64 grc jobs at 43 companies in Boston, MA

1d
Save
Mark Applied
Hide
GRC Analyst
Boston, Massachusetts, United States
$83k-$105k/yr HybridFull Time
American Tower
American TowerNYSE: AMT: Leases space on wireless and broadcast towers for communications.
2+ YOERequires 2+ years in GRC or information security, strong project management and communication skills, Microsoft Office and Oracle proficiency, and knowledge of security standards and privacy regulations.
Microsoft Office, Oracle, ISO 27001, ISO 27002, ITIL, Identity and Access Management (IAM)
2w
Save
Mark Applied
Hide
Associate GRC Analyst
Cambridge or Concord
$85k-$95k/yr HybridFull Time
KAYAK: Global travel search engine for flights, hotels, and rentals.
Foundational GRC knowledge, familiarity with NIST CSF/SOC 2/PCI DSS/GDPR, BC/DR basics, clear communication, organizational skills, and interest in automating GRC processes.
Drata, RiskConnect, APIs
1mo
Save
Mark Applied
Hide
Staff GRC Engineer (Remote)
Boston or United States
$165k-$210k/yr HybridFull Time
ezCater
ezCater: Online marketplace for business catering and food for work
8+ YOE8+ years in security GRC or compliance for SaaS/cloud; deep knowledge of ISO-27001, NIST CSF, SOC 2, ITGC, PCI; experience automating control testing and evidence collection; familiarity with Policy-as-Code (Terraform), AWS, GitHub; strong communication.
Terraform, AWS, GitHub, APIs
1mo
Save
Mark Applied
Hide
GRC Analyst - Third Party Risk
Boston, Massachusetts, United States
$70k-$110k/yr OnsiteFull Time
WHOOP
WHOOP: Wearable technology for personalized health and performance tracking.
2+ YOE2+ years GRC or third‑party risk experience, bachelor’s degree required; knowledge of ISO 27001, NIST CSF, COSO, SOC 2, PCI‑DSS; strong organization, communication, and operational discipline.
ISO 27001, NIST CSF, COSO, SOC 2, PCI-DSS
2mo
Save
Mark Applied
Hide
Manager, Security GRC - Compliance Onboarding & Readiness
Cambridge or United States
$146k-$234k/yr RemoteFull Time
HubSpot
HubSpotNYSE: HUBS: Provides a customer platform for marketing, sales, and service.
Experience in Security GRC/IT Compliance or IT Audit, people management plus hands-on IC work, deep control design (SOX 404), risk-based scoping/testing, AWS/microservices/CI/CD familiarity, strong communication.
AWS, CI/CD, IAM, ISO 27001, SOC 1, SOC 2, NIST, ISO 42001
6d
Save
Mark Applied
Hide
Risk Consulting - Risk Technology - SAP GRC & Security - Senior Consultant
New York or Atlanta or Boston or Chicago or Cleveland or Dallas or Detroit or Pittsburgh or Hoboken or Houston or Los Angeles or McLean or Miami or Minneapolis or Charlotte or Philadelphia or Portland or San Francisco or Seattle or North America
$123k-$213k/yr HybridFull Time
EY
EY: Global firm providing audit, tax, and professional consulting services.
3+ YOERequires 3–5+ years of SAP Security/GRC experience, bachelor's degree preferred, SAP implementation expertise, GRC Access Control and IAM experience, U.S. driver's license, passport, and willingness to travel up to 80%.
SAP Application Security, SAP GRC Access Control, S/4HANA, SAP ECC, FIORI, ARIBA, HCM, SuccessFactors, Saviynt, SailPoint, SAP IAG, ServiceNow, HP ALM, BTP, SAC, AI, RPA
3w
Save
Mark Applied
Hide
Head of GRC (Governance, Risk, & Compliance)
Cambridge, Massachusetts, United States
$220k-$260k/yr OnsiteFull Time
Blitzy
Blitzy: Autonomous AI platform for enterprise software development.
