164 grc risk analyst jobs at 137 companies in United States
1mo
Save
Mark Applied
Hide
1mo
Senior GRC Risk Analyst
Carmel or Eagan
$105k-$130k/yrOnsiteFull Time
MISO: Manages the high-voltage electricity grid and wholesale energy markets.
5+ YOEBachelor's degree in a related field, 5+ years cybersecurity risk management experience, vendor risk assessment expertise, knowledge of NIST frameworks, and relevant certifications (CRISC/CISSP/CISA/CISM) preferred.
Headway: A healthtech accelerating access to mental healthcare
5+ YOE5+ years in GRC/compliance/security risk; knowledge of HITRUST/SOC 2/PCI-DSS/HIPAA; experience with GRC platforms; strong communication; ability to build repeatable processes; interest in AI-enabled security workflows; healthcare/healthtech HIPAA understanding a plus
University of Oklahoma: A public research university in Norman, Oklahoma.
Bachelor's in Computer Science/IT or equivalent experience; knowledge of cybersecurity frameworks, risk assessments, GRC platforms, vulnerability scanning, strong communication and analytical skills.
Freeman: Design and production of live events and exhibitions.
1+ YOEBachelor's degree in risk/finance/business/economics,1+ years risk/insurance/finance/audit/analytics experience preferred,advanced Excel,Power BI,strong analytical and communication skills.
Microsoft Excel, Microsoft Office, Power BI, RMIS, GRC
Zip: AI-powered intake-to-procure platform for enterprise spend management
2+ YOEBachelor's degree,2+ years GRC or security risk/audit experience,knowledge of SOC/ISO/PCI/FedRAMP/WCAG frameworks,strong written and verbal communication.
SOC 1, SOC 2, ISO 27001, ISO 42001, PCI DSS, WCAG, FedRAMP
Live Nation EntertainmentNYSE: LYV: Sells tickets and produces concerts for live entertainment events.
6+ YOELead and mature a third-party risk management program within a GRC framework; manage a team of risk analysts; collaborate across security, privacy, legal, and technology.
WHOOP: Providing wearable health trackers and physiological performance analytics.
2+ YOE2+ years GRC experience, knowledge of ISO 27001, NIST CSF, COSO, SOC 2, PDI-DSS, bachelor’s degree, strong organizational and communication skills.
ViasatNASDAQ: VSAT: Provider of global satellite-based connectivity and secure communication solutions.
5+ YOE5+ years in IT audit/compliance/risk, bachelor’s in related field or equivalent, SOX/ITGC expertise, experience designing/testing IT controls, strong communication, CISA/CRISC/CISSP/CPA preferred, U.S. citizenship required.
MACOMNASDAQ: MTSI: Designs and manufactures semiconductor products for communications infrastructure.
1+ YOEBachelor's in relevant field (or equivalent), 1–3 years information security/risk/compliance experience, knowledge of security frameworks, strong analytical and communication skills, and willingness to learn ServiceNow GRC.
ServiceNow GRC, NIST, ISO 27001, SOC2, CIS, ISO9001, ISO14001
4+ YOE4+ years GRC or information security governance experience; hands-on change management, risk assessment, policy management; familiarity with ISO 27001/SOC 2/NIST CSF; stakeholder engagement and strong written communication.
Delta Dental of Missouri: Provides dental and vision insurance plans and provider networks.
3+ YOE3+ years experience in IT/security risk, knowledge of SOC 2/PCI/ISO, experience with security questionnaires, vendor risk reviews, and working in regulated environments; Bachelor's degree preferred; certifications such as CISA/CRISC/CISSP/SSCP/Security+ preferred.
JIRA, Confluence, AWS, Azure, Microsoft 365, NIST Special Publications, Cyber Security Framework, CIS Controls, ISO/IEC 27000/31000, OWASP
Black & Veatch: Provides engineering, procurement, and construction services for global infrastructure.
2+ YOEBachelor's in IT/CS or equivalent experience; 2+ years in GRC; experience with risk assessment frameworks (NIST CSF, ISO 27001, SOC), ServiceNow Risk Management, and enterprise cyber/compliance risk practices; CRISC/CISSP preferred.
Protective: Provides life insurance, annuities, and retirement protection solutions
1+ YOEExecute GRC functions including risk assessments, vendor risk, compliance, security awareness, reporting, and audit readiness; 1+ years GRC or risk experience; bachelor\u0002s degree in related field.
ServiceNow, Archer, Microsoft SharePoint, Microsoft Power BI, UpGuard, Azure, AWS
Kokosing: Provides heavy civil, industrial, and marine construction services.
5+ YOE5+ years GRC/cybersecurity experience; knowledge of CMMC and NIST 800-171; strong risk management, policy and vendor risk experience; ability to influence stakeholders and support audits and data governance.
Morgan & Morgan: Provides legal representation for personal injury and consumer litigation.
4+ YOE4+ years in GRC/IT audit/compliance/information security; hands-on GRC platform experience (Vanta preferred); strong knowledge of ISO 27001, NIST CSF, CIS v8.1; ISC2 or ISACA certification required; experience leading audits and vendor risk assessments.
Benepass: Platform for distributing and managing flexible employee benefits.
5+ YOE5+ years in GRC, information security, IT audit or risk management; hands-on SOC 2, ISO 27001/HITRUST; policy, evidence & audit readiness; strong communication.
Sr. GRC (Governance, Risk, and Compliance) Analyst
Tampa, Florida, United States
HybridFull Time
Bloomin' BrandsNASDAQ: BLMN: Operates a portfolio of casual and fine dining restaurant brands.
6+ YOEBachelor's degree required; 6+ years in information security, risk management, and IT auditing; knowledge of PCI DSS, SOX, SOC1/2, ITGC, ISO2700x; strong communication and project management skills; security certs preferred.
Compyl: A provider of a platform to help companies understand and manage risk, security, and compliance.
5+ YOE5+ years GRC experience with audits, risk assessments, and policy/control rollouts; familiarity with SOC 2/ISO 27001/HIPAA/PCI-DSS/NIST; strong consultative communication and judgment.