1

It Risk And Compliance Analyst Jobs in Spring, TX

Enterprise Architect (IT)

Houston, TX · On-site +1

$66 - $85/hr

Partner with cybersecurity, technology risk, compliance, infrastructure, application, data, and ... Bachelor's degree in computer science, Information Technology, Engineering, Business, or a related ...

Enterprise Architect (IT)

Houston, TX · On-site +1

$102K - $208K/yr

Partner with cybersecurity, technology risk, compliance, infrastructure, application, data, and ... Bachelor's degree in computer science, Information Technology, Engineering, Business, or a related ...

Audit, Business Continuity Planning, and Regulatory Compliance). In-depth understanding of ... Ability to manage and analyze data. Experience raising awareness of information and technology risk ...

The ideal candidate will bring a strong combination of IT audit, SOX compliance, IT risk management ... Strong analytical and problem-solving skills with the ability to identify trends, anomalies, and ...

next page

Showing results 1-20

It Risk And Compliance Analyst information

See Spring, TX salary details

$13

$36

$58

How much do it risk and compliance analyst jobs pay per hour?

As of Sep 2, 2026, the average hourly pay for it risk and compliance analyst in Spring, TX is $36.03, according to ZipRecruiter salary data. Most workers in this role earn between $26.54 and $43.85 per hour, depending on experience, location, and employer.

What is an IT Risk and Compliance Analyst?

IT Risk and Compliance Analysts are professionals who identify, assess, and manage risks related to information technology systems within an organization. They ensure that IT processes and systems comply with internal policies and external regulations, such as GDPR or SOX. Their responsibilities include conducting risk assessments, developing mitigation strategies, monitoring compliance, and reporting on the effectiveness of controls. By doing so, they help protect the organization from cyber threats, data breaches, and regulatory penalties.

What are the key skills and qualifications needed to thrive as an IT Risk and Compliance Analyst?

To thrive as an IT Risk and Compliance Analyst, you need a solid understanding of risk management frameworks, regulatory compliance standards (such as SOX, HIPAA, or GDPR), and a bachelor's degree in information technology or a related field. Familiarity with risk assessment tools, GRC (Governance, Risk, and Compliance) platforms, and relevant certifications like CRISC or CISA is typically required. Strong analytical thinking, attention to detail, and effective communication skills help analysts interpret regulations and collaborate across departments. These skills ensure organizations proactively manage risks, maintain regulatory compliance, and protect sensitive information.

What are some common challenges an IT Risk and Compliance Analyst faces when balancing regulatory requirements with business objectives?

One common challenge IT Risk and Compliance Analysts face is ensuring that regulatory requirements are fully met without hindering business operations or innovation. Balancing security protocols and compliance standards—such as GDPR, SOX, or HIPAA—with the need for efficient workflows can be complex. Analysts must collaborate closely with IT, legal, and business units to interpret regulations pragmatically, design effective controls, and communicate the importance of compliance while minimizing disruption. This often requires strong negotiation, communication, and analytical skills to find solutions that satisfy both compliance mandates and business goals.

What is the difference between It Risk And Compliance Analyst vs It Security Analyst?

AspectIt Risk And Compliance AnalystIt Security Analyst
CertificationsISO 27001, CISSP, CISACISSP, CompTIA Security+
Work EnvironmentRisk assessments, policy development, compliance auditsNetwork monitoring, incident response, security infrastructure
Industry UsageFinancial, healthcare, government sectorsTech, finance, healthcare sectors

The It Risk And Compliance Analyst focuses on ensuring organizational adherence to regulations and managing risk frameworks, while the It Security Analyst primarily handles security measures, threat detection, and incident response. Both roles require similar certifications and often work within the same industries, but their core responsibilities differ: one emphasizes compliance and risk management, the other emphasizes security operations.

What does an IT risk and compliance analyst do?

An IT risk and compliance analyst evaluates and manages an organization's technology-related risks to ensure adherence to regulatory standards and internal policies. They identify vulnerabilities, implement controls, and monitor compliance using tools like risk assessment frameworks and audit procedures to protect information systems.

What are popular job titles related to It Risk And Compliance Analyst jobs in Spring, TX?

For It Risk And Compliance Analyst jobs in Spring, TX, the most frequently searched job titles are:

What job categories do people searching It Risk And Compliance Analyst jobs in Spring, TX look for?