Hands-on ownership of SOC 2 Type II or ISO 27001:2022 audits, Vanta or equivalent GRC platform experience, auditor/vendor management, FedRAMP exposure preferred, strong written and judgment skills.
Vanta, Google Workspace
1mo
Save
Mark Applied
Hide
Regulatory Change Management Officer
Rockland, Massachusetts, United States
$90k-$110k/yr OnsiteFull Time
Rockland Trust
Rockland TrustNASDAQ: INDB: Provides commercial and retail banking and financial management services.
3+ YOEBachelor's degree required, 3+ years compliance/regulatory change experience, strong communication, project leadership, GRC experience (WolfPAC/Archer Risk Central) preferred, ability to assess regulatory impact and lead cross-functional implementation.
GRC, WolfPAC, Archer Risk Central
1mo
Save
Mark Applied
Hide
Senior Analyst, IT Internal Controls & SOX Compliance
San Francisco or Salt Lake City or Phoenix or Los Angeles or Chicago or Boston or Austin or New York City or Miami or Tampa or Atlanta or Columbus or Boise or San Diego or Minneapolis or Houston or Raleigh or Nashville or Kansas City or Charlotte or Portland or Philadelphia or Dallas or Washington D.C. or Seattle
$113k-$148k/yr RemoteFull Time
Circle
CircleNYSE: CRCL: Digital currency issuer and blockchain financial infrastructure provider.
4+ YOE4+ years Big 4 IT audit/controls experience, Bachelor's in related field, CPA/CISA/CIA/CISSP required; strong SOX/ITGC knowledge, cloud/SaaS/SDLC/IAM experience, ERP/GRC familiarity, and stakeholder communication skills.
Slack, Apple MacOS, Google Workspace, ERP, GRC, AI
1mo
Save
Mark Applied
Hide
Sr. Compliance Administrator
Providence, Rhode Island, United States
OnsiteFull Time
Charles IT
Charles IT: Provides managed IT and cybersecurity compliance services.
5+ YOEBachelor's (or equivalent experience), 5+ years in compliance/audit/IT-security, experience with GRC platforms, policy management, audit processes, knowledge of SOC 2, NIST, HIPAA, CMMC, NYDFS; relevant certifications preferred; valid U.S. driver\u0002s license and background check.
GRC platforms, SOC 2, NIST CSF 2.0, HIPAA, CMMC, NYDFS
1w
Save
Mark Applied
Hide
Senior Associate, SAP Security & Controls
Denver or Stamford or Washington or Orlando or Tampa or Atlanta or Chicago or Boston or Minneapolis or Charlotte or Short Hills or New York City or Philadelphia or Dallas or Houston or McLean
FieldFull Time
KPMG
KPMG: Global professional services network providing audit, tax, and advisory.
3+ YOERequires 3+ years in SAP audit, controls, security, GRC, ERP implementation, or transformation; bachelor's degree; SAP GRC and security experience; and strong communication skills.
SAP, SAP GRC, SAP S/4HANA
1mo
Save
Mark Applied
Hide
IT Risk & Compliance Analyst
North Andover or United States
$84k-$94k/yr RemoteFull Time
Watts Water Technologies
Watts Water TechnologiesNYSE: WTS: Manufactures water flow control and water quality products.
3+ YOEBachelor's or equivalent; 3+ years IT compliance/internal audit/GRC experience; working knowledge of ITGCs and SOX; experience with GRC/audit platforms; strong communication and organizational skills.
Optro (AuditBoard), ServiceNow GRC, Archer, MetricStream, Jira, Microsoft Power Automate, SQL, Python, APIs
1mo
Save
Mark Applied
Hide
SAP GTS Sr Associate
Chicago or Tampa or Charlotte or Atlanta or Austin or Washington or Dallas or Los Angeles or Boston or Florham Park or New York City or San Francisco or San Jose or Philadelphia or Houston
$77k-$202k/yr OnsiteFull Time
PwC
PwC: Providing audit, tax, and management consulting services to businesses.
