1

It Grc Analyst Jobs (NOW HIRING)

GRC Analyst - Remote

$80K - $137K/yr

Overview The GRC Analyst will play a critical role in strengthening the security posture of our ... Leads and maintains information security risk assessments across IT, operational, and third-party ...

As a GRC Analyst, you will manage compliance frameworks, assess organizational risk, and help ... This role partners closely with IT, Legal, and R&D to keep Zywave's security posture audit-ready ...

The Opportunity We are hiring a Security GRC & Risk Analyst to own the governance, risk, and ... portfolio company IT teams to assess and close control gaps. * Build and maintain a unified ...

PrizePicks is seeking an experienced and detail-oriented Senior GRC Analyst to join our expanding ... You will partner closely with Security, IT, Legal, Engineering, and business stakeholders to help ...

Senior GRC Analyst

Westerville, OH · On-site

$92K - $121K/yr

We are looking for a Security Governance, Risk, and Compliance (GRC) Analyst to support and mature ... Partner with IT, legal, and business teams to embed security into daily work * Deliver security ...

Senior GRC Analyst

Westerville, OH · On-site

$92K - $121K/yr

We are looking for a Security Governance, Risk, and Compliance (GRC) Analyst to support and mature ... Partner with IT, legal, and business teams to embed security into daily work * Deliver security ...

PrizePicks is seeking an experienced and detail-oriented Senior GRC Analyst to join our expanding ... You will partner closely with Security, IT, Legal, Engineering, and business stakeholders to help ...

As a GRC Analyst, you will manage compliance frameworks, assess organizational risk, and help ... This role partners closely with IT, Legal, and R&D to keep Zywave's security posture audit-ready ...

GRC Analyst

New York, NY · On-site

$150K - $200K/yr

The Role Rogo is hiring a GRC Analyst to support our customer trust, security assurance, and ... If you're obsessed with AI, this is where it's happening.

The Global GRC Senior Analyst will report directly to the Global Cybersecurity Governance, Risk and ... Ensure IT functions are in compliance with best practices and company policies and standards ...

Showing results 41-60

It Grc Analyst information

See salary details

$36.5K

$97.7K

$228.5K

How much do it grc analyst jobs pay per year?

As of Aug 7, 2026, the average yearly pay for it grc analyst in the United States is $97,659.00, according to ZipRecruiter salary data. Most workers in this role earn between $55,000.00 and $111,000.00 per year, depending on experience, location, and employer.

What is an IT GRC analyst?

IT GRC Analysts are professionals who specialize in managing and overseeing an organization's Information Technology (IT) Governance, Risk, and Compliance (GRC) programs. Their main responsibilities include assessing risks to IT systems, ensuring compliance with relevant laws and regulations, and developing policies to strengthen IT governance. They also work closely with other departments to identify and mitigate security risks, conduct audits, and provide recommendations for process improvements. By doing so, IT GRC Analysts help organizations protect their data and maintain regulatory compliance.

Are IT GRC analysts in demand?

IT GRC analysts are in high demand due to increasing cybersecurity regulations and the need for organizations to manage governance, risk, and compliance effectively. Employers seek professionals with knowledge of frameworks like ISO 27001, NIST, and relevant certifications such as CISA or CISSP, making this a growing field with strong job prospects.

What are the key skills and qualifications needed to thrive as an IT GRC analyst?

To thrive as an IT GRC Analyst, you need a solid understanding of IT risk management, compliance frameworks (like ISO 27001 or NIST), and a relevant degree in information technology or cybersecurity. Familiarity with GRC tools (such as Archer or ServiceNow), audit management systems, and industry certifications like CISA or CRISC are commonly required. Strong analytical thinking, attention to detail, and effective communication skills help you interpret complex regulations and work with diverse stakeholders. These competencies ensure organizations effectively manage risks, maintain regulatory compliance, and protect critical information assets.

What is the difference between It Grc Analyst vs It Security Analyst?

