1

It Grc Analyst Jobs (NOW HIRING)

GRC Analyst

Los Angeles, CA · On-site

$100K - $135K/yr

The future isn't coming; it's here, and we need builders, innovators and problem solvers to help us create it. Who you are Metropolis is seeking a Governance, Risk, and Compliance (GRC) Analyst to ...

Associate GRC Analyst

Richmond, VA · On-site

$76K - $102K/yr

Associate GRC Analyst Overview CoStar Group (NASDAQ: CSGP) is a leading global provider of ... What's in it for You When you join CoStar Group, you'll experience a collaborative and innovative ...

About the Role The SAP GRC Analyst will be responsible for GRC administration and segregation of ... Support internal and external audits as it relates to access controls, mitigation, and remediation ...

Sr. GRC Analyst About Subsplash Subsplash is an exciting award-winning team of 280+ mission-driven ... Don't take our word for it--head to Glassdoor and see for yourself! About the Team The IT Team at ...

Sr. GRC Analyst About Subsplash Subsplash is an exciting award-winning team of 280+ mission-driven ... Don't take our word for it--head to Glassdoor and see for yourself! About the Team The IT Team at ...

Sr. GRC Analyst About Subsplash Subsplash is an exciting award-winning team of 280+ mission-driven ... Don't take our word for it--head to Glassdoor and see for yourself! About the Team The IT Team at ...

This role provides strategic oversight of cyber and IT operational risk assessments, regulatory compliance, IT audit coordination, and IT policy development. GRC Cybersecurity Analyst III serves as a ...

What You Will Do As an Entry Level GRC Analyst at Hotman Group you will work side by side with ... Solid understanding of fundamental security and IT concepts including access controls, data ...

About the Role As a Senior GRC Analyst, HIPAA, you will be a subject matter expert for HIPAA ... You will work directly with Engineering, Product, Security Engineering, Legal, IT, and business ...

Associate GRC Analyst

Richmond, VA · On-site

$76K - $102K/yr

Associate GRC Analyst Overview CoStar Group (NASDAQ: CSGP) is a leading global provider of ... What's in it for You When you join CoStar Group, you'll experience a collaborative and innovative ...

Sr. GRC Analyst

Charlotte, NC · On-site

$95K - $105K/yr

Sr. GRC Analyst About Subsplash Subsplash is an exciting award-winning team of 280+ mission-driven ... Don't take our word for it--head to Glassdoor and see for yourself! About the Team The IT Team at ...

Sr. GRC Analyst

Louisville, KY · On-site

$95K - $105K/yr

Sr. GRC Analyst About Subsplash Subsplash is an exciting award-winning team of 280+ mission-driven ... Don't take our word for it--head to Glassdoor and see for yourself! About the Team The IT Team at ...

What You Will Do As an Entry Level GRC Analyst at Hotman Group you will work side by side with ... Solid understanding of fundamental security and IT concepts including access controls, data ...

Associate GRC Analyst

Richmond, VA

$76K - $102K/yr

Associate GRC Analyst Overview CoStar Group (NASDAQ: CSGP) is a leading global provider of ... What's in it for You When you join CoStar Group, you'll experience a collaborative and innovative ...

Sr. GRC Analyst

Albuquerque, NM · On-site

$95K - $105K/yr

Sr. GRC Analyst About Subsplash Subsplash is an exciting award-winning team of 280+ mission-driven ... Don't take our word for it--head to Glassdoor and see for yourself! About the Team The IT Team at ...

Sr. GRC Analyst

Indianapolis, IN · On-site

$95K - $105K/yr

Sr. GRC Analyst About Subsplash Subsplash is an exciting award-winning team of 280+ mission-driven ... Don't take our word for it--head to Glassdoor and see for yourself! About the Team The IT Team at ...

$41.75 - $55.75/hr

The IT GRC Analyst plays a critical role in ensuring that the organization's IT governance is aligned with business objectives while also adhering to governance standards, risk management practices ...

GRC Analyst II

Colorado Springs, CO · On-site

$73K - $92K/yr

The Governance, Risk, and Compliance (GRC) Analyst II configures, implements, and manages security ... Experience supporting IT audits, risk assessments, or compliance assessments * Working knowledge of ...

