Grc Analyst Jobs in USA with Visa Sponsorship
GRC Analyst roles qualify for H-1B visa and O-1 visa sponsorship as specialty occupations requiring a bachelor's degree in information systems, cybersecurity, or a related field. Employers in financial services, healthcare, and tech actively sponsor, particularly for candidates with frameworks like SOC 2, ISO 27001, or NIST experience. For detailed occupation requirements, see the O*NET profile.
See All Grc Analyst JobsOverview
Showing 5 of 31+ Grc Analyst jobs


Have you applied for this role?


Have you applied for this role?


Have you applied for this role?


Have you applied for this role?


Have you applied for this role?
See all 31+ Grc Analyst jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Grc Analyst roles.
Get Access To All Jobs
Date: May 4, 2026
Location: Greenville, SC, US, 29601
Company: Purpose Financial
Brand: Purpose Financial
Address: 322 Rhett Street, Greenville, South Carolina, United States - 29601
Purpose Financial, Inc. is an innovative consumer financial services company that offers a diverse suite of credit products, promoting financial inclusion and meeting consumers wherever they are. Through its brands, the company is committed to helping customers achieve their version of financial stability in the moment and in the future. Since 1997, Purpose Financial has been a pioneer in the consumer credit and financial services market offering money solutions in over 800 storefronts locations and online lending. Providing services in over 23 states, Purpose Financial employs over 2,500 team members.
At Purpose Financial we are always on the lookout for motivated individuals who share in our values of mutual respect to join our team of outstanding professionals.
We offer:
- Competitive Wages
- Health/Life Benefits
- Health Savings Account plus Employer Seed
- 401(k) Savings Plan with Company Match
- Paid Parental Leave
- Company Paid Holidays
- Paid Time Off including Volunteer Time
- Tuition Reimbursement
- Business Casual Environment
- Rewards & Recognition Program
- Employee Assistance Program
- Office in downtown Greenville that offers free parking, onsite gym, free snacks/drinks
Position Summary
Design, implement, audit, and maintain governance, risk management, and compliance (GRC) controls for Purpose Financial's information security program. This role is the operational backbone of our compliance posture owing to SOC 2 Type II readiness and certification, driving ISO 27001 certification and ongoing ISMS maintenance, and supporting the broader Information Security Program across NIST CSF, NIST SP 800-53/800-171, CIS Controls, and PCI DSS. The ideal candidate brings an organized, project-managed approach to policy, risk, third-party oversight, audit readiness, and continuous compliance. Partnering closely with IT, SecOps, Legal, Internal Audit, and business stakeholders to protect the information assets owned by or entrusted to the Company.
Job Responsibility
- Governance & Policy - Maintain and evolve the Company's information security policies, standards, and controls mapped to SOC 2, ISO 27001, NIST, and CIS frameworks; manage the policy exception process with documented justification and approval.
- Risk Management - Conduct risk assessments, maintain the risk register, and support risk acceptance decisions with structured evidence; escalate material risks to leadership with mitigation plans.
- Compliance & Audit Readiness - Own end-to-end audit preparation for SOC 2 Type II and ISO 27001 certification, including control testing, evidence collection, gap remediation, and findings tracking. Maintain the Company's ISMS, conduct Statement of Applicability (SoA) reviews, support internal audits and management reviews, and serve as the primary liaison with external certification bodies throughout the certification and surveillance audit lifecycle.
- Control Implementation & Monitoring - Partner with IT and SecOps to operationalize controls across access management, encryption, logging, vulnerability management, and backup/DR; define evidence sources and test cadence.
- Continuous Monitoring - Leverage GRC platform automated monitoring capabilities to maintain real-time visibility into control health; triage failing controls, coordinating remediation with owners, and ensure evidence remains audit-ready throughout the observation period.
- Evidence Collection & Management - Maintain a structured evidence repository (e.g., SharePoint, GRC platform) to support SOC 2 Type II and ISO 27001 audit cycles; coordinate evidence requests from external auditors, establish and enforce evidence collection cadences (monthly, quarterly, and annual), and ensure completeness and integrity of the evidence package throughout the audit observation period.