AspectIt Grc AnalystIt Security Analyst
CertificationsISO 27001, CISSP, CISACISSP, CEH, CompTIA Security+
Work EnvironmentRisk management, policy development, complianceSecurity monitoring, incident response, threat analysis
Employer & Industry UsageFinance, healthcare, government, corporateIT firms, cybersecurity companies, large enterprises

The It Grc Analyst primarily focuses on governance, risk management, and compliance frameworks, ensuring organizations adhere to regulations. In contrast, the It Security Analyst concentrates on protecting systems from security threats through monitoring and incident response. Both roles require certifications like CISSP and work within similar industries, but their core responsibilities differ—one emphasizes policy and compliance, the other security operations.

What are some common challenges faced by IT GRC analysts, and how can they effectively address them?

IT GRC Analysts often face challenges such as keeping up with rapidly changing compliance regulations, managing complex risk assessments, and ensuring organization-wide adherence to policies. To address these, analysts should prioritize continuous learning, collaborate closely with IT and business teams, and utilize automated GRC tools to streamline processes. Building strong communication skills also helps in advocating for compliance and fostering a culture of risk awareness across the organization.

Is an IT GRC analyst entry-level?

An IT GRC analyst role is often considered entry-level or suitable for candidates with some experience in IT, cybersecurity, or compliance. Typically, it requires foundational knowledge of governance, risk management, and compliance frameworks, along with relevant certifications like CISA or CISSP. However, the level of experience required can vary depending on the organization and specific job responsibilities.

What does an IT GRC analyst do?

An IT GRC analyst is responsible for managing and implementing governance, risk management, and compliance processes within an organization. They assess security policies, ensure regulatory adherence, and use tools like GRC software to identify and mitigate IT risks. Strong knowledge of cybersecurity standards and certifications such as ISO 27001 or COBIT is often required.
More about It Grc Analyst jobs
What cities are hiring for It Grc Analyst jobs? Cities with the most It Grc Analyst job openings:
What states have the most It Grc Analyst jobs? States with the most job openings for It Grc Analyst jobs include:
Infographic showing various It Grc Analyst job openings in the United States as of August 2026, with employment types broken down into 1% Internship, 84% Full Time, 7% Part Time, 1% Temporary, and 7% Contract. Highlights an 81% Physical, 7% Hybrid, and 12% Remote job distribution, with an average salary of $97,659 per year, or $47 per hour.

$80K - $137K/yr

Full-time

Posted 4 days ago


U.S. Anesthesia Partners rating

8.3

Company rating: 8.3 out of 10

Based on 7 frontline employees who took The Breakroom Quiz


Job description

Overview

The GRC Analyst will play a critical role in strengthening the security posture of our growing organization by designing, implementing, and managing control and risk workflows, as well as performing third-party risk assessments. This position is pivotal in ensuring compliance with industry standards and regulations, identifying and mitigating risks, and supporting USAP's overall security governance framework.

At this time, US Anesthesia Partners does not hire candidates residing in California, Hawaii, or Alaska.

The base pay estimate for this role is $80,900 - $137,600 annually. The final offer will depend on the skills, experience, and qualifications of the selected candidate. This range is for base pay only and does not include bonuses or other compensation. This position is eligible for an annual bonus. Bonuses are not guaranteed and are awarded based on company and individual performance.

Job Highlights

ESSENTIAL DUTIES AND RESPONSIBILITIES: (The ideal candidate must be able to complete all physical requirements of the job with or without a reasonable accommodation)

