Governance Risk And Compliance Jobs for OPT Students
Governance, risk, and compliance jobs are a strong fit for F-1 OPT students with backgrounds in business, information systems, finance, or law. Most GRC roles qualify as specialty occupations, supporting STEM OPT extension eligibility for qualifying degree fields. Demand spans financial services, healthcare, and tech.
See All Governance Risk And Compliance JobsOverview
Showing 5 of 19+ Governance Risk And Compliance jobs


Have you applied for this role?


Have you applied for this role?


Have you applied for this role?


Have you applied for this role?


Have you applied for this role?
See all 19+ Governance Risk And Compliance jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Governance Risk And Compliance roles.
Get Access To All Jobs
INTRODUCTION
MatchPoint Solutions is a fast-growing, young, energetic global IT-Engineering services company with clients across the US. We provide technology solutions to various clients like Uber, Robinhood, Netflix, Airbnb, Google, Sephora, and more! More recently, we have expanded to working internationally in Canada, China, Ireland, UK, Brazil, and India. Through our culture of innovation, we inspire, build, and deliver business results, from idea to outcome. We keep our clients on the cutting edge of the latest technologies and provide solutions by using industry-specific best practices and expertise. We are excited to be continuously expanding our team. If you are interested in this position, please send over your updated resume. We look forward to hearing from you!
ROLE AND RESPONSIBILITIES
OneTrust GRC SME
Need hands-on experience as a OneTrust admin with several different modules. 100% onsite in Houston, zip code 70779. 12 months Contract Pay $60 to $65.
Note from the customer: We need someone who knows the OneTrust product line. Can get in quickly evaluate the issues in the environment and put an actionable plan together to resolve and get the work done. Highly qualified candidate is most important over rate right now.
Position Overview
The OneTrust GRC Systems Engineer will serve as the technical owner and system administrator for the organization’s Governance, Risk, and Compliance (GRC) platforms—primarily OneTrust. The engineer will configure, integrate, and manage the lifecycle of GRC systems to support IT General Controls (ITGC), Data Privacy, Cookie Compliance, and IT Risk Management across IT and OT environments. The ideal candidate will be able to quickly assess the current environment, identify issues, and deliver an actionable remediation plan.
Responsibilities:
Develops & Maintains:
- GRC system configurations, data models, and workflow designs supporting evolving compliance and risk processes.
- API integrations between OneTrust and systems such as identity management, ServiceNow CMDB, and ticketing platforms.
- Dashboards, reports, and analytics for real-time visibility into control health, risk posture, and remediation progress.
- Documentation of system configurations, data flows, and integration logic for audit, transparency, and change tracking.
Governance & Release Management:
- Manage intake of platform releases, review vendor release notes, assess impacts, and coordinate changes in alignment with IT change and release management practices.
Coordinates With:
- IT, cybersecurity, COE, GRC program owners, internal audit, IT operations, OT teams, and vendors for issue resolution, platform enhancements, and roadmap planning.
- Stakeholders to triage bugs, prioritize enhancements, and align GRC systems with broader governance strategies.
- End users to manage access requests, permissions, and troubleshooting.
Assesses & Monitors:
- System performance, integration reliability, and data accuracy, identifying opportunities for optimization.
- Automation and workflow effectiveness, recommending improvements.
- Enhancement/defect resolution throughput, ensuring timely execution and documentation.
- New GRC capabilities or vendor releases for alignment with business requirements and technology roadmaps.
SKILLS AND COMPETENCIES
Required:
- Hands-on experience supporting or engineering GRC platforms— OneTrust required.
- Strong experience in system configuration, user administration, data management, and workflow customization.
- API development & integration, including:
- FreeMarker (FTL) – required for OneTrust Logic
- Preferred: RESTful APIs, JavaScript for middleware/webhooks, Python or PowerShell for automation, JSON for structured data work
- Solid understanding of ITSM processes (change, release, incident, configuration), aligned with ITIL.
- Working knowledge of governance frameworks such as NIST CSF, COBIT 2019, ISO 27001, and GRC best practices.
- Strong analytical capabilities, including experience with data visualization tools (Power BI, Tableau).
- Strong documentation, troubleshooting, and cross-team communication skills.
Ability to Achieve:
- Stable, secure, high-performing GRC platforms supporting compliance, audit, and cybersecurity needs.
- Streamlined ITGC, risk, and workflow automation.
- Improved platform enhancements and data-driven insights.
- Stronger IT/OT governance maturity through scalable GRC technologies.
Risk Assessment Process Support
The engineer will support enhancement of the risk assessment process to:
- Determine inherent risk
- Assign controls
- Collect evidence or create remediation issues
- Generate residual risk scoring
- Update asset records
- Deliver real-time dashboards
Capabilities & Integration Work
ServiceNow CMDB - OneTrust Integration:
- APM record - OneTrust Inventory Asset creation/update
- Asset update triggers ITRM Risk Assessment
- Risk Assessment triggers:
- Control Templates
- Control Profiles
- Updates to Risk & Asset attributes
- Control Templates trigger:
- Implementations
- Evidence Collection
- Issues (remediation/exceptions)
- Risk scoring
- SNOW ticket creation
- Develop custom dashboards and build/maintain OneTrust integrations.
MatchPoint Solutions provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training.

