Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

GRC Analyst

GovernmentJobs.com

Job Summary

The Governance, Risk, and Compliance (GRC) Analyst is responsible for identifying, assessing, monitoring, and mitigating organizational risks while ensuring compliance with applicable regulatory requirements, industry standards, and internal policies. This role works closely with business units, Information Technology (IT), cybersecurity, audit, and leadership to strengthen the organization's governance, risk management, and compliance framework. *This job posting will close down once it exceeds 200 applicants*

Duties & Responsibilities

Enterprise & Information Security Risk Management

  • Conduct comprehensive enterprise and information security risk assessments to identify threats and vulnerabilities across IT, Operational Technology (OT), and business processes.
  • Maintain and continuously update the MBTA's risk register, ensuring timely tracking of remediation actions and residual risk. Evaluate business processes, technical controls, and governance workflows to ensure they effectively mitigate identified risks and align with MBTA's centralized compliance strategy.
  • Support the maturation of risk methodologies, including development of risk scoring models, prioritization frameworks, and automated reporting feeds.

Governance, Compliance & Regulatory Alignment

  • Support the development, implementation, and continuous improvement of governance, risk, and compliance programs and procedures.
  • Monitor and report compliance against regulatory requirements, industry standards, and internal policies, including International Organization for Standardization (ISO) 27001, National Institute of Standards and Technology Cybersecurity Framework (NIST CSF)/800-53, Service Organization Control (SOC) 2, Payment Card Industry Data Security Standard (PCI DSS), Transportation Security Administration (TSA) Surface Directives, United States Coast Guard (USCG) requirements, General Data Protection Regulation (GDPR), Health Insurance Portability and Accountability Act (HIPAA), Sarbanes-Oxley Act (SOX), and other MBTA-applicable mandates.
  • Assist with maintaining authoritative policy and standards documentation; participate in policy review cycles and support enterprise-wide enforcement.

Third-Party & Supply-Chain Risk

  • Perform detailed third-party/vendor security assessments covering onboarding, due-diligence, SOC 2/Federal Risk and Authorization Management Program (FedRAMP)/ISO attestation reviews, contractual security clauses, and ongoing monitoring.
  • Track vendor remediation activities and partner with Procurement, Legal, and business owners to ensure sustained compliance.

Audit Support & Evidence Management

  • Assist with internal and external audits by gathering documentation, coordinating evidence collection, validating controls, and supporting remediation plans.
  • Serve as a liaison between business units, auditors, and Information Security to ensure timely and accurate audit responses.

Analytics, Reporting & Executive Dashboards

  • Develop risk dashboards, status reports, metrics, and executive-level summaries for leadership, including trends, Key Performance Indicators (KPIs), Key Risk Indicators (KRIs), and compliance performance indicators.
  • Maintain high-quality data integrity within GRC platforms (e.g., ServiceNow GRC, Archer) by ensuring accuracy of control catalogs, assessments, exceptions, and workflow automation.

Cross-Functional Collaboration & Advisory Support

  • Partner with IT, Cybersecurity, Operations, Legal, Finance, and business teams to identify control gaps and recommend actionable mitigation strategies.
  • Support enterprise roadmaps by providing risk insights that influence technology, process, and operational decisions.
  • Assist team leaders and stakeholders in understanding risk exposure, obligations, and governance expectations.

Policy Governance & Awareness

  • In collaboration with the GRC Policy Analyst, support policy development, review cycles, distribution, and enforcement efforts across the enterprise.
  • Promote risk awareness, compliance practices, and security-first principles through communications, targeted training, and awareness campaigns.

Continuous Monitoring & Professional Development

  • Stay informed of emerging cybersecurity threats, regulatory changes, industry frameworks, and best practices relevant to MBTA operations.
  • Evaluate opportunities for process improvements, automation, and enhanced risk analysis techniques.

Additional Responsibilities

  • Provide risk assessment and compliance support for OT environments and transit-related systems.
  • Assist the team's Deputy Director or other leadership in executing enterprise-level initiatives related to centralized compliance, regulatory coordination, and risk governance. Stakeholder Engagement & Communication
  • Prepare briefing materials for executive committees, regulatory inquiries, and cross-department collaborations.
  • Perform all other duties and projects that may be assigned.
Minimum Requirements & Qualifications
  • Bachelor's degree in Information Technology, Cybersecurity, Information Systems, Business, Finance, Risk Management, or a related field.
  • Two (2) years of experience in Governance, Risk, Compliance, Information Security, Internal Audit, or Enterprise Risk Management.
  • Experience performing risk assessments and documenting findings.
  • Knowledge of risk management methodologies and control frameworks.
  • Familiarity with regulatory and compliance standards (e.g., NIST CSF/800-53, ISO 27001, SOC 2, PCI DSS, HIPAA GDPR, SOX).
  • Strong analytical, organizational, and problem-solving skills.
  • Excellent written and verbal communication skills.
  • Ability to work cross-functionally with technical and non-technical stakeholders.

