Sr. GRC Analyst
$105k - $135kAya Healthcare
Join Aya Healthcare, winner of multiple Top Workplace awards!
We are seeking a Senior Governance, Risk & Compliance (GRC) Analyst to help operate and mature Aya’s enterprise GRC program, with a strong emphasis on compliance automation, scalability, and operational excellence. In this role, you will own GRC projects and deliverables across the organization while serving as a subject-matter expert in compliance operations, risk management, and ServiceNow GRC / IRM.
This is a hands-on opportunity for someone energized by improving modern GRC capabilities and moving away from manual, point-in-time audit work toward automated, continuously operating compliance processes.
You will work cross-functionally across Information Security, IT, Legal, Privacy, Engineering, Finance, and Audit to translate regulatory and framework requirements into practical controls, improve evidence collection and reporting, and deliver clear, actionable insights to stakeholders and leadership.
You will work in the Security organization and report to the Manager, Governance, Risk & Compliance.
This role is remote and will work PST business hours.
Who We Are:
We’re an $8+ billion, rapidly growing workforce solutions provider in the healthcare industry. We deliver tech-enabled services that help healthcare organizations meet and manage their contingent labor needs. We build and manage tech-enabled marketplaces for national and local healthcare talent and deliver contingent labor management solutions through our proprietary software platform.
At Aya, we’re obsessed with creating exceptional experiences for our clients, clinicians, and employees. In fact, we put employee satisfaction above all else. Our team members are responsible for incomparable customer experience and we know that happy employees are critical to maintaining happy clients. We foster an entrepreneurial, high-energy, low-bureaucracy culture and value innovative thinking and creative problem-solving. We embrace diversity in thought and backgrounds unified by a commitment to high achievement. When you join Aya, you’ll be surrounded by teammates who care about you as an individual and leaders who will help you grow both personally and professionally.
Responsibilities:
- Own assigned GRC projects, compliance deliverables, and process improvements from planning through completion.
- Support the day-to-day operation and continuous improvement of Aya’s enterprise GRC program.
- Design and improve scalable workflows that translate regulatory and framework requirements into clear control activities and operational responsibilities.
- Support compliance efforts for SOC 2 and ISO/IEC 27001:2022, including readiness activities, audit preparation, evidence coordination, control testing, auditor support, and remediation tracking.
- Establish and maintain clear control ownership, traceability, documentation, and evidence requirements.
- Identify opportunities to replace manual or spreadsheet-driven compliance activities with automated, system-driven processes.
- Improve automated evidence collection, control testing, issue and remediation tracking, dashboards, and reporting.
- Conduct control reviews, risk assessments, evidence evaluations, and compliance gap analyses.
- Monitor remediation activities, follow up with control owners, identify delivery risks, and escalate issues when appropriate.
- Build and maintain dashboards, metrics, and reports that communicate compliance status, trends, exceptions, risks, and remediation progress.
- Partner with ServiceNow platform and engineering teams to ensure GRC solutions are scalable, supportable, and aligned with enterprise processes.
- Engage with customers to respond to compliance, security, privacy, and risk-related questions in RFPs, due diligence requests, contracts, and customer meetings.
- Collaborate with Security, IT, Engineering, Finance, Legal, Privacy, Internal Audit, and business stakeholders to resolve control and compliance issues.
- Translate risk and compliance requirements into clear, business-relevant guidance that enables teams to take action.
- Lead working sessions, walkthroughs, and process discussions with control owners and subject-matter experts.
- Identify emerging risks, process dependencies, and long-term improvement opportunities within the GRC domain.
- Guide and support junior analysts and teammates through collaboration, knowledge sharing, and example.
- Review work products for accuracy, completeness, and alignment with established quality standards.
- Document process improvements, design decisions, procedures, and lessons learned.
Required Qualifications:
- 4+ years of experience in Governance, Risk, and Compliance, Information Security, IT Audit, or a related discipline.
- Hands-on experience operating or configuring GRC tools such as ServiceNow GRC / IRM, Drata, Vanta, or Hyperproof to automate and manage compliance workflows.
- Demonstrated experience owning GRC projects, compliance deliverables, or process-improvement initiatives from planning through completion.
