1

Security Risk Compliance Jobs in Colorado (NOW HIRING)

Zayo is seeking a Risk & Compliance Analyst to serve as the key liaison between our Security organization and our customers, focusing on responding to security-related customer inquiries and ...

Security Risk Lead Fastly helps people stay better connected with the things they love. Fastly ... Experience using governance, risk management, and compliance (GRC) tools preferred Work Hours:

The Compliance Manager will oversee healthcare regulatory compliance (including HIPAA and state ... Manage HIPAA Security Risk Assessments and remediation efforts, internally or through vendors

You will work closely with engineering, security, legal, compliance, and operations teams to help identify, document, and track risk across the enterprise and its third-party supply chain.

IT Controls & Compliance Analyst

Denver, CO

$96.80K - $97.30K/yr

... risk assessments, POAM management, remediation tracking, and security awareness initiatives ... Ensures IT staff understand assigned compliance responsibilities, risks, and controls through ...

next page

Showing results 1-20

Security Risk Compliance information

See Colorado salary details

$34.2K

$85.3K

$129.9K

How much do security risk compliance jobs pay per year?

As of May 30, 2026, the average yearly pay for security risk compliance in Colorado is $85,324.00, according to ZipRecruiter salary data. Most workers in this role earn between $63,600.00 and $105,200.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Security Risk Compliance professional, and why are they important?

To thrive as a Security Risk Compliance professional, you need a solid understanding of information security frameworks, risk assessment methodologies, and relevant regulations, often supported by a degree in cybersecurity or a related field. Familiarity with tools such as GRC (Governance, Risk, and Compliance) platforms, vulnerability scanners, and certifications like CISSP, CISA, or CRISC is typically required. Strong analytical thinking, attention to detail, and effective communication skills help you identify risks and collaborate with stakeholders. These skills are vital to ensure organizations meet compliance requirements, mitigate risks, and maintain trust with clients and regulators.

What are some common challenges faced by Security Risk Compliance professionals when balancing regulatory requirements with business objectives?

Security Risk Compliance professionals often need to navigate the delicate balance between adhering to complex regulatory standards and supporting the organization's operational goals. A major challenge is ensuring compliance without hindering business innovation or efficiency. This involves working closely with various departments to interpret regulations, communicate risks, and implement pragmatic controls that satisfy both legal requirements and business needs. Effective collaboration and ongoing education are key to overcoming these challenges and maintaining a strong security posture.

What is Security Risk Compliance?

Security Risk Compliance refers to the process of identifying, assessing, and managing risks to an organization's information systems while ensuring adherence to relevant laws, regulations, and industry standards. Professionals in this field develop policies, conduct risk assessments, and implement controls to protect sensitive data from threats. Their work helps organizations minimize security vulnerabilities and avoid legal or financial consequences related to non-compliance.

What is the difference between Security Risk Compliance vs Security Analyst?

AspectSecurity Risk ComplianceSecurity Analyst
CertificationsISO 27001 Lead Implementer, CISSP, CISACISSP, CompTIA Security+, GIAC Security Certifications
Work EnvironmentPolicy development, compliance audits, risk assessmentsMonitoring security systems, incident response, vulnerability analysis
Employer & Industry UsageFinancial, healthcare, government sectors focusing on regulatory adherenceIT departments across various industries focusing on security operations

Security Risk Compliance professionals focus on ensuring organizations meet regulatory standards and manage security risks through policies and audits. Security Analysts primarily monitor security systems, analyze threats, and respond to incidents. While both roles require security certifications and work within similar environments, their core responsibilities differ: compliance versus active security monitoring.

What are popular job titles related to Security Risk Compliance jobs in Colorado? For Security Risk Compliance jobs in Colorado, the most frequently searched job titles are:
What cities in Colorado are hiring for Security Risk Compliance jobs? Cities in Colorado with the most Security Risk Compliance job openings:
Governance Risk & Compliance (GRC) Analyst

Governance Risk & Compliance (GRC) Analyst

Judge Group, Inc.

Lakewood, CO • Remote

$55 - $65/hr

Other

Posted 2 days ago


Job description

Location: Lakewood, CO
Salary: $55.00 USD Hourly - $65.00 USD Hourly
Description: Our client is currently seeking a Governance Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst
Contract-to-Hire | $130-140K Conversion Salary | Remote OK (Denver onsite preferred; relocation available upon conversion)
Role Overview
The GRC Analyst supports the Global Information Security Office by driving governance, risk management, and compliance initiatives across the organization. This role requires a proactive, flexible professional who can operate in a fast-changing environment, communicate effectively with leadership, and quickly take ownership of key GRC activities.
Key Responsibilities
Risk, Audit & Compliance
  • Support company-wide information security risk assessments for projects, systems, and vendors.
  • Assist with internal and external audits (e.g., J-SOX), evidence collection, and remediation tracking.
  • Maintain compliance with ISO 27001, NIS2, GDPR, and other regulatory frameworks.
  • Contribute to policy development, updates, and global rollout.
Vendor & Third-Party Risk
  • Conduct vendor security assessments, review questionnaires, validate controls, and document findings.
  • Escalate high-risk issues and support mitigation follow-up.
Dashboards & Reporting
  • Develop and maintain dashboards, including the CISO Dashboard.
  • Collect, validate, and analyze KPIs/KRIs related to compliance, risk, audits, incidents, and training.
  • Present insights to leadership with clear, accurate reporting.
Security Awareness & Training
  • Support security awareness initiatives, including e-learning content, phishing exercises, and internal communications.
Regulatory Monitoring
  • Track global cybersecurity regulatory changes (e.g., NIS2, ICS/OT requirements, FDA expectations).
  • Support gap assessments and compliance readiness.
AI Security Oversight
  • Assist in evaluating risks related to AI systems and third-party AI tools.
  • Support governance controls for secure AI use.
Additional Responsibilities
  • Improve GRC processes, tools, and documentation.
  • Support internal projects, automation efforts, and cross-functional initiatives.
  • Provide coordination for security committees and working groups.

Required Qualifications
  • 3-5+ years in information security, GRC, IT audit, or risk management.
  • Strong communication skills; comfortable engaging with leadership.
  • Experience with ISO 27001 and NIS2 (required).
  • Experience conducting or supporting risk assessments and audits.
  • Understanding of vendor security assessment processes.
  • Ability to work independently in a dynamic environment with shifting priorities.

Preferred Skills
  • Experience with GRC platforms (e.g., BitSight, Drata, OneTrust, Archer).
  • Familiarity with cybersecurity domains (IAM, endpoint security, cloud, vulnerability management).
  • Data analysis and dashboard/reporting experience.
  • Awareness of emerging regulations (NIS2, AI governance, critical infrastructure).
  • Experience working with global teams.

Education
  • Bachelor's degree in Cybersecurity, Information Systems, Computer Science, or related field-or equivalent experience.
  • Certifications such as CISSP, CISA, CISM, or ISO 27001 Lead Implementer/Auditor are a plus.

By providing your phone number, you consent to: (1) receive automated text messages and calls from the Judge Group, Inc. and its affiliates (collectively "Judge") to such phone number regarding job opportunities, your job application, and for other related purposes. Message & data rates apply and message frequency may vary. Consistent with Judge's Privacy Policy, information obtained from your consent will not be shared with third parties for marketing/promotional purposes. Reply STOP to opt out of receiving telephone calls and text messages from Judge and HELP for help.
Contact:
This job and many more are available through The Judge Group. Please apply with us today!