1

It Grc Analyst Jobs (NOW HIRING)

GRC Analyst I

Madison, WI · On-site

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

The GRC Analyst I also supports emerging AI Governance initiatives by assisting with the ... Participate in business continuity, IT disaster recovery, crisis management, resilience planning ...

GRC Analyst I

Madison, WI · On-site

  • Medical

  • Dental

  • Vision

  • Retirement

  • PTO

The GRC Analyst I also supports emerging AI Governance initiatives by assisting with the ... Participate in business continuity, IT disaster recovery, crisis management, resilience planning ...

About the Role Merci Technologies is seeking a GRC Analyst to support the governance, risk, and ... Ability to read a control requirement and translate it into clear, actionable guidance * Strong ...

GRC Analyst

Los Angeles, CA

$100K - $135K/yr

  • Medical

  • Life

  • Retirement

The future isn't coming; it's here, and we need builders, innovators and problem solvers to help us create it. Who you are Metropolis is seeking a Governance, Risk, and Compliance (GRC) Analyst to ...

GRC Analyst

Boston, MA · On-site

$82K - $105K/yr

  • Medical

  • Retirement

  • PTO

Act as a liaison between IT and business units to support the development and implementation of ... Manages GRC ticket maintenance and provides guidance to stakeholders on GRC topics. * Monitor and ...

Senior GRC Analyst

Pittsburgh, PA · On-site

$114K - $163K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

Senior GRC Analyst Department: Compliance & Fraud Employment Type: Full Time Location: Pittsburgh ... Own IT general control readiness across change management, logical access, SDLC, and backup and job ...

GRC Analyst

Charleston, WV

  • Medical

  • Dental

  • Vision

  • PTO

The GRC Analyst supports the Information Security Office by managing third-party vendor risk ... Supporting an internal ISRM program focused on uncovering cybersecurity risk and adding it to a ...

New

About the Role The SAP GRC Analyst will be responsible for GRC administration and segregation of ... Support internal and external audits as it relates to access controls, mitigation, and remediation ...

About the Role The SAP GRC Analyst will be responsible for GRC administration and segregation of ... Support internal and external audits as it relates to access controls, mitigation, and remediation ...

The future isn't coming; it's here, and we need builders, innovators and problem solvers to help us create it. Who you are Metropolis is seeking a Governance, Risk, and Compliance (GRC) Analyst to ...

GRC Analyst

Los Angeles, CA · On-site

$100K - $135K/yr

  • Medical

  • Life

  • Retirement

The future isn't coming; it's here, and we need builders, innovators and problem solvers to help us create it. Who you are Metropolis is seeking a Governance, Risk, and Compliance (GRC) Analyst to ...

GRC Analyst

Boston, MA · On-site

  • Medical

  • Retirement

  • PTO

Act as a liaison between IT and business units to support the development and implementation of ... Manages GRC ticket maintenance and provides guidance to stakeholders on GRC topics. * Monitor and ...

Sr. GRC Analyst About Subsplash Subsplash is an exciting award-winning team of 280+ mission-driven ... Don't take our word for it--head to Glassdoor and see for yourself! About the Team The IT Team at ...

Sr. GRC Analyst About Subsplash Subsplash is an exciting award-winning team of 280+ mission-driven ... Don't take our word for it--head to Glassdoor and see for yourself! About the Team The IT Team at ...

Sr. GRC Analyst About Subsplash Subsplash is an exciting award-winning team of 280+ mission-driven ... Don't take our word for it--head to Glassdoor and see for yourself! About the Team The IT Team at ...

What You Will Do As an Entry Level GRC Analyst at Hotman Group you will work side by side with ... Solid understanding of fundamental security and IT concepts including access controls, data ...

$41.75 - $55.75/hr

The IT GRC Analyst plays a critical role in ensuring that the organization's IT governance is aligned with business objectives while also adhering to governance standards, risk management practices ...

This role provides strategic oversight of cyber and IT operational risk assessments, regulatory compliance, IT audit coordination, and IT policy development. GRC Cybersecurity Analyst III serves as a ...

Showing results 21-40

It Grc Analyst information

See salary details

$36.5K

$97.7K

$228.5K

How much do it grc analyst jobs pay per year?

As of Aug 17, 2026, the average yearly pay for it grc analyst in the United States is $97,659.00, according to ZipRecruiter salary data. Most workers in this role earn between $55,000.00 and $111,000.00 per year, depending on experience, location, and employer.

What is an IT GRC analyst?