- Strong working knowledge of SOC 2 or ISO/IEC 27001:2022. Familiarity with HIPAA and other healthcare-related compliance requirements is preferred.
- Experience with control design, evidence evaluation, risk assessments, audit support, remediation tracking, or compliance testing.
- Experience improving manual compliance processes through automation, workflow design, or system-based reporting.
- Strong written and verbal communication skills, with the ability to explain risk and compliance concepts to both technical and non-technical audiences.
- Demonstrated ability to work independently, manage competing priorities, anticipate next steps, and escalate risks early.
- Experience collaborating across Information Security, IT, Engineering, Legal, Privacy, Finance, Audit, and business teams.
- Bachelor’s degree in IT / CS is preferred.
- CISA, CISSP (or CISSP Associate), CCSP, ISO 27001 credential, or another relevant security or compliance certification is preferred.
- Experience with additional security, compliance, AI governance, and privacy frameworks or regulatory requirements, such as ISO/IEC 42001, NIST AI RMF, NIST CSF, GDPR/UK GDPR, and CCPA/CPRA, is a plus.
- Experience with ServiceNow GRC / IRM implementation, administration, configuration, or integration is preferred.
- Experience developing GRC metrics, dashboards, key performance indicators, or leadership reporting is preferred.
- Experience supporting internal or external audits in a regulated or healthcare-related environment is preferred.
Core Role Criteria:
- GRC Subject-Matter Expertise: Demonstrates deep knowledge within GRC and understands how compliance activities affect related security, technology, privacy, legal, and business processes.
- Project and Outcome Ownership: Owns assigned outcomes end to end, delivers high-quality work, and holds self and project participants accountable for commitments.
- GRC Tool Capability: Experience with modern GRC tools such as ServiceNow, Drata, or Vanta. Experience with ServiceNow GRC / IRM beyond basic end-user activity is preferred.
- Compliance Automation Mindset: Identifies opportunities to reduce manual effort and validates automation or process improvements through measurable results.
- Analytical Judgment: Evaluates evidence, identifies control gaps and emerging risks, understands dependencies, and recommends practical solutions.
- Cross-Functional Collaboration: Builds effective working relationships and guides stakeholders through compliance requirements using clear, business-relevant language.
- Strategic Orientation: Understands emerging risks and long-term trends within GRC and connects day-to-day work to broader organizational objectives.
- Informal Leadership: Leads projects from start to completion and guides teammates through collaboration, knowledge sharing, and example without requiring formal management authority.
- Delivery and Initiative: Manages work independently, anticipates next steps, improves processes, and delivers projects on schedule.
What We Offer:
- Free premium medical, dental, life and vision insurance
- Generous 401(k) match
- Aya also offers other benefits to those that are eligible and where required by applicable law, including reimbursements and discretionary bonuses
- Aya provides paid sick leave in accordance with all applicable state, federal, and local laws. Aya’s general sick leave policy is that employees accrue one hour of paid sick leave for every 30 hours worked. However, to the extent any provisions of the statement above conflict with any applicable paid sick leave laws, the applicable paid sick leave laws are controlling
- Celebrations! We hit our goals and reward ourselves.
- Company-sponsored virtual events, happy hours and team-building activities are always on the horizon — plus, you get a special treat on your birthday!
- Unlimited DTO — we believe in time off!
- Virtual yoga, meditation or boot camp classes offered daily
Compensation : Aya reasonably anticipates the pay scale for this position to be an annual salary of $105,000 to $135,000.
The pay scale for this position may vary if applicant possesses experience outside of what Aya reasonably anticipates for this position. Bonuses are subject to the role and your manager’s discretion.