INTRODUCTION
MatchPoint Solutions is a fast-growing, young, energetic global IT-Engineering services company with clients across the US. We provide technology solutions to various clients like Uber, Robinhood, Netflix, Airbnb, Google, Sephora, and more! More recently, we have expanded to working internationally in Canada, China, Ireland, UK, Brazil, and India. Through our culture of innovation, we inspire, build, and deliver business results, from idea to outcome. We keep our clients on the cutting edge of the latest technologies and provide solutions by using industry-specific best practices and expertise. We are excited to be continuously expanding our team. If you are interested in this position, please send over your updated resume. We look forward to hearing from you!
ROLE AND RESPONSIBILITIES
OneTrust GRC SME
Need hands-on experience as a OneTrust admin with several different modules. 100% onsite in Houston, zip code 70779. 12 months Contract Pay $60 to $65.
Note from the customer: We need someone who knows the OneTrust product line. Can get in quickly evaluate the issues in the environment and put an actionable plan together to resolve and get the work done. Highly qualified candidate is most important over rate right now.
Position Overview
The OneTrust GRC Systems Engineer will serve as the technical owner and system administrator for the organization’s Governance, Risk, and Compliance (GRC) platforms—primarily OneTrust. The engineer will configure, integrate, and manage the lifecycle of GRC systems to support IT General Controls (ITGC), Data Privacy, Cookie Compliance, and IT Risk Management across IT and OT environments. The ideal candidate will be able to quickly assess the current environment, identify issues, and deliver an actionable remediation plan.
Responsibilities:
Develops & Maintains:
- GRC system configurations, data models, and workflow designs supporting evolving compliance and risk processes.
- API integrations between OneTrust and systems such as identity management, ServiceNow CMDB, and ticketing platforms.
- Dashboards, reports, and analytics for real-time visibility into control health, risk posture, and remediation progress.
- Documentation of system configurations, data flows, and integration logic for audit, transparency, and change tracking.
Governance & Release Management:
- Manage intake of platform releases, review vendor release notes, assess impacts, and coordinate changes in alignment with IT change and release management practices.
Coordinates With:
- IT, cybersecurity, COE, GRC program owners, internal audit, IT operations, OT teams, and vendors for issue resolution, platform enhancements, and roadmap planning.
- Stakeholders to triage bugs, prioritize enhancements, and align GRC systems with broader governance strategies.
- End users to manage access requests, permissions, and troubleshooting.
Assesses & Monitors:
- System performance, integration reliability, and data accuracy, identifying opportunities for optimization.
- Automation and workflow effectiveness, recommending improvements.
- Enhancement/defect resolution throughput, ensuring timely execution and documentation.
- New GRC capabilities or vendor releases for alignment with business requirements and technology roadmaps.
SKILLS AND COMPETENCIES
Required:
- Hands-on experience supporting or engineering GRC platforms— OneTrust required.
- Strong experience in system configuration, user administration, data management, and workflow customization.
- API development & integration, including:
- FreeMarker (FTL) – required for OneTrust Logic
- Preferred: RESTful APIs, JavaScript for middleware/webhooks, Python or PowerShell for automation, JSON for structured data work
- Solid understanding of ITSM processes (change, release, incident, configuration), aligned with ITIL.
- Working knowledge of governance frameworks such as NIST CSF, COBIT 2019, ISO 27001, and GRC best practices.
- Strong analytical capabilities, including experience with data visualization tools (Power BI, Tableau).
- Strong documentation, troubleshooting, and cross-team communication skills.
Ability to Achieve:
- Stable, secure, high-performing GRC platforms supporting compliance, audit, and cybersecurity needs.
- Streamlined ITGC, risk, and workflow automation.
- Improved platform enhancements and data-driven insights.
- Stronger IT/OT governance maturity through scalable GRC technologies.
Risk Assessment Process Support
The engineer will support enhancement of the risk assessment process to:
- Determine inherent risk
- Assign controls
- Collect evidence or create remediation issues
- Generate residual risk scoring
- Update asset records
- Deliver real-time dashboards
Capabilities & Integration Work
ServiceNow CMDB - OneTrust Integration:
- APM record - OneTrust Inventory Asset creation/update
- Asset update triggers ITRM Risk Assessment
