Grc Analyst Jobs
Grc Analyst jobs are open across financial services, healthcare, technology, and government contracting, from entry-level to senior and lead roles, with specializations in compliance program management, enterprise risk frameworks, and IT security governance. Find a role that fits from the openings below and apply directly.
Find Grc Analyst JobsOverview
Showing 5 of 77+ Grc Analyst jobs











Just as our employees are committed to helping our customers manage their finances, we’re committed to our employees. After all, they make it happen for our customers every day.
To ensure our people can enjoy long and successful careers here at CFSI, we offer competitive compensation, great benefits, and professional development and advancement opportunities. As an equal-opportunity workplace and affirmative-action employer, we celebrate and support a diverse workplace for the benefit of all: our employees, customers and communities.
Essential Duties:
- Administer and maintain the third-party due diligence portal, ensuring current content, standard responses, supporting documentation, and security artifacts remain aligned with internal policies and controls.
- Coordinate, complete, and track information security questionnaires from customers, partners, auditors, and other authorized third parties.
- Partner with stakeholders across various business lines to gather responses and supporting evidence.
- Perform information security due diligence reviews of new and existing vendors through review of SOC reports, questionnaires, policies, penetration test summaries, business continuity materials, and other documentation to assess security posture, control environments, data protection practices, regulatory considerations, and overall risk.
- Identify, document, and communicate information security risks, control gaps, due diligence findings, and remediation recommendations to support management and governance decision-making.
- Support AI Governance activities related to third-party AI solution evaluations, ongoing monitoring of approved use cases, and governance processes involving internally developed AI and agent solutions, in alignment with guidance established by the AI Governance Committee.
- Support enhancements to third-party risk processes, standards, reporting, workflows, templates, metrics, and ongoing monitoring activities.
- Support identity and access management governance, review, and related coordination activities as assigned.
- Track remediation items, follow-up actions, and review outcomes to support timely resolution.
- Maintain organized assessment records, questionnaires, exceptions, and supporting documentation in accordance with policy and regulatory expectations.
- Support audits, examinations, and internal reviews related to vendor management, information security due diligence, and AI Governance oversight.
- Perform other Information Security, third-party risk, and related governance duties as assigned by management.
Qualifications:
- Bachelor’s Degree required in Information Security, Cybersecurity, Information Technology or equivalent experience considered
- Strong analytical and communication skills. Proficient in conducting third-party information security due diligence, including reviewing SOC reports, penetration tests, and security questionnaires. Familiarity with risk assessment frameworks (e.g., NIST, SIG, CIS) and emerging AI governance guidelines. Ability to work independently and collaboratively to identify, document, and communicate security risks.
- 4+ years of experience in Information Security; OR
- 4+ years of experience in Risk Management or Third-Party Risk Management (TPRM) with a strong focus on Information Security and GRC; OR
- 4+ years of experience in Information Technology with a dedicated focus on Security or GRC.
- Experience or familiarity with emerging technology risk frameworks (such as AI Governance or the NIST AI Risk Management Framework) is highly desired.
- Financial industry experience (e.g., familiarity with GLBA, FFIEC, or FDIC guidelines) is preferred but not required.
- All applicants must be 18 years of age or older.
Min: USD $28.85/Yr. Max: USD $47.54/Yr. Other Job Information:
Compensation: Commensurate with experience plus potential for annual merit increase. In addition to your competitive salary, you will be rewarded benefits including: 11 paid holidays, paid vacation, Medical, Vision & Dental insurance, 401K with generous match, Pension, Tuition Reimbursement, Banking discounts and the list goes on!
Physical Requirements:
Grc Analyst Jobs by Experience Level
See All 77 Grc Analyst Jobs
Find roles that match your experience and apply in just a few clicks.
Find Grc Analyst JobsGrc Analyst Job Market
Who's Hiring


Top Industries Hiring
- Technology & Software
- Construction & Real Estate
- Education
- Energy
- Automotive
What Employers Look For
The qualifications that appear most often in grc analyst jobs.
