Grc Analyst Jobs in USA with Visa Sponsorship
GRC Analyst roles qualify for H-1B and O-1 visa sponsorship as specialty occupations requiring a bachelor's degree in information systems, cybersecurity, or a related field. Employers in financial services, healthcare, and tech actively sponsor, particularly for candidates with frameworks like SOC 2, ISO 27001, or NIST experience. For detailed occupation requirements, see the O*NET profile.
See All Grc Analyst JobsOverview
Showing 5 of 38+ Grc Analyst jobs


Have you applied for this role?


Have you applied for this role?


Have you applied for this role?


Have you applied for this role?


Have you applied for this role?
See all 38+ Grc Analyst jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Grc Analyst roles.
Get Access To All Jobs
Welcome to the Agentic Commerce Era
At Commerce, our mission is to empower businesses to innovate, grow, and thrive with our open, AI-driven commerce ecosystem. As the parent company of BigCommerce, Feedonomics, and Makeswift, we connect the tools and systems that power growth, enabling businesses to unlock the full potential of their data, deliver seamless and personalized experiences across every channel, and adapt swiftly to an ever-changing market. Simply said, we help businesses confidently solve complex commerce challenges so they can build smarter, adapt faster, and grow on their own terms. If you want to be part of a team of bold builders, sharp thinkers, and technical trailblazers, working together to shape the future of commerce, this is the place for you.
As a Senior Security GRC Analyst and Internal Security Assessor (ISA), you will serve as the primary Subject Matter Expert (SME) for our global PCI DSS program at Commerce. We operate a highly mature PCI DSS 4.0 environment; your mission is to lead the continuous evolution of this program, ensuring that compliance is integrated into our "business as usual" (BAU) operations.
While your primary focus is PCI, you will be a key player in our broader GRC function, supporting our SOC2 and ISO 27001 certifications. You will act as the technical bridge between our Engineering, Infrastructure, and IT teams and external auditors, ensuring that our high-security standards are documented, validated, and maintained.
What You'll Do:
PCI SME & Internal Security Assessor (ISA)
- ISA Leadership: Serve as the officially designated PCI ISA for the organization. Manage the annual assessment lifecycle, including scoping, evidence collection, and validation of controls.
- PCI 4.0 Evolution: Direct the ongoing maintenance of our PCI 4.0 program, with a specific focus on managing Targeted Risk Analyses (TRAs) and the customized approach where applicable.
- Scoping & Segmentation: Partner with Cloud Engineering to validate PCI scope across our global footprint, ensuring effective network segmentation and data flow isolation.
- QSA Liaison: Act as the primary point of contact for our external QSA, defending our control environment and streamlining the audit process to minimize disruption to technical teams.
- Continuous Compliance: Operationalize PCI requirements (e.g., quarterly scans, penetration test remediation) into automated workflows.
Multi-Framework Audit Management
- Unified Control Framework: Support the broader GRC team in managing our SOC2 Type 2, ISO 27001, and other regulatory audits.
- Technical Advisory: Provide GRC perspective on architectural designs, product launches, and infrastructure changes to ensure "compliance by design."
- Remediation Management: Track and drive the remediation of audit findings and security gaps, working closely with asset owners to find pragmatic, secure solutions.
Who You Are:
- Experience: 6+ years in an Information Security or IT Audit role, with at least 3 years of deep focus on PCI DSS within a major cloud-native environment.
- Certification: Active PCI ISA (Internal Security Assessor) or PCI QSA certification is mandatory.
- Regulatory Expertise: Thorough understanding of PCI DSS 4.0 requirements and the practical application of the standard in modern environments.
- Audit Fluency: Proven experience leading Level 1 Service Provider assessments.
- Communication: Ability to explain complex compliance requirements to developers and business leaders in a way that emphasizes enablement rather than "blockage."
Preferred Qualifications
- Broad Framework Knowledge: Experience with SOC2 and ISO 27001:2022.
- Cloud Security: Experience with GRC automation and familiarity with modern cloud-native security and observability tools.
- Automation Mindset: Experience using GRC platforms and a desire to automate manual evidence collection to reduce audit fatigue.
About You
- You understand the "Why": You don't just "do compliance"; you understand the security intent behind every control and can help teams meet the requirement in a way that actually improves our security posture.
- Technical Curiosity: You are comfortable diving into technical configurations (IAM policies, VPC flow logs, etc.) to verify control effectiveness yourself.
- Adaptable: You enjoy the challenge of a high-paced environment where scale and security must coexist and evolve together.
LI-KE1
LIHYBRID
(Pay Transparency Range: $88,951.00 - $150,432.00)**
The exact salary will be dependent on the successful candidate’s location, relevant knowledge, skills, and qualifications.
Inclusion and Belonging
At Commerce, we believe that celebrating the unique histories, perspectives and abilities of every employee makes a difference for our company, our customers and our community. We are an equal opportunity employer and the inclusive atmosphere we build together will make room for every person to contribute, grow and thrive.
We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the interview process, to perform essential job functions and to receive other benefits and privileges of employment. If you need an accommodation in order to interview at Commerce, please let us know during any of your interactions with our recruiting team.
Protect Yourself Against Hiring Scams: Our Corporate Disclaimer
Commerce, along with many other employers, has become the subject of fraudulent job offers to hopeful prospective job seekers.
Be advised:
Commerce does not offer jobs to individuals who do not go through our formal hiring process.
Commerce will never:
- require payment of recruitment fees from candidates;
- request personally identifiable information through unsanctioned websites or applications;
- attempt to solicit money from you as part of the hiring process or as part of an employment offer;
- solicit money to complete visa requirements as part of a job offer.
If you receive unsolicited offers of employment from Commerce, we urge you to be extremely cautious and avoid engaging or responding.

