1

It Security Grc Analyst Jobs (NOW HIRING)

WI ยท On-site

$55 - $80/hr

We are seeking an IT GRC Analyst to join the IT Security and Governance team on a 6-month contract-to-hire basis, working remotely within the USA. The IT GRC Analyst will play a key role in ...

$55 - $80/hr

We are seeking an IT GRC Analyst to join the IT Security and Governance team on a 6-month contract-to-hire basis, working remotely within the USA. The IT GRC Analyst will play a key role in ...

WI ยท On-site

$55 - $80/hr

We are seeking an IT GRC Analyst to join the IT Security and Governance team on a 6-month contract-to-hire basis, working remotely within the USA. The IT GRC Analyst will play a key role in ...

... Analyst III, IT Information Security is a contributor responsible for strengthening the ... The UCT GRC Specialist will support the design, execution, and maturity of UCT's IT governance, ...

GRC Analyst We are looking for an individual who is personable, comfortable working within a ... Work with Internal Audit and outside teams to effectively manage IT security framework and ...

The IT GRC Analyst II assess, tests, documents, and monitors the SECU technology ecosystem to ... IT Security and/or IT Risk Management experience working in a mid-to-large size company Basic ...

... Risk & Compliance (GRC Senior Analyst) to support and strengthen our security governance and ... , IT, Legal, Internal Audit, and other cross-functional stakeholders to help maintain and improve ...

... Risk & Compliance (GRC Senior Analyst) to support and strengthen our security governance and ... , IT, Legal, Internal Audit, and other cross-functional stakeholders to help maintain and improve ...

C2 Labs [www.c2labs.com] partners with clients on their IT transformation journey via data-driven ... You will draft security control implementation statements with enough detail to facilitate the ...

Cybersecurity GRC Analyst (Remote) Location: 100% Remote Rate: $51/hour (No PTO) Overview We are ... Partner with IT, Audit, Compliance, and business teams to address security risks and improve ...

Information Security / Risk & Compliance Reports To: Director, Global Information Security**Job ... IT, Internal and External auditors. The analyst administers Varonis to classify, monitor, and ...

next page

Showing results 1-20

It Security Grc Analyst information

See salary details

$40.5K

$108K

$186K

How much do it security grc analyst jobs pay per year?

As of Sep 10, 2026, the average yearly pay for it security grc analyst in the United States is $108,050.00, according to ZipRecruiter salary data. Most workers in this role earn between $60,000.00 and $148,000.00 per year, depending on experience, location, and employer.

What does an IT Security GRC Analyst do?

An IT Security GRC (Governance, Risk, and Compliance) Analyst is responsible for ensuring that an organization follows industry regulations and security standards related to information technology. They assess security risks, develop and enforce policies, and monitor compliance with laws such as GDPR, HIPAA, or SOX. Their role often includes conducting audits, managing risk assessments, and collaborating with different departments to ensure security best practices are followed. By doing so, they help protect sensitive data and reduce the risk of security breaches.

What are the key skills and qualifications needed to thrive as an IT Security GRC Analyst?

To thrive as an IT Security GRC Analyst, you need strong knowledge of risk management, compliance frameworks (such as ISO 27001, NIST, or GDPR), and security best practices, often backed by a degree in information security or a related field. Familiarity with GRC tools (like RSA Archer or ServiceNow), audit software, and relevant certifications (such as CISSP, CISA, or CRISC) is highly valuable. Excellent analytical thinking, attention to detail, and strong communication skills help you interpret regulations and collaborate effectively across teams. These skills ensure that organizations stay compliant, manage risks proactively, and maintain a robust security posture.

What are some common challenges IT Security GRC Analysts face when implementing new compliance frameworks within an organization?

IT Security GRC Analysts often encounter challenges such as navigating complex regulatory requirements, aligning different departments on risk management goals, and ensuring consistent documentation across the organization. Balancing business objectives with stringent security controls can also be difficult, especially when introducing new frameworks like ISO 27001 or NIST. Effective communication, cross-functional collaboration, and ongoing training are essential to overcome these obstacles and ensure successful compliance implementation.

What is the difference between It Security Grc Analyst vs Cybersecurity Analyst?

