OPT Governance Risk And Compliance Jobs
Governance, risk, and compliance jobs are a strong fit for F-1 OPT students with backgrounds in business, information systems, finance, or law. Most GRC roles qualify as specialty occupations, supporting STEM OPT extension eligibility for qualifying degree fields. Demand spans financial services, healthcare, and tech.
See All OPT Governance Risk And Compliance JobsOverview
Showing 5 of 15+ Governance Risk And Compliance jobs


Have you applied for this role?


Have you applied for this role?


Have you applied for this role?


Have you applied for this role?


Have you applied for this role?
See all Governance Risk And Compliance Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Governance Risk And Compliance roles.
Get Access To All Jobs
INTRODUCTION
As CohnReznick grows, so do our career opportunities. As one of the nation’s top professional services firms, CohnReznick creates rewarding careers in advisory, assurance, and tax with team members who value innovation and collaboration in everything they do!
CohnReznick helps organizations optimize performance, manage risk, and maximize value through CohnReznick LLP (assurance services) and CohnReznick Advisory LLC (advisory and tax services). Together, the firm provides leaders with deep industry knowledge and relationships, solutions to address clients’ unique business goals and risks, and insight on how emerging market forces can drive opportunity. With offices nationwide, the firm serves organizations around the world as an independent member of Nexia.
We currently have an exciting career opportunity for an Governance, Risk, and Compliance Senior Specialist to join our Legal & Risk team.
CohnReznick is a hybrid firm and most of our professionals are located within a commutable distance to one of our offices. This position is considered remote which means it does not require job duties be performed within proximity of a CohnReznick office location. However, as a remote employee, you may be required to be present at a CohnReznick office with scheduled notice for client work, team meetings, or trainings.
YOUR TEAM.
This position will support our Governance, Risk & Compliance team. The Governance, Risk, and Compliance Senior Specialist is responsible for actively supporting and enhancing the organization’s security and compliance initiatives. The Senior Specialist will serve as a key contributor to both security awareness training and third-party risk management programs.
WHY COHNREZNICK?
At CohnReznick, we’re united by a common mission to create opportunity, value, and trust for our clients, our people, and our communities. Whether it’s working alongside your peers to solve a client challenge, or volunteering together at the local food bank, there are so many ways to find your “why” at the firm.
We believe it’s important to balance work with everyday life – and make time for enjoyment and fun. We invest in a robust Total Rewards package that includes everything from generous PTO, a flexible work environment, expanded parental leave, extensive learning & development, and even paid time off for employees to volunteer.
YOUR ROLE.
Responsibilities include but not limited to:
- Conduct third-party risk assessments, analyzing vendor practices to identify and mitigate potential risks.
- Manage and maintain dashboards, trackers, and logs for compliance activities, including risk assessments and training metrics.
- Review and recommend updates to standard operating procedures related to IT governance, security awareness, and vendor risk management.
- Serve as a point of contact for internal and external stakeholders on third-party compliance matters and security awareness initiatives.
- Provide insights and recommendations for process improvements and contribute to the development of automation tools for tracking compliance metrics.
- Act as back-up support for distributing security awareness training communications as needed.
- Coordinate vendor information requests and follow-ups, ensuring timely collection of security artifacts and responses to questionnaires.
- Track third-party remediation items and exceptions, preparing status updates and escalating risks when appropriate.
- Support periodic reporting (e.g., program metrics, trends, and key risks) for leadership and governance forums.
- Assist with policy, standard, and control documentation by gathering evidence and maintaining organized, audit-ready records.
- Partner with Procurement, Legal, IT, and Information Security to align third-party reviews with contracting and onboarding timelines.
YOUR EXPERIENCE.
The successful candidate will have:
Required:
- Proven ability to manage multiple projects and meet deadlines in a dynamic environment.
- Strong interpersonal skills and the ability to work collaboratively across teams and with external vendors.
- Highly organized; capable of prioritizing and executing tasks efficiently in a fast-paced environment with the ability to manage time effectively.
- Capable of handling issues involving confidentiality and discretion in a mature professional manner.
- Strong written and verbal communication skills, with the ability to translate technical and compliance concepts for non-technical audiences.
- Working knowledge of third-party risk management concepts (e.g., due diligence, risk tiering, remediation tracking) and the ability to learn internal methodologies quickly.
- Proficiency with Microsoft Office tools (Excel, PowerPoint, Word) and experience maintaining trackers, dashboards, and status reporting.
- Experience reviewing vendor security documentation (e.g., SOC reports, security questionnaires) and summarizing findings for stakeholders.
- Ability to document processes and maintain clear audit-ready evidence (e.g., screenshots, approvals, and assessment artifacts).
- Strong analytical and problem-solving skills, with attention to detail when assessing risk, exceptions, and remediation plans.
- Comfort working with cross-functional partners (IT, Security, Procurement, Legal) to drive vendor follow-ups and close action items.
Preferred:
- Bachelor’s degree in Information Technology, Business Administration, or related field, or 3-5 years of equivalent experience.
- Third-Party Risk Management program implementation experience, a plus.
- Business Resiliency experience or related experience, a plus.
- Familiarity with security frameworks (e.g., NIST, ISO 27001) and regulatory standards (e.g., PCI, HIPAA).
In addition, please take a moment to review our Universal Job Standards.
Studies have shown that we are less likely to apply to jobs unless we meet every single qualification. At CohnReznick, we are dedicated to building a diverse, equitable, and inclusive workplace, so if you’re excited about this role but your experience doesn’t align perfectly with every qualification in the job description, we still encourage you to apply. You may be just the right candidate for this or one of our other roles.