Aya is an Equal Opportunity Employer (EEO), including Disability / Vets, and welcomes all to apply. Please click herefor our EEO policy
- ...billion gallons of propane from 1,800+ distribution points across the United States.Job Summary:The Global Cybersecurity Senior GRC Analyst plays a critical role in ensuring that the organization operates within its regulatory, legal, and compliance obligations while managing...SeniorFor contractors
$115k - $125k
...Contract-to-HireCategory: Information TechnologyReference ID: 10081639Job record: a1qPL000008IyU9YAKValid through: 2027-09-15Senior GRC Analyst Industry: Professional Services / Information SecurityLocation: Chicago, ILWork Schedule: Hybrid - Onsite Monday, Wednesday &...SeniorContract workTemporary workLocal areaFlexible hours$95k - $105k
...Job Description Job Description Sr. GRC Analyst About Subsplash Subsplash is an exciting award-winning team of 280+ mission-driven people who are committed to our core values of humility, innovation, and excellence. Founded in 2005, we've remained family owned and...SeniorTemporary workCurrently hiringRemote workRelocation- Sr. Governance, Risk & Compliance (GRC)Analyst Newly created seat on a small, growing GRC team inside a global engineering and construction organization. The security program is early in its maturity curve — policies and standards are being rewritten this year, and risk...SeniorContract workH1bImmediate start
- ...Our client is seeking a Senior Information Security GRC Analyst to support and advance their Information Security Governance, Risk, and Compliance (GRC) program. In this role, the selected candidate will assess and strengthen IT and security controls across the organization...Senior
$80.05k - $165k
...end-to-end issue management activities, including intake, validation, prioritization, assignment, remediation tracking, and closure of GRC-related issues in ServiceNow, ensuring timely resolution, appropriate evidence, and alignment with audit, risk, and regulatory...SeniorFull timeWork at office- ...To support the security program, the full-time Senior GRC Analyst will develop, maintain, and assess an integrated security and privacy management framework while managing compliance with industry standards and leading risk assessments, all in a remote capacity for candidates...SeniorFull timeWork experience placementRemote work
$142k - $220.5k
...want to meet you.Ditch the old-school “box-checking” mentality — that's not us. Join the Governance, Risk, and Compliance (GRC) team as a Senior Analyst on the Compliance Assessment team, where you'll own the Common Control Framework (CCF) from the ground up: maturing it,...SeniorFull timeWork experience placementWork at office$138k - $173k
THE POSITIONOur roster has an opening with your name on itFanDuel is seeking a Senior Technology Governance, Risk & Compliance (GRC) Analyst to join its Technology GRC team as a strategic specialist supporting our first line of defense (1LOD) function. This role offers...SeniorTemporary workWork at officeLocal areaWorldwideShift work- ...The Senior IT GRC Analyst leads policy development and audit execution within CMG's IT Governance, Risk, and Compliance program, with particular emphasis on CMG's upcoming SOC 2 readiness effort. This role works closely with the GRC team and the broader IT department to...SeniorWork at officeRemote work
$175k
...deployment, turning real-world deployment signals into better data, evaluations, and more capable models. Learn more at Senior GRC Analyst About the role We're looking for a Senior GRC Analyst to help run our governance, risk, and compliance program day to...SeniorRemote work- ...The Role We Want You For Under the direction of and in collaboration with the GRC Manager, the Sr. GRC Analyst, Third-Party & Human Risk Management (TPHRM) is a risk focused, highly analytical role that ensures all human and third‑party risk to Clayco is identified, quantified...SeniorImmediate startFlexible hours
- Nordstrom is seeking a Senior Analyst for the Governance, Risk and Compliance (GRC) program. You will own the Common Control Framework (CCF) from inception, mature it, run it, and test control effectiveness in a scalable, AI-enabled environment. This role requires cross...SeniorWork at office
- UT Southwestern Medical Center seeks a Senior Governance Risk Compliance Analyst to lead information security governance, risk management, and compliance for the Texas Behavioral Health Center program. This role applies NIST, HIPAA, PCI standards and coordinates enterprise...Senior
- BERRY Appleman & Leiden (BAL) is seeking a GRC/Information Security professional to lead internal audits and manage ISO 27001/27701 programs from its Richardson, TX location. You’ll drive risk-based audits, support privacy operations, and help shape AI governance and vendor...Senior
- Gilder Search Group is looking for a Sr. GRC Analyst focusing on Third-Party & Human Risk Management in Atlanta, Georgia. This role involves risk analysis, compliance assessments, vendor management, and developing security awareness training. The ideal candidate has 6-8...Senior
