1

Senior Grc Analyst Jobs (NOW HIRING)

Sr. GRC Analyst

Irving, TX ยท On-site

$100K - $168K/yr

Reporting to the Senior Director of SOX Governance, you will play a key role in enabling compliance ... Perform complex business analysis and build analytical frameworks to support decision-making

Sr. GRC Analyst

Irving, TX ยท On-site

$100K - $168K/yr

Reporting to the Senior Director of SOX Governance, you will play a key role in enabling compliance ... Perform complex business analysis and build analytical frameworks to support decision-making

Sr. GRC Analyst

Irving, TX ยท On-site

$100K - $168K/yr

Reporting to the Senior Director of SOX Governance, you will play a key role in enabling compliance ... Perform complex business analysis and build analytical frameworks to support decision-making

Mentor GRC Analysts and GRC Consultants while contributing to the continuous improvement of MAD ... senior leadership. * Education * Bachelor's degree in Cybersecurity, Information Technology ...

Mentor GRC Analysts and GRC Consultants while contributing to the continuous improvement of MAD ... senior leadership. * Education * Bachelor's degree in Cybersecurity, Information Technology ...

... personnel, senior management, and the board of directors Applies Cybersecurity architecture ... General Governance, Risk, and Compliance (GRC) Support Leads process analysis, development ...

About the Role As a member of the Information Security team, the IS GRC - Risk & Compliance Senior Analyst will support the firm's Governance, Risk, and Compliance (GRC) program by managing security ...

GRC Analyst

Los Angeles, CA ยท On-site

$100K - $135K/yr

Who you are Metropolis is seeking a Governance, Risk, and Compliance (GRC) Analyst to join our ... Reporting to the Senior Manager, GRC, you will mature information security policies, drive employee ...

The IT GRC Analyst will leverage GRC tooling to automate and streamline compliance monitoring ... Identify, document, and escalate control exceptions, discrepancies, and potential gaps to senior ...

Showing results 41-60

Senior Grc Analyst information

See salary details

$53.5K

$109.8K

$142.5K

How much do senior grc analyst jobs pay per year?

As of Sep 3, 2026, the average yearly pay for senior grc analyst in the United States is $109,846.00, according to ZipRecruiter salary data. Most workers in this role earn between $90,500.00 and $137,000.00 per year, depending on experience, location, and employer.

What is a senior GRC analyst?

Senior GRC Analysts are experienced professionals who oversee an organization's Governance, Risk, and Compliance (GRC) programs. They are responsible for identifying and managing risks, ensuring compliance with laws and regulations, and developing policies and controls to protect the organization. Senior GRC Analysts often lead risk assessments, design compliance frameworks, and collaborate with different departments to implement best practices. Their expertise helps organizations navigate complex regulatory environments and maintain a strong security posture.

What are the key skills and qualifications needed to thrive as a senior GRC analyst?

To thrive as a Senior GRC Analyst, you need expertise in risk management, compliance frameworks (such as SOX, GDPR, or ISO 27001), and a solid understanding of business processes, usually supported by a relevant degree or certification (e.g., CISA, CRISC). Familiarity with GRC platforms like RSA Archer or ServiceNow, as well as audit and risk assessment tools, is typically required. Strong analytical thinking, communication, and stakeholder management skills help you influence decision-making and foster organizational buy-in. These skills and qualities are crucial for effectively identifying risks, ensuring regulatory compliance, and supporting the organization's overall risk posture.

What are some common challenges faced by senior GRC analysts, and how can applicants prepare to address them?

Senior GRC Analysts often encounter challenges such as navigating evolving regulatory requirements, managing cross-departmental collaboration, and ensuring that risk management processes align with business objectives. To succeed, applicants should be prepared to communicate effectively with stakeholders at all levels, stay updated on relevant compliance frameworks, and be proactive in identifying and mitigating potential risks. Gaining experience with industry-standard tools and frameworks, as well as honing project management skills, can help candidates excel in this dynamic and impactful role.
More about Senior Grc Analyst jobs

What cities are hiring for Senior Grc Analyst jobs?

Cities with the most Senior Grc Analyst job openings:

What are the most commonly searched types of Grc Analyst jobs?

The most popular types of Grc Analyst jobs are:

What states have the most Senior Grc Analyst jobs?