AspectIt Security Grc AnalystCybersecurity Analyst
CertificationsISO 27001, CISSP, CISACISSP, CEH, CompTIA Security+
Work EnvironmentPolicy, compliance, risk management teamsTechnical security operations and incident response
Employer & Industry UsageFinancial, healthcare, government sectors focusing on governanceTech companies, security firms, and organizations with active threat monitoring

While both roles focus on security, the It Security Grc Analyst emphasizes governance, risk, and compliance, ensuring policies align with standards. The Cybersecurity Analyst is more technical, focusing on threat detection and incident response. Understanding these differences helps organizations assign the right responsibilities and professionals to their security needs.

What cities are hiring for It Security Grc Analyst jobs?

Cities with the most It Security Grc Analyst job openings:

What states have the most It Security Grc Analyst jobs?

States with the most job openings for It Security Grc Analyst jobs include:

What are popular job titles related to It Security Grc Analyst jobs?

For It Security Grc Analyst jobs, the most frequently searched job titles are:

Security GRC Analyst

San Francisco, CA โ€ข On-site

NAVA Software Solutions
IT Servicesย โ€ขย 51 - 200 employees

Full-time

This job post hasย expired today.ย Applications are no longer accepted.


Job description

NAVA Software solutions is looking for a Security GRC Analyst
Details:
Security GRC Analyst
Location: San Francisco , CA - Hybrid
Duration: 6 months CTH
Qualifications:
  • Analyst with 2+ years' experience and with good understanding of security controls and compliance
  • Experience GRC in Risk Management (identify, assess, monitor, and report risks)
  • Experience performing IAM focused assessments
  • Experience operationalizing SLAs for issue management
  • Certified Information Systems Auditor (CISA) certification preferred
  • Ability to work with minimal supervision

Knowledge Skills and Abilities:
  • Triage issues to accurately assess and capture them within the GRC tool
  • Manage and enhance the issue reporting metrics
  • Integrate Issue program across the processes and effectively measures effectiveness of the integrations
  • Effectively document, review, and enhance the issue management standard, methodologies, policy or operating procedures
  • Provide subject matter expertise on issues tracked by issue management
  • Evaluate remediation efforts including the design and effectiveness of operational controls, based on industry best practice models in accordance w/ risk and compliance requirements
  • Engage with your stakeholders to identify issues, understand their needs and challenges to proactively find ways that your program can support
  • Complete targeted risk assessments based on framework as well as industry requirements
  • Support and enhance the risk reporting metrics
  • Integrate Risk program across the processes and effectively measures effectiveness of the integrations.
  • Support documentation, review, and enhancement of the risk management standard, methodologies, policy or operating procedures
  • Provide subject matter expertise on risks tracked by risk management
  • Evaluates mitigation efforts including the design and effectiveness of operational controls, based on industry best practice models in accordance w/ risk and compliance requirements.
  • Engage with your stakeholders to identify issues, understand their needs and challenges to proactively find ways that your program can support
  • Conduct data security assessments based on industry standard best practices and bring recommendations for security posture improvement
  • Perform IAM focused assessments on internal applications and systems to ensure compliance with internal IAM Standards and best practices
  • Update inventory of critical applications and systems and ensure they undergo standardized account recertifications, have appropriate IAM processes, and are accessed through a standardized SSO solution
  • Identify data security threats/risks through collaborating with other Data Security team members/application & system owners/stakeholders
  • Map data flow diagrams to provide visibility on where sensitive data lies and document how they are adequately secured
  • Provide ongoing reporting to data security and access governance program
  • Respond to and follow up with Data Security questions/concerns and provide cybersecurity / technical advisory

NAVA Software Solutions logo

About NAVA Software Solutions

Sourced by ZipRecruiter

NAVA is a strategic partner for companies seeking to develop or customize software and products. Our team of experts leverages cutting-edge technology and deep industry knowledge to provide customized solutions that drive business success. Whether you're looking to improve your operations, increase efficiency, or bring a new product to market, NAVA has the expertise and resources to help you achieve your goals. Trust us to be your partner in software and product development.

Industry

It services

Company size

51 - 200 Employees

Headquarters location

Rocky Hill, CT, US

Social media