Substitutions

  • A high school diploma or GED with an additional seven (7) years of directly related experience substitutes for the bachelor's degree requirement.
  • An associate's degree from an accredited institution and an additional three (3) years of directly related experience substitutes for the bachelor's degree requirement.
  • A master's degree in a related subject substitutes for two (2) years of general experience.
  • A nationally recognized certification, or statewide/professional certification in a related field substitutes for one (1) year of experience.
Preferred Experience & Skills
  • Certified Information Systems Auditor (CISA).
  • Certified in Risk and Information Systems Control (CRISC).
  • Certified Information Systems Security Professional (CISSP).
  • Certified Information Security Manager (CISM).
  • Project Management Professional (PMP).

Job Conditions:

  • Ability to effectively read, comprehend, communicate, and respond to instructions, orders, signs, notices, inquiries, etc. in English.
  • Be at least eighteen (18) years of age, except if participating in an approved high school internship / co-op program.
  • Ability to commute to assigned work locations in the Boston, MA metro area, as required by the role.
  • Ability to provide internal and external customers with courteous and professional experiences.
  • Ability to work effectively, independently, and as part of a diverse workforce team (or supervise, if required).
  • Ability to uphold the rights and interests of the MBTA while building and maintaining effective relationships with employees and co-workers.
  • Ability to adhere to rules, regulations, collective bargaining agreements (if applicable), and policies of the MBTA, including the EEO, anti-discrimination, anti-harasssment, and anti-retaliation policies.
  • Have a satisfactory work record for the two (2) years immediately prior to the closing date of this posting (unless if current student or recent graduate), including overall employment, job performance, discipline, and safety records (infractions and/or offenses occurring after the closing of the posting and before the filling of a vacancy may preclude a candidate from consideration for selection).
  • Ability to pass a Criminal Offender Record Information (CORI) check, comprehensive background screening, and / or medical Clinic screening, potentially including physical examination and drug and alcohol screenings.
  • Ability to work all shifts and / or locations assigned, directed, or necessary for this position, including (for some transit / operations roles) up to twenty-four (24) hours per day, seven (7) days per week as necessary to accommodate severe weather conditions, emergencies, or any other circumstances that may potentially impact service or the safety of service.
  • Intern / co-op staff must be enrolled full or part-time in an accredited educational program and maintain a cumulative GPA of at least 2.5 for the entire duration of the internship / co-op. Additionally, interns / co-ops must have valid work authorization and U.S. Social Security Number prior to starting pre-employment screenings / pre-boarding, working in their positions, and throughout the duration of
Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the GRC Analyst in Boston, MA vacancy
  • The TeamThe Analyst Governance, Risk, and Compliance, a member of the Information Security - Governance, Risk and Compliance (GRC) team, focuses on implementing and maintaining governance frameworks, managing risk remediation activities, and ensuring adherence to regulatory... 
    Suggested
    Work experience placement
    Work at office
    Local area

    American Tower

    Boston, MA
    4 days ago
  • $130k - $170k

     ...Senior Governance, Risk, and Compliance Analyst At WHOOP, we are on a mission to unlock human performance and extend healthspan. The Governance, Risk, and Compliance (GRC) team helps ensure technology and cybersecurity risks are identified, assessed, and communicated... 
    Suggested
    Full time
    Work at office
    Relocation

    WHOOP

    Boston, MA
    4 days ago
  • $90k - $110k

     ...Governance, Risk, and Compliance Analyst The Governance, Risk, and Compliance (GRC) Analyst is a strategic and critical role that closely collaborates with the Senior Director, Information Security on expanding and supporting the company's brand-wide governance, risk... 
    Suggested
    Work at office
    Remote work
    Work from home

    Planet Fitness

    Boston, MA
    3 days ago
  • $120k - $150k

     ...than 50 different countries and cultures and together we are creating the future of insurance. Learn more at As a Senior GRC Analyst, you will be a cornerstone of Shift’s security program, responsible for developing, maintaining, and assessing our integrated... 
    Suggested
    Permanent employment
    Full time
    Contract work
    Apprenticeship
    Work experience placement
    Internship
    Remote work
    Flexible hours
    Shift work

    Shift Technology

    Boston, MA
    3 days ago
  •  ...participation, and contribution in local safety committee meetings as needed. Job Summary The Governance, Risk, and Compliance (GRC) Analyst is responsible for identifying, assessing, monitoring, and mitigating organizational risks while ensuring compliance with... 
    Suggested
    Full time
    Part time
    Internship
    Local area
    Immediate start
    Remote work
    All shifts

    MBTA

    Boston, MA
    3 days ago
  • The Team The Analyst Governance, Risk, and Compliance, a member of the Information Security - Governance, Risk and Compliance (GRC) team, focuses on implementing and maintaining governance frameworks, managing risk remediation activities, and ensuring adherence to regulatory... 