Showing results 21-40

It Grc Analyst information

See salary details

$36.5K

$97.7K

$228.5K

How much do it grc analyst jobs pay per year?

As of Aug 7, 2026, the average yearly pay for it grc analyst in the United States is $97,659.00, according to ZipRecruiter salary data. Most workers in this role earn between $55,000.00 and $111,000.00 per year, depending on experience, location, and employer.

What is an IT GRC analyst?

IT GRC Analysts are professionals who specialize in managing and overseeing an organization's Information Technology (IT) Governance, Risk, and Compliance (GRC) programs. Their main responsibilities include assessing risks to IT systems, ensuring compliance with relevant laws and regulations, and developing policies to strengthen IT governance. They also work closely with other departments to identify and mitigate security risks, conduct audits, and provide recommendations for process improvements. By doing so, IT GRC Analysts help organizations protect their data and maintain regulatory compliance.

Are IT GRC analysts in demand?

IT GRC analysts are in high demand due to increasing cybersecurity regulations and the need for organizations to manage governance, risk, and compliance effectively. Employers seek professionals with knowledge of frameworks like ISO 27001, NIST, and relevant certifications such as CISA or CISSP, making this a growing field with strong job prospects.

What are the key skills and qualifications needed to thrive as an IT GRC analyst?

To thrive as an IT GRC Analyst, you need a solid understanding of IT risk management, compliance frameworks (like ISO 27001 or NIST), and a relevant degree in information technology or cybersecurity. Familiarity with GRC tools (such as Archer or ServiceNow), audit management systems, and industry certifications like CISA or CRISC are commonly required. Strong analytical thinking, attention to detail, and effective communication skills help you interpret complex regulations and work with diverse stakeholders. These competencies ensure organizations effectively manage risks, maintain regulatory compliance, and protect critical information assets.

What is the difference between It Grc Analyst vs It Security Analyst?

AspectIt Grc AnalystIt Security Analyst
CertificationsISO 27001, CISSP, CISACISSP, CEH, CompTIA Security+
Work EnvironmentRisk management, policy development, complianceSecurity monitoring, incident response, threat analysis
Employer & Industry UsageFinance, healthcare, government, corporateIT firms, cybersecurity companies, large enterprises

The It Grc Analyst primarily focuses on governance, risk management, and compliance frameworks, ensuring organizations adhere to regulations. In contrast, the It Security Analyst concentrates on protecting systems from security threats through monitoring and incident response. Both roles require certifications like CISSP and work within similar industries, but their core responsibilities differ—one emphasizes policy and compliance, the other security operations.

What are some common challenges faced by IT GRC analysts, and how can they effectively address them?

IT GRC Analysts often face challenges such as keeping up with rapidly changing compliance regulations, managing complex risk assessments, and ensuring organization-wide adherence to policies. To address these, analysts should prioritize continuous learning, collaborate closely with IT and business teams, and utilize automated GRC tools to streamline processes. Building strong communication skills also helps in advocating for compliance and fostering a culture of risk awareness across the organization.

Is an IT GRC analyst entry-level?

An IT GRC analyst role is often considered entry-level or suitable for candidates with some experience in IT, cybersecurity, or compliance. Typically, it requires foundational knowledge of governance, risk management, and compliance frameworks, along with relevant certifications like CISA or CISSP. However, the level of experience required can vary depending on the organization and specific job responsibilities.

What does an IT GRC analyst do?

An IT GRC analyst is responsible for managing and implementing governance, risk management, and compliance processes within an organization. They assess security policies, ensure regulatory adherence, and use tools like GRC software to identify and mitigate IT risks. Strong knowledge of cybersecurity standards and certifications such as ISO 27001 or COBIT is often required.
More about It Grc Analyst jobs
What cities are hiring for It Grc Analyst jobs? Cities with the most It Grc Analyst job openings:
What states have the most It Grc Analyst jobs? States with the most job openings for It Grc Analyst jobs include:
Infographic showing various It Grc Analyst job openings in the United States as of August 2026, with employment types broken down into 1% Internship, 84% Full Time, 7% Part Time, 1% Temporary, and 7% Contract. Highlights an 81% Physical, 7% Hybrid, and 12% Remote job distribution, with an average salary of $97,659 per year, or $47 per hour.

