Governance Risk And Compliance Jobs
Governance Risk And Compliance jobs are open across financial services, healthcare, technology, and energy, from analyst to director level, with specializations in regulatory compliance, enterprise risk management, and internal audit. Find a role that fits from the openings below and apply directly.
Find JobsLooking for remote work? View remote governance risk and compliance jobs →Overview
Showing 5 of 99+ Governance Risk And Compliance jobs











Ardent is seeking a Governance, Risk, and Compliance (GRC) / Compliance Analyst to join our team.
This is a remote position with expected travel to Tallahassee, FL.
Position Description:
Ardent is seeking a Governance, Risk, and Compliance (GRC) / Compliance Analyst that integrates technical evidence with governance, risk, compliance, and internal-audit support requirements. The role maintains traceability among agency documentation, Rule 60GG-2, NIST CSF, approved procedures, factual findings, remediation actions, and deliverable acceptance criteria while protecting confidential and exempt information across a potentially broad multi-agency environment.
Responsibilities and Duties:
- Lead ingestion and analysis of agency documentation, including risk assessments, remediation plans, prior findings, corrective actions, inventories, and strategic plans.
- Direct development of the Agency Risk Understanding Memorandum, including environmental summaries, agency-specific risks, assumptions, documentation gaps, and impacts on testing priorities.
- Design the Ground-Truth and Ad Hoc Testing Strategies and approve detailed procedures defining objectives, systems, controls, access points, tools, sampling, scripts, evidence, thresholds, stop conditions, and escalation paths.
- Map procedures and results to NIST CSF DE.AE, DE.DP, PR.AC; Rule 60GG-2, F.A.C.; and the applicable approved criteria.
- Ensure testing remains within written OCIG authorization, avoids duplication of operational testing, and complies with agency-specific Rules of Engagement.
- Review evidence for relevance, reliability, sufficiency, attribution, timestamps, chain of custody, and reproducibility.
- Validate that reports accurately state procedures performed and factual results without an audit opinion; ensure advisory recommendations are distinctly labeled.
- Conduct independent QA reviews of technical deliverables not authored solely by the reviewer and document sign-off.
- Lead technical briefings, workshops, job aids, and knowledge transfer so OCIG and OIG staff can understand and reuse procedures.
- Support urgent analysis of logs, timelines, after-action reports, remediation evidence, and incident-specific control issues when directed.
Requirements:
- Bachelor's degree in cybersecurity, information assurance, audit, information systems, or related discipline.
- Proof of relevant professional certifications such as CISSP, CISA, PMP, CEH, or other relevant certifications.
- 10 years of progressive cybersecurity experience, including security operations, incident response, vulnerability management, intrusion analysis, adversary simulation, technical assessment, or audit support.
- 5 years supporting or conducting audits, compliance reviews, independent assessments, or assurance work in government or similarly regulated environments.
- Demonstrated ability to design defensible test procedures, evaluate control performance, distinguish fact from opinion, and communicate technical results to senior stakeholders.
- Working knowledge of professional auditing or assurance standards and evidence requirements.
Preferred Qualifications:
- Purple-team or adversary-emulation leadership using MITRE ATT&CK and threat-informed kill chains.
- Government incident-command experience.
- CISA, CIA, or other audit credential.
- Experience with Active Directory, cloud platforms, APIs, web applications, databases, endpoints, SIEM/EDR, vulnerability scanners, and evidence repositories.
Due to the nature of the work we support, all candidates in consideration for this role must be willing to undergo the government issued background investigation process.
Ardent is an equal opportunity employer. We will not discriminate in employment, recruitment, advertisements for employment, compensation, termination, upgrading, promotions, and other conditions of employment against any employee or job applicant on the bases of race, color, gender, national origin, age, religion, creed, disability, veteran's status, sexual orientation, gender identity, gender expression, or any other basis protected by state, local, or federal law.
Governance Risk And Compliance Jobs by Experience Level
See All 99 Governance Risk And Compliance Jobs
Find roles that match your experience and apply in just a few clicks.
Find JobsGovernance Risk And Compliance Job Market
Who's Hiring



Top Industries Hiring
- Technology & Software
- Healthcare & Medical Services
- Accounting & Auditing
- Consulting & Professional Services
- Education
What Employers Look For
The qualifications that appear most often in governance risk and compliance jobs.
