73 grc jobs at 44 companies in Massachusetts

2d
Save
Mark Applied
Hide
GRC Analyst
Boston, Massachusetts, United States
$83k-$105k/yr HybridFull Time
American Tower
American TowerNYSE: AMT: Leases space on wireless and broadcast towers for communications.
2+ YOERequires 2+ years in GRC or information security, strong project management and communication skills, Microsoft Office and Oracle proficiency, and knowledge of security standards and privacy regulations.
Microsoft Office, Oracle, ISO 27001, ISO 27002, ITIL, Identity and Access Management (IAM)
2w
Save
Mark Applied
Hide
Associate GRC Analyst
Cambridge or Concord
$85k-$95k/yr HybridFull Time
KAYAK: Global travel search engine for flights, hotels, and rentals.
Foundational GRC knowledge, familiarity with NIST CSF/SOC 2/PCI DSS/GDPR, BC/DR basics, clear communication, organizational skills, and interest in automating GRC processes.
Drata, RiskConnect, APIs
1mo
Save
Mark Applied
Hide
Staff GRC Engineer (Remote)
Boston or United States
$165k-$210k/yr HybridFull Time
ezCater
ezCater: Online marketplace for business catering and food for work
8+ YOE8+ years in security GRC or compliance for SaaS/cloud; deep knowledge of ISO-27001, NIST CSF, SOC 2, ITGC, PCI; experience automating control testing and evidence collection; familiarity with Policy-as-Code (Terraform), AWS, GitHub; strong communication.
Terraform, AWS, GitHub, APIs
1mo
Save
Mark Applied
Hide
GRC Analyst - Third Party Risk
Boston, Massachusetts, United States
$70k-$110k/yr OnsiteFull Time
WHOOP
WHOOP: Wearable technology for personalized health and performance tracking.
2+ YOE2+ years GRC or third‑party risk experience, bachelor’s degree required; knowledge of ISO 27001, NIST CSF, COSO, SOC 2, PCI‑DSS; strong organization, communication, and operational discipline.
ISO 27001, NIST CSF, COSO, SOC 2, PCI-DSS
2mo
Save
Mark Applied
Hide
Manager, Security GRC - Compliance Onboarding & Readiness
Cambridge or United States
$146k-$234k/yr RemoteFull Time
HubSpot
HubSpotNYSE: HUBS: Provides a customer platform for marketing, sales, and service.
Experience in Security GRC/IT Compliance or IT Audit, people management plus hands-on IC work, deep control design (SOX 404), risk-based scoping/testing, AWS/microservices/CI/CD familiarity, strong communication.
AWS, CI/CD, IAM, ISO 27001, SOC 1, SOC 2, NIST, ISO 42001
1mo
Save
Mark Applied
Hide
Senior GRC Engineer, Trust
New York City or Maryland or Massachusetts or Virginia or Georgia or New York
$97k-$184k/yr OnsiteFull Time
Chainalysis
Chainalysis: Blockchain data platform for cryptocurrency investigation and compliance.
Experience implementing and operating security and compliance controls in cloud/SaaS environments; built evidence collection, control testing, or remediation workflows; supported SOC 2/ISO 27001 or similar; strong written/verbal communication; US citizenship required.
AWS, Terraform, Vanta, Jira, Okta
1w
Save
Mark Applied
Hide
Risk Consulting - Risk Technology - SAP GRC & Security - Senior Consultant
New York or Atlanta or Boston or Chicago or Cleveland or Dallas or Detroit or Pittsburgh or Hoboken or Houston or Los Angeles or McLean or Miami or Minneapolis or Charlotte or Philadelphia or Portland or San Francisco or Seattle or North America
$123k-$213k/yr HybridFull Time
EY
EY: Global firm providing audit, tax, and professional consulting services.
3+ YOERequires 3–5+ years of SAP Security/GRC experience, bachelor's degree preferred, SAP implementation expertise, GRC Access Control and IAM experience, U.S. driver's license, passport, and willingness to travel up to 80%.
