Grc Analyst Jobs in USA with Visa Sponsorship
GRC Analyst roles qualify for H-1B visa and O-1 visa sponsorship as specialty occupations requiring a bachelor's degree in information systems, cybersecurity, or a related field. Employers in financial services, healthcare, and tech actively sponsor, particularly for candidates with frameworks like SOC 2, ISO 27001, or NIST experience. For detailed occupation requirements, see the O*NET profile.
Find Grc Analyst JobsOverview
Showing 5 of 1,171+ Grc Analyst jobs










See all 1,171+ Grc Analyst Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Grc Analyst roles.
Get Access To All Jobs
About us
Fanatics is building a leading global digital sports platform. We ignite the passions of global sports fans and maximize the presence and reach for our hundreds of sports partners globally by offering products and services across Fanatics Commerce, Fanatics Collectibles, and Fanatics Betting & Gaming, allowing sports fans to Buy, Collect, and Bet. Through the Fanatics platform, sports fans can buy licensed fan gear, jerseys, lifestyle and streetwear products, headwear, and hardgoods; collect physical and digital trading cards, sports memorabilia, and other digital assets; and bet as the company builds its Sportsbook and iGaming platform. Fanatics has an established database of over 100 million global sports fans; a global partner network with approximately 900 sports properties, including major national and international professional sports leagues, players associations, teams, colleges, college conferences and retail partners, 2,500 athletes and celebrities, and 200 exclusive athletes; and over 2,000 retail locations, including its Lids retail stores. Our more than 22,000 employees are committed to relentlessly enhancing the fan experience and delighting sports fans globally.
The Role
The Information Security GRC Analyst III, Controls Assurance (Fanatics Corporate) sits at the center of how Fanatics proves its security controls actually work, testing across PCI DSS, SOX ITGC, SOC reporting, and our internal NIST-aligned control baselines. This is a Corporate-level role with direct exposure across the full Fanatics portfolio: you will work daily with business units, IT teams, Security Operations, and InfoSec GRC counterparts across our subsidiaries and brands, giving you a rare, enterprise-wide view of how a global, multi-brand organization operates and secures itself.
Working in partnership with the designated owner of each control set, you will execute assigned control testing, collect and evaluate evidence, support user access reviews and control exception administration, and contribute to findings tracking and control reporting. Control effectiveness is rarely a clean pass or fail; you will need to read the intent behind a control, work through the grey areas, and take a practical, risk-based approach to compensating controls, tailored to how each subsidiary or brand actually does business. Strong communication is central to the role: you will explain technical and non-technical control requirements clearly and consistently to control owners, and use that clarity to influence timely, positive adoption of controls and remediation.
Control baselines and framework control sets are established and owned within the GRC team, so this is a controls assurance role rather than a program build-out or control design role. A substantial portion of the work is recurring and deadline-driven, including access review cycles, evidence collection, and assessment calendars.
- Execute assigned control tests in partnership with control set owners, including: sample selection, evidence requests, walkthroughs, and documented conclusions on operating effectiveness.
- Communicate control requirements, testing results, and rationale clearly and consistently to control owners across technical and non-technical audiences, and use that clarity to influence timely, positive adoption of controls and remediation.
- Prepare workpapers that withstand assessor review without rework.
- Evaluate evidence critically, identifying artifacts that do not substantiate the control.
- Support QSA, audit, and service auditor engagements, including evidence request lists and walkthrough preparation.
- Support user access review campaigns: population scoping, reviewer assignments, completion monitoring, and verification that revocations were executed.
- Collect and quality-check evidence for framework cycles, resolving gaps before assessor fieldwork.
- Support the control exception process: intake, routing, compensating controls, expiry tracking, and re-review.
- Apply practical, risk-based judgment to grey-area control questions, including whether a compensating control adequately addresses the underlying risk given how a specific subsidiary or brand operates.
- Identify opportunities to reduce manual evidence collection.
- Help maintain the control library: owners, test procedures, evidence requirements, testing frequency, and system mappings.
- Support cross-framework mapping, including mapping internal baseline controls to the external requirements they satisfy.
- Support findings tracking and remediation follow-up, retesting closed items rather than accepting closure on assertion.
- Contribute to control reporting and metrics, and to workflow upkeep in the designated GRC platform.
- Partner day-to-day with business units, IT teams, Security Operations, and InfoSec GRC counterparts across Fanatics' subsidiaries and brands, understanding how each operates in order to apply controls appropriately.
- Build sufficient depth across control sets to provide backup coverage during leave, peak workload, or overlapping cycles.
What We're Looking For
- Four years + in IT audit, IT control testing, information security GRC, or a related discipline; Big Four or regional firm IT audit experience applies directly.
- Demonstrated experience executing control tests to a defined procedure, including sampling, evidence evaluation, and documented conclusions.
- Experience with user access reviews, either administering campaigns or testing them as a control.
- Exposure to at least one of PCI DSS, SOX ITGC, SOC, or an internal security control baseline.
- Experience driving a recurring process across stakeholders outside a direct reporting line, with a record of following items to completion.
- Curiosity and adaptability to understand how Fanatics' different subsidiaries and brands operate, and how that context shapes how a control should be applied and assessed for effectiveness.
- Working knowledge of core control domains: access management and access reviews, privileged access, change management, SDLC, logging and monitoring, encryption, vulnerability and patch management, backup and recovery, and cloud platform fundamentals.
