Grc Analyst Jobs
Grc Analyst jobs are open across financial services, healthcare, technology, and government contracting, from entry-level to senior and lead roles, with specializations in compliance program management, enterprise risk frameworks, and IT security governance. Find a role that fits from the openings below and apply directly.
Find Grc Analyst JobsOverview
Showing 5 of 70+ Grc Analyst jobs








- Location: On-site in Danvers, MA
Who We Are
Samsung HME America (Healthcare and Medical Equipment) is Samsung’s U.S. medical imaging organization, delivering advanced diagnostic solutions across Ultrasound, Digital Radiography, and Computed Tomography. We lead nationwide sales, marketing, service, and distribution of Samsung’s imaging technologies, partnering with healthcare providers to strengthen diagnostic capabilities, streamline clinical workflows, and support better patient care. Samsung HME America also serves as the global manufacturing center for Samsung’s mobile Computed Tomography (mCT) business, leading the development of advanced CT systems used by healthcare providers worldwide.
Backed by Samsung Electronics’ global technology leadership, our teams work closely with clinicians to translate real-world challenges into innovative imaging solutions. Our culture combines a sense of urgency, customer focus, and clinical collaboration to advance the future of medical imaging.
We are seeking a junior-to-mid level Information Security Analyst to support and own key elements of our information security and compliance program, with a strong emphasis on ISO 27001 and CMMC frameworks. This role focuses on policy creation, documentation, and audit readiness while supporting operational security across Microsoft 365, DLP, and incident response.
The analyst will work closely with IT and Compliance to maintain a strong security posture and will play a key role in driving compliance initiatives, managing documentation, and coordinating security processes. This role requires a hands-on approach, including participation in help desk support and day-to-day IT security operations.
Compliance Ownership & Governance (ISO 27001 / CMMC):
- Own and maintain ISO 27001 and CMMC compliance programs
- Manage evidence, remediation tracking, and audit readiness
- Perform gap assessments and risk analyses
Policy Development & Documentation
- Develop and maintain security policies, procedures, and runbooks
- Ensure documentation is audit-ready and version controlled
DLP & Microsoft 365 Security
- Configure and manage DLP policies across Microsoft 365
- Support Microsoft Purview and identity security controls
Security Operations & SIEM:
- Monitor alerts using SIEM tools
- Support incident response and tabletop exercises
AI Policy & Usage:
- Support the development and maintenance of an Acceptable AI Usage Policy
- Evaluate AI models and use cases to determine appropriate application across organizational roles
- Support tracking, logging, and governance methodologies for AI usage
Disaster Recovery:
- Support disaster recovery planning, documentation, and testing activities
- Assist with tabletop exercises and post-test remediation tracking
IT Support:
- Provide help desk support and security guidance to end users
- Assist with day-to-day IT security operations and user education
Skills & Experience
- 2–5 years of experience in IT or information security
- Experience with ISO 27001 and/or CMMC
- Strong documentation and policy writing skills
- Familiarity with Microsoft 365 security
- Understanding of DLP, incident response, and DR
- Understanding of AI models and their use within an organization
- Willingness to support help desk operations
- Experience supporting ISO or CMMC audits
- Familiarity with Microsoft Purview
- Experience with SIEM tools (e.g., Microsoft Sentinel, Splunk)
- Knowledge of NIST frameworks
- Relevant certifications (Security+, SC-900, etc.)
- Strong documentation skills
- Ownership and accountability
- Attention to detail
- Collaboration
- Problem-solving
- Customer service mindset
- Occasionally lift and /or move up to 25 pounds
- Frequently required to sit; use hands to finger, handle, or feel; reach with hands; and talk or hear
- Must be able to sit for long periods of time
- Medical (Blue Benefit Administrators): 5 PPO Plans (with up to 95% employer contribution)
- Dental (Blue Cross Blue Shield): 2 PPO Plans (with up to 80% employer contribution)
- Vision (Blue Cross Blue Shield): 100% company paid
- Short/Long Term Disability, Life & AD&D (The Standard): 100% company paid
- 401k Retirement (Fidelity): 100% company match up to 5%
- Tax Deferred Health Care Savings Programs
- Accident Insurance, Critical Illness, Hospital Indemnity, Pet, Legal, ID Theft
- Generous paid time off, tuition reimbursement, and more!
Inclusion and Diversity Statement: We are an Equal Opportunity Employer and value diversity at all levels of the organization. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, protected veteran status, or any other characteristic protected by applicable law. We are committed to providing reasonable accommodation to individuals with disabilities throughout the application and employment process. If you require assistance or accommodation, please contact Human Resources.
