1

Principal Grc Analyst Jobs (NOW HIRING)

$125 - $150/hr

## Principal, GRC Cyber Risk ManagementApplylocations: Tempe, AZtime type: Full timeposted on: Posted ... Enhance cyber risk intelligence capabilities through analytics, automation, and AI-enabled ...

As a Principal Security GRC Analyst, you will serve as a senior individual contributor driving control implementation, audit readiness, and cross-framework harmonization across Rescale's cloud-based ...

$125 - $150/hr

T he Cyber Risk Principal will partner with peers to drive the modernization of cyber risk ... Enhance cyber risk intelligence capabilities through analytics, automation, and AI-enabled ...

next page

Showing results 1-20

Principal Grc Analyst information

What is a Principal GRC Analyst?

A Principal GRC Analyst is a senior professional responsible for overseeing and enhancing an organization's Governance, Risk, and Compliance (GRC) programs. They develop and implement strategies to manage risk, ensure regulatory compliance, and improve internal controls. This role often involves collaborating with various departments to assess risks, conduct audits, and recommend solutions for complex compliance issues. Principal GRC Analysts also mentor junior analysts and help shape the organization’s overall risk management framework.

What are the key skills and qualifications needed to thrive as a Principal GRC Analyst?

To thrive as a Principal GRC Analyst, you need deep expertise in governance, risk management, and compliance frameworks, often supported by a relevant degree and certifications such as CISA, CRISC, or CISSP. Familiarity with GRC platforms (like Archer or ServiceNow), risk assessment tools, and regulatory compliance systems is essential. Exceptional analytical thinking, stakeholder communication, and project management skills help you navigate complex regulatory environments and lead effective initiatives. These competencies ensure robust risk mitigation, streamlined compliance, and strategic alignment with organizational goals.

How does a Principal GRC Analyst typically interact with other departments to ensure effective risk management and compliance?

A Principal GRC Analyst regularly collaborates with various departments such as IT, legal, finance, and operations to identify, assess, and mitigate risks across the organization. This involves leading cross-functional meetings, communicating policy changes, and providing guidance on compliance requirements. The role often requires translating complex regulatory standards into practical actions for different teams and ensuring their understanding and adherence. Building strong relationships and maintaining clear communication are key to driving a unified risk management strategy and fostering a culture of compliance.

What are popular job titles related to Principal Grc Analyst jobs?

For Principal Grc Analyst jobs, the most frequently searched job titles are:

Infographic showing various Principal Grc Analyst job openings in the United States as of September 2026, with employment types broken down into 96% Full Time, and 4% Contract. Highlights an 80% In-person, 8% Hybrid, and 12% Remote job distribution.

Governance Risk and Compliance Analyst Intermediate

Remote

Cone Health
Hospitals • 10K+ employees

$96K - $96K/yr

Full-time

Posted 8 days ago


Cone Health rating

6.7

Company rating: 6.7 out of 10

Based on 144 frontline employees who took The Breakroom Quiz

535th of 898 rated healthcare providers


Job description

Information Systems
Excited to grow your career?
We value our talented employees, and whenever possible strive to help one of our associates grow professionally before recruiting new talent to our open positions. If you think the open position you see is right for you, we encourage you to apply!
Our people make all the difference in our success.
The Governance, Risk & Compliance (GRC) Analyst - Intermediate will collaborate with process owners, internal auditors, external auditors, and other stakeholders in order to assist in reviewing, monitoring, and resolving cybersecurity risk. This includes helping the organization manage HITRUST, HIPAA and NIST Common Security Framework (CSF) audits and attestations. By supporting the implementation of internal and external assessments, responding to and managing the full lifecycle of compliance audits, and ensuring compliance with existing and emerging regulations and standards including SOC2, ISO 27001, PCI-DSS, SOX, and other GRC activities, the Principal GRC Analyst will also contribute to managing the organization's IT compliance program.
Essential Job Function:
  • Lead the execution and reporting of outcomes derived from Third Party Risk Assessments.
  • Manage the completion of risk and vulnerability assessments, validation testing, compliance reviews, and audits in accordance with NIST and HITRUST standards.
  • Manage and monitor a central repository for all security risks and audit evidence.
  • Maintain security standards, policies, and practices on an annual basis to make sure they meet organizational and regulatory requirements.
  • Manage a security awareness training program in order to educate associates about security compliance standards, risk management practices, and ethical behavior.
  • Collaborate with legal and compliance teams to ensure policies and security controls align with regulatory requirements.
  • Conduct internal audits to assess the effectiveness of security controls and identify areas for improvement.
  • Performs other duties as assigned.

Education:
  • Required: Bachelor's Degree and/or equivalent experience.

Experience:
  • Required: 5 years

Licensure/Certification/Listing:
  • Required: Certified Information Systems Auditor (CISA) - Obtain within 12 months.

Work Shift :
Days/No Weekends (United States of America)
On Call Required
No
FTE:
1
Job Type:
Full Time (40 Hours/Week)

What Cone Health employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom


Cone Health logo

About Cone Health

Sourced by ZipRecruiter

Cone Health , established in 1953, is a large 5 hospital, 501c(3), not-for-profit healthcare system. We provide a full range of health care services distinguished by superior patient care and outcomes. We tied for top honors in this year's annual ranking of North Carolina's best hospitals.

Industry

Hospitals

Company size

10,000+ Employees

Headquarters location

Greensboro, NC, US

Year founded

1953