Governance Risk And Compliance Jobs
Governance Risk And Compliance jobs are open across financial services, healthcare, technology, and energy, from analyst to director level, with specializations in regulatory compliance, enterprise risk management, and internal audit. Find a role that fits from the openings below and apply directly.
Find JobsLooking for remote work? View remote governance risk and compliance jobs →Overview
Showing 5 of 95+ Governance Risk And Compliance jobs











Job Title: Governance Risk & Compliance Manager
Department: Information Security
Location: Remote, United States
Schedule: Days, Monday - Friday
SUMMARY
The Governance, Risk & Compliance [GRC] Manager at ACM Global Laboratories translates strategic direction into actionable workflows, coordinates cross-functional teams, supports evidence lifecycle management, maps frameworks to control implementation, leads readiness activities, and ensures all ACM GRC processes operate smoothly and efficiently.
RESPONSIBILITIES
Leads the GRC program activities and a team of professionals related to third-party risk, security internal audit, security compliance, and ISMS program management.
Develop, document, and implement internal policies and procedures to ensure compliance with industry standards and legal requirements.
Facilitate regular risk assessments against security frameworks such as SOC 2, ISO 27001, and PCI-DSS, maintain a risk register, and collaborate on mitigation strategies for identified threats. Manage CAPAs for non-compliance.
Define specific, assignable actions to mitigate the identified risks or exploit the opportunities.
Evaluate how to embed the planned actions directly into daily operational processes.
Manage security responses to client questions and questionnaires, including RFPs, RFIs, annual risk reviews, and ad-hoc communication requests.
Manage and update business continuity and disaster recovery documentation, including BIAs, plan revisions, team rosters, and dependencies. Plan, coordinate, and document annual exercises, such as tests, tabletops, and other exercises.
Build and manage a security metrics (KPI’s) program.
Develop relationships with cross-functional teams, understanding their needs in relation to security standards, to drive risk-informed decision-making and build a culture of compliance.
Provide expert guidance and support in navigating complex regulatory environments in relation to the management of alignment to ISO-27001 and other applicable security frameworks.
Stay updated on applicable industry trends and regulations to ensure ISMS compliance.
Monitor and analyze GRC processes and systems, making recommendations for improvement.
Document risk reduction plan. Annually, document “Opportunities” (potential positive improvements like adopting some technology for improved efficiency).
Other duties as assigned.
REQUIRED QUALIFICATIONS
Minimum of 5 years of experience leading Governance, Risk, and Compliance (GRC) programs.
Proficiency in ISO 27001
PREFERRED QUALIFICATIONS
GRC certifications (e.g. CGRC, CRISC, etc)
A bachelor’s degree in IT, cybersecurity, business, or law is preferred, or strong demonstrable background in GRC Management.
Previous experience in GRC, risk management, or internal audit, often with a mid-level leadership background.
Proficiency in frameworks like SOC2, NIST CSF, and HIPAA regulations.
Strong ability to analyze risk data and translate complex regulations into actionable controls.
Excellent communication skills to interact with stakeholders and lead team efforts.
Experience with 3rd party/vendor risk management processes.
Experience in working with sales teams to complete Requests for Proposals and security questionnaires.
Understanding of GRC processes such as policy management, risk assessment, and IT audits.
Exceptional verbal and written communication skills.
EDUCATION:
LICENSES / CERTIFICATIONS:
PHYSICAL REQUIREMENTS:
L - Light Work - Exerting up to 20 pounds of force occasionally, and/or up to 10 pounds of force frequently, and/or a negligible amount of force constantly; requires occasional walking, standing or squatting.For disease specific care programs refer to the program specific requirements of the department for further specifications on experience and educational expectations, including continuing education requirements.
Any physical requirements reported by a prospective employee and/or employee’s physician or delegate will be considered for accommodations.
PAY RANGE:
$115,000.00 - $140,000.00CITY:
POSTAL CODE:
The listed base pay range is a good faith representation of current potential base pay for a successful full time applicant. It may be modified in the future and eligible for additional pay components. Pay is determined by factors including experience, relevant qualifications, specialty, internal equity, location, and contracts.
Rochester Regional Health is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, creed, religion, sex (including pregnancy, childbirth, and related medical conditions), sexual orientation, gender identity or expression, national origin, age, disability, predisposing genetic characteristics, marital or familial status, military or veteran status, citizenship or immigration status, or any other characteristic protected by federal, state, or local law.