SAP Application Security, SAP GRC Access Control, S/4HANA, SAP ECC, FIORI, ARIBA, HCM, SuccessFactors, Saviynt, SailPoint, SAP IAG, ServiceNow, HP ALM, BTP, SAC, AI, RPA
4w
Save
Mark Applied
Hide
Head of GRC (Governance, Risk, & Compliance)
Cambridge, Massachusetts, United States
$220k-$260k/yr OnsiteFull Time
Blitzy
Blitzy: Autonomous AI platform for enterprise software development.
Hands-on ownership of SOC 2 Type II or ISO 27001:2022 audits, Vanta or equivalent GRC platform experience, auditor/vendor management, FedRAMP exposure preferred, strong written and judgment skills.
Vanta, Google Workspace
1mo
Save
Mark Applied
Hide
Principal Sales Engineer – Cyber Risk and GRC
United States or Illinois or Colorado or Hawaii or District of Columbia or Maryland or Minnesota or New York or Washington or New Jersey or Vermont or Massachusetts or California or Kansas
$97k-$227k/yr RemoteFull Time
Comcast
ComcastNASDAQ: CMCSA: Provides global telecommunications, media content, and entertainment services.
5+ YOE5+ years enterprise sales engineering experience in B2B SaaS, GRC/cyber risk expertise, data fluency including SQL, strong PoV/demo/communication skills, ability to travel and influence product direction.
DataBee, SQL, Business Intelligence (BI) Reporting Tools
2d
Save
Mark Applied
Hide
GRC/IRM ServiceNow Technology Implementation Solutions – Senior Manager
Chicago or Miami or Tampa or Los Angeles or Boston or Cleveland or New York City or Florham Park or San Diego or San Francisco or Philadelphia or Houston
$124k-$280k/yr FieldFull Time
PwC
PwC: Providing audit, tax, and management consulting services to businesses.
7+ YOEBachelor’s degree and 7+ years of experience; GRC technology proficiency, ISO/IEC 27001, NIST CSF, compliance programs, risk assessments, data analysis, and team leadership.
ServiceNow, ISO/IEC 27001, NIST Cybersecurity Framework (CSF)
3w
Save
Mark Applied
Hide
Risk Consulting - Risk Technology - GRC/IRM Platforms - Manager
New York or Atlanta or Boston or Chicago or Cleveland or Dallas or Detroit or Pittsburgh or Hoboken or Houston or Los Angeles or McLean or Miami or Minneapolis or North Carolina or Philadelphia or Portland or San Francisco or Seattle or Tampa
$150k-$260k/yr HybridFull Time
EY
EY: Provides audit, tax, consulting, and strategy services globally.
4+ YOEBachelor's degree plus 5 years or master's degree plus 4 years implementing ServiceNow IRM, TPRM, or BCM solutions; ServiceNow CSA and GRC certification required; project leadership and client-facing consulting experience.
ServiceNow IRM, Archer, AuditBoard, Microsoft PowerPoint, Microsoft Word, Microsoft Excel, Microsoft Visio, Integration Hub, API, Waterfall, Agile, REST, SOAP, Spotfire, PowerBI, Tableau, OneTrust, AI
1w
Save
Mark Applied
Hide
Information Security Administrator, GRC - Boston
Boston, Massachusetts, United States
$85k-$100k/yr OnsiteFull Time
Mintz
Mintz: Full-service law firm providing legal and regulatory counsel.
3+ YOE3-5 years experience in information security/compliance/audit or related discipline, Bachelor's degree or equivalent experience, strong organizational and communication skills, Microsoft 365 proficiency, experience with compliance frameworks.
Microsoft 365, ISO 27001, NIST, SOC 2, HIPAA
1mo
Save
Mark Applied
Hide
Regulatory Change Management Officer
Rockland, Massachusetts, United States
$90k-$110k/yr OnsiteFull Time
Rockland Trust
Rockland TrustNASDAQ: INDB: Provides commercial and retail banking and financial management services.
3+ YOEBachelor's degree required, 3+ years compliance/regulatory change experience, strong communication, project leadership, GRC experience (WolfPAC/Archer Risk Central) preferred, ability to assess regulatory impact and lead cross-functional implementation.
GRC, WolfPAC, Archer Risk Central
1mo
Save
Mark Applied
Hide
Senior Analyst, IT Internal Controls & SOX Compliance
San Francisco or Salt Lake City or Phoenix or Los Angeles or Chicago or Boston or Austin or New York City or Miami or Tampa or Atlanta or Columbus or Boise or San Diego or Minneapolis or Houston or Raleigh or Nashville or Kansas City or Charlotte or Portland or Philadelphia or Dallas or Washington D.C. or Seattle
$113k-$148k/yr RemoteFull Time
Circle
CircleNYSE: CRCL: Digital currency issuer and blockchain financial infrastructure provider.
4+ YOE4+ years Big 4 IT audit/controls experience, Bachelor's in related field, CPA/CISA/CIA/CISSP required; strong SOX/ITGC knowledge, cloud/SaaS/SDLC/IAM experience, ERP/GRC familiarity, and stakeholder communication skills.
Slack, Apple MacOS, Google Workspace, ERP, GRC, AI
1w
Save
Mark Applied
Hide
Senior Associate, SAP Security & Controls
Denver or Stamford or Washington or Orlando or Tampa or Atlanta or Chicago or Boston or Minneapolis or Charlotte or Short Hills or New York City or Philadelphia or Dallas or Houston or McLean
FieldFull Time
KPMG
KPMG: Global professional services network providing audit, tax, and advisory.
3+ YOERequires 3+ years in SAP audit, controls, security, GRC, ERP implementation, or transformation; bachelor's degree; SAP GRC and security experience; and strong communication skills.
SAP, SAP GRC, SAP S/4HANA
1mo
Save
Mark Applied
Hide
IT Risk & Compliance Analyst
North Andover or United States
$84k-$94k/yr RemoteFull Time
Watts Water Technologies
Watts Water TechnologiesNYSE: WTS: Manufactures water flow control and water quality products.
3+ YOEBachelor's or equivalent; 3+ years IT compliance/internal audit/GRC experience; working knowledge of ITGCs and SOX; experience with GRC/audit platforms; strong communication and organizational skills.
Optro (AuditBoard), ServiceNow GRC, Archer, MetricStream, Jira, Microsoft Power Automate, SQL, Python, APIs
1w
Save
Mark Applied
Hide
Security & Trust Manager
Boston, Massachusetts, United States
RemoteFull Time
Reco
Reco: AI-native platform for SaaS security and identity governance.
5+ YOERequires 5+ years in security trust, GRC, compliance, or customer-facing security; enterprise security review experience; compliance framework knowledge; IAM, cloud security, application security, and GRC tool experience.
SOC 2, ISO 27001, NIST CSF, HIPAA, GDPR, ISO 42001, EU AI Act, SSO, Okta, Azure AD, SCIM, AWS, GCP, Azure, Vanta, Drata, SafeBase, Conveyor, MDM
1w
Save
Mark Applied
Hide
Information Security Risk and Compliance Analyst
Boston, Massachusetts, United States
$84k-$106k/yr HybridFull Time
CarGurus
CarGurusNASDAQ: CARG: Operates an online marketplace for buying and selling vehicles.
Manage third-party risk, customer security assurance, cyber risk, SOX ITGCs and governance; experience with GRC platforms, cloud environments, and security/IT certifications.
Auditboard, SAFE, Loopio
4w
Save
Mark Applied
Hide
Director, Security Governance
Boston, Massachusetts, United States
$177k-$206k/yr OnsiteFull Time
Beth Israel Lahey Health
Beth Israel Lahey Health: Integrated regional healthcare provider operating hospitals and clinical centers.
11+ YOE3+ MgmtLead GRC program, develop security policies, oversee audits and training; requires bachelor's degree, 10+ years IT/security experience, 3+ years supervisory experience.
2w
Save
Mark Applied
Hide
Assoc Dir, Information Security Governance Risk & Compliance
Boston, Massachusetts, United States
$179k-$212k/yr HybridFull Time
Servier
Servier: Independent global pharmaceutical group developing innovative treatments for patients.
8+ YOE3+ Mgmt8+ years in information security GRC or related discipline, 3+ years leadership, expertise with risk frameworks, audit readiness, third-party risk, and strong executive communication.
NIST CSF 2.0, ISO 27001, PCI, SOX, FAIR