Governance, Risk & Compliance (GRC) Analyst
DataStaff, Inc.
DataStaff Inc is seeking an experienced Governance, Risk & Compliance (GRC) Analyst to support and independently lead cybersecurity governance, risk, and compliance initiatives across a complex technology environment for our client in Morrisville, NC.
Job Description
This position will play an important role in strengthening the organization's risk management practices, control environment, audit readiness, and overall security governance program.
The ideal candidate combines hands-on GRC experience with enough technical understanding to evaluate controls across modern cloud, SaaS, API, distributed-system, and DevSecOps environments. This person must be comfortable working independently while partnering with stakeholders across Information Security, IT, Product, Legal, Privacy, Procurement, Finance, HR, Audit, and other business functions.
Successful candidates should demonstrate strong risk-based judgment, consultative communication, stakeholder influence, ownership, and continuous improvement. The position requires someone capable of independently managing complex workstreams while creating repeatable processes, templates, mappings, and guidance that improve the maturity and consistency of the GRC program.
Key Responsibilities
- Lead cybersecurity risk assessments, maturity assessments, framework gap analyses, and control-mapping exercises, developing well-supported findings and practical recommendations.
- Coordinate internal and external audits, certification activities, customer security and assurance requests, evidence collection, and related compliance activities.
- Manage remediation efforts from identification through resolution, including issue tracking, exceptions, evidence reviews, corrective actions, and cross-functional follow-up.
- Develop and maintain security policies, standards, procedures, control mappings, governance templates, assessment methodologies, and other reusable GRC documentation.
- Support the organization's third-party risk management program, including vendor due diligence, risk assessments, documentation reviews, remediation follow-up, and ongoing monitoring.
- Partner with technical and business stakeholders to evaluate control requirements, risk treatment strategies, compensating controls, exceptions, and corrective actions.
- Evaluate the design, applicability, and operating effectiveness of security controls across technology environments.
- Develop dashboards, metrics, management reports, and status updates that provide visibility into risks, remediation efforts, compliance activities, and program performance.
- Help improve GRC processes, methodologies, documentation, and overall audit readiness.
- Provide guidance and mentoring to less-experienced team members when appropriate.
Required Experience & Qualifications
- 5–8 years of relevant professional experience in cybersecurity GRC, information security risk management, internal audit, compliance, third-party risk, privacy, control assurance, or a closely related discipline.
- At least 2 years of hands-on experience performing risk or control assessments, framework mapping, control reviews, audit coordination, remediation management, or similar GRC activities.
- Demonstrated ability to independently lead work across multiple programs, systems, products, security/control domains, frameworks, or stakeholder groups.
- Strong understanding of cybersecurity governance, risk management, compliance practices, security policies, control frameworks, control taxonomies, issue management, evidence management, and exception processes.
- Working knowledge of technical security controls and modern SaaS, cloud, API, distributed-system, and DevSecOps environments sufficient to assess control design and effectiveness.
- Experience coordinating audits and reviewing evidence for completeness and sufficiency.
- Experience creating policies, standards, procedures, control mappings, assessment documentation, dashboards, and management reporting.
- Strong analytical and risk-based decision-making skills, including the ability to develop practical recommendations when requirements or circumstances are ambiguous.
- Ability to communicate GRC and security concepts effectively to both technical and non-technical audiences.
- Demonstrated ability to influence stakeholders and drive issues toward resolution without relying on direct authority.
- Bachelor's degree in Cybersecurity, Information Systems, Business, Accounting, Risk Management, Public Policy, or a related discipline, or an equivalent combination of directly relevant education and professional experience.
Preferred Qualifications
- Experience within B2B SaaS, healthcare, regulated industries, cloud-based organizations, or multi-product technology environments is preferred.
- Candidates with experience developing formal GRC documentation—including policies, standards, control mappings, assessment procedures, governance templates, audit packages, and executive/management reporting—will be particularly relevant.
- Professional certifications are also desirable, including CISA, CRISC, CISM, CISSP, ISO 27001 Lead Implementer, ISO 27001 Lead Auditor, or relevant certifications in third-party risk, privacy, or auditing.
- Experience mentoring other analysts or leading a significant audit, certification, product compliance, third-party risk, or remediation initiative is also preferred.
This opportunity is available on a corp to corp basis or as a W2 position with a competitive benefits package. DataStaff, Inc. offers medical, dental, and vision coverage options as well as paid vacation, sick, and holiday leave. As many of our opportunities are long-term, we also have a 401k program available for employees after 6 months.
