2

Remote Grc Analyst (Contractual) Jobs (NOW HIRING)

Senior Security Compliance Analyst

OR · On-site +1

$110K - $140K/yr

... contractual obligations. * Perform gap analyses and risk assessments to identify and remediate ... Ability to work independently and collaboratively in a remote environment. * Familiarity with GRC ...

... contractual obligations. * Perform gap analyses and risk assessments to identify and remediate ... Ability to work independently and collaboratively in a remote environment. * Familiarity with GRC ...

... contractual obligations. * Perform gap analyses and risk assessments to identify and remediate ... Ability to work independently and collaboratively in a remote environment. * Familiarity with GRC ...

Translates regulatory and contractual requirements into structured, enforceable, and testable ... GRC inputs to support enterprise visibility. * Acts as a core support partner to EEOs and ...

Translates regulatory and contractual requirements into structured, enforceable, and testable ... GRC inputs to support enterprise visibility. * Acts as a core support partner to EEOs and ...

Showing results 41-60

Remote Grc Analyst Contractual information

What is a remote GRC analyst (contractual)?

A Remote GRC Analyst (Contractual) is a professional who works on a contract basis to help organizations manage their Governance, Risk, and Compliance (GRC) programs, all while working remotely. Their responsibilities typically include assessing risk, developing compliance policies, monitoring regulatory changes, and ensuring that company practices align with legal and industry standards. These analysts often collaborate with various departments to identify potential risks and recommend strategies for mitigation. Since the position is remote and contractual, work is usually project-based or for a specific period, providing flexibility for both the employer and the analyst.

What are the key skills and qualifications needed to thrive as a remote GRC analyst (contractual), and why are they important?

To thrive as a Remote GRC Analyst (Contractual), you need a solid understanding of governance, risk management, and compliance frameworks, often backed by a degree in information security or related fields. Familiarity with tools like GRC platforms (e.g., Archer, ServiceNow GRC), audit management software, and relevant certifications such as CISSP, CISA, or CRISC are typically required. Strong analytical thinking, communication skills, and self-motivation are essential soft skills for effective collaboration and independent work in a remote setting. These competencies ensure the analyst can identify and mitigate risks, maintain regulatory compliance, and support organizational security objectives efficiently from a remote environment.

What are some common challenges faced by remote GRC analysts working on a contract basis, and how can they be addressed?

Remote GRC Analysts on contract often navigate challenges such as limited access to internal resources, varying client expectations, and quickly adapting to different organizational cultures. To address these, it's important to establish clear communication channels, proactively set expectations around deliverables, and utilize secure collaboration tools. Staying organized, being flexible, and continuously updating your knowledge of compliance frameworks can also help you deliver effective results in diverse environments.

What is the difference between Remote Grc Analyst (Contractual) vs Remote Grc Analyst?

AspectRemote Grc Analyst (Contractual)Remote Grc Analyst
CredentialsCertifications like CISA, CISSP often preferredSame certifications typically required
Work EnvironmentContract-based, project-specificFull-time or part-time employment
Employer & Industry UsageUsed by consulting firms, temporary staffingUsed by corporations, financial institutions
Search & Comparison IntentOften compared for contract vs permanent rolesCompared for employment type and stability

The main difference between a Remote Grc Analyst (Contractual) and a Remote Grc Analyst lies in employment type and work arrangement. Contractual roles are project-based and temporary, often with consulting firms, while permanent roles offer ongoing employment with companies. Both roles typically require similar certifications and skills, but the contractual position provides flexibility and short-term engagement, whereas the permanent role offers stability and benefits.

More about Remote Grc Analyst Contractual jobs

What cities are hiring for Remote Grc Analyst (Contractual) jobs?

Cities with the most Remote Grc Analyst (Contractual) job openings:

What are popular job titles related to Remote Grc Analyst (Contractual) jobs?

For Remote Grc Analyst (Contractual) jobs, the most frequently searched job titles are:

Infographic showing various Remote Grc Analyst (Contractual) job openings in the United States as of September 2026, with employment types broken down into 1% Internship, 88% Full Time, 6% Part Time, 1% Temporary, and 4% Contract. Highlights an 81% Physical, 7% Hybrid, and 12% Remote job distribution.

Lead Analyst - Information Technology

Remote

US Anesthesia Partners, Inc.
Outpatient Health Care • 1 - 5K employees

$80K - $137K/yr

Full-time

This job post has expired today. Applications are no longer accepted.