    American Tower Global

    Boston, MA
    4 days ago
  • $100k - $140k

     ...performance and extend healthspan. The Governance, Risk, and Compliance (GRC) team helps ensure technology and cybersecurity risks are...  ....WHOOP is seeking a Governance, Risk, and Compliance Analyst II, to lead the day-to-day operation and support the ongoing risk... 
    Full time
    Work at office
    Relocation

    WHOOP

    Boston, MA
    13 hours ago
  • $90k - $200k

    Senior Manager, Financial Investigations Kroll's North American Investigations, Diligence and Compliance practice is seeking a Senior Manager based in the U.S. This is a wide-ranging role in the Financial Investigations team. The Senior Manager will develop and manage...
    Temporary work
    Flexible hours

    Kroll

    Boston, MA
    2 days ago
  • $160k - $190k

     ...related to regulatory adoption or compliance changes Audit or certification readiness Familiarity or direct experience with GRC/Cybersecurity solutions, tools and technologies Control design or maturation for high-demand technical areas such as ERP, Identity... 
    Permanent employment

    SEI

    Boston, MA
    3 days ago
  • $109.04k - $163.56k

    Sr Risk Analyst - KR07DEWe’re determined to make a difference and are proud to be an insurance company that goes well beyond coverages and policies. Working here means having every opportunity to achieve your goals - and to help others accomplish theirs, too. Join our team... 
    Full time
    Temporary work
    Work at office
    3 days per week

    The Hartford Financial Services Group

    Boston, MA
    2 days ago
  • $110k - $140k

    At Franklin Templeton, we believe success is built through powerful partnerships. As a forward thinking asset manager, we build dynamic relationships with clients, understand their goals, and navigate complex markets together. We leverage cutting edge strategies and deep...
    Work at office
    Local area
    3 days per week

    Franklin Templeton

    Boston, MA
    3 days ago
  •  ...is committed to your professional growth? Look no further! Join us at Gallagher Re and fast-track your career as a Catastrophe Risk Analyst through our REACH Program.This is a 24-month structured learning and development program that will equip upcoming and recent... 
    Full time
    Work experience placement
    Internship
    Work at office
    Local area
    Remote work
    Home office

    Arthur J. Gallagher & Co.

    Boston, MA
    3 days ago
  • $154.4k - $242.55k

    By clicking the “Apply” button, I understand that my employment application process with Takeda will commence and that the information I provide in my application will be processed in line with Takeda’s Privacy Notice and Terms of Use. I further attest that all information...
    Minimum wage
    Temporary work
    Local area
    Remote work
    Worldwide

    Takeda

    Boston, MA
    2 days ago
  • $170.9k - $231.3k

    OverviewThe Associate Director of Regulatory Affairs Strategy will work on assigned programs with the respective Global Regulatory Portfolio Lead, Global Regulatory Lead and cross-functional team to lead and define the regulatory strategy, facilitate submission of data ...
    Full time
    Temporary work
    Local area
    Worldwide
    Flexible hours
    2 days per week

    Alnylam Pharmaceuticals

    Cambridge, MA
    2 days ago
  • $161.6k - $242.4k

    Job DescriptionGeneral Summary:The Regulatory Labeling Associate Director will be responsible for strategic labeling and for executing on one or more products either at the global label-level (CCDS, USPI, EuSmPC) or in multiple ROW countries/regions for a given therapeutic...
    Full time
    Summer work
    Work at office
    Remote work
    Flexible hours
    2 days per week

    Vertex Pharmaceuticals

    Boston, MA
    3 days ago
  • Company DescriptionBy working at Harvard University, you join a vibrant community that advances Harvard's world-changing mission in meaningful ways, inspires innovation and collaboration, and builds skills and expertise. We are dedicated to creating a diverse and welcoming...
    Work at office
    Local area

    Harvard University

    Cambridge, MA
    2 days ago
  • $119k - $193k

     ...future.About This Role:Forrester is currently looking for a Senior Analyst to conduct research and deliver strategic advice for risk...  ...Expertise in compliance management, internal or external audit, and GRC platforms is strongly desired.The successful candidate researches... 
    Full time
    For contractors
    Remote work

    Forrester Research

    Cambridge, MA
    2 days ago
  •  ...consulting services to insurers, reinsurers, brokers, and other financial intermediaries. We're looking for a Risk Consultant or Risk Analyst to join our Consulting and Client Service Team, based in Boston, MA. In this role, you will build client relationships based on... 
    Work at office