- Third-Party Risk Management (TPRM) - Manage the third-party risk management program including vendor risk assessments, security questionnaires (SIG/CAIQ), contract review support, and ongoing monitoring of critical vendors to ensure alignment with the Company's security and compliance requirements.
- Change Management & Control Lifecycle - Manage the full control lifecycle including new control design, change management, deprecation, and exception handling; ensure all control changes are documented, reviewed, and aligned with SOC 2 Type II and ISO 27001 audit requirements.
- Stakeholder Communications & Training - Develop and deliver control owner training, security awareness materials, and compliance guidance to drive adoption of security controls across business units; serve as a trusted advisor to cross-functional teams on GRC-related obligations and best practices.
- Metrics & Reporting - Produce dashboards and status reports on risk posture, control health, and audit readiness for both technical teams and executive/Board-level stakeholders.
- Operational Support - Support incident response, BCP/DR planning, and privacy obligations; publish practical guidance and job aids to drive control adoption across the organization.
Education Required
Bachelor’s degree in Information Security or equivalent experience.
Experience Required
- 3–5+ years of experience in information security GRC, compliance, or audit roles.
- Hands-on experience with SOC 2 Type II audits (as auditee, control owner, or auditor).
- Working knowledge of SOC 2, ISO 27001, NIST CSF, NIST SP 800-53, and CIS Controls.
- Experience maintaining risk registers, conducting risk assessments, and managing remediation tracking.
- Strong written communication skills - ability to produce clear policy documents, audit evidence packages, and executive-level reports.
- Demonstrated ability to manage multiple workstreams with a project-managed approach.
- Experience with GRC platforms.
Knowledge Required
Excellent written and verbal communications skills; adaptability and flexibility to changing environment; and comfortable working in a dynamic, high volume, fast-paced environment. Ability to understand and ensure compliance with policies, procedures, and laws governing our industry/business and products.
Preferred Qualifications:
- Experience in financial services, fintech, or consumer lending environments.
- Familiarity with PCI DSS requirements and control environments.
- Certifications: CISA, CRISC, CISSP, ISO 27001 Lead Auditor/Implementer, or equivalent.
- Exposure to privacy frameworks (GLBA, CCPA, state-level financial privacy regulations).
- Ability to work collaboratively with cross-functional teams and influence stakeholders.
Physical Requirements
Sitting for long periods of time; standing occasionally; walking; bending; squatting; kneeling; pushing/pulling; reaching; twisting; frequent lifting of less than 10 lbs., occasional lifting of up to 20 lbs.; driving and having access during the workday to an insured and reliable transportation; typing; data entry; grasping; transferring items between hands and/or to another person or receptacle; use of office equipment to include computers; ability to travel to, be physically present at, and complete the physical requirements of the position at any assigned location.
Competencies
OKR
Travel
0-10%
Attire
Business Casual
Other
Must be eligible to work in the USA and able to pass a background check
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or disability.
Requisition ID: 46232
Nearest Major Market: Greenville
Nearest Secondary Market: South Carolina
See all 31+ Grc Analyst jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Grc Analyst roles.
Get Access To All JobsTips for Finding Visa Sponsorship as a Grc Analyst
Lead with your compliance framework expertise
Certifications like CISA, CRISC, or CISSP signal to employers that you meet specialty occupation standards USCIS expects. List every framework you've worked with, SOC 2, ISO 27001, NIST CSF, prominently on your resume.
Target regulated industries first
Financial services, healthcare, and government contractors have dedicated compliance teams and established sponsorship processes. These employers file H-1B petitions regularly and are far less likely to hesitate over the paperwork than a smaller startup.
Document the degree-to-role connection clearly