U.S. Anesthesia Partners rating

8.3

Company rating: 8.3 out of 10

Based on 7 frontline employees who took The Breakroom Quiz


Job description

Overview
The GRC Analyst will play a critical role in strengthening the security posture of our growing organization by designing, implementing, and managing control and risk workflows, as well as performing third-party risk assessments. This position is pivotal in ensuring compliance with industry standards and regulations, identifying and mitigating risks, and supporting USAP's overall security governance framework.
At this time, US Anesthesia Partners does not hire candidates residing in California, Hawaii, or Alaska.
The base pay estimate for this role is $80,900 - $137,600 annually. The final offer will depend on the skills, experience, and qualifications of the selected candidate. This range is for base pay only and does not include bonuses or other compensation. This position is eligible for an annual bonus. Bonuses are not guaranteed and are awarded based on company and individual performance.
Job Highlights
ESSENTIAL DUTIES AND RESPONSIBILITIES: (The ideal candidate must be able to complete all physical requirements of the job with or without a reasonable accommodation)
  • Leads the design, configuration, and governance of control frameworks and risk workflows within the GRC platform, ensuring alignment with organizational objectives and compliance requirements.
  • Establishes and maintains control procedures, ensuring alignment with relevant frameworks (internal policy, HIPAA, HITRUST, PCI, SOC 2, NIST, and other applicable frameworks).
  • Oversees the development and maintenance of control libraries, including control narratives, ownership assignments, testing frequency, and evidence requirements.
  • Monitors and updates risk registers, ensuring accurate tracking, scoring, and prioritization of risks within the platform.
  • Drives automation workflows to streamline control testing, evidence collection, attestations, and remediation processes.
  • Tracks policy review cycles and ensures documentation remains current with regulatory and business changes.
  • Leads and maintains information security risk assessments across IT, operational, and third-party domains.
  • Performs control walkthroughs and operating effectiveness testing; documents results and identifies control gaps.
  • Collaborates with internal teams and external auditors to facilitate audits and assessments using the GRC platform for evidence management, issue tracking, and reporting.
  • Ensures ongoing compliance with regulatory requirements and industry standards by maintaining up-to-date documentation and control mappings.
  • Prepares and presents reports, dashboards, and metrics on control effectiveness, risk status, and compliance gaps.
  • Maps controls to applicable regulatory and framework requirements, identifying overlaps to reduce duplicative testing.
  • Supports internal and external audits by gathering evidence, coordinating stakeholder responses, and tracking remediation through closure.
  • Tracks and manages audit findings, corrective action plans (CAPs), and remediation timelines within the GRC platform.
  • Guides risk assessments to identify potential vulnerabilities and threats, documenting findings and supporting evidence in the GRC platform.
  • Partners with stakeholders to develop and implement risk mitigation strategies, tracking progress and ownership within the platform.
  • Develops, monitors, and reports on key risk indicators (KRIs) and key performance indicators (KPIs) to proactively identify and address emerging risks.
  • Maintains and applies consistent risk scoring methodologies, including likelihood, impact, and residual risk calculations.
  • Escalates significant risks and control deficiencies to management and governance committees, providing recommendations for mitigation and improvement, in a timely manner.
  • Leads the development, maintenance, and lifecycle management of information security policies, procedures, standards, and guidelines.
  • Directs policy review and approval workflows with policy owners and stakeholders.
  • Ensures policies remain aligned with evolving regulatory requirements and organizational changes.
  • Leads evaluations of third-party vendors for security and compliance risks, including review of SOC reports, security questionnaires, and contractual requirements.
  • Tracks vendor risk assessments, reassessment cycles, and risk ratings within the GRC platform.
  • Works with business owners to develop and monitor vendor remediation action plans.
  • Supports vendor onboarding and offboarding risk reviews, ensuring appropriate due diligence is documented.
  • Identifies opportunities to enhance GRC processes and workflows to improve efficiency, accuracy, and effectiveness.
  • Stays current on industry trends, emerging threats, and best practices in GRC, recommending improvements to the security and compliance program.
  • Champions automation and integration initiatives to reduce manual effort.
  • Guides periodic program assessments and maturity benchmarking to guide roadmap priorities.
  • Performs other duties and responsibilities as assigned.

Qualifications
KNOWLEDGE/SKILLS/ABILITIES (KSAs):
  • Bachelor's degree in information security, cybersecurity, computer science, information technology, business administration, or a closely related field required. Equivalent experience may be considered in lieu of a degree (e.g., 4+ years of relevant experience in information security, compliance, or GRC roles).
  • Minimum of 5 years relevant experience in governance, risk, and compliance functions within IT or information security.
  • Experience with AuditBoard (now named Optro) is highly preferred.
  • Certified Information Systems Auditor (CISA) preferred.
  • Certified Risk and Information Systems Control (CRISC) preferred.
  • Certified Information Security Manager (CISM) preferred.
  • Other relevant certifications (e.g., CompTIA Security+, ISO 27001 Lead Auditor) preferred.
  • Prior experience implementing, managing, or auditing security policies and procedures.
  • Familiarity with compliance frameworks (HIPAA, NIST CSF, SOC 2, HITRUST, etc.).
  • Prior experience conducting risk assessments and supporting risk management activities.
  • Excellent written and verbal communication skills, including the ability to communicate technical concepts and compliance requirements to both technical and non-technical stakeholders.
  • Ability to manage multiple priorities, work independently, and collaborate effectively across cross-functional teams.
*The physical demands described here are representative of those that may need to be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions
  • Occasional Standing
  • Occasional Walking
  • Frequent Sitting
  • Frequent hand, finger movement
  • Use office equipment (in office or remote)
  • Communicate verbally and in writing

US Anesthesia Partners, Inc. provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, sex, gender identity, sexual orientation, pregnancy, status as a parent, national origin, age, disability (physical or mental), family medical history or genetic information, political affiliation, military service, or other non-merit based factors.

What U.S. Anesthesia Partners employees say

Pay

Hours and flexibility

Workplace

Get the full story on Breakroom