- Bachelor's degree in finance, accounting, law, business, or a related field
- Certifications such as CISA, CRISC, CIA, CGRC, or CISM
- Experience conducting internal audits, risk assessments, or compliance reviews
- Knowledge of regulatory frameworks including SOX, COSO, NIST, or ISO 31000
- Proficiency with GRC platforms such as Archer, ServiceNow GRC, or MetricStream
- Strong written communication skills for policy documentation and audit reporting
Tips for Your Governance Risk And Compliance Job Search
Tailor your resume to each framework
GRC job postings reference specific frameworks like COSO, ISO 31000, or NIST. Match your resume language to the exact framework named in each posting rather than listing all of them generically. Recruiters scan for direct alignment.
Highlight certifications above your degree
Credentials like CISA, CRISC, or CGRC often carry more weight than your undergraduate major in GRC hiring. Place your active certifications near the top of your resume so hiring managers see them before reading your work history.
Apply early to roles that fit
Migrate Mate lists governance risk and compliance openings from across the United States in one place, so you can find roles that match and apply directly to each listing.
Filter openings by industry vertical
Your regulatory experience in banking differs sharply from healthcare or energy. Targeting openings in the sector where you built your expertise sharpens your fit and reduces the time you spend explaining transferable context in interviews.
Prepare scenario answers for audit findings
GRC interviewers frequently ask how you handled a significant control failure or escalated a finding to leadership. Prepare two or three concrete examples with the outcome and remediation steps, not just the problem you identified.
Negotiate scope before accepting an offer
In GRC roles, reporting lines and escalation authority define how effective you can actually be. Before accepting, clarify whether you report to the board, legal, or a business unit, because that structure shapes your real leverage on compliance issues.
Governance Risk And Compliance Jobs: Frequently Asked Questions
Which companies are hiring the most governance risk and compliances?
The companies hiring the most governance risk and compliances right now include Ivalua, Weaver, and Capital One, with the largest share of openings in California, Texas, and New York, based on current listings on Migrate Mate as of September 2026. Demand is consistently strong in financial services, healthcare systems, and large technology firms with public regulatory obligations.
How many governance risk and compliance jobs are remote?
About 64% of governance risk and compliance openings are fully remote or hybrid as of September 2026, making it one of the more flexible fields in finance and legal operations. Sub-areas like third-party risk management, policy writing, and regulatory reporting tend to offer the highest share of remote arrangements, while roles involving on-site audits or physical controls testing are more often in-person.
How do you become a governance risk and compliance?
Start with a degree in accounting, finance, law, or business administration, then pursue an entry-level role in internal audit, compliance operations, or risk analysis to build foundational exposure. Earn a recognized certification such as CISA or CRISC to validate technical skills. From there, move into broader GRC roles by demonstrating experience across risk assessment, control testing, and regulatory reporting across multiple business areas.
How do you get hired in governance risk and compliance with little experience?
Target entry-level titles like compliance analyst, risk analyst, or audit associate rather than applying to senior GRC roles directly. Internships in internal audit or legal and compliance departments at banks, insurers, or large employers provide concrete exposure. A foundational certification like the CGRC or completing coursework tied to SOX or HIPAA compliance signals commitment to the field even before your first full-time role.
What does the governance risk and compliance interview process look like?
Most GRC interview processes run through an initial recruiter screen followed by a technical interview covering your knowledge of specific frameworks, regulatory requirements, or audit methodology relevant to the employer's industry. A case study or take-home exercise asking you to evaluate a control gap or draft a risk register entry is common at mid to senior levels. Final rounds typically involve meeting cross-functional stakeholders in legal, finance, or IT who assess how you communicate findings and manage competing priorities.
Where can I find and apply to governance risk and compliance jobs?
You can find and apply to governance risk and compliance jobs on Migrate Mate, which lists current openings from across the United States. Find roles that match your experience level, industry background, and preferred work arrangement, then apply directly to each listing without any intermediate steps.
See All 99 Governance Risk And Compliance Jobs
Find roles that match your experience and apply in just a few clicks.
Find Jobs