1

It Grc Jobs (NOW HIRING)

GRC Platforms * Policy Management * Compliance Automation Tools * IT Risk Assessment * Control Design * Security Testing This describes the general nature and level of work performed in this role. It ...

GRC Platforms * Policy Management * Compliance Automation Tools * IT Risk Assessment * Control Design * Security Testing This describes the general nature and level of work performed in this role. It ...

Overview The IT GRC Analyst operates within the enterprise Cybersecurity Operations function and supports the Information Technology, Information Systems, and other technology teams aligned under the ...

This role provides strategic oversight of cyber and IT operational risk assessments, regulatory compliance, IT audit coordination, and IT policy development. GRC Cybersecurity Analyst III serves as a ...

This role provides strategic oversight of cyber and IT operational risk assessments, regulatory compliance, IT audit coordination, and IT policy development. GRC Cybersecurity Analyst III serves as a ...

This role provides strategic oversight of cyber and IT operational risk assessments, regulatory compliance, IT audit coordination, and IT policy development. GRC Cybersecurity Analyst III serves as a ...

IT GRC Auditor Consultant ONSITE - CORAL GABLES, MIAMI, FLORIDA www.elevateconsult.com Are you passionate about working in a complex IT environment where security and data privacy are a primary focus ...

Showing results 21-40

It Grc information

See salary details

$27

$57

$84

How much do it grc jobs pay per hour?

As of Sep 5, 2026, the average hourly pay for it grc in the United States is $57.43, according to ZipRecruiter salary data. Most workers in this role earn between $48.80 and $65.87 per hour, depending on experience, location, and employer.

What is IT GRC?

IT GRC stands for Information Technology Governance, Risk, and Compliance. It refers to the framework and processes that organizations use to ensure their IT operations align with business goals, effectively manage risks, and comply with relevant laws and regulations. IT GRC professionals help organizations create policies, implement controls, monitor compliance, and respond to audits. Their work is essential for protecting data, reducing security risks, and maintaining the trust of customers and stakeholders.

What are the key skills and qualifications needed to thrive as an IT GRC professional?

To thrive as an IT GRC professional, you need a solid understanding of information security, risk management frameworks, regulatory compliance, and often a bachelor's degree in information technology or a related field. Familiarity with tools like GRC platforms (e.g., RSA Archer, ServiceNow GRC), audit management systems, and certifications such as CISA, CISSP, or CRISC are typically required. Strong analytical thinking, attention to detail, and effective communication skills help you assess risks and collaborate with stakeholders. These skills are crucial for ensuring organizations meet regulatory requirements, manage IT risks, and maintain robust security postures.

What are some common challenges faced by IT GRC professionals, and how can they be addressed?

IT GRC (Governance, Risk, and Compliance) professionals often encounter challenges such as keeping up with rapidly evolving regulations, balancing security with business objectives, and ensuring cross-departmental collaboration. Staying updated requires continuous learning and leveraging industry resources. Building strong relationships with stakeholders across IT, legal, and business teams helps streamline compliance processes, while utilizing automated GRC tools can improve efficiency and accuracy. Proactive communication and ongoing training are key strategies for overcoming these challenges.

What is the difference between It Grc vs Cybersecurity Analyst?

AspectIt GrcCybersecurity Analyst
Required CertificationsISO 27001 Lead Implementer, CISSP, CISACISSP, CompTIA Security+, CEH
Work EnvironmentPolicy development, risk management, complianceThreat detection, incident response, security monitoring
Employer & Industry UsageCorporate compliance, risk management teamsSecurity operations centers, IT departments

It Grc professionals focus on establishing policies, managing risks, and ensuring compliance with regulations. Cybersecurity Analysts primarily monitor security threats, respond to incidents, and protect systems. While both roles require security knowledge, It Grc emphasizes governance and risk management, whereas Cybersecurity Analysts are more involved in technical threat mitigation.

Are IT GRC jobs in demand?

IT GRC (Governance, Risk, and Compliance) jobs are in high demand due to increasing cybersecurity threats and regulatory requirements. Professionals with skills in risk management, compliance frameworks, and security tools are sought after across various industries, often requiring certifications like CISA or CISSP. The role offers strong growth prospects as organizations prioritize IT governance and security.

Is IT GRC a good career?