Governance Risk And Compliance Jobs by Experience Level
See All 95 Governance Risk And Compliance Jobs
Find roles that match your experience and apply in just a few clicks.
Find JobsGovernance Risk And Compliance Job Market
Who's Hiring



Top Industries Hiring
- Technology & Software14
- Consulting & Professional Services4
- Accounting & Auditing3
- Healthcare & Medical Services3
- Manufacturing2
What Employers Look For
The qualifications that appear most often in governance risk and compliance jobs.
- Bachelor's degree in finance, accounting, law, business, or a related field
- Certifications such as CISA, CRISC, CIA, CGRC, or CISM
- Experience conducting internal audits, risk assessments, or compliance reviews
- Knowledge of regulatory frameworks including SOX, COSO, NIST, or ISO 31000
- Proficiency with GRC platforms such as Archer, ServiceNow GRC, or MetricStream
- Strong written communication skills for policy documentation and audit reporting
Tips for Your Governance Risk And Compliance Job Search
Tailor your resume to each framework
GRC job postings reference specific frameworks like COSO, ISO 31000, or NIST. Match your resume language to the exact framework named in each posting rather than listing all of them generically. Recruiters scan for direct alignment.
Highlight certifications above your degree
Credentials like CISA, CRISC, or CGRC often carry more weight than your undergraduate major in GRC hiring. Place your active certifications near the top of your resume so hiring managers see them before reading your work history.
Apply early to roles that fit
Migrate Mate lists governance risk and compliance openings from across the United States in one place, so you can find roles that match and apply directly to each listing.
Filter openings by industry vertical
Your regulatory experience in banking differs sharply from healthcare or energy. Targeting openings in the sector where you built your expertise sharpens your fit and reduces the time you spend explaining transferable context in interviews.
Prepare scenario answers for audit findings
GRC interviewers frequently ask how you handled a significant control failure or escalated a finding to leadership. Prepare two or three concrete examples with the outcome and remediation steps, not just the problem you identified.
Negotiate scope before accepting an offer
In GRC roles, reporting lines and escalation authority define how effective you can actually be. Before accepting, clarify whether you report to the board, legal, or a business unit, because that structure shapes your real leverage on compliance issues.
Governance Risk And Compliance Jobs: Frequently Asked Questions
Which companies are hiring the most governance risk and compliances?
The companies hiring the most governance risk and compliances right now include Figma, Ivalua, and Weaver, with the largest share of openings in California, Texas, and Georgia, based on current listings on Migrate Mate as of August 2026. Demand is consistently strong in financial services, healthcare systems, and large technology firms with public regulatory obligations.
How many governance risk and compliance jobs are remote?
About 61% of governance risk and compliance openings are fully remote or hybrid as of August 2026, making it one of the more flexible fields in finance and legal operations. Sub-areas like third-party risk management, policy writing, and regulatory reporting tend to offer the highest share of remote arrangements, while roles involving on-site audits or physical controls testing are more often in-person.
How do you become a governance risk and compliance?
Start with a degree in accounting, finance, law, or business administration, then pursue an entry-level role in internal audit, compliance operations, or risk analysis to build foundational exposure. Earn a recognized certification such as CISA or CRISC to validate technical skills. From there, move into broader GRC roles by demonstrating experience across risk assessment, control testing, and regulatory reporting across multiple business areas.
How do you get hired in governance risk and compliance with little experience?
Target entry-level titles like compliance analyst, risk analyst, or audit associate rather than applying to senior GRC roles directly. Internships in internal audit or legal and compliance departments at banks, insurers, or large employers provide concrete exposure. A foundational certification like the CGRC or completing coursework tied to SOX or HIPAA compliance signals commitment to the field even before your first full-time role.
What does the governance risk and compliance interview process look like?
Most GRC interview processes run through an initial recruiter screen followed by a technical interview covering your knowledge of specific frameworks, regulatory requirements, or audit methodology relevant to the employer's industry. A case study or take-home exercise asking you to evaluate a control gap or draft a risk register entry is common at mid to senior levels. Final rounds typically involve meeting cross-functional stakeholders in legal, finance, or IT who assess how you communicate findings and manage competing priorities.
Where can I find and apply to governance risk and compliance jobs?
You can find and apply to governance risk and compliance jobs on Migrate Mate, which lists current openings from across the United States. Find roles that match your experience level, industry background, and preferred work arrangement, then apply directly to each listing without any intermediate steps.
See All 95 Governance Risk And Compliance Jobs
Find roles that match your experience and apply in just a few clicks.
Find Jobs