- Excellent written and verbal communication, with the ability to explain technical and non-technical control concepts clearly and consistently to control owners, and to influence stakeholders toward timely, positive adoption of controls and remediation, even without direct authority over them.
- Effective use of approved AI tools in day-to-day work, with sound judgment about where AI output can and cannot be relied upon in an audit context.
- Organizational discipline, persistence, and judgment about when to escalate.
- Detail-oriented, with sound judgment for navigating grey areas in control descriptions and a practical, risk-based approach to evaluating compensating controls rather than a strict pass/fail mindset.
- Bachelor's degree in information security, cybersecurity, information systems, accounting, or a related field, or equivalent practical experience.
- Preferred: CISA certification.
- Preferred: exposure to two or more of PCI DSS, SOX ITGC, and SOC, including familiarity with PCI DSS v4.0.1, and testing against NIST 800-53 or the NIST Cybersecurity Framework.
- Preferred: familiarity with an enterprise GRC or IRM platform.
By submitting your application, you agree to our terms of service and acknowledge you have read our Candidate Privacy Policy.
See all 1,171+ Grc Analyst Jobs
Sign up for free to unlock all listings, filter by visa type, and get alerts for new Grc Analyst roles.
Get Access To All JobsTips for Finding Visa Sponsorship as a Grc Analyst
Lead with your compliance framework expertise
Certifications like CISA, CRISC, or CISSP signal to employers that you meet specialty occupation standards USCIS expects. List every framework you've worked with, SOC 2, ISO 27001, NIST CSF, prominently on your resume.
Target regulated industries first
Financial services, healthcare, and government contractors have dedicated compliance teams and established sponsorship processes. These employers file H-1B petitions regularly and are far less likely to hesitate over the paperwork than a smaller startup.
Document the degree-to-role connection clearly
USCIS requires GRC roles to demonstrate a direct relationship between your degree field and the job duties. A degree in information systems, computer science, or cybersecurity is the strongest fit, be explicit about this connection in applications.
Negotiate sponsorship terms before accepting an offer
Confirm whether the employer covers H-1B filing fees, premium processing, and legal costs upfront. Some companies treat these as employee expenses, knowing the terms before you sign avoids an expensive surprise during the petition process.
Highlight your audit and risk quantification experience
Employers and immigration attorneys both need to demonstrate the role requires specialized knowledge. GRC candidates who can show they've led audits, written risk assessments, or managed vendor compliance programs make the specialty occupation case much stronger.
Apply early relative to the H-1B cap cycle
If you need cap-subject H-1B sponsorship, employers must register in March for an October start date. Securing a role offer by January gives your employer time to prepare the petition, run premium processing, and respond to any RFEs before the deadline.
Frequently Asked Questions
Does a GRC Analyst role qualify for H-1B visa sponsorship?
Yes, GRC Analyst positions generally qualify as H-1B visa specialty occupations because they require at minimum a bachelor's degree in a specific field such as information systems, cybersecurity, computer science, or a related discipline. USCIS evaluates whether the role's duties, risk assessment, compliance program management, audit oversight, require that specialized degree. Employers with established GRC functions in regulated industries have successfully sponsored this role consistently.
What degree do I need for an employer to sponsor my GRC Analyst visa?
A bachelor's degree in information systems, cybersecurity, computer science, or business information management is the most defensible match for GRC roles. Degrees in general business or management are riskier and can prompt a Request for Evidence from USCIS questioning the specialty occupation standard. If your degree is adjacent, pairing it with certifications like CISA or CRISC and documented GRC work experience strengthens the petition considerably.
Are there visa options besides H-1B for GRC Analysts seeking sponsorship?
Yes. Australian citizens can pursue the E-3 visa, which has no lottery and a much faster path. Canadians and Mexicans may qualify under the TN visa category, though GRC roles require careful matching to the approved TN occupation list. Candidates with exceptional achievements, published research, speaking engagements, industry awards, may also qualify for the O-1A. Browse GRC roles on Migrate Mate to filter by employers who sponsor specific visa types.
How likely is an H-1B petition for a GRC Analyst to be approved?
USCIS approval rates for information security and compliance roles are generally strong when the degree field aligns with the job duties. The most common reason for a Request for Evidence is a weak nexus between the applicant's degree and the GRC role's specific requirements. Employers with experienced immigration counsel and well-documented job descriptions see significantly fewer RFEs. The lottery remains the main uncertainty, selection is random, and approximately 25% of registrations were selected in recent fiscal years.
What should I look for in a GRC Analyst job listing to assess sponsorship likelihood?
Look for listings that specify a required degree in a technical or compliance-related field rather than 'any bachelor's degree,' as that distinction matters for the specialty occupation determination. Employers in financial services, healthcare, and federal contracting are more accustomed to the sponsorship process. Job postings that mention NIST, ISO 27001, or SOC 2 by name suggest a specialized compliance function, which supports a stronger H-1B petition. Migrate Mate surfaces GRC roles from employers with verified sponsorship history.
What is the prevailing wage requirement for sponsored Grc Analyst jobs?
U.S. employers sponsoring a visa must pay at least the prevailing wage, which is what workers in the same role, area, and experience level typically earn. The Department of Labor sets this rate to make sure companies aren't hiring foreign workers simply because they'd accept lower pay than a U.S. worker. It varies by job title, location, and experience. You can look up current prevailing wage rates for any occupation and location using the OFLC Wage Search page.