams aligned under the ...

Governance, Risk, and Compliance (GRC) Analyst - SOX & Data Security Focus Location: Clemmons, NC ... Support the design, documentation, and operation of IT General Controls (ITGCs). * Execute and ...

GRC Analyst

Clemmons, NC · On-site

$80 - $100/hr

Job Summary**The GRC Analyst - SOX & Data Security Focus plays a critical role in ensuring the ... Support the design, documentation, and operation of IT General Controls (ITGCs).* Execute and ...

The IT Governance, Risk, and Compliance (GRC) Lead Analyst serves as a subject matter expert ... Establish and maintain IT control frameworks, including ITGCs, cybersecurity controls, and key risk ...

Snr GRC Analyst

California, MO · On-site

$100 - $150/hr

Overview Our client seeks a Sr. GRC Analyst in Orange County, CA. This is an onsite position ... It reports directly to the CISO and has an excellent path for promotion to a GRC Manager position.

The IT Governance, Risk, and Compliance (GRC) Lead Analyst serves as a subject matter expert ... Establish and maintain IT control frameworks, including ITGCs, cybersecurity controls, and key risk ...

Governance, Risk, and Compliance (GRC) Analyst - SOX & Data Security Focus Location: Clemmons,NC ... Support the design, documentation, and operation of IT General Controls (ITGCs). * Execute ...

Overview Hexagon's Autonomous Solutions division is looking for an IT GRC Specialist to join our ... Strong analytical skills with the ability to identify risks and develop practical remediation ...

Senior GRC Analyst

$115K - $145K/yr

They need a trusted voice who can help them think through it. As a Senior GRC Analyst, you'll be the person customers turn to when a risk assessment gets complicated, an audit raises an unexpected ...

... the IS GRC - Risk & Compliance Senior Analyst will support the firm's Governance, Risk, and ... The role partners closely with IT leadership, business stakeholders, and third-party vendors to ...

The GRC Analyst supports the administration of Information Security Governance, Risk, and ... Communicate with IT staff, business stakeholders, system owners, managers, and security teams.

GRC Analyst

Dallas, TX · On-site

$95 - $125/hr

NMC2 is hiring a GRC Analyst to join the Information Security team, reporting to the GRC & Privacy ... Own and operate the security change management review process -- triaging incoming IT and ...

next page

Showing results 1-20

It Grc Analyst information

See salary details

$36.5K

$97.7K

$228.5K

How much do it grc analyst jobs pay per year?

As of Aug 28, 2026, the average yearly pay for it grc analyst in the United States is $97,659.00, according to ZipRecruiter salary data. Most workers in this role earn between $55,000.00 and $111,000.00 per year, depending on experience, location, and employer.

What is an IT GRC analyst?

IT GRC Analysts are professionals who specialize in managing and overseeing an organization's Information Technology (IT) Governance, Risk, and Compliance (GRC) programs. Their main responsibilities include assessing risks to IT systems, ensuring compliance with relevant laws and regulations, and developing policies to strengthen IT governance. They also work closely with other departments to identify and mitigate security risks, conduct audits, and provide recommendations for process improvements. By doing so, IT GRC Analysts help organizations protect their data and maintain regulatory compliance.

What are the key skills and qualifications needed to thrive as an IT GRC analyst?

To thrive as an IT GRC Analyst, you need a solid understanding of IT risk management, compliance frameworks (like ISO 27001 or NIST), and a relevant degree in information technology or cybersecurity. Familiarity with GRC tools (such as Archer or ServiceNow), audit management systems, and industry certifications like CISA or CRISC are commonly required. Strong analytical thinking, attention to detail, and effective communication skills help you interpret complex regulations and work with diverse stakeholders. These competencies ensure organizations effectively manage risks, maintain regulatory compliance, and protect critical information assets.

What are some common challenges faced by IT GRC analysts, and how can they effectively address them?

IT GRC Analysts often face challenges such as keeping up with rapidly changing compliance regulations, managing complex risk assessments, and ensuring organization-wide adherence to policies. To address these, analysts should prioritize continuous learning, collaborate closely with IT and business teams, and utilize automated GRC tools to streamline processes. Building strong communication skills also helps in advocating for compliance and fostering a culture of risk awareness across the organization.

What is the difference between It Grc Analyst vs It Security Analyst?