- Bachelor's degree in information security, business, finance, or a related field
- Hands-on experience with frameworks such as NIST CSF, ISO 27001, SOC 2, or COBIT
- Proficiency in GRC platforms such as ServiceNow GRC, Archer, or OneTrust
- Professional certification such as CISA, CRISC, CISM, or CompTIA Security+
- Experience conducting risk assessments, control testing, and audit evidence collection
- Strong written communication skills for policy documentation and executive reporting
Tips for Your Grc Analyst Job Search
Tailor your resume to framework keywords
GRC job postings frequently filter candidates by named frameworks like NIST CSF, ISO 27001, or SOC 2. Pull the exact framework acronyms from each posting and mirror them in your resume's skills and experience sections, not just a generic skills list.
Highlight your certification timing strategically
If you're pursuing CISA, CRISC, or CISSP, list it as 'in progress' with your expected exam date. Hiring managers for grc analyst roles often prefer a candidate actively testing over one with no certification path visible at all.
Apply early to roles that fit
Migrate Mate lists grc analyst openings from across the United States in one place, so you can find roles that match and apply directly to each listing.
Filter openings by regulated industry first
A grc analyst role in healthcare operates under HIPAA and HITRUST, while one in financial services centers on SOX and PCI DSS. Targeting industries where you already know the regulatory environment makes your application far more competitive than applying broadly.
Prepare a controls-testing scenario for interviews
Most grc analyst interviews include a scenario question about a failed control or an audit finding. Walk through how you'd scope the issue, assign risk ownership, and document remediation. Practicing one or two realistic walkthroughs before the interview is more useful than rehearsing definitions.
Negotiate using scope, not just title
When negotiating a grc analyst offer, ask about the number of business units in scope, whether the role owns policy writing or only monitors, and who the function reports to. These scope details affect workload and career trajectory as much as the base offer does.
Grc Analyst Jobs: Frequently Asked Questions
Which companies are hiring the most grc analysts?
The companies hiring the most grc analysts right now include Clayco, c2 labs, and DoorDash, with the largest share of openings in California, Georgia, and Pennsylvania, based on current listings on Migrate Mate as of August 2026. Demand is concentrated in financial services, defense contracting, and large healthcare systems that operate under multiple regulatory frameworks simultaneously.
How many grc analyst jobs are remote?
About 73% of grc analyst openings are fully remote or hybrid as of August 2026, reflecting the desk-based and documentation-heavy nature of the role. Sub-specializations focused on policy management, vendor risk assessment, and compliance monitoring tend to offer the highest share of remote arrangements, while roles requiring hands-on audit walkthroughs or on-site system access are more likely to require in-person presence.
How do you become a grc analyst?
Start by building foundational knowledge in information security and regulatory compliance through a relevant degree or self-study using O*NET occupation guidance for the role's core competencies. Earn an entry-level certification such as CompTIA Security+ or the Certified in Risk and Information Systems Control credential. Then pursue roles with direct exposure to control testing, policy documentation, or internal audit work to build the hands-on experience most employers require before hiring into a dedicated grc analyst position.
Can you get a grc analyst job with little or no experience?
Yes, entry-level grc analyst roles exist, and employers often hire candidates who can demonstrate regulatory awareness even without formal job titles. Internships in internal audit, IT compliance, or information security operations are the most direct path in. Passing the CompTIA Security+ or completing a GRC platform certification on tools like ServiceNow GRC can offset limited experience. Roles at smaller companies or in compliance-adjacent positions such as risk analyst or audit associate are also practical entry points.
What does the grc analyst interview process look like?
Most grc analyst interview processes include an initial recruiter screen focused on regulatory background and tool familiarity, followed by a hiring manager interview that covers framework knowledge and past audit or risk assessment work. A technical or scenario-based round is common, where candidates walk through how they would handle a control failure, gap assessment, or policy exception. Final-stage interviews often involve the compliance, legal, or IT security leadership team depending on the organization's reporting structure.
Where can I find and apply to grc analyst jobs?
You can find and apply to grc analyst jobs on Migrate Mate, which lists current openings from across the United States in one place. Find roles that match your experience level, industry focus, and framework background, then apply directly to each listing without being redirected away from your search.
See All 77 Grc Analyst Jobs
Find roles that match your experience and apply in just a few clicks.
Find Grc Analyst Jobs