OPT Grc Analyst Jobs
GRC Analyst roles sit at the intersection of governance, risk, and compliance, making them a strong fit for OPT students with backgrounds in information systems, cybersecurity, or business. Most positions qualify as STEM OPT extensions. Cap-exempt employers in finance, healthcare, and tech actively hire for this role year-round.
Find OPT Grc Analyst JobsOverview
Showing 5 of 12+ Grc Analyst jobs










See all Grc Analyst Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Grc Analyst roles.
Get Access To All Jobs
Number of Positions In Requisition
1
Job Details
Contributes to the effective management of information security and resilience risks through domain expertise in areas such as regulatory compliance, risk management, security data engineering, or organizational resilience. This position applies information security policies and best practices, performs risk assessments, and ensures alignment with regulatory requirements. Uses data driven decision making to protect assets by identifying vulnerabilities, measuring risks, improving resilience, and promoting compliance through security awareness.
Job Description
Summary
Contributes to the effective management of information security and resilience risks through domain expertise in areas such as regulatory compliance, risk management, security data engineering, or organizational resilience. This position applies information security policies and best practices, performs risk assessments, and ensures alignment with regulatory requirements. Uses data driven decision making to protect assets by identifying vulnerabilities, measuring risks, improving resilience, and promoting compliance through security awareness.
Job Duties
- Contribute to the implementation of an integrated Governance, Risk, and Compliance (GRC) program and tools to support GRC workflows, which align with organizational objectives and regulatory requirements.
- Apply established enterprise-wide information security policies, standards, and procedures to support robust information security and operational resilience, including processes to manage exceptions to policies and standards.
- Perform risk assessments, including business impact assessments, third party risk assessments, and assessments of cloud systems. Synthesize data to inform the team on security posture, resilience gaps, and emerging threats.
- Contribute to the prioritization and deployment of risk mitigation strategies using risk quantification methodologies, ensuring a coordinated response across business units and with external partners.
- Advance the culture of compliance and resilience by assisting with enterprise-level information security awareness and business resilience training campaigns and tabletop exercises.
- Collaborate with team members to share information, interpret requirements, and resolve issues related to governance, risk and compliance.
- Contribute to the development of key performance indicators and risk quantification to measure and communicate risk trends, compliance metrics, and strategic security objectives within the GRC team.
Minimum Qualifications
- Bachelor’s Degree in a science, technology, engineering, or math discipline or High School Diploma/GED and preferred certifications.
- 3 years related work experience
Physical Demands
Lift and carry 25 lbs. frequent sitting/standing, frequent keyboard use, patient care providers may be required to perform activities specific to their role including kneeling, bending, squatting and performing CPR.
Job Description Disclaimer: This position description provides the major duties/responsibilities, requirements and working conditions for the position. It is intended to be an accurate reflection of the current position, however management reserves the right to revise or change as necessary to meet organizational needs. Other responsibilities may be assigned when circumstances require.
Work Shift
Workday Day (United States of America)
Worker Sub Type
Regular
Employee Entity
Thomas Jefferson University
Primary Location Address
1100 Virginia Drive, Fort Washington, Pennsylvania, United States of America
Nationally ranked, Jefferson, which is principally located in the greater Philadelphia region, Lehigh Valley and Northeastern Pennsylvania and southern New Jersey, is reimagining health care and higher education to create unparalleled value. Jefferson is more than 65,000 people strong, dedicated to providing the highest-quality, compassionate clinical care for patients; making our communities healthier and stronger; preparing tomorrow's professional leaders for 21st-century careers; and creating new knowledge through basic/programmatic, clinical and applied research. Thomas Jefferson University, home of Sidney Kimmel Medical College, Jefferson College of Nursing, and the Kanbar College of Design, Engineering and Commerce, dates back to 1824 and today comprises 10 colleges and three schools offering 200+ undergraduate and graduate programs to more than 8,300 students. Jefferson Health, nationally ranked as one of the top 15 not-for-profit health care systems in the country and the largest provider in the Philadelphia and Lehigh Valley areas, serves patients through millions of encounters each year at 32 hospitals campuses and more than 700 outpatient and urgent care locations throughout the region. Jefferson Health Plans is a not-for-profit managed health care organization providing a broad range of health coverage options in Pennsylvania and New Jersey for more than 35 years.