IT GRC Analysts are professionals who specialize in managing and overseeing an organization's Information Technology (IT) Governance, Risk, and Compliance (GRC) programs. Their main responsibilities include assessing risks to IT systems, ensuring compliance with relevant laws and regulations, and developing policies to strengthen IT governance. They also work closely with other departments to identify and mitigate security risks, conduct audits, and provide recommendations for process improvements. By doing so, IT GRC Analysts help organizations protect their data and maintain regulatory compliance.

What are the key skills and qualifications needed to thrive as an IT GRC analyst?

To thrive as an IT GRC Analyst, you need a solid understanding of IT risk management, compliance frameworks (like ISO 27001 or NIST), and a relevant degree in information technology or cybersecurity. Familiarity with GRC tools (such as Archer or ServiceNow), audit management systems, and industry certifications like CISA or CRISC are commonly required. Strong analytical thinking, attention to detail, and effective communication skills help you interpret complex regulations and work with diverse stakeholders. These competencies ensure organizations effectively manage risks, maintain regulatory compliance, and protect critical information assets.

What are some common challenges faced by IT GRC analysts, and how can they effectively address them?

IT GRC Analysts often face challenges such as keeping up with rapidly changing compliance regulations, managing complex risk assessments, and ensuring organization-wide adherence to policies. To address these, analysts should prioritize continuous learning, collaborate closely with IT and business teams, and utilize automated GRC tools to streamline processes. Building strong communication skills also helps in advocating for compliance and fostering a culture of risk awareness across the organization.

What is the difference between It Grc Analyst vs It Security Analyst?

AspectIt Grc AnalystIt Security Analyst
CertificationsISO 27001, CISSP, CISACISSP, CEH, CompTIA Security+
Work EnvironmentRisk management, policy development, complianceSecurity monitoring, incident response, threat analysis
Employer & Industry UsageFinance, healthcare, government, corporateIT firms, cybersecurity companies, large enterprises

The It Grc Analyst primarily focuses on governance, risk management, and compliance frameworks, ensuring organizations adhere to regulations. In contrast, the It Security Analyst concentrates on protecting systems from security threats through monitoring and incident response. Both roles require certifications like CISSP and work within similar industries, but their core responsibilities differ—one emphasizes policy and compliance, the other security operations.

Are IT GRC analysts in demand?

IT GRC analysts are in high demand due to increasing cybersecurity regulations and the need for organizations to manage governance, risk, and compliance effectively. Employers seek professionals with knowledge of frameworks like ISO 27001, NIST, and relevant certifications such as CISA or CISSP, making this a growing field with strong job prospects.

Is an IT GRC analyst entry-level?

An IT GRC analyst role is often considered entry-level or suitable for candidates with some experience in IT, cybersecurity, or compliance. Typically, it requires foundational knowledge of governance, risk management, and compliance frameworks, along with relevant certifications like CISA or CISSP. However, the level of experience required can vary depending on the organization and specific job responsibilities.

What does an IT GRC analyst do?

An IT GRC analyst is responsible for managing and implementing governance, risk management, and compliance processes within an organization. They assess security policies, ensure regulatory adherence, and use tools like GRC software to identify and mitigate IT risks. Strong knowledge of cybersecurity standards and certifications such as ISO 27001 or COBIT is often required.
More about It Grc Analyst jobs

What cities are hiring for It Grc Analyst jobs?

Cities with the most It Grc Analyst job openings:

What states have the most It Grc Analyst jobs?

States with the most job openings for It Grc Analyst jobs include:

Infographic showing various It Grc Analyst job openings in the United States as of August 2026, with employment types broken down into 1% Internship, 86% Full Time, 6% Part Time, and 7% Contract. Highlights an 81% Physical, 9% Hybrid, and 10% Remote job distribution, with an average salary of $97,659 per year, or $47 per hour.

Full-time

Medical, Dental, Vision, Retirement, PTO

Posted 10 days ago


Job description

Job Overview
The GRC Analyst I is responsible for supporting the organization's Governance, Risk, and Compliance (GRC) program through risk management, policy governance, compliance monitoring, reporting, and continuous improvement activities. This role assists with risk assessments, maintenance of the risk register, control evaluations, mitigation tracking, policy management, and compliance-related activities that help protect the organization and enable business objectives.
The GRC Analyst I also supports emerging AI Governance initiatives by assisting with the identification, assessment, monitoring, and reporting of risks associated with artificial intelligence technologies. Working closely with IT Security, Legal, Business Continuity, Data Governance, and business stakeholders, this position helps promote responsible technology use, organizational resilience, and a risk-aware culture that enables the business to move faster with greater confidence.
This is a full-time position based at Sub-Zero Group's headquarters in Fitchburg, Wisconsin, just outside Madison.
Job Responsibilities
Responsibilities include, but are not limited to:
Governance:
  • Assist with policy governance activities, including the development, maintenance, review, and administration of policies, standards, procedures, and related governance documentation, while providing guidance to employees and business units on their application.
  • Support the organization's AI Governance program through documentation, inventories, risk assessments, stakeholder coordination, and monitoring activities that promote the responsible, secure, and compliant use of AI technologies.
  • Help maintain alignment with governance frameworks and industry standards, including NIST CSF, NIST AI RMF, and ISO standards, while assessing governance implications of new technologies, AI initiatives, business process changes, and emerging regulatory requirements.