USCIS requires GRC roles to demonstrate a direct relationship between your degree field and the job duties. A degree in information systems, computer science, or cybersecurity is the strongest fit, be explicit about this connection in applications.
Negotiate sponsorship terms before accepting an offer
Confirm whether the employer covers H-1B filing fees, premium processing, and legal costs upfront. Some companies treat these as employee expenses, knowing the terms before you sign avoids an expensive surprise during the petition process.
Highlight your audit and risk quantification experience
Employers and immigration attorneys both need to demonstrate the role requires specialized knowledge. GRC candidates who can show they've led audits, written risk assessments, or managed vendor compliance programs make the specialty occupation case much stronger.
Apply early relative to the H-1B cap cycle
If you need cap-subject H-1B sponsorship, employers must register in March for an October start date. Securing a role offer by January gives your employer time to prepare the petition, run premium processing, and respond to any RFEs before the deadline.
Grc Analyst jobs are hiring across the US. Find yours.
Find Grc Analyst JobsFrequently Asked Questions
Does a GRC Analyst role qualify for H-1B visa sponsorship?
Yes, GRC Analyst positions generally qualify as H-1B specialty occupations because they require at minimum a bachelor's degree in a specific field such as information systems, cybersecurity, computer science, or a related discipline. USCIS evaluates whether the role's duties, risk assessment, compliance program management, audit oversight, require that specialized degree. Employers with established GRC functions in regulated industries have successfully sponsored this role consistently.
What degree do I need for an employer to sponsor my GRC Analyst visa?
A bachelor's degree in information systems, cybersecurity, computer science, or business information management is the most defensible match for GRC roles. Degrees in general business or management are riskier and can prompt a Request for Evidence from USCIS questioning the specialty occupation standard. If your degree is adjacent, pairing it with certifications like CISA or CRISC and documented GRC work experience strengthens the petition considerably.
Are there visa options besides H-1B for GRC Analysts seeking sponsorship?
Yes. Australian citizens can pursue the E-3 visa, which has no lottery and a much faster path. Canadians and Mexicans may qualify under the TN visa category, though GRC roles require careful matching to the approved TN occupation list. Candidates with exceptional achievements, published research, speaking engagements, industry awards, may also qualify for the O-1A. Browse GRC roles on Migrate Mate to filter by employers who sponsor specific visa types.
How likely is an H-1B petition for a GRC Analyst to be approved?
USCIS approval rates for information security and compliance roles are generally strong when the degree field aligns with the job duties. The most common reason for a Request for Evidence is a weak nexus between the applicant's degree and the GRC role's specific requirements. Employers with experienced immigration counsel and well-documented job descriptions see significantly fewer RFEs. The lottery remains the main uncertainty, selection is random, and approximately 25% of registrations were selected in recent fiscal years.
What should I look for in a GRC Analyst job listing to assess sponsorship likelihood?
Look for listings that specify a required degree in a technical or compliance-related field rather than 'any bachelor's degree,' as that distinction matters for the specialty occupation determination. Employers in financial services, healthcare, and federal contracting are more accustomed to the sponsorship process. Job postings that mention NIST, ISO 27001, or SOC 2 by name suggest a specialized compliance function, which supports a stronger H-1B petition. Migrate Mate surfaces GRC roles from employers with verified sponsorship history.
What is the prevailing wage requirement for sponsored Grc Analyst jobs?
U.S. employers sponsoring a visa must pay at least the prevailing wage, which is what workers in the same role, area, and experience level typically earn. The Department of Labor sets this rate to make sure companies aren't hiring foreign workers simply because they'd accept lower pay than a U.S. worker. It varies by job title, location, and experience. You can look up current prevailing wage rates for any occupation and location using the OFLC Wage Search page.
See which Grc Analyst employers are hiring and sponsoring visas right now.
Search Grc Analyst Jobs