2+ YOEBachelor's degree and at least 2 years delivering SAP compliance, security, and governance solutions (GRC); proficiency with SAP GRC and SAP BW/4HANA; strong communication and analytical skills.
SAP Governance, Risk and Compliance (GRC), SAP BW/4HANA, SAP
6d
Save
Mark Applied
Hide
Security & Trust Manager
Boston, Massachusetts, United States
RemoteFull Time
Reco
Reco: AI-native platform for SaaS security and identity governance.
5+ YOERequires 5+ years in security trust, GRC, compliance, or customer-facing security; enterprise security review experience; compliance framework knowledge; IAM, cloud security, application security, and GRC tool experience.
SOC 2, ISO 27001, NIST CSF, HIPAA, GDPR, ISO 42001, EU AI Act, SSO, Okta, Azure AD, SCIM, AWS, GCP, Azure, Vanta, Drata, SafeBase, Conveyor, MDM
1mo
Save
Mark Applied
Hide
Solution Advisor
United States or Boston or Knoxville or Washington
RemoteFull Time
RegScale
RegScale: Automated compliance software for continuous security controls monitoring.
4+ YOE4+ years experience in compliance/cybersecurity/GRC or SaaS professional services; Bachelor's (4 yrs exp) or Master's (3 yrs exp); strong communication, GRC framework knowledge, SaaS/product familiarity, and willingness to travel up to 25%.
Python, C#
1w
Save
Mark Applied
Hide
Information Security Risk and Compliance Analyst
Boston, Massachusetts, United States
$84k-$106k/yr HybridFull Time
CarGurus
CarGurusNASDAQ: CARG: Operates an online marketplace for buying and selling vehicles.
Manage third-party risk, customer security assurance, cyber risk, SOX ITGCs and governance; experience with GRC platforms, cloud environments, and security/IT certifications.
Auditboard, SAFE, Loopio
3w
Save
Mark Applied
Hide
Director, Security Governance
Boston, Massachusetts, United States
$177k-$206k/yr OnsiteFull Time
Beth Israel Lahey Health
Beth Israel Lahey Health: Integrated regional healthcare provider operating hospitals and clinical centers.
11+ YOE3+ MgmtLead GRC program, develop security policies, oversee audits and training; requires bachelor's degree, 10+ years IT/security experience, 3+ years supervisory experience.
1w
Save
Mark Applied
Hide
Assoc Dir, Information Security Governance Risk & Compliance
Boston, Massachusetts, United States
$179k-$212k/yr HybridFull Time
Servier
Servier: Independent global pharmaceutical group developing innovative treatments for patients.
8+ YOE3+ Mgmt8+ years in information security GRC or related discipline, 3+ years leadership, expertise with risk frameworks, audit readiness, third-party risk, and strong executive communication.
NIST CSF 2.0, ISO 27001, PCI, SOX, FAIR
2w
Save
Mark Applied
Hide
Senior Director Cybersecurity Operations and Risk
Providence, Rhode Island, United States
$160k-$260k/yr RemoteFull Time
UNFI
UNFINYSE: UNFI: Distributors of natural, organic, and conventional food products.
12+ YOE5+ Mgmt12+ years cybersecurity experience,5+ years leadership,BS in CS or related,industry cybersecurity certification,experience with SOC,VM,GRC,incident command,and vendor/MSSP management.
NIST CSF, ISO 27001, FAIR, Zero Trust, SASE, VPN, MSSP, SaaS
2d
Save
Mark Applied
Hide
Information Protection Specialist
Quincy, Massachusetts, United States
$120k-$203k/yr OnsiteFull Time
State Street
State StreetNYSE: STT: Provides investment servicing and management to institutional investors.
10+ YOEBachelor's degree required; 10+ years in cybersecurity, technology risk, GRC, or related fields; experience with cyber policy enforcement, risk governance, executive reporting, and enterprise stakeholder management.
NIST, ISO 27001, COBIT, FFIEC, SEC