Risk Management:
  • Support risk assessment activities by gathering information, documenting risks, facilitating stakeholder discussions, evaluating inherent and residual risk, and tracking follow-up actions and remediation activities.
  • Maintain the risk register, including risk documentation, ownership assignments, risk scoring, review cadences, mitigation plans, control effectiveness evaluations, and reporting activities.
  • Partner with risk owners to evaluate risk events, root causes, business impacts, existing controls, and risk response strategies while developing dashboards, metrics, KPIs, and executive reporting that communicate organizational risk exposure and program maturity.

Compliance:
  • Monitor compliance with internal policies, regulatory requirements, contractual obligations, and applicable industry standards while supporting assessments against relevant governance and compliance frameworks.
  • Assist with compliance reviews, internal audits, and audit readiness activities by collecting evidence, validating controls, documenting findings, maintaining records, and tracking remediation activities through resolution.
  • Track and report compliance metrics, audit findings, governance performance indicators, corrective actions, and overall program effectiveness and maturity.

Additional Opportunities
The GRC Analyst I may have opportunities to contribute to additional initiatives based on business needs, program priorities, and individual career interests.
  • Business Continuity & Resilience: Participate in business continuity, IT disaster recovery, crisis management, resilience planning, business impact analyses, exercises, and improvement activities in support of organizational resilience efforts.
  • Third-Party Risk Management: Assist with vendor due diligence, third-party governance activities, and ongoing monitoring efforts as the organization's third-party risk management capabilities evolve and mature.
  • Awareness, Training & Risk Culture: Contribute to governance, risk, compliance, cybersecurity, and responsible AI awareness initiatives through the development of training materials, communications, workshops, and other educational opportunities that promote a culture of accountability and risk-informed decision-making.

Required Qualifications
  • Associate's or Bachelor's degree in enterprise risk management, information technology, cybersecurity, business administration, finance, accounting, or related field.
  • 0-3 years of relevant experience in risk management, governance, compliance, auditing, or related disciplines.
  • Strong analytical, organizational, and communication skills.

Preferred Qualifications
  • Experience supporting risk assessments, maintaining risk registers, or tracking remediation activities.
  • Experience supporting policy management, compliance reviews, control assessments, or audit activities.
  • Familiarity with NIST CSF, NIST AI RMF, ISO 27001, ISO 31000, ISO 22301, or similar frameworks.
  • Familiarity with regulations and standards such as CCPA/CPRA, GDPR, PCI DSS, or similar requirements.
  • Relevant certifications or progress toward certification, such as ISC2 CC, Security+, CISA, CRISC, CGRC, or similar credentials.

Why Join Sub-Zero Group?
Join a growing Governance, Risk, and Compliance program that is helping embed governance, risk management, compliance, and resilience into the fabric of the organization. This role offers a unique opportunity to help shape and mature a developing GRC program while gaining hands-on experience across technology risk management, cybersecurity governance, compliance, policy management, internal audit, and business continuity. Working closely with organizational leaders, you will have a direct impact on strengthening the company's ability to reliably achieve its objectives, address uncertainty, build resilience, and act with integrity.
We value our employees by providing:
  • Competitive compensation based on skills
  • Industry leading health, dental, and vision plans
  • Generous 401(k) savings and profit sharing
  • 10 Paid Holidays
  • Paid Time Off (PTO)
  • Parental Leave
  • On-site UW Health clinic, fitness center, and walking paths
  • Education assistance and internal training programs
  • Employee discount program
  • Employee Assistance Program (EAP)
  • Electric vehicle charging
  • Department & Company-wide social events

Interested in learning more about our robust benefits package? Click here!
This position requires a pre-employment drug/alcohol test and background check, which will be administered after a conditional job offer is extended. A negative drug/alcohol test result is required for employment. Refusal to take the test or a positive result may disqualify a candidate from further consideration. All drug testing will be conducted in accordance with federal and state laws.
Equal Opportunity Employer
This employer is required to notify all applicants of their rights pursuant to federal employment laws.
For further information, please review the Know Your Rights notice from the Department of Labor.