AspectIt Grc AnalystIt Security Analyst
CertificationsISO 27001, CISSP, CISACISSP, CEH, CompTIA Security+
Work EnvironmentRisk management, policy development, complianceSecurity monitoring, incident response, threat analysis
Employer & Industry UsageFinance, healthcare, government, corporateIT firms, cybersecurity companies, large enterprises

The It Grc Analyst primarily focuses on governance, risk management, and compliance frameworks, ensuring organizations adhere to regulations. In contrast, the It Security Analyst concentrates on protecting systems from security threats through monitoring and incident response. Both roles require certifications like CISSP and work within similar industries, but their core responsibilities differ—one emphasizes policy and compliance, the other security operations.

Are IT GRC analysts in demand?

IT GRC analysts are in high demand due to increasing cybersecurity regulations and the need for organizations to manage governance, risk, and compliance effectively. Employers seek professionals with skills in risk assessment, compliance frameworks, and tools like GRC software, often requiring relevant certifications such as CISSP or CISA.

Is an IT GRC analyst entry level?

An IT GRC analyst role can be entry-level or require some experience, depending on the organization. Entry-level positions typically focus on basic compliance, risk management, and supporting GRC processes, often requiring foundational knowledge of cybersecurity and relevant certifications like CISA or CISSP. More advanced roles may demand prior experience or specialized skills in governance, risk, and compliance tools.

What does an IT GRC analyst do?

An IT GRC analyst is responsible for managing and implementing governance, risk management, and compliance processes within an organization. They assess security policies, ensure regulatory adherence, and use tools like GRC software to identify and mitigate IT risks. Strong knowledge of cybersecurity frameworks and certifications such as CISSP or CISA are often required.
More about It Grc Analyst jobs

What cities are hiring for It Grc Analyst jobs?

Cities with the most It Grc Analyst job openings:

What states have the most It Grc Analyst jobs?

States with the most job openings for It Grc Analyst jobs include:

What job categories do people searching It Grc Analyst jobs look for?

The top searched job categories for It Grc Analyst jobs are:

Infographic showing various It Grc Analyst job openings in the United States as of August 2026, with employment types broken down into 90% Full Time, 5% Part Time, and 5% Contract. Highlights an 80% Physical, 8% Hybrid, and 12% Remote job distribution, with an average salary of $97,659 per year, or $47 per hour.

IT GRC Analyst

Globalstar

Covington, LA • On-site

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 16 days ago


Job description

Who we are:
Globalstar pioneered personal safety by introducing its SPOT Satellite GPS Messenger in 2007. Today, leveraging its low-earth orbit (LEO) satellite constellation, Globalstar reliably connects and protects assets, transmits key operational data, and saves lives - from any location - for consumers, industrial companies and government agencies in over 120 countries. With a portfolio that includes SPOT GPS messengers, next-generation IoT products and modems, and cloud-based telematics solutions, Globalstar's cost effective satellite-powered innovations give users visibility and intelligence for improving safety and operational efficiencies.
What we offer:
  • Work/Life Balance: Paid Time Off, Paid Holidays
  • Financial Benefits: 401(k) Plan with Company Match, Employee Stock Purchase Program, Voluntary and Company Paid Group Life Insurance, Short- and Long-Term Disability Insurance, Medical FSA, Dependent Care, Competitive Salaries
  • Health & Wellness: Health Insurance, Dental Insurance, Vision Insurance, Employee Assistance Program, Comprehensive and Interactive Wellness Program

Job Summary:
The IT GRC Analyst is responsible for supporting Globalstar's information security governance, risk, and compliance programs. This role executes control oversight activities, maintains compliance with applicable regulatory frameworks, supports internal and external audit readiness, and assists with vendor risk management. The IT GRC Analyst will leverage GRC tooling to automate and streamline compliance monitoring, produce highly accurate and consistent documentation, and serve as a knowledgeable resource across IT and business teams. Additionally, this role provides project coordination support for IT implementations and installations, assisting in the organization, scheduling, and communication of project activities as needed.
Supervisory Responsibilities:
  • None

Duties/Responsibilities:
Governance, Risk & Compliance
  • Execute user access reviews, control evidence collection, and recurring risk reviews.
  • Collect, review, and validate control evidence and supporting artifacts to assess completeness, accuracy, and alignment with defined requirements.
  • Maintain and update the organization's risk register, documenting identified risks, current controls and recommended treatment options.
  • Identify, document, and escalate control exceptions, discrepancies, and potential gaps to senior team members for evaluation and remediation.
  • Monitor compliance with information security policies and assess potential risks associated with data handling and system changes.
  • Support the maintenance of governance documentation and continuous improvement of department processes and procedures.