Welcome to the Agentic Commerce Era
At Commerce, our mission is to empower businesses to innovate, grow, and thrive with our open, AI-driven commerce ecosystem. As the parent company of BigCommerce, Feedonomics, and Makeswift, we connect the tools and systems that power growth, enabling businesses to unlock the full potential of their data, deliver seamless and personalized experiences across every channel, and adapt swiftly to an ever-changing market. Simply said, we help businesses confidently solve complex commerce challenges so they can build smarter, adapt faster, and grow on their own terms. If you want to be part of a team of bold builders, sharp thinkers, and technical trailblazers, working together to shape the future of commerce, this is the place for you.
As a Senior Security GRC Analyst and Internal Security Assessor (ISA), you will serve as the primary Subject Matter Expert (SME) for our global PCI DSS program at Commerce. We operate a highly mature PCI DSS 4.0 environment; your mission is to lead the continuous evolution of this program, ensuring that compliance is integrated into our "business as usual" (BAU) operations.
While your primary focus is PCI, you will be a key player in our broader GRC function, supporting our SOC2 and ISO 27001 certifications. You will act as the technical bridge between our Engineering, Infrastructure, and IT teams and external auditors, ensuring that our high-security standards are documented, validated, and maintained.
What You'll Do:
PCI SME & Internal Security Assessor (ISA)
- ISA Leadership: Serve as the officially designated PCI ISA for the organization. Manage the annual assessment lifecycle, including scoping, evidence collection, and validation of controls.
- PCI 4.0 Evolution: Direct the ongoing maintenance of our PCI 4.0 program, with a specific focus on managing Targeted Risk Analyses (TRAs) and the customized approach where applicable.
- Scoping & Segmentation: Partner with Cloud Engineering to validate PCI scope across our global footprint, ensuring effective network segmentation and data flow isolation.
- QSA Liaison: Act as the primary point of contact for our external QSA, defending our control environment and streamlining the audit process to minimize disruption to technical teams.
- Continuous Compliance: Operationalize PCI requirements (e.g., quarterly scans, penetration test remediation) into automated workflows.
Multi-Framework Audit Management
- Unified Control Framework: Support the broader GRC team in managing our SOC2 Type 2, ISO 27001, and other regulatory audits.
- Technical Advisory: Provide GRC perspective on architectural designs, product launches, and infrastructure changes to ensure "compliance by design."
- Remediation Management: Track and drive the remediation of audit findings and security gaps, working closely with asset owners to find pragmatic, secure solutions.
Who You Are:
- Experience: 6+ years in an Information Security or IT Audit role, with at least 3 years of deep focus on PCI DSS within a major cloud-native environment.
- Certification: Active PCI ISA (Internal Security Assessor) or PCI QSA certification is mandatory.
- Regulatory Expertise: Thorough understanding of PCI DSS 4.0 requirements and the practical application of the standard in modern environments.
- Audit Fluency: Proven experience leading Level 1 Service Provider assessments.
- Communication: Ability to explain complex compliance requirements to developers and business leaders in a way that emphasizes enablement rather than "blockage."
Preferred Qualifications
- Broad Framework Knowledge: Experience with SOC2 and ISO 27001:2022.
- Cloud Security: Experience with GRC automation and familiarity with modern cloud-native security and observability tools.
- Automation Mindset: Experience using GRC platforms and a desire to automate manual evidence collection to reduce audit fatigue.
About You
- You understand the "Why": You don't just "do compliance"; you understand the security intent behind every control and can help teams meet the requirement in a way that actually improves our security posture.
- Technical Curiosity: You are comfortable diving into technical configurations (IAM policies, VPC flow logs, etc.) to verify control effectiveness yourself.
- Adaptable: You enjoy the challenge of a high-paced environment where scale and security must coexist and evolve together.
LI-KE1
LIHYBRID
(Pay Transparency Range: $88,951.00 - $150,432.00)**
The exact salary will be dependent on the successful candidate’s location, relevant knowledge, skills, and qualifications.
Inclusion and Belonging
At Commerce, we believe that celebrating the unique histories, perspectives and abilities of every employee makes a difference for our company, our customers and our community. We are an equal opportunity employer and the inclusive atmosphere we build together will make room for every person to contribute, grow and thrive.
We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the interview process, to perform essential job functions and to receive other benefits and privileges of employment. If you need an accommodation in order to interview at Commerce, please let us know during any of your interactions with our recruiting team.
Protect Yourself Against Hiring Scams: Our Corporate Disclaimer
Commerce, along with many other employers, has become the subject of fraudulent job offers to hopeful prospective job seekers.
Be advised:
Commerce does not offer jobs to individuals who do not go through our formal hiring process.
Commerce will never:
- require payment of recruitment fees from candidates;
- request personally identifiable information through unsanctioned websites or applications;