Grc Analyst Jobs by Experience Level
See All 70 Grc Analyst Jobs
Find roles that match your experience and apply in just a few clicks.
Find Grc Analyst JobsGrc Analyst Job Market
Who's Hiring



Top Industries Hiring
- Technology & Software
- Manufacturing
What Employers Look For
The qualifications that appear most often in grc analyst jobs.
- Bachelor's degree in information security, business, finance, or a related field
- Hands-on experience with frameworks such as NIST CSF, ISO 27001, SOC 2, or COBIT
- Proficiency in GRC platforms such as ServiceNow GRC, Archer, or OneTrust
- Professional certification such as CISA, CRISC, CISM, or CompTIA Security+
- Experience conducting risk assessments, control testing, and audit evidence collection
- Strong written communication skills for policy documentation and executive reporting
Tips for Your Grc Analyst Job Search
Tailor your resume to framework keywords
GRC job postings frequently filter candidates by named frameworks like NIST CSF, ISO 27001, or SOC 2. Pull the exact framework acronyms from each posting and mirror them in your resume's skills and experience sections, not just a generic skills list.
Highlight your certification timing strategically
If you're pursuing CISA, CRISC, or CISSP, list it as 'in progress' with your expected exam date. Hiring managers for grc analyst roles often prefer a candidate actively testing over one with no certification path visible at all.
Apply early to roles that fit
Migrate Mate lists grc analyst openings from across the United States in one place, so you can find roles that match and apply directly to each listing.
Filter openings by regulated industry first
A grc analyst role in healthcare operates under HIPAA and HITRUST, while one in financial services centers on SOX and PCI DSS. Targeting industries where you already know the regulatory environment makes your application far more competitive than applying broadly.
Prepare a controls-testing scenario for interviews
Most grc analyst interviews include a scenario question about a failed control or an audit finding. Walk through how you'd scope the issue, assign risk ownership, and document remediation. Practicing one or two realistic walkthroughs before the interview is more useful than rehearsing definitions.
Negotiate using scope, not just title
When negotiating a grc analyst offer, ask about the number of business units in scope, whether the role owns policy writing or only monitors, and who the function reports to. These scope details affect workload and career trajectory as much as the base offer does.
Grc Analyst Jobs: Frequently Asked Questions
Which companies are hiring the most grc analysts?
The companies hiring the most grc analysts right now include TikTok USDS Joint Venture, Vercel, and Kura Sushi, with the largest share of openings in California, Virginia, and Pennsylvania, based on current listings on Migrate Mate as of September 2026. Demand is concentrated in financial services, defense contracting, and large healthcare systems that operate under multiple regulatory frameworks simultaneously.
How many grc analyst jobs are remote?
About 66% of grc analyst openings are fully remote or hybrid as of September 2026, reflecting the desk-based and documentation-heavy nature of the role. Sub-specializations focused on policy management, vendor risk assessment, and compliance monitoring tend to offer the highest share of remote arrangements, while roles requiring hands-on audit walkthroughs or on-site system access are more likely to require in-person presence.
How do you become a grc analyst?
Start by building foundational knowledge in information security and regulatory compliance through a relevant degree or self-study using O*NET occupation guidance for the role's core competencies. Earn an entry-level certification such as CompTIA Security+ or the Certified in Risk and Information Systems Control credential. Then pursue roles with direct exposure to control testing, policy documentation, or internal audit work to build the hands-on experience most employers require before hiring into a dedicated grc analyst position.
Can you get a grc analyst job with little or no experience?
Yes, entry-level grc analyst roles exist, and employers often hire candidates who can demonstrate regulatory awareness even without formal job titles. Internships in internal audit, IT compliance, or information security operations are the most direct path in. Passing the CompTIA Security+ or completing a GRC platform certification on tools like ServiceNow GRC can offset limited experience. Roles at smaller companies or in compliance-adjacent positions such as risk analyst or audit associate are also practical entry points.
What does the grc analyst interview process look like?
Most grc analyst interview processes include an initial recruiter screen focused on regulatory background and tool familiarity, followed by a hiring manager interview that covers framework knowledge and past audit or risk assessment work. A technical or scenario-based round is common, where candidates walk through how they would handle a control failure, gap assessment, or policy exception. Final-stage interviews often involve the compliance, legal, or IT security leadership team depending on the organization's reporting structure.
Where can I find and apply to grc analyst jobs?
You can find and apply to grc analyst jobs on Migrate Mate, which lists current openings from across the United States in one place. Find roles that match your experience level, industry focus, and framework background, then apply directly to each listing without being redirected away from your search.
See All 70 Grc Analyst Jobs
Find roles that match your experience and apply in just a few clicks.
Find Grc Analyst Jobs