- ...Job Description: Senior Information Security GRC Analyst Department: Information Security Job Title: Senior Information Security Governance, Risk, and Compliance (GRC) Analyst Reports To: Information Security GRC Manager / Head of Information Security Location...SuggestedContract workWork at officeRemote work
- ...for this position.Do you want to help shape the future of AI governance and risk management across the enterprise?The AI Center of... ...organization.You will work closely with business, technology, risk, compliance, cybersecurity, and audit partners to identify, assess, and...SuggestedFull time
- Join to apply for the Junior GRC Risk Analyst role at Jobright.ai . Jobright is an AI-powered career platform that helps job seekers discover... ...and security solutions. The GRC Risk Analyst will conduct compliance assessments, develop policies, and manage risks, ensuring...SuggestedFull time
$145k - $165k
...position ensures the legal, regulatory, operational, and risk management compliance of Human Resources programs, policies, practices, and systems... ..., including employment-related regulations, HR policy governance, regulatory change management, data privacy requirements,...SuggestedRemote work- ...individual in this position is responsible for administering a compliance program in conjunction with a Chief Compliance Officer,... ...and Pet Insurance. About ACA: ACA Group is the leading governance, risk, and compliance (GRC) advisor in financial services. We empower our clients...SuggestedSummer workCasual workWork at officeRemote workFlexible hours2 days per week
$220k - $270k
...motivated individual to serve as Global CDMO Compliance Officer for its FUJIFILM Biotechnologies... ...manage new and evolving compliance risks.This individual will support the leadership... ...of applicable laws, regulations, government guidance, industry codes, FUJIFILM Holdings...Contract workLocal areaFlexible hours- ...Job Description The Director of Governance and Risk will report to the CISO within Advance Auto Parts and will focus on the defining and... ...will oversee cybersecurity policy, standards, procedures, compliance, ensuring the company adheres to relevant regulations, industry...Contract workTemporary workWork at officeLocal areaRemote work1 day per week
$60k - $75k
...Opportunity: The AML/KYC Senior Analyst supports the day-to-day... ...gaps, escalating risk triggers, and maintaining... ...~2–4 years of AML/KYC, compliance, or financial services experience... ...ACA Group is the leading governance, risk, and compliance (GRC) advisor in financial services...Full timeSummer workWork at officeFlexible hours$220.9k - $291.5k
...with limited exceptions.”Meet the TeamThe Regulatory Affairs & Compliance team within Cisco’s Legal department is comprised of lawyers, program... ...that identify, mitigate, and monitor legal and regulatory risks as aligned with business objectives, ethical standards, and...Full timeTemporary workWork at officeLocal areaFlexible hours$160k - $200k
...OpportunityThe Director, Head of Compliance Technology, is accountable... ...enable regulatory, governance, and operational objectives.The... ...architecture, information security, risk management, operations, and external... ...product managers, business analysts, engineers, and delivery...Full timeContract workTemporary workWork at officeLocal areaWorldwideRelocation package3 days per week- ...:Title: Principal Technology Risk AnalystNote: Fidelity will not... ...control documentation and governance practicesOverseeing control certification... ...and supporting SOX 404 compliance, including control... ...Governance, Risk, and Compliance (GRC) tools, such as Archer is preferredYour...Full time
- Join us at Towne Insurance! Your Career. Your Future. Your Towne. Towne Insurance is hiring a Commercial Lines Risk Advisor to join our Raleigh, NC team. This is a sales oriented position, requiring advanced communication skills, a thorough knowledge of the insurance products...Full timeWork at office
$136k - $170k
...following job description:The Operational Risk Management Programs Risk Officer II-Fraud... ...monitor fraud issue remediations using GRC tools and report status updates to management... ...rigor and discipline focused on risk and compliance awareness, ethical business practices,...Full timePart timeWork at officeShift workDay shift- ...ongoing growth and success. WHAT WE’RE LOOKING FOR The Risk Advisor is responsible for new insurance account production and... ...a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various...Full timeWork at officeLocal area
- ...description:First line of defense risk professional within the... ...: Credit, Market, Liquidity, Compliance, Operational, Reputation and... ...change.Strong quantitative, governance, and analytic abilities.Ability... ...Manager (FRM)/Certified Financial Analyst (CFA) or equivalent advanced...Full timePart timeWork at officeShift workNight shiftDay shift