The top searched job categories for It Risk And Compliance Analyst jobs in Spring, TX are:

What cities near Spring, TX are hiring for It Risk And Compliance Analyst jobs?

Cities near Spring, TX with the most It Risk And Compliance Analyst job openings:

Infographic showing various It Risk And Compliance Analyst job openings in Spring, TX as of August 2026, with employment types broken down into 1% As Needed, 83% Full Time, 13% Part Time, and 3% Contract. Highlights an 93% Physical, 3% Hybrid, and 4% Remote job distribution, with an average salary of $74,937 per year, or $36 per hour.

Cybersecurity Risk & Compliance Analyst

VoltaGrid

Houston, TX • On-site

Full-time

Posted 7 days ago


Job description

Position Title: Cybersecurity Risk & Compliance Analyst
Location: HOUSTON, TX
FLSA Class: EXEMPT
Responsible to: Senior Manager of Technical Operations
Position Summary: VoltaGrid is seeking a Cybersecurity Risk & Compliance Analyst to help formalize and scale our risk governance, compliance, and policy framework across both IT and operational environments.
This role is central to evolving our cybersecurity program from reactive support to structured, institutionalized risk governance. You will drive clarity and consistency in how we manage risk, controls, policies, and audit readiness, ensuring alignment with both regulatory requirements and real-world operational needs.
The ideal candidate brings a strong understanding of GRC principles, paired with the ability to translate complex requirements into practical, enforceable processes that integrate seamlessly into day-to-day operations.
As VoltaGrid continues to scale, cybersecurity must evolve into a structured, measurable, and governance-driven function. This role ensures that our approach to risk and compliance is not just about meeting requirements, but about building a repeatable, scalable framework that supports secure growth across both digital and physical infrastructure. You will play a key role in establishing clarity, accountability, and trust in how VoltaGrid manages risk across the organization
Essential Duties and Responsibilities:
  • Develop, implement, and maintain cybersecurity policies, standards, and procedures, ensuring they are clear, actionable, and aligned with organizational needs.
  • Own and manage risk assessment processes, including identifying, evaluating, and tracking risks across IT and operational technology environments.
  • Support and drive compliance initiatives (e.g., SOC 2, ISO 27001), including control design, evidence collection, and audit coordination.
  • Establish and maintain a control framework that aligns security practices with regulatory and business requirements.
  • Partner with engineering, IT, and operations teams to ensure controls are implemented effectively and embedded into workflows.
  • Manage and track risk registers, control gaps, and remediation efforts, providing visibility to leadership.
  • Support third-party risk management, including vendor assessments and ongoing monitoring.
  • Collaborate with cybersecurity and technology teams to align security tooling and monitoring with compliance and risk objectives.
  • Assist in developing and maintaining security awareness and policy training programs.
  • Produce clear, executive-ready reporting on risk posture, compliance status, and program maturity.
  • Continuously evaluate and improve the organization's governance model, processes, and documentation.

Other Requirements:
  • 3-6 years of experience in GRC, cybersecurity compliance, risk management, or related roles.
  • Strong understanding of common frameworks and standards such as:
    • SOC 2
    • ISO 27001
    • NIST CSF or similar
  • Experience developing and managing policies, controls, and risk assessments.
  • Familiarity with audit processes and evidence management.
  • Ability to translate technical and regulatory requirements into practical processes.
  • Strong organizational, analytical, and communication skills.

Preferred Qualification:
  • Experience in critical infrastructure, energy, or industrial environments.
  • Familiarity with OT/ICS risk and compliance considerations.
  • Experience with GRC tools or compliance automation platforms (e.g., Drata).
  • Understanding of third-party risk management frameworks.
  • Relevant certifications (e.g., CISA, CRISC, CISSP, ISO 27001 Lead Implementer)

VoltaGrid is an Equal Opportunity Employer that does not discriminate on the basis of actual or perceived race, creed, color, religion, alienage or national origin, ancestry, citizenship status, age, disability or handicap, sex, marital status, veteran status, sexual orientation, genetic information, arrest record, or any other characteristic protected by applicable federal, state or local laws.
Our management team is dedicated to this policy with respect to recruitment, hiring, placement, promotion, transfer, training, compensation, benefits, employee activities, and general treatment during employment
Equal Opportunity Employer
This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.