- attempt to solicit money from you as part of the hiring process or as part of an employment offer;
- solicit money to complete visa requirements as part of a job offer.
If you receive unsolicited offers of employment from Commerce, we urge you to be extremely cautious and avoid engaging or responding.
How to Get Visa Sponsorship as a Grc Analyst
Lead with your compliance framework expertise
Certifications like CISA, CRISC, or CISSP signal to employers that you meet specialty occupation standards USCIS expects. List every framework you've worked with, SOC 2, ISO 27001, NIST CSF, prominently on your resume.
Target regulated industries first
Financial services, healthcare, and government contractors have dedicated compliance teams and established sponsorship processes. These employers file H-1B petitions regularly and are far less likely to hesitate over the paperwork than a smaller startup.
Document the degree-to-role connection clearly
USCIS requires GRC roles to demonstrate a direct relationship between your degree field and the job duties. A degree in information systems, computer science, or cybersecurity is the strongest fit, be explicit about this connection in applications.
Negotiate sponsorship terms before accepting an offer
Confirm whether the employer covers H-1B filing fees, premium processing, and legal costs upfront. Some companies treat these as employee expenses, knowing the terms before you sign avoids an expensive surprise during the petition process.
Highlight your audit and risk quantification experience
Employers and immigration attorneys both need to demonstrate the role requires specialized knowledge. GRC candidates who can show they've led audits, written risk assessments, or managed vendor compliance programs make the specialty occupation case much stronger.
Apply early relative to the H-1B cap cycle
If you need cap-subject H-1B sponsorship, employers must register in March for an October start date. Securing a role offer by January gives your employer time to prepare the petition, run premium processing, and respond to any RFEs before the deadline.
Grc Analyst jobs are hiring across the US. Find yours.
Find Grc Analyst JobsSee all 38+ Grc Analyst jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Grc Analyst roles.
Get Access To All JobsFrequently Asked Questions
Does a GRC Analyst role qualify for H-1B visa sponsorship?
Yes, GRC Analyst positions generally qualify as H-1B specialty occupations because they require at minimum a bachelor's degree in a specific field such as information systems, cybersecurity, computer science, or a related discipline. USCIS evaluates whether the role's duties, risk assessment, compliance program management, audit oversight, require that specialized degree. Employers with established GRC functions in regulated industries have successfully sponsored this role consistently.
What degree do I need for an employer to sponsor my GRC Analyst visa?
A bachelor's degree in information systems, cybersecurity, computer science, or business information management is the most defensible match for GRC roles. Degrees in general business or management are riskier and can prompt a Request for Evidence from USCIS questioning the specialty occupation standard. If your degree is adjacent, pairing it with certifications like CISA or CRISC and documented GRC work experience strengthens the petition considerably.
Are there visa options besides H-1B for GRC Analysts seeking sponsorship?
Yes. Australian citizens can pursue the E-3 visa, which has no lottery and a much faster path. Canadians and Mexicans may qualify under the TN visa category, though GRC roles require careful matching to the approved TN occupation list. Candidates with exceptional achievements, published research, speaking engagements, industry awards, may also qualify for the O-1A. Browse GRC roles on Migrate Mate to filter by employers who sponsor specific visa types.
How likely is an H-1B petition for a GRC Analyst to be approved?
USCIS approval rates for information security and compliance roles are generally strong when the degree field aligns with the job duties. The most common reason for a Request for Evidence is a weak nexus between the applicant's degree and the GRC role's specific requirements. Employers with experienced immigration counsel and well-documented job descriptions see significantly fewer RFEs. The lottery remains the main uncertainty, selection is random, and approximately 25% of registrations were selected in recent fiscal years.
What should I look for in a GRC Analyst job listing to assess sponsorship likelihood?
Look for listings that specify a required degree in a technical or compliance-related field rather than 'any bachelor's degree,' as that distinction matters for the specialty occupation determination. Employers in financial services, healthcare, and federal contracting are more accustomed to the sponsorship process. Job postings that mention NIST, ISO 27001, or SOC 2 by name suggest a specialized compliance function, which supports a stronger H-1B petition. Migrate Mate surfaces GRC roles from employers with verified sponsorship history.
What is the prevailing wage requirement for sponsored Grc Analyst jobs?
U.S. employers sponsoring a visa must pay at least the prevailing wage, which is what workers in the same role, area, and experience level typically earn. The Department of Labor sets this rate to make sure companies aren't hiring foreign workers simply because they'd accept lower pay than a U.S. worker. It varies by job title, location, and experience. You can look up current prevailing wage rates for any occupation and location using the OFLC Wage Search page.
See which Grc Analyst employers are hiring and sponsoring visas right now.
Search Grc Analyst Jobs