$91k - $202.8k
...the company’s success. As a(n) Technology Risk Advisor within PNC's Technology Risk... ...Information Security, Operational Risk, Audit, Compliance, Finance, and Enterprise Risk Management... ...· Regulatory expectations for model governance and risk measurement· Industry...Full timeTemporary workPart timeWork experience placementWork at office- ...highly skilled Senior Identity Governance & Administration (IGA) Analyst to lead the administration... ...) processes, and ensuring compliance with multiple regulatory... ...solutions that reduce risk while improving operational... ...privacy, and other relevant GRC areas.All applicants must...Full timePart timeWork experience placementRelocationVisa sponsorshipFlexible hours
$100k
...Compliance ManagerRelay is the Intelligent System of Action for the physical economy. While... ...DSS — and serve as our Drata expert, the GRC platform at the center of everything we do... ...policy lifecycle, and third-party vendor risk program will all be yours. And because compliance...- A leading consulting firm located in Cary, North Carolina seeks an IT Business Analyst with over a year of experience. Key responsibilities include running monthly security reports, establishing reporting schedules, and contributing to security vendor relationships. The...Work at office
- ...experience level and expertise. The Ipas Network Risk Service Node is responsible for... ...internal audit, and ethics. The Network Risk Analyst plays a critical role in strengthening... ...risks affecting program delivery, donor compliance, safeguarding commitments, and strategic...Work at officeLocal areaRemote work
$87.5k - $202.8k
...contribute to the company’s success. As a Credit Risk Review Advisor within PNC's Independent... ...quality, ongoing monitoring, and policy compliance; identifying emerging risks and trends;... ..., Loan Review, Organizational Governance, Regulatory Environment - Financial ServicesWork...Full timeTemporary workPart timeWork experience placementWork at office- ...Private Risk Advisor The USI Insurance Services Personal Risk Practice provides comprehensive risk management and insurance consultation to high net worth individuals and family offices with complex financial and insurance needs. The Private Risk Advisor is an outside...Temporary workWork at officeLocal areaFlexible hours
- ...Surety Risk Advisor Join us at Towne Insurance! Your career. Your future. Your Towne. Towne Insurance is hiring a Surety Risk Advisor in Raleigh, North Carolina. This is a sales-oriented position, requiring advanced communication skills, a thorough knowledge of...Work at office
$144k - $180k
...second-line-of-defense (LoD2) Technology Risk team responsible for independent risk... ...other related risks (e.g., operational, compliance) within Enterprise Technology. 2. Serve... ...Tableau). 5. Familiarity with enterprise Governance Risk and Compliance (eGRC) platforms and...Full timePart timeWork at officeShift workDay shift- DescriptionPosition Overview:The Compliance Operations Manager executes the day-to-day operations of Mayne Pharma's Compliance & Risk Program. Working closely with business stakeholders... ...national, state and local laws governing nondiscrimination in employment as well...Casual workLocal area
$105.4k - $207.8k
Position Summary Cyber Security & Risk Strategy Senior Consultant Our Deloitte... ...models, including organizational structure, governance, roles and responsibilities, and process... ...with governance, risk, and compliance tools, identity and access management solutions...Local areaVisa sponsorship$82.24k - $133.64k
...empower the American dream. How This Role Impacts Live Oak And Its People As a Model Risk Analyst , you help ensure Live Oak's models and AI-enabled solutions are sound, well-governed, and aligned with business objectives and regulatory expectations. Working within the...Work experience placement- ...Description Business Operations Analyst The Company: Varonis (Nasdaq: VRNS) is a... ...(DSPM), data classification, data access governance (DAG), data detection and response (DDR), data loss prevention (DLP), and insider risk management. Varonis protects data first...Work experience placementWork at officeRemote workWorldwide
$113k - $188.4k
...Analytics and Insights Engineer III on the project, you will:Support risk adjustment analytics, data validation, and business analysis... ...to provide clear guidance to othersThe teamDeloitte’s Government & Public Services (GPS) practice - our people, ideas, technology...Local area- ...providing clear guidance on their obligations, label use, and compliance responsibilities. Cascade changes from the basic registrations... ...distribution, providing early warning to the business on risks, restrictions, and opportunities. Drive process efficiency and...Permanent employmentFull time
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Governance, Risk & Compliance (GRC) Analyst. Be the first to apply!