GRC Analyst

Metropolis

Los Angeles, CA • On-site

$100K - $135K/yr

Full-time

Posted 7 days ago


Job description

Who we are

The real world is the next frontier, and at Metropolis, we are creating the artificial intelligence to make it responsive. We are pioneering the Recognition Economy — a future where mundane repetition disappears and being known unlocks access, comfort and belonging everywhere you go. From transforming parking into a seamless drive-in, drive-out experience for millions of Members to expanding our intelligence layer across retail and hospitality, we are building a world that feels instinctive and magical. The future isn't coming; it's here, and we need builders, innovators and problem solvers to help us create it.

Who you are

Metropolis is seeking a Governance, Risk, and Compliance (GRC) Analyst to join our expanding Security team. Reporting to the Senior Manager, GRC, you will mature information security policies, drive employee security awareness, and pioneer our AI governance framework. You will partner across Technology, Legal, Internal Audit, Procurement, and People Operations to safeguard customer trust and support operational excellence.

What you'll do
  • Author, update, and enforce corporate security policies to guarantee cross-departmental compliance
  • Deploy and manage required information security training campaigns as the platform owner
  • Transform static policies into interactive modules with comprehension quizzes for mandatory sign-offs
  • Establish and enforce an internal AI governance framework with Data, Legal, and Tech teams
  • Conduct structured risk assessments on emerging tools and internal AI models to maintain behavioral guardrails
  • Report training metrics, policy exceptions, and risk postures directly to senior management
  • Review vendor security profiles and software pipelines to mitigate security risk
What we're looking for
  • 3+ years of experience in information security GRC, cybersecurity training, or technology compliance
  • Proven track record of managing required security awareness programs and driving cross-functional accountability
  • Experience with modern training orchestration platforms and understanding of AI and machine learning data security
  • Working knowledge of standard industry frameworks, specifically SOC 2 and PCI-DSS
  • Communication skills with the ability to explain complex regulatory needs to non-technical employees
  • Bachelor's degree in Cybersecurity, Information Systems, or an equivalent technical discipline
While not required, these are a plus:
  • GRC certifications such as CISA or CRISC

4 Days in Office: Metropolis values in-person collaboration to drive innovation, strengthen culture, and enhance the Member experience. Our corporate team members hold to our office-first model, which requires employees to be on-site at least four days a week, fostering organic interactions that spark creativity and connection

When you join Metropolis, you'll join a team of world-class product leaders and engineers, building an ecosystem of technologies at the intersection of parking, mobility, and real estate. Our goal is to build an inclusive culture where everyone has a voice and the best idea wins. You will play a key role in building and maintaining this culture as our organization grows. The anticipated base salary for this position is $100,000.00 USD to $135,000.00 USD annually. The actual base salary offered is determined by a number of variables, including, as appropriate, the applicant's qualifications for the position, years of relevant experience, distinctive skills, level of education attained, certifications or other professional licenses held, and the location of residence and/or place of employment. Base salary is one component of Metropolis's total compensation package, which may also include access to or eligibility for healthcare benefits, a 401(k) plan, short-term and long-term disability coverage, basic life insurance, a lucrative stock option plan, bonus plans and more. #LI-CM1 #LI-Onsite

Metropolis may utilize an automated employment decision tool (AEDT) to assess or evaluate your candidacy for employment or promotion. AEDTs are used to assist in assessing a candidate's application relative to the required job qualifications and responsibilities listed in the job posting.

As part of this process, Metropolis retains data relevant to your candidacy, including personal information, for a period that is reasonably necessary for the use of the tool. If you are hired for the position, your data may become part of your employee records.

Metropolis Technologies is an equal opportunity employer. We make all hiring decisions based on merit, qualifications, and business needs, without regard to race, color, religion, sex (including gender identity, sexual orientation, or pregnancy), national origin, disability, veteran status, or any other protected characteristic under federal, state, or local law.