    Verisk Analytics

    Boston, MA
    1 day ago
  • Job Description Job Description Associate Director, Global RA Labeling Lead – W2 - BB1309 BB10309 Cambridge, MA 6+ Months *Onsite Requirement: 2 days a week; Tuesdays & Thursdays *Occasional Need: Participation in early-morning meetings, such as at 7:...
    2 days per week
    Early shift

    TechData Service Company LLC

    Cambridge, MA
    3 days ago
  • QUALIFICATIONSMaster’s degree in quantitative fields such as mathematics, statistics, analytics, computational finance, computer science, economics, financial engineering, physics, or another relevant field2+ years of hands-on experience in quantitative modeling using advanced...
    Apprenticeship
    Work at office
    Easy work

    McKinsey & Company

    Boston, MA
    2 days ago
  • $160k - $180k

     ...Risk Audit & Compliance (GRAC) team as a Technology Senior Risk Analyst. In this newly created role, the Technology Senior Risk Analyst...  ...experience in Technology risk, Technology audit/compliance, or cyber GRC.Experience running RCSAs, defining KRIs/KPIs, and presenting... 
    Temporary work
    Flexible hours

    Berkshire Hathaway Specialty Insurance

    Boston, MA
    2 days ago
  • Greenberg Traurig (GT), a global law firm, has an exciting full‑time employment opportunity for an IT Third Party and Compliance Analyst in the Technology Department of various office locations. We offer competitive compensation and an excellent benefits package. Position... 
    Full time
    Work experience placement
    Work at office

    100KCrossing

    Boston, MA
    1 day ago
  • QUALIFICATIONSBachelor's degree required, advanced degree(s) and or applicable professional certifications preferred; Juris Doctor preferred8+ years professional experience in legal, regulatory, compliance environments; attorneys with “Big Law” and/or in house experience...
    Apprenticeship
    Work at office

    McKinsey & Company

    Boston, MA
    2 days ago
  • $180k - $245k

    OverviewMonte Rosa Therapeutics is seeking an experienced and strategic Director of Regulatory Affairs to lead and support global regulatory efforts across our development programs, with a focus on immunology. The ideal candidate will be responsible for developing and executing...

    Monte Rosa Therapeutics

    Boston, MA
    2 days ago
  • Reference: 630467Posted: 2026-09-09Location: Cambridge, MassachusettsCompany: Planet Pharma GroupContact: ApplicationsEmail: ****@*****.***: Watertown, MA - Hybrid, 2-3 days/week onsiteReports to: Chief Medical OfficerPosition SummaryThis individual...
    2 days per week
    3 days per week

    Planet Pharma

    Cambridge, MA
    3 days ago
  • $150k - $170k

     ...We are seeking an experienced and strategic Senior Cyber Risk Analyst to join our team. This role requires deep expertise in enterprise...  ...compliance frameworks (SOC 2, ISO 27001, NIST 800-53) Experience with GRC (Governance, Risk, and Compliance) platforms Understanding of... 
    Contract work
    Work at office
    Local area
    Remote work
    Work from home
    3 days per week

    Informa

    Newton, MA
    3 days ago
  • $110k - $160k

    Compliance Manager Position, $110,000 - $160,000, discretionary annual bonusSenior professionals with 10+ years may command higher compensation Boston, MA Downtown Financial District, Partial HybridPrincipals ONLY, No Visa Sponsorship availablePosition SummaryWe are seeking...
    Work at office
    Local area
    Visa sponsorship

    BlueSkyClarity

    Boston, MA
    2 days ago
  • $136.5k - $270k

    In this role, you'll make an impact in the following ways:Lead and manage a regional Financial Reporting organization, providing strategic oversight of client relationships and ensuring exceptional service delivery across the jurisdiction.Develop and execute business plans...
    Temporary work
    Worldwide
    Flexible hours

    The Bank of New York Mellon

    Boston, MA
    3 days ago
  • About the OpportunityAn innovative neuropsychology company is seeking an experienced and strategic regulatory leader to join a growing biotechnology organization advancing innovative therapies for patients with significant unmet medical needs. This individual will play ...

    GQR

    Boston, MA
    3 days ago
  • $177k - $278.08k

    By clicking the “Apply” button, I understand that my employment application process with Takeda will commence and that the information I provide in my application will be processed in line with Takeda’s Privacy Notice and Terms of Use. I further attest that all information...
    Minimum wage
    Temporary work
    Local area
    Remote work
    Worldwide

    Takeda

    Boston, MA
    2 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to GRC Analyst. Be the first to apply!

Related searches