Demo

Governance Risk and Compliance Analyst

Source Technology
Chicago, IL Contractor
POSTED ON 3/3/2025
AVAILABLE BEFORE 3/30/2025

Governance Risk and Compliance Analyst


Job Summary

The GRC Analyst plays a critical role in supporting the organization’s governance, risk management, and compliance programs. The individual will work to identify, assess, and monitor risks, ensure compliance with regulatory requirements, and help implement and maintain internal security policies and controls. The GRC Analyst is responsible for managing risk assessments, monitoring security and compliance activities, and supporting the overall security posture of the organization.


Key Responsibilities

Governance:

  • Assist in the development, implementation, and monitoring of the organization’s governance frameworks, security policies, standards, and procedures to ensure alignment with regulatory and compliance requirements.
  • Monitor and support the organization’s compliance with relevant standards (e.g., NIST, ISO 27001, HIPAA, GDPR, SOC 2) and legal requirements.
  • Coordinate audits and assessments (internal and external) to ensure ongoing compliance and address audit findings.

Risk Management:

  • Conduct risk assessments to identify vulnerabilities, threats, and potential impact to the organization’s information assets.
  • Maintain the risk register, tracking identified risks and mitigation efforts.
  • Collaborate with various departments to develop and implement risk mitigation strategies and ensure risks are reduced to an acceptable level.
  • Perform third-party vendor risk assessments to evaluate the security posture of external partners and service providers.

Incident Response & Management:

  • Assist with incident response activities, including coordinating with stakeholders to ensure risks and compliance issues are addressed in a timely manner.
  • Help to establish corrective action plans for identified issues and follow up to ensure remediation is completed.

Policy and Procedure Development:

  • Contribute to the creation and maintenance of security-related policies and procedures.
  • Ensure that policies and controls are communicated effectively to stakeholders and staff, and that proper training is conducted.

Training and Awareness:

  • Assist in the development and delivery of training programs to raise awareness on risk management, compliance obligations, and security best practices.
  • Track the completion of required compliance training and ensure ongoing awareness of relevant risks.

Reporting:

  • Prepare reports and dashboards for senior management, highlighting key risk indicators, audit results, and compliance status.
  • Provide insights and recommendations based on risk and compliance findings.

Continuous Improvement:

  • Stay up-to-date on evolving regulatory requirements, industry standards, and best practices in risk management and information security.
  • Identify opportunities for improving the GRC program and participate in initiatives to enhance security and compliance posture.


Required Qualifications:


  • Bachelor’s degree in Information Security, Business, or a related GRC field.
  • 2-3 years of experience in governance, risk, and compliance roles, preferably within a regulated industry (e.g., healthcare)
  • Familiarity with regulatory knowledge of GRC frameworks, such as NIST, ISO 27001, COBIT, HIPAA, SOC 2 and PCI-DSS.
  • Proven experience in conducting risk assessments, managing compliance audits, and implementing GRC solutions.
  • Strong project management skills, with the ability to lead and execute cross-functional initiatives.
  • Excellent written and verbal communication skills


Preferred Qualifications:


  • Master’s degree in Information Security, Business, or a related GRC field
  • 3-5 years of experience in governance, risk, and compliance roles, preferably within a regulated industry (e.g., healthcare)
  • Professional certifications such as: CGRC (Governance Risk and Compliance Certification) Certified Information Systems Auditor (CISA), Certified Information Systems Security Professional (CISSP), Certified in Risk and Information Systems Control (CRISC), or Certified Information Security Manager (CISM).

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Governance Risk and Compliance Analyst?

Sign up to receive alerts about other jobs on the Governance Risk and Compliance Analyst career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$105,259 - $133,442
Income Estimation: 
$129,191 - $164,117
Income Estimation: 
$152,549 - $188,894
Income Estimation: 
$194,072 - $240,547
Income Estimation: 
$135,994 - $168,063
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$70,462 - $84,818
Income Estimation: 
$77,991 - $108,747
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$87,093 - $107,335
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$139,945 - $168,577
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Source Technology

Source Technology
Hired Organization Address Chicago, IL Contractor
Governance, Risk, and Compliance (GRC) Manager Initially onsite for 3 months and then will be hybrid 12 month rolling co...
Source Technology
Hired Organization Address Chicago, IL Contractor
12 Month Contract - Onsite Chicago Job Summary We are seeking an experienced and dynamic Identity and Access Management ...
Source Technology
Hired Organization Address New York, NY Full Time
Job Title: Security Incident Response (IR) Lead Location: New York City Role Overview: We are seeking an experienced Sec...
Source Technology
Hired Organization Address Seattle, WA Contractor
🚀 Senior Full-Stack Software Engineer | Contract Opportunity | Seattle, WA (Onsite) 10 roles available Are you a Full-S...

Not the job you're looking for? Here are some other Governance Risk and Compliance Analyst jobs in the Chicago, IL area that may be a better fit.

AI Assistant is available now!

Feel free to start your new journey!