IT GRC (Governance, Risk, and Compliance) is a growing field that offers opportunities in cybersecurity, risk management, and regulatory compliance. Professionals in this area typically need knowledge of security frameworks, certifications like CISSP or CISA, and strong analytical skills. It can be a stable career with demand across various industries, especially as organizations prioritize data security and compliance.
More about It Grc jobs

What cities are hiring for It Grc jobs?

Cities with the most It Grc job openings:

What are the most commonly searched types of It Grc jobs?

The most popular types of It Grc jobs are:

What states have the most It Grc jobs?

States with the most job openings for It Grc jobs include:

What job categories do people searching It Grc jobs look for?

The top searched job categories for It Grc jobs are:

Infographic showing various It Grc job openings in the United States as of August 2026, with employment types broken down into 1% As Needed, 92% Full Time, 1% Part Time, and 6% Contract. Highlights an 71% Physical, 8% Hybrid, and 21% Remote job distribution, with an average salary of $119,446 per year, or $57.4 per hour.

IT GRC Lead Analyst

Westfield Insurance

Westfield Center, OH • On-site

$90 - $120/hr

Other

Posted 4 days ago


Westfield Insurance rating

8.7

Company rating: 8.7 out of 10

Based on 12 frontline employees who took The Breakroom Quiz

72nd of 315 rated insurance


Job description

Job Summary:

The IT Governance, Risk, and Compliance (GRC) Lead Analyst serves as a subject matter expert responsible for leading the design, implementation, maturity, and continuous improvement of the organization’s IT governance, risk management, and compliance programs.

This role provides strategic oversight of technology risk and control management, partners with business and technology leaders to ensure alignment with enterprise objectives and drives a proactive risk-aware culture across the organization. The GRC Lead Analyst serves as a trusted advisor to senior leadership, influencing risk-based decision-making and ensuring compliance with regulatory requirements, industry standards, and internal policies.

The ideal candidate possesses deep expertise in governance frameworks, regulatory compliance, IT controls, risk management, audit practices, and cybersecurity governance, along with demonstrated leadership in driving enterprise-wide initiatives and mentoring others.

Applicants must be currently authorized to work in the United States on a full-time basis without employer sponsorship.

Job Responsibilities:

  • Lead the development, execution, and continuous improvement of the enterprise IT Governance, Risk, and Compliance (GRC) program, frameworks, and operating model.
  • Serve as the organization's subject matter expert for IT governance, risk management, compliance, and control oversight.
  • Lead enterprise technology risk assessments and provide risk-based recommendations aligned with business objectives and risk appetite.
  • Drive the maturity of risk management practices through governance enhancements, process optimization, and industry best practices.
  • Oversee compliance with regulatory requirements, industry standards, and internal policies, ensuring effective implementation of controls and monitoring mechanisms.
  • Establish and maintain IT control frameworks, including ITGCs, cybersecurity controls, and key risk indicators (KRIs).
  • Lead control assessments, testing, continuous monitoring, and remediation efforts to strengthen the organization's control environment.
  • Serve as the primary liaison for internal and external audits, regulatory examinations, and issue remediation governance.
  • Lead third-party technology risk management activities, including vendor assessments and ongoing risk oversight.
  • Champion the implementation, optimization, and automation of GRC processes and technologies to improve efficiency and effectiveness.
  • Develop and deliver executive-level reporting, dashboards, and insights on risk, compliance, audit results, and remediation activities.
  • Lead cross-functional GRC initiatives, influence strategic decision-making, and mentor team members to foster a culture of risk awareness and continuous improvement.

Job Qualifications:

  • 7+ years of experience in IT Governance, Risk, and Compliance, Information Security, IT Audit, or related disciplines.
  • Bachelor's degree in Information Technology, Cybersecurity, Information Systems, Risk Management, Business, or related field.

Location
Hybrid defined as three (3) or more days per week in the office.

Licenses and Certifications:

  • CISSP
  • CISA
  • CRISC
  • CISM
  • CGEIT

Behavioral Competencies:

  • Collaborates
  • Communicates Effectively
  • Customer Focus
  • Decision Quality
  • Nimble Learning

Technical Skills:

  • Insurance Industry Knowledge
  • Regulatory Examinations
  • GRC Platforms
  • Policy Management
  • Compliance Automation Tools
  • IT Risk Assessment
  • Control Design
  • Security Testing

This job description describes the general nature and level of work performed in this role. It is not intended to be an exhaustive list of all duties, skills, responsibilities, knowledge, etc. These may be subject to change and additional functions may be assigned as needed by management.

#J-18808-Ljbffr

What Westfield Insurance employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom