164 grc risk analyst jobs at 137 companies in United States

1mo
Save
Mark Applied
Hide
Senior GRC Risk Analyst
Carmel or Eagan
$105k-$130k/yr OnsiteFull Time
MISO
MISO: Manages the high-voltage electricity grid and wholesale energy markets.
5+ YOEBachelor's degree in a related field, 5+ years cybersecurity risk management experience, vendor risk assessment expertise, knowledge of NIST frameworks, and relevant certifications (CRISC/CISSP/CISA/CISM) preferred.
NIST Cybersecurity Framework (CSF), NIST 800-37, NIST 800-53
2w
Save
Mark Applied
Hide
GRC Analyst - Third Party Risk
Boston, Massachusetts, United States
$70k-$110k/yr OnsiteFull Time
WHOOP
WHOOP: Wearable technology for personalized health and performance tracking.
2+ YOE2+ years GRC or third‑party risk experience, bachelor’s degree required; knowledge of ISO 27001, NIST CSF, COSO, SOC 2, PCI‑DSS; strong organization, communication, and operational discipline.
ISO 27001, NIST CSF, COSO, SOC 2, PCI-DSS
2mo
Save
Mark Applied
Hide
Senior Governance, Risk, Compliance (GRC) Analyst
San Francisco, California, United States
$162k-$202k/yr OnsiteFull Time
Headway
Headway: A healthtech accelerating access to mental healthcare
5+ YOE5+ years in GRC/compliance/security risk; knowledge of HITRUST/SOC 2/PCI-DSS/HIPAA; experience with GRC platforms; strong communication; ability to build repeatable processes; interest in AI-enabled security workflows; healthcare/healthtech HIPAA understanding a plus
HITRUST, SOC 2, PCI-DSS, HIPAA, GRC platform (e.g., Vanta, Drata, OneTrust)
1w
Save
Mark Applied
Hide
GRC Analyst
Norman, Oklahoma, United States
$46k-$60k/yr OnsiteFull Time
University of Oklahoma
University of Oklahoma: A public research university in Norman, Oklahoma.
Bachelor's in Computer Science/IT or equivalent experience; knowledge of cybersecurity frameworks, risk assessments, GRC platforms, vulnerability scanning, strong communication and analytical skills.
2w
Save
Mark Applied
Hide
Enterprise Risk Management Analyst (94263)
Dallas, Texas, United States
HybridFull Time
Freeman
Freeman: Design and production of live events and exhibitions.
1+ YOEBachelor's degree in risk/finance/business/economics,1+ years risk/insurance/finance/audit/analytics experience preferred,advanced Excel,Power BI,strong analytical and communication skills.
Microsoft Excel, Microsoft Office, Power BI, RMIS, GRC
1d
Save
Mark Applied
Hide
GRC Analyst
San Francisco, California, United States
$95k-$150k/yr HybridFull Time
Zip
Zip: AI-powered intake-to-procure platform for enterprise spend management
2+ YOEBachelor's degree,2+ years GRC or security risk/audit experience,knowledge of SOC/ISO/PCI/FedRAMP/WCAG frameworks,strong written and verbal communication.
SOC 1, SOC 2, ISO 27001, ISO 42001, PCI DSS, WCAG, FedRAMP
1mo
Save
Mark Applied
Hide
Director of GRC Operational Risk Management
United States
$140k-$175k/yr RemoteFull Time
Live Nation Entertainment
Live Nation EntertainmentNYSE: LYV: Sells tickets and produces concerts for live entertainment events.
6+ YOELead and mature a third-party risk management program within a GRC framework; manage a team of risk analysts; collaborate across security, privacy, legal, and technology.
ProcessUnity, OneTrust, Workiva, Prevalent, GRC, Optro
2w
Save
Mark Applied
Hide
GRC Analyst - Third Party Risk
Boston, Massachusetts, United States
$70k-$110k/yr OnsiteFull Time
WHOOP
WHOOP: Providing wearable health trackers and physiological performance analytics.
2+ YOE2+ years GRC experience, knowledge of ISO 27001, NIST CSF, COSO, SOC 2, PDI-DSS, bachelor’s degree, strong organizational and communication skills.
ISO 27001, NIST CSF, COSO, SOC 2, PDI-DSS
3mo
Save
Mark Applied
Hide
GRC Analyst
Dallas, Texas, United States
OnsiteFull Time
Momentum
Momentum: A collection of companies powering digital commerce and transformation.
5+ YOE5-7 years in GRC/security compliance/risk management; SOC 2 Type II experience; NIST CSF knowledge; policy library development; vendor risk management; client security questionnaires; strong written communication; AI/automation use.
OneTrust, Drata, Vanta, Whistic, Okta, Google Workspace, AWS, GCP, Azure, CrowdStrike, KnowBe4
2w
Save
Mark Applied
Hide
Senior Analyst, IT Risk & GRC
Carlsbad or Duluth or Tempe
$91k-$143k/yr HybridFull Time
Viasat
ViasatNASDAQ: VSAT: Provider of global satellite-based connectivity and secure communication solutions.
5+ YOE5+ years in IT audit/compliance/risk, bachelor’s in related field or equivalent, SOX/ITGC expertise, experience designing/testing IT controls, strong communication, CISA/CRISC/CISSP/CPA preferred, U.S. citizenship required.
SAP, Oracle, Workday, GCP, Tableau
1mo
Save
Mark Applied
Hide
GRC Analyst
Lowell, Massachusetts, United States
$78k-$125k/yr OnsiteFull Time
MACOM
MACOMNASDAQ: MTSI: Designs and manufactures semiconductor products for communications infrastructure.
1+ YOEBachelor's in relevant field (or equivalent), 1–3 years information security/risk/compliance experience, knowledge of security frameworks, strong analytical and communication skills, and willingness to learn ServiceNow GRC.
ServiceNow GRC, NIST, ISO 27001, SOC2, CIS, ISO9001, ISO14001
3d
Save
Mark Applied
Hide
GRC Analyst
Dallas, Texas, United States
OnsiteFull Time
NorthMark Strategies
NorthMark Strategies: Investment firm providing asset management and high-performance computing infrastructure.
4+ YOE4+ years GRC or information security governance experience; hands-on change management, risk assessment, policy management; familiarity with ISO 27001/SOC 2/NIST CSF; stakeholder engagement and strong written communication.
ServiceNow GRC, Vanta, Drata, Hyperproof, Archer, Jira, Confluence
3w
Save
Mark Applied
Hide
Governance, Risk & Compliance (GRC) Analyst
Saint Louis, Missouri, United States
HybridFull Time
Delta Dental of Missouri
Delta Dental of Missouri: Provides dental and vision insurance plans and provider networks.
3+ YOE3+ years experience in IT/security risk, knowledge of SOC 2/PCI/ISO, experience with security questionnaires, vendor risk reviews, and working in regulated environments; Bachelor's degree preferred; certifications such as CISA/CRISC/CISSP/SSCP/Security+ preferred.
JIRA, Confluence, AWS, Azure, Microsoft 365, NIST Special Publications, Cyber Security Framework, CIS Controls, ISO/IEC 27000/31000, OWASP
1mo
Save
Mark Applied
Hide
Senior Analyst, GRC
Overland Park or Cary
HybridFull Time
Black & Veatch
Black & Veatch: Provides engineering, procurement, and construction services for global infrastructure.
2+ YOEBachelor's in IT/CS or equivalent experience; 2+ years in GRC; experience with risk assessment frameworks (NIST CSF, ISO 27001, SOC), ServiceNow Risk Management, and enterprise cyber/compliance risk practices; CRISC/CISSP preferred.
ServiceNow Risk Management, GenAI, NIST CSF, ISO 27001, AICPA SOC, FAR, DFARS, CMMC
2d
Save
Mark Applied
Hide
Security GRC Analyst
United States
$70k-$77k/yr RemoteFull Time
Protective
Protective: Provides life insurance, annuities, and retirement protection solutions
1+ YOEExecute GRC functions including risk assessments, vendor risk, compliance, security awareness, reporting, and audit readiness; 1+ years GRC or risk experience; bachelor\u0002s degree in related field.
ServiceNow, Archer, Microsoft SharePoint, Microsoft Power BI, UpGuard, Azure, AWS
1mo
Save
Mark Applied
Hide
Senior GRC Analyst
Westerville, Ohio, United States
OnsiteFull Time
Kokosing
Kokosing: Provides heavy civil, industrial, and marine construction services.
5+ YOE5+ years GRC/cybersecurity experience; knowledge of CMMC and NIST 800-171; strong risk management, policy and vendor risk experience; ability to influence stakeholders and support audits and data governance.
CMMC, NIST 800-171
3w
Save
Mark Applied
Hide
Senior GRC Analyst
Orlando, Florida, United States
OnsiteFull Time
Morgan & Morgan
Morgan & Morgan: Provides legal representation for personal injury and consumer litigation.
4+ YOE4+ years in GRC/IT audit/compliance/information security; hands-on GRC platform experience (Vanta preferred); strong knowledge of ISO 27001, NIST CSF, CIS v8.1; ISC2 or ISACA certification required; experience leading audits and vendor risk assessments.
Vanta, ISO 27001, NIST CSF, CIS v8.1
2mo
Save
Mark Applied
Hide
Senior GRC Analyst
United States or Canada
$130k-$160k/yr RemoteFull Time
Benepass
Benepass: Platform for distributing and managing flexible employee benefits.
5+ YOE5+ years in GRC, information security, IT audit or risk management; hands-on SOC 2, ISO 27001/HITRUST; policy, evidence & audit readiness; strong communication.
Vanta, Drata, Thoropass, Secureframe
1w
Save
Mark Applied
Hide
Sr. GRC (Governance, Risk, and Compliance) Analyst
Tampa, Florida, United States
HybridFull Time
Bloomin' Brands
Bloomin' BrandsNASDAQ: BLMN: Operates a portfolio of casual and fine dining restaurant brands.
6+ YOEBachelor's degree required; 6+ years in information security, risk management, and IT auditing; knowledge of PCI DSS, SOX, SOC1/2, ITGC, ISO2700x; strong communication and project management skills; security certs preferred.
Microsoft Office Suite, GRC tools
1w
Save
Mark Applied
Hide
Senior GRC Analyst
New York City, New York, United States
$115k-$145k/yr RemoteFull Time
Compyl
Compyl: A provider of a platform to help companies understand and manage risk, security, and compliance.
5+ YOE5+ years GRC experience with audits, risk assessments, and policy/control rollouts; familiarity with SOC 2/ISO 27001/HIPAA/PCI-DSS/NIST; strong consultative communication and judgment.