States with the most job openings for Senior Grc Analyst jobs include:

Infographic showing various Senior Grc Analyst job openings in the United States as of August 2026, with employment types broken down into 89% Full Time, 6% Part Time, and 5% Contract. Highlights an 82% Physical, 7% Hybrid, and 11% Remote job distribution, with an average salary of $109,846 per year, or $52.8 per hour.

Experienced or Senior GRC Analyst (Remote)

Hotman Group

Fort Worth, TX โ€ข Remote

$90K - $119K/yr

Full-time, Contractor

Re-posted 22 days ago


Job description

About the Role 

Hotman Group is a boutique cybersecurity and GRC consulting firm doing meaningful work for clients who need GRC done right ranging from Fortune 1000 companies to high-growth startups. We are looking for an experienced GRC practitioner who is ready to work directly with clients, own deliverables end to end, and contribute to a team that holds itself to a high standard. This is not an entry point. We expect you to bring your expertise and use it. 

This is a full-time, remote, contract-to-hire position. Top performers move into permanent roles within 6 months. 

What You Will Do 

As an Experienced or Senior GRC Analyst at Hotman Group you will work directly with clients to help them build, mature, and sustain their cybersecurity and compliance programs. This is active delivery work. You will: 

  • Lead assessments and audits of security and IT control environments 
  • Design, implement, and mature cybersecurity and compliance programs 
  • Develop risk registers, conduct risk assessments, and track remediation efforts 
  • Create and refine policies, standards, and procedures aligned with top frameworks including SOC 2, ISO 27001, NIST CSF, HIPAA, HITRUST, CMMC, and others 
  • Prepare clients for internal audits and external assessments 
  • Translate technical, regulatory, and business requirements into clear, actionable deliverables for client stakeholders 
  • Communicate findings, manage client feedback, and drive outcomes even when stakeholders push back 
  • Mentor junior analysts and contribute to the growth of our GRC practice 
  • Participate in peer review of deliverables before they go to clients your work will be reviewed and you will review others 

You will work across multiple industries on diverse engagements. No two projects are the same and no day looks exactly like the last. 

What You Bring 

  • Hands-on GRC experience with a track record of owning deliverables, producing frameworks-based documentation, and driving remediation -- not just supporting programs from the inside 
  • Deep working knowledge of compliance standards including SOC 2, ISO 27001, NIST CSF, HIPAA, and HITRUST 
  • Experience communicating findings and recommendations directly to clients or senior internal stakeholders -- you can hold a room, manage pushback, and present complex findings in plain language 
  • Excellent writing skills -- your deliverables are clear, polished, and do not require heavy editing before they go to a client 
  • Strong critical thinking and professional judgment -- you know when to escalate, when to hold your position, and when to ask for help 
  • A high level of accountability and ownership -- you manage your own workload, communicate proactively, and hold yourself to deadlines without being managed closely 
  • Comfort working independently in a fully remote environment with minimal hand-holding 
  • A default toward communication you keep the team informed, you acknowledge quickly, and you do not go dark on a deliverable or a client 

Active certifications such as CISA, CISM, CISSP, or CRISC are strongly preferred. If you do not currently hold a relevant certification, we expect you to be actively pursuing one. 

This role requires direct accountability for work product and outcomes. If your experience has been primarily internal, supporting programs from the inside without stakeholder-facing delivery responsibility, this role will be a significant adjustment. 

Requirements 

  • Permanent authorization to work in the U.S. -- no sponsorship of any kind now or in the future 
  • Able to pass a background check 
  • Reliable high-speed internet and a secure, private remote workspace 

Our Hiring Process 

Our process is designed to be straightforward but rigorous. In addition to a written questionnaire and video responses, finalists will complete a practical skills assessment before advancing to a panel interview with our delivery team. The assessment reflects the type of work you will do on day one. If you are confident in your GRC expertise, this is your opportunity to show it. 

Why Hotman Group 

At Hotman Group we are not just another consulting firm. You will work alongside people who care about the craft and push each other to do better. No politics, no silos, no hierarchy between you and the people making decisions. 

You will touch more GRC frameworks, more industries, and more client situations in one year here than most practitioners see in five. You will grow because the work demands it. 

The clients you serve will actually notice your work. You are not a number on a headcount. Your name is on the deliverable. 

If you want to do real GRC work, get better at it every day, and work with a team that holds itself to a high standard this is the place. 

No phone calls or emails please.