Grc Analyst Jobs for OPT Students
GRC Analyst roles sit at the intersection of governance, risk, and compliance, making them a strong fit for OPT students with backgrounds in information systems, cybersecurity, or business. Most positions qualify as STEM OPT extensions. Cap-exempt employers in finance, healthcare, and tech actively hire for this role year-round.
See All Grc Analyst JobsOverview
Showing 5 of 14+ Grc Analyst jobs


Have you applied for this role?


Have you applied for this role?


Have you applied for this role?


Have you applied for this role?


Have you applied for this role?
See all 14+ Grc Analyst jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Grc Analyst roles.
Get Access To All Jobs
ABOUT VERCEL: Vercel gives developers the tools and cloud infrastructure to build, scale, and secure a faster, more personalized web. As the team behind v0, Next.js, and AI SDK, Vercel helps customers like Ramp, Supreme, PayPal, and Under Armour build for the AI-native web. Our mission is to enable the world to ship the best products. That starts with creating a place where everyone can do their best work. Whether you're building on our platform, supporting our customers, or shaping our story: You can just ship things.
ABOUT THE ROLE: We are looking for a Staff GRC Analyst to join our Governance, Risk, and Compliance (GRC) team. You will have the opportunity to enhance our global compliance posture and further our commitment to managing enterprise risk. Your role will be instrumental in ensuring that our company operates in accordance with security requirements and embodies an environment where it’s everyone’s responsibility. This role will help shape the next iteration of the GRC program and further embed compliance requirements into the business. Think you may not have all the skills and are hesitant to apply? There is no “perfect” candidate and encourage you to apply if you think that you can bring value to our team and are passionate and committed to upholding the highest standards of compliance and ethics. If you’re based within a pre-determined commuting distance of one of our offices (SF, NY, London, or Berlin), the role includes in-office anchor days on Monday, Tuesday, and Friday, even if the role is listed as remote. For location-specific details, please connect with our recruiting team.
GETTING STARTED:
* We want you to feel like part of the team early on! Our team will help integrate you into the company with explanations on our product, policies, processes, team structure and roadmap.
* We’re excited for you to learn, grow, and contribute right away! We trust that you’ll bring experience and knowledge that will uplift and up-level the team, but we don’t expect you to know everything on Day 1.
WHAT YOU WILL DO:
* Own and scale commercial attestation program and audits (i.e., SOC 2, ISO 27001, PCI DSS, etc.) while maintaining alignment with business objectives and market demand.
* Design and strengthen continuous monitoring processes to improve control effectiveness and mature control implementation from audit-ready to always-ready.
* Drive evolution of security and compliance control frameworks that set the direction for proactive risk management.
* Partner with cross-functional stakeholders, acting as a strategic connector to plan, implement, maintain & remediate control activities and supporting requirements (e.g. policies, standards, processes, system configurations, etc.)
* Champion a culture of compliance accountability and business-enablement across the organization through autonomous program governance and reporting and building trusted relationships.
ABOUT YOU:
* Experience managing and running audits, certification programs and enterprise control assessments, including scope planning, defining requirements, policy and standards development, and control testing.
* Deep knowledge of audit processes, evidence requirements, and remediation lifecycle management for security and compliance frameworks (i.e., SOC 2, ISO 27001, PCI DSS).
* Proven experience owning large-scale GRC programs, collaborating with technical and non-technical teams and driving initiatives to completion.
BONUS IF YOU:
* Familiarity with data governance, compliance or software development tools and systems (e.g., Drata, Linear, Github, etc.)
* Experience supporting cloud, AI-native, and open source development environments and systems.
* Experience with FedRAMP or NIST frameworks, such as 800-53, AI RMF.
* Security certifications (e.g. CISA, CISSP).
BENEFITS:
* Competitive compensation package, including equity.
* Inclusive Healthcare Package.
* Learn and Grow - we provide mentorship and send you to events that help you build your network and skills.
* Flexible Time Off.
* We will provide you the gear you need to do your role, and a WFH budget for you to outfit your space as needed.
COMPENSATION:
- The San Francisco, CA base pay range for this role is $180,000.00 - $270,000.00. Actual salary will be based on job-related skills, experience, and location. Compensation outside of San Francisco may be adjusted based on employee location. The total compensation package may include benefits, equity-based compensation, and eligibility for a company bonus or variable pay program depending on the role. Your recruiter can share more details during the hiring process.
Vercel is committed to fostering and empowering an inclusive community within our organization. We do not discriminate on the basis of race, religion, color, gender expression or identity, sexual orientation, national origin, citizenship, age, marital status, veteran status, disability status, or any other characteristic protected by law. Vercel encourages everyone to apply for our available positions, even if they don't necessarily check every box on the job description.