"CohnReznick" is the brand name under which CohnReznick LLP and CohnReznick Advisory LLC and their respective subsidiaries provide professional services. CohnReznick LLP and CohnReznick Advisory LLC (and their respective subsidiaries) practice in an alternative practice structure in accordance with the AICPA Code of Professional Conduct and applicable law, regulations, and professional standards. CohnReznick LLP is a licensed CPA firm that provides attest services to its clients. CohnReznick Advisory LLC provides tax and business consulting services to its clients. CohnReznick Advisory LLC and its subsidiaries are not licensed CPA firms.
CohnReznick is an equal opportunity employer, committed to a diverse and inclusive team to drive business results and create a better future every day for our team members, clients, partners, and communities. We believe a diverse workforce allows us to match our growth ambitions and drive inclusion across the business. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, age, national origin, or protected veteran status and will not be discriminated against on the basis of disability. For more information, please see Equal Employment Opportunity Posters.
If you are an individual with a disability in need of assistance at any time during our recruitment process, please contact us at CRaccommodation@cohnreznick.com. Please note: This email address is reserved for individuals with disabilities in need of assistance and are not a means of inquiry about positions or application statuses.
CohnReznick does not accept unsolicited resumes from third-party recruiters unless such recruiters are currently engaged by CohnReznick Talent Acquisition Team by way of a written agreement to provide candidates for a specified opening. Any employment agency, person or entity that submits an unsolicited resume does so with the understanding that CohnReznick will have the right to hire that applicant at its discretion without any fee owed to the submitting employment agency, person or entity.
LOCATION
Location(s): Atlanta
State: Georgia
DEPARTMENT
Department: Practice Management
See all OPT Governance Risk And Compliance Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new OPT Governance Risk And Compliance Jobs.
Get Access To All JobsTips for Finding OPT Sponsorship in Governance Risk And Compliance
Lead with your degree field alignment
GRC roles require a direct connection between your degree and the position. Emphasize coursework in risk management, auditing, cybersecurity, or compliance law in your resume so hiring managers and USCIS can clearly see the specialty occupation link.
Target employers with established compliance teams
Large financial institutions, healthcare systems, and technology companies maintain dedicated GRC departments and are more experienced with OPT work authorization. Smaller firms often lack the infrastructure to support international candidates through compliance-heavy hiring processes.
Pursue relevant certifications early
Certifications like CISA, CRISC, or CompTIA Security+ strengthen your GRC candidacy and signal commitment to the field. Employers in heavily regulated industries view certifications as evidence of specialized knowledge, which also reinforces your specialty occupation argument during OPT.
Clarify your OPT timeline upfront
GRC hiring cycles at banks and regulated firms move slowly. Be transparent about your OPT end date and H-1B visa eligibility from the first conversation so employers can assess sponsorship feasibility before investing significant time in the interview process.
Focus on regulated industries for H-1B pathways
Financial services, healthcare, and government contractors sponsor more GRC professionals than most other sectors. These industries operate under mandatory compliance frameworks, making GRC roles genuinely indispensable rather than discretionary, which strengthens the business case for sponsoring your H-1B.
Frame your international background as a compliance asset
Experience navigating multiple regulatory environments, foreign data privacy laws, or cross-border transactions is genuinely valuable in GRC. Articulate how your international perspective contributes to a firm's risk management capabilities rather than treating your background as a neutral biographical fact.
Governance Risk And Compliance OPT: Frequently Asked Questions
Do governance, risk, and compliance roles qualify as specialty occupations for OPT?
Most GRC roles qualify as specialty occupations because they typically require a bachelor's degree or higher in a specific field such as information systems, finance, accounting, or cybersecurity. Job titles like compliance analyst, risk analyst, and GRC specialist have been approved under this standard. The key is that the role must require your specific degree field, not just any bachelor's degree.
Can I use STEM OPT extension for a GRC job?
Yes, if your degree is in a STEM-designated field such as management information systems, computer science, finance, or applied mathematics, and the GRC role is substantively tied to that field. Cybersecurity GRC and technology risk roles most reliably qualify. GRC positions focused purely on legal or policy compliance may be harder to connect to a STEM degree for extension purposes.
Which industries hire the most GRC professionals willing to sponsor visas?
Financial services, healthcare, and enterprise technology are the strongest sectors for GRC hiring and visa sponsorship. Banks, insurance companies, and hospital networks operate under strict regulatory mandates that require permanent GRC staffing. Government contractors and global consulting firms are also reliable sponsors, as GRC work is core to their service delivery rather than an optional function.
How do I find GRC jobs where employers are open to OPT candidates?
Migrate Mate filters job listings specifically for employers open to sponsoring F-1 OPT students, which removes the guesswork of applying to roles where your authorization status will disqualify you. Searching by GRC-related job titles on Migrate Mate surfaces positions from employers already familiar with OPT work authorization requirements.
What should I include on my resume to show I qualify for a GRC specialty occupation?
List your degree field prominently and connect it directly to GRC functions. Include relevant coursework such as audit methodology, risk frameworks, data privacy regulations, or financial controls. Certifications, internship experience involving compliance tools like GRC platforms, and any work involving regulatory reporting all reinforce that your role requires specialized academic preparation rather than general business knowledge.