Audit & Regulatory Readiness
  • Administer and support the organization's audit plan across SOC 2, ISO 27001, and SOX, ensuring controls are designed and operating effectively.
  • Support internal and external audit activities by organizing evidence, coordinating with control owners, and responding to information requests.
  • Assist with the preparation and maintenance of compliance artifacts.
  • Coordinate with independent auditors and ensure the timely delivery of supporting documentation and data.
  • Analyze audit results, prepare presentations of findings, and develop recommendations to reduce risk and increase protection of organizational assets.
  • Review SOC reporting for third-party compliance and coordinate data privacy matters with the Data Protection Officer (DPO) as applicable.

Vendor & Third-Party Risk Management
  • Support third-party risk management activities including vendor intake, security questionnaire review, ongoing monitoring, and follow-up with internal stakeholders.
  • Evaluate vendors' security posture and assess residual risk for inclusion in procurement and program decisions.
  • Maintain accurate and up-to-date information within vendor and control tracking systems.

Data Privacy Oversight
  • Support oversight and ongoing management of Globalstar's data privacy program, ensuring compliance with applicable privacy regulations including GDPR, CCPA, and other relevant privacy frameworks.
  • Coordinate with the Data Protection Officer (DPO) and relevant stakeholders to monitor data privacy obligations, assess compliance posture, and track remediation of identified gaps.
  • Support privacy impact assessments and data mapping activities to maintain an accurate record of personal data processing activities across the organization.
  • Incorporate data privacy requirements into vendor risk assessments and third-party due diligence activities, ensuring vendors handling personal data meet applicable contractual and regulatory obligations.

GRC Tooling & Documentation
  • Administer and maintain GRC platform(s) (Drata, OneTrust), including control mapping, evidence collection workflows, and compliance dashboards.
  • Produce compliance posture reporting and audit readiness metrics for governance forums and leadership review.
  • Recommend new or modified procedures that improve efficiency or compliance and mitigate risk or loss.

IT Project Coordination Support
  • Provide coordination support for IT implementation and installation projects, including scheduling, stakeholder communication, task tracking, and follow-up on open items across internal teams and vendors.
  • Serve as the primary point of contact for project coordination activities, ensuring timely communication of status, issues, and dependencies to relevant stakeholders.
  • Assist in ensuring that IT implementations satisfy applicable compliance and control requirements prior to go-live.

Skills and Competencies:
  • Excellent verbal and written communication skills, including the ability to interact clearly and concisely with all departments and levels of management with a focus on customer service
  • Excellent organizational skills with attention-to-detail
  • Ability to meet multiple deadlines in a fast-paced environment
  • Ability to effectively manage time and prioritize tasks
  • Ability to act with integrity, professionalism, and confidentiality
  • Proficiency with Microsoft Office
  • Strong problem-solving skills, especially under time constraints
  • In-depth understanding of IT compliance frameworks and regulations such as NIST SP 800-53, SOC 2, SOX, CCPA, and GDPR
  • Comprehensive knowledge of the concepts and principles of internal controls and regulatory compliance

Education, Experience, and Licenses/Certifications:
  • Bachelor's degree in Business Administration, Information Systems, Risk Management, Security Management, or equivalent work experience.
  • 2-5 years of progressive experience in IT governance, risk, and compliance, IT audit, or a closely related discipline.
  • Demonstrated hands-on experience with SOC 2 and/or ISO 27001 audit or assessment cycles.
  • IT security and privacy certifications such as CISA, CISSP, CRISC, CISM, CIPM, or CDPSE preferred.

Physical Requirements:
  • Willingness and ability to travel as needed
  • Willingness and ability to work after regularly scheduled hours as needed
  • Ability to sit at a desk for prolonged periods working on a computer (4 to 8 hours)
  • Ability to operate the equipment used for the job
  • Ability to lift 15 pounds at times
  • Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions of this job

Marginal Functions:
A review of this job description may have omitted some of the marginal functions of the position that are incidental to the performance of the job duties and responsibilities. This job description, in no way, states or implies that these are the only duties and/or responsibilities to be performed by the employee in this position. The employee in this position will be required to follow any other job-related instructions and to perform any other job-related duties requested by his/her supervisor.
Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities
This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.