- ...About the Role Hotman Group is a boutique cybersecurity and GRC consulting firm doing meaningful work for clients who need GRC... ...months. What You Will Do As an Experienced or Senior GRC Analyst at Hotman Group you will work directly with clients to help them...SeniorPermanent employmentFull timeContract workTemporary workRemote work
- ...Senior GRC Analyst Wolfe is a Pittsburgh-based FinTech company operating consumer gifting and payments brands, and we are actively embedding AI across our products, our internal processes, and the way our teams work day-to-day. As Senior GRC Analyst, you will be the...Senior
$93.8k - $121.8k
...have current authorization to work in the United States on a full-time basis.Reporting to the Manager or Sr.Manager, IT Risk and Compliance, the Senior GRC analyst will be responsible for supporting the day to day IT compliance, data governance, and IT risk management...SeniorFull timeWork at officeFlexible hours- ...entertainment related building projects. The Role We Want You For Under the direction of and in collaboration with the GRC Manager, the Sr. GRC Analyst, Risk Management is the primary owner and operational steward of the Enterprise Risk Register. This role is...SeniorFor contractorsImmediate startFlexible hours
$130k - $170k
...performance and extend healthspan. TheGovernance, Risk, and Compliance (GRC) team helps ensure technology and cybersecurityrisks are... ...seeking an execution-oriented Senior Governance, Risk, and Compliance Analyst tolead the day-to-day execution and support the ongoing...SeniorFull timeWork at officeRelocation$183k - $205k
...security governance, risk and compliance initiatives. This person will guide the company from foundational Governance, Risk & Compliance (GRC) maturity through to steady-state operations, leveraging AI to automate and improve old practices and tools, ensuring ongoing...SeniorFull timeWork at officeLocal area2 days per week3 days per week- Senior GRC Analyst job at Quantexa. New York, NY. What we’re all about. We find, when we come together in the pursuit of excellence, great things happen. And that’s how we do things at Quantexa - together. Our business is data, but our culture is collective. We’re about...SeniorContract workTemporary workWork experience placementImmediate start
$76k - $134k
...driven decisions, mitigate risks & deliver projects on time & within budget. Position Responsibilities Responsibilities: As a Senior GRC Analyst, you will support assessment, audit readiness, cloud security compliance, risk management, & security tooling across SaaS/cloud...SeniorContract workTemporary workFor contractors- Procore Technologies in Austin, TX is seeking a Senior Cybersecurity Risk Analyst to join the GRC organization. You will manage technical risk across the cloud and information assets, collaborating with security, engineering, IT and business teams. The role emphasizes AI...Senior
- ...site in either King of Prussia, PA or Denver, PA Our client is seeking a Senior Cybersecurity Governance, Risk & Compliance (GRC) Analyst to support cybersecurity governance, regulatory compliance, and risk management initiatives within a critical infrastructure environment...SeniorHourly payPermanent employmentFull timeLocal areaRemote work
- ...office presence required based on division responsibilities and business needs. This is not a remote position. The GRC Senior Regulatory Compliance Analyst, who has proficient knowledge in regulatory compliance rules and regulations will be responsible for assisting the...SeniorContract workWork at office1 day per week
$117.2k - $176.7k
To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts.Job CategoryEnterprise Technology & InfrastructureJob DetailsAbout SalesforceSalesforce is the #1 AI CRM, where humans with...SeniorFull time$57k - $113k
## Senior GRC Programmer/AnalystApplyremote type: Officelocations: Columbus, OH: Chicago, IL: Detroit, MI: Tupelo, MS: Charlotte... ...TX* Detroit, MI* Chicago, IL* Charlotte, NC**Summary:** The Sr GRC Programmer/Analyst modifies existing software/application programs, which are...SeniorFull timeH1bWork at officeRemote workWork from homeFlexible hours$117.2k - $176.7k
To get the best candidate experience, please consider applying for a maximum of 3 roles within 12 months to ensure you are not duplicating efforts.Job CategoryEnterprise Technology & InfrastructureJob DetailsAbout SalesforceSalesforce is the #1 AI CRM, where humans with...SeniorFull time
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Sr. GRC Analyst. Be the first to apply!
- grc analyst United States
- senior facilities maintenance technician United States
- senior operations technician United States
- senior groundskeeper United States
- senior operations associate United States
- senior cloud service delivery manager United States
- senior it service manager United States
- senior project engineer United States
- senior chief engineer United States
- senior manufacturing supervisor United States