ABOUT VERCEL: Vercel gives developers the tools and cloud infrastructure to build, scale, and secure a faster, more personalized web. As the team behind v0, Next.js, and AI SDK, Vercel helps customers like Ramp, Supreme, PayPal, and Under Armour build for the AI-native web. Our mission is to enable the world to ship the best products. That starts with creating a place where everyone can do their best work. Whether you're building on our platform, supporting our customers, or shaping our story: You can just ship things.
ABOUT THE ROLE: We are looking for a Staff GRC Analyst to join our Governance, Risk, and Compliance (GRC) team. You will have the opportunity to enhance our global compliance posture and further our commitment to managing enterprise risk. Your role will be instrumental in ensuring that our company operates in accordance with security requirements and embodies an environment where it’s everyone’s responsibility. This role will help shape the next iteration of the GRC program and further embed compliance requirements into the business. Think you may not have all the skills and are hesitant to apply? There is no “perfect” candidate and encourage you to apply if you think that you can bring value to our team and are passionate and committed to upholding the highest standards of compliance and ethics. If you’re based within a pre-determined commuting distance of one of our offices (SF, NY, London, or Berlin), the role includes in-office anchor days on Monday, Tuesday, and Friday, even if the role is listed as remote. For location-specific details, please connect with our recruiting team.
GETTING STARTED:
* We want you to feel like part of the team early on! Our team will help integrate you into the company with explanations on our product, policies, processes, team structure and roadmap.
* We’re excited for you to learn, grow, and contribute right away! We trust that you’ll bring experience and knowledge that will uplift and up-level the team, but we don’t expect you to know everything on Day 1.
WHAT YOU WILL DO:
* Own and scale commercial attestation program and audits (i.e., SOC 2, ISO 27001, PCI DSS, etc.) while maintaining alignment with business objectives and market demand.
* Design and strengthen continuous monitoring processes to improve control effectiveness and mature control implementation from audit-ready to always-ready.
* Drive evolution of security and compliance control frameworks that set the direction for proactive risk management.
* Partner with cross-functional stakeholders, acting as a strategic connector to plan, implement, maintain & remediate control activities and supporting requirements (e.g. policies, standards, processes, system configurations, etc.)
* Champion a culture of compliance accountability and business-enablement across the organization through autonomous program governance and reporting and building trusted relationships.
ABOUT YOU:
* Experience managing and running audits, certification programs and enterprise control assessments, including scope planning, defining requirements, policy and standards development, and control testing.
* Deep knowledge of audit processes, evidence requirements, and remediation lifecycle management for security and compliance frameworks (i.e., SOC 2, ISO 27001, PCI DSS).
* Proven experience owning large-scale GRC programs, collaborating with technical and non-technical teams and driving initiatives to completion.
BONUS IF YOU:
* Familiarity with data governance, compliance or software development tools and systems (e.g., Drata, Linear, Github, etc.)
* Experience supporting cloud, AI-native, and open source development environments and systems.
* Experience with FedRAMP or NIST frameworks, such as 800-53, AI RMF.
* Security certifications (e.g. CISA, CISSP).
BENEFITS:
* Competitive compensation package, including equity.
* Inclusive Healthcare Package.
* Learn and Grow - we provide mentorship and send you to events that help you build your network and skills.
* Flexible Time Off.
* We will provide you the gear you need to do your role, and a WFH budget for you to outfit your space as needed.
COMPENSATION:
- The San Francisco, CA base pay range for this role is $180,000.00 - $270,000.00. Actual salary will be based on job-related skills, experience, and location. Compensation outside of San Francisco may be adjusted based on employee location. The total compensation package may include benefits, equity-based compensation, and eligibility for a company bonus or variable pay program depending on the role. Your recruiter can share more details during the hiring process.