  • Leads the design, configuration, and governance of control frameworks and risk workflows within the GRC platform, ensuring alignment with organizational objectives and compliance requirements.
  • Establishes and maintains control procedures, ensuring alignment with relevant frameworks (internal policy, HIPAA, HITRUST, PCI, SOC 2, NIST, and other applicable frameworks).
  • Oversees the development and maintenance of control libraries, including control narratives, ownership assignments, testing frequency, and evidence requirements.
  • Monitors and updates risk registers, ensuring accurate tracking, scoring, and prioritization of risks within the platform.
  • Drives automation workflows to streamline control testing, evidence collection, attestations, and remediation processes.
  • Tracks policy review cycles and ensures documentation remains current with regulatory and business changes.
  • Leads and maintains information security risk assessments across IT, operational, and third-party domains.
  • Performs control walkthroughs and operating effectiveness testing; documents results and identifies control gaps.
  • Collaborates with internal teams and external auditors to facilitate audits and assessments using the GRC platform for evidence management, issue tracking, and reporting.
  • Ensures ongoing compliance with regulatory requirements and industry standards by maintaining up-to-date documentation and control mappings.
  • Prepares and presents reports, dashboards, and metrics on control effectiveness, risk status, and compliance gaps.
  • Maps controls to applicable regulatory and framework requirements, identifying overlaps to reduce duplicative testing.
  • Supports internal and external audits by gathering evidence, coordinating stakeholder responses, and tracking remediation through closure.
  • Tracks and manages audit findings, corrective action plans (CAPs), and remediation timelines within the GRC platform.
  • Guides risk assessments to identify potential vulnerabilities and threats, documenting findings and supporting evidence in the GRC platform.
  • Partners with stakeholders to develop and implement risk mitigation strategies, tracking progress and ownership within the platform.
  • Develops, monitors, and reports on key risk indicators (KRIs) and key performance indicators (KPIs) to proactively identify and address emerging risks.
  • Maintains and applies consistent risk scoring methodologies, including likelihood, impact, and residual risk calculations.
  • Escalates significant risks and control deficiencies to management and governance committees, providing recommendations for mitigation and improvement, in a timely manner.
  • Leads the development, maintenance, and lifecycle management of information security policies, procedures, standards, and guidelines.
  • Directs policy review and approval workflows with policy owners and stakeholders.
  • Ensures policies remain aligned with evolving regulatory requirements and organizational changes.
  • Leads evaluations of third-party vendors for security and compliance risks, including review of SOC reports, security questionnaires, and contractual requirements.
  • Tracks vendor risk assessments, reassessment cycles, and risk ratings within the GRC platform.
  • Works with business owners to develop and monitor vendor remediation action plans.
  • Supports vendor onboarding and offboarding risk reviews, ensuring appropriate due diligence is documented.
  • Identifies opportunities to enhance GRC processes and workflows to improve efficiency, accuracy, and effectiveness.
  • Stays current on industry trends, emerging threats, and best practices in GRC, recommending improvements to the security and compliance program.
  • Champions automation and integration initiatives to reduce manual effort.
  • Guides periodic program assessments and maturity benchmarking to guide roadmap priorities.
  • Performs other duties and responsibilities as assigned.

Qualifications

KNOWLEDGE/SKILLS/ABILITIES (KSAs):
  • Bachelor's degree in information security, cybersecurity, computer science, information technology, business administration, or a closely related field required. Equivalent experience may be considered in lieu of a degree (e.g., 4+ years of relevant experience in information security, compliance, or GRC roles).
  • Minimum of 5 years relevant experience in governance, risk, and compliance functions within IT or information security.
  • Certified Information Systems Auditor (CISA) preferred.
  • Certified Risk and Information Systems Control (CRISC) preferred.
  • Certified Information Security Manager (CISM) preferred.
  • Other relevant certifications (e.g., CompTIA Security+, ISO 27001 Lead Auditor) preferred.
  • Prior experience implementing, managing, or auditing security policies and procedures.
  • Familiarity with compliance frameworks (HIPAA, NIST CSF, SOC 2, HITRUST, etc.).
  • Prior experience conducting risk assessments and supporting risk management activities.
  • Excellent written and verbal communication skills, including the ability to communicate technical concepts and compliance requirements to both technical and non-technical stakeholders.
  • Ability to manage multiple priorities, work independently, and collaborate effectively across cross-functional teams.
*The physical demands described here are representative of those that may need to be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions
  • Occasional Standing
  • Occasional Walking
  • Frequent Sitting
  • Frequent hand, finger movement
  • Use office equipment (in office or remote)
  • Communicate verbally and in writing

US Anesthesia Partners, Inc. provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, sex, gender identity, sexual orientation, pregnancy, status as a parent, national origin, age, disability (physical or mental), family medical history or genetic information, political affiliation, military service, or other non-merit based factors.

Employment Type: FULL_TIME

What U.S. Anesthesia Partners employees say

Pay

Hours and flexibility

Workplace

Get the full story on Breakroom