Jefferson is committed to providing equal educational and employment opportunities for all persons without regard to age, race, color, religion, creed, sexual orientation, gender, gender identity, marital status, pregnancy, national origin, ancestry, citizenship, military status, veteran status, handicap or disability or any other protected group or status.
Benefits
Jefferson offers a comprehensive package of benefits for full-time and part-time colleagues, including medical (including prescription), supplemental insurance, dental, vision, life and AD&D insurance, short- and long-term disability, flexible spending accounts, retirement plans, tuition assistance, as well as voluntary benefits, which provide colleagues with access to group rates on insurance and discounts. Colleagues have access to tuition discounts at Thomas Jefferson University after one year of full time service or two years of part time service. All colleagues, including those who work less than part-time (including per diem colleagues, adjunct faculty, and Jeff Temps), have access to medical (including prescription) insurance.
See all OPT Grc Analyst Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new OPT Grc Analyst Jobs.
Get Access To All JobsTips for Finding OPT Sponsorship as a Grc Analyst
Lead with your STEM OPT eligibility
GRC Analyst roles frequently qualify for the 24-month STEM OPT extension. Confirm your degree field qualifies early, then communicate your three-year work authorization window clearly in your cover letter and recruiter conversations.
Target cap-exempt and H-1B-friendly employers
Universities, nonprofits, and large financial institutions often sponsor visas and are familiar with OPT. Prioritize companies with a track record of H-1B visa filings in compliance and risk functions, since GRC roles translate directly to that pathway.
Get certified before you apply
CompTIA Security+, CISA, or a GRC-specific certification like GRCP signals genuine commitment to the field. Certifications offset limited U.S. work history and strengthen your candidacy at employers evaluating OPT candidates against domestic applicants.
Highlight hands-on framework experience
Employers hire GRC Analysts to implement NIST, ISO 27001, or SOC 2. If your coursework or internships touched any of these frameworks, name them explicitly in your resume rather than describing them in general compliance terms.
Clarify your OPT timeline upfront with recruiters
Asking about sponsorship after an offer wastes everyone's time. Mention your OPT status and current authorization end date in early recruiter conversations so both sides can assess fit before investing in the full interview process.
Build experience through contract or consulting roles
Short-term GRC consulting engagements count as valid OPT employment if structured correctly. They build your U.S. resume, expose you to real compliance environments, and can lead to full-time offers at companies that value proven contributors.
Grc Analyst OPT: Frequently Asked Questions
Do GRC Analyst jobs qualify for the STEM OPT extension?
Most GRC Analyst positions qualify for the 24-month STEM OPT extension if your degree is in a STEM-designated field such as information systems, cybersecurity, or computer science. The job itself must also involve work directly related to your degree. Confirm your degree's CIP code with your DSO before assuming eligibility, as business degrees without a technology focus may not qualify.
How do I find GRC Analyst employers who are comfortable hiring OPT students?
Migrate Mate is built specifically for this search. It filters GRC Analyst openings by OPT-friendliness and visa sponsorship history, so you're not wasting applications on employers who won't hire international students. Financial services firms, healthcare systems, and government contractors tend to have established compliance teams and familiarity with OPT and H-1B processes.
Can I work as a GRC Analyst for a consulting firm on OPT?
Yes. Consulting firms are common employers of GRC Analysts and are generally experienced with OPT work authorization. The key requirement is that you have a formal employment relationship with the firm, not just a client-facing engagement. Self-employment or independent contracting without a sponsoring employer entity is not permitted under OPT regulations.
What GRC skills are employers prioritizing for entry-level OPT candidates?
Employers consistently look for familiarity with frameworks like NIST CSF, ISO 27001, and SOC 2, along with experience in risk assessment documentation and policy writing. GRC platform knowledge such as Archer, ServiceNow GRC, or OneTrust is increasingly valued. For OPT candidates, pairing these technical skills with a relevant certification like CISA or CompTIA Security+ meaningfully strengthens your profile.
What happens to my OPT if I lose my GRC Analyst job?
You have a 90-day unemployment buffer across your entire OPT period, reduced to 60 days if you have a STEM extension. If you lose your position, you must report the change to your DSO within 10 days. Actively searching for a new GRC role during this period is permitted, but exceeding the unemployment limit terminates your OPT status regardless of remaining authorized time.