Vercel is committed to fostering and empowering an inclusive community within our organization. We do not discriminate on the basis of race, religion, color, gender expression or identity, sexual orientation, national origin, citizenship, age, marital status, veteran status, disability status, or any other characteristic protected by law. Vercel encourages everyone to apply for our available positions, even if they don't necessarily check every box on the job description.
How to Get Visa Sponsorship as a Grc Analyst
Lead with your STEM OPT eligibility
GRC Analyst roles frequently qualify for the 24-month STEM OPT extension. Confirm your degree field qualifies early, then communicate your three-year work authorization window clearly in your cover letter and recruiter conversations.
Get certified before you apply
CompTIA Security+, CISA, or a GRC-specific certification like GRCP signals genuine commitment to the field. Certifications offset limited U.S. work history and strengthen your candidacy at employers evaluating OPT candidates against domestic applicants.
Highlight hands-on framework experience
Employers hire GRC Analysts to implement NIST, ISO 27001, or SOC 2. If your coursework or internships touched any of these frameworks, name them explicitly in your resume rather than describing them in general compliance terms.
Clarify your OPT timeline upfront with recruiters
Asking about sponsorship after an offer wastes everyone's time. Mention your OPT status and current authorization end date in early recruiter conversations so both sides can assess fit before investing in the full interview process.
Build experience through contract or consulting roles
Short-term GRC consulting engagements count as valid OPT employment if structured correctly. They build your U.S. resume, expose you to real compliance environments, and can lead to full-time offers at companies that value proven contributors.
Grc Analyst jobs are hiring across the US. Find yours.
Find Grc Analyst JobsSee all 14+ Grc Analyst jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Grc Analyst roles.
Get Access To All JobsFrequently Asked Questions
Do GRC Analyst jobs qualify for the STEM OPT extension?
Most GRC Analyst positions qualify for the 24-month STEM OPT extension if your degree is in a STEM-designated field such as information systems, cybersecurity, or computer science. The job itself must also involve work directly related to your degree. Confirm your degree's CIP code with your DSO before assuming eligibility, as business degrees without a technology focus may not qualify.
How do I find GRC Analyst employers who are comfortable hiring OPT students?
Migrate Mate is built specifically for this search. It filters GRC Analyst openings by OPT-friendliness and visa sponsorship history, so you're not wasting applications on employers who won't hire international students. Financial services firms, healthcare systems, and government contractors tend to have established compliance teams and familiarity with OPT and H-1B processes.
Can I work as a GRC Analyst for a consulting firm on OPT?
Yes. Consulting firms are common employers of GRC Analysts and are generally experienced with OPT work authorization. The key requirement is that you have a formal employment relationship with the firm, not just a client-facing engagement. Self-employment or independent contracting without a sponsoring employer entity is not permitted under OPT regulations.
What GRC skills are employers prioritizing for entry-level OPT candidates?
Employers consistently look for familiarity with frameworks like NIST CSF, ISO 27001, and SOC 2, along with experience in risk assessment documentation and policy writing. GRC platform knowledge such as Archer, ServiceNow GRC, or OneTrust is increasingly valued. For OPT candidates, pairing these technical skills with a relevant certification like CISA or CompTIA Security+ meaningfully strengthens your profile.
What happens to my OPT if I lose my GRC Analyst job?
You have a 90-day unemployment buffer across your entire OPT period, reduced to 60 days if you have a STEM extension. If you lose your position, you must report the change to your DSO within 10 days. Actively searching for a new GRC role during this period is permitted, but exceeding the unemployment limit terminates your OPT status regardless of remaining authorized time.
See which Grc Analyst employers are hiring and sponsoring visas right now.
Search Grc Analyst Jobs