- Risk Assessment triggers:
- Control Templates
- Control Profiles
- Updates to Risk & Asset attributes
- Control Templates trigger:
- Implementations
- Evidence Collection
- Issues (remediation/exceptions)
- Risk scoring
- SNOW ticket creation
- Develop custom dashboards and build/maintain OneTrust integrations.
MatchPoint Solutions provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training.
How to Get Visa Sponsorship in Governance Risk And Compliance
Lead with your degree field alignment
GRC roles require a direct connection between your degree and the position. Emphasize coursework in risk management, auditing, cybersecurity, or compliance law in your resume so hiring managers and USCIS can clearly see the specialty occupation link.
Target employers with established compliance teams
Large financial institutions, healthcare systems, and technology companies maintain dedicated GRC departments and are more experienced with OPT work authorization. Smaller firms often lack the infrastructure to support international candidates through compliance-heavy hiring processes.
Pursue relevant certifications early
Certifications like CISA, CRISC, or CompTIA Security+ strengthen your GRC candidacy and signal commitment to the field. Employers in heavily regulated industries view certifications as evidence of specialized knowledge, which also reinforces your specialty occupation argument during OPT.
Focus on regulated industries for H-1B pathways
Financial services, healthcare, and government contractors sponsor more GRC professionals than most other sectors. These industries operate under mandatory compliance frameworks, making GRC roles genuinely indispensable rather than discretionary, which strengthens the business case for sponsoring your H-1B.
Frame your international background as a compliance asset
Experience navigating multiple regulatory environments, foreign data privacy laws, or cross-border transactions is genuinely valuable in GRC. Articulate how your international perspective contributes to a firm's risk management capabilities rather than treating your background as a neutral biographical fact.
Governance Risk And Compliance jobs are hiring across the US. Find yours.
Find Governance Risk And Compliance JobsSee all 19+ Governance Risk And Compliance jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Governance Risk And Compliance roles.
Get Access To All JobsFrequently Asked Questions
Do governance, risk, and compliance roles qualify as specialty occupations for OPT?
Most GRC roles qualify as specialty occupations because they typically require a bachelor's degree or higher in a specific field such as information systems, finance, accounting, or cybersecurity. Job titles like compliance analyst, risk analyst, and GRC specialist have been approved under this standard. The key is that the role must require your specific degree field, not just any bachelor's degree.
Can I use STEM OPT extension for a GRC job?
Yes, if your degree is in a STEM-designated field such as management information systems, computer science, finance, or applied mathematics, and the GRC role is substantively tied to that field. Cybersecurity GRC and technology risk roles most reliably qualify. GRC positions focused purely on legal or policy compliance may be harder to connect to a STEM degree for extension purposes.
Which industries hire the most GRC professionals willing to sponsor visas?
Financial services, healthcare, and enterprise technology are the strongest sectors for GRC hiring and visa sponsorship. Banks, insurance companies, and hospital networks operate under strict regulatory mandates that require permanent GRC staffing. Government contractors and global consulting firms are also reliable sponsors, as GRC work is core to their service delivery rather than an optional function.
How do I find GRC jobs where employers are open to OPT candidates?
Migrate Mate filters job listings specifically for employers open to sponsoring F-1 OPT students, which removes the guesswork of applying to roles where your authorization status will disqualify you. Searching by GRC-related job titles on Migrate Mate surfaces positions from employers already familiar with OPT work authorization requirements.
What should I include on my resume to show I qualify for a GRC specialty occupation?
List your degree field prominently and connect it directly to GRC functions. Include relevant coursework such as audit methodology, risk frameworks, data privacy regulations, or financial controls. Certifications, internship experience involving compliance tools like GRC platforms, and any work involving regulatory reporting all reinforce that your role requires specialized academic preparation rather than general business knowledge.
See which Governance Risk And Compliance employers are hiring and sponsoring visas right now.
Search Governance Risk And Compliance Jobs