Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Governance, Risk & Compliance (GRC) Analyst

DataStaff, Inc.

Job Description

DataStaff Inc is seeking an experienced Governance, Risk & Compliance (GRC) Analyst to support and independently lead cybersecurity governance, risk, and compliance initiatives across a complex technology environment for our client in Morrisville, NC.

\n

\n

Job Description

\n

This position will play an important role in strengthening the organization's risk management practices, control environment, audit readiness, and overall security governance program.

\n

The ideal candidate combines hands-on GRC experience with enough technical understanding to evaluate controls across modern cloud, SaaS, API, distributed-system, and DevSecOps environments. This person must be comfortable working independently while partnering with stakeholders across Information Security, IT, Product, Legal, Privacy, Procurement, Finance, HR, Audit, and other business functions.

\n

Successful candidates should demonstrate strong risk-based judgment, consultative communication, stakeholder influence, ownership, and continuous improvement. The position requires someone capable of independently managing complex workstreams while creating repeatable processes, templates, mappings, and guidance that improve the maturity and consistency of the GRC program.

\n

\n

Key Responsibilities

\n
    \n
  • Lead cybersecurity risk assessments, maturity assessments, framework gap analyses, and control-mapping exercises, developing well-supported findings and practical recommendations.
  • \n
  • Coordinate internal and external audits, certification activities, customer security and assurance requests, evidence collection, and related compliance activities.
  • \n
  • Manage remediation efforts from identification through resolution, including issue tracking, exceptions, evidence reviews, corrective actions, and cross-functional follow-up.
  • \n
  • Develop and maintain security policies, standards, procedures, control mappings, governance templates, assessment methodologies, and other reusable GRC documentation.
  • \n
  • Support the organization's third-party risk management program, including vendor due diligence, risk assessments, documentation reviews, remediation follow-up, and ongoing monitoring.
  • \n
  • Partner with technical and business stakeholders to evaluate control requirements, risk treatment strategies, compensating controls, exceptions, and corrective actions.
  • \n
  • Evaluate the design, applicability, and operating effectiveness of security controls across technology environments.
  • \n
  • Develop dashboards, metrics, management reports, and status updates that provide visibility into risks, remediation efforts, compliance activities, and program performance.
  • \n
  • Help improve GRC processes, methodologies, documentation, and overall audit readiness.
  • \n
  • Provide guidance and mentoring to less-experienced team members when appropriate.
  • \n
\n

\n

Required Experience & Qualifications

\n
    \n
  • 5–8 years of relevant professional experience in cybersecurity GRC, information security risk management, internal audit, compliance, third-party risk, privacy, control assurance, or a closely related discipline.
  • \n
  • At least 2 years of hands-on experience performing risk or control assessments, framework mapping, control reviews, audit coordination, remediation management, or similar GRC activities.
  • \n
  • Demonstrated ability to independently lead work across multiple programs, systems, products, security/control domains, frameworks, or stakeholder groups.
  • \n
  • Strong understanding of cybersecurity governance, risk management, compliance practices, security policies, control frameworks, control taxonomies, issue management, evidence management, and exception processes.
  • \n
  • Working knowledge of technical security controls and modern SaaS, cloud, API, distributed-system, and DevSecOps environments sufficient to assess control design and effectiveness.
  • \n
  • Experience coordinating audits and reviewing evidence for completeness and sufficiency.
  • \n
  • Experience creating policies, standards, procedures, control mappings, assessment documentation, dashboards, and management reporting.
  • \n
  • Strong analytical and risk-based decision-making skills, including the ability to develop practical recommendations when requirements or circumstances are ambiguous.
  • \n
  • Ability to communicate GRC and security concepts effectively to both technical and non-technical audiences.
  • \n
  • Demonstrated ability to influence stakeholders and drive issues toward resolution without relying on direct authority.
  • \n
  • Bachelor's degree in Cybersecurity, Information Systems, Business, Accounting, Risk Management, Public Policy, or a related discipline, or an equivalent combination of directly relevant education and professional experience.
  • \n
\n

\n

Preferred Qualifications

\n
    \n
  • Experience within B2B SaaS, healthcare, regulated industries, cloud-based organizations, or multi-product technology environments is preferred.
  • \n
  • Candidates with experience developing formal GRC documentation—including policies, standards, control mappings, assessment procedures, governance templates, audit packages, and executive/management reporting—will be particularly relevant.
  • \n
  • Professional certifications are also desirable, including CISA, CRISC, CISM, CISSP, ISO 27001 Lead Implementer, ISO 27001 Lead Auditor, or relevant certifications in third-party risk, privacy, or auditing.
  • \n
  • Experience mentoring other analysts or leading a significant audit, certification, product compliance, third-party risk, or remediation initiative is also preferred.
  • \n
\n

\n

This opportunity is available on a corp to corp basis or as a W2 position with a competitive benefits package. DataStaff, Inc. offers medical, dental, and vision coverage options as well as paid vacation, sick, and holiday leave. As many of our opportunities are long-term, we also have a 401k program available for employees after 6 months.

Vacancy posted 5 days ago
Similar jobs that could be interesting for youBased on the Governance, Risk & Compliance (GRC) Analyst in Morrisville, NC vacancy
  •  ...Join to apply for the Junior GRC Risk Analyst role at Jobright.ai . Jobright is an AI-powered career platform that helps job seekers discover...  ...and security solutions. The GRC Risk Analyst will conduct compliance assessments, develop policies, and manage risks, ensuring... 
    Suggested
    Full time

    jobright.com

    Durham, NC
    20 hours ago
  • $220k - $270k

     ...motivated individual to serve as Global CDMO Compliance Officer for its FUJIFILM Biotechnologies...  ...manage new and evolving compliance risks.This individual will support the leadership...  ...of applicable laws, regulations, government guidance, industry codes, FUJIFILM Holdings... 
    Suggested
    Contract work
    Local area
    Flexible hours

    FUJIFILM

    Morrisville, NC
    3 days ago
  •  ...individual in this position is responsible for administering a compliance program in conjunction with a Chief Compliance Officer,...  ...and Pet Insurance. About ACA: ACA Group is the leading governance, risk, and compliance (GRC) advisor in financial services. We empower our clients... 
    Suggested
    Summer work
    Casual work
    Work at office
    Remote work
    Flexible hours
    2 days per week

    ACA Group

    Durham, NC
    1 day ago
  • $220.9k - $291.5k

     ...with limited exceptions.”Meet the TeamThe Regulatory Affairs & Compliance team within Cisco’s Legal department is comprised of lawyers, program...  ...that identify, mitigate, and monitor legal and regulatory risks as aligned with business objectives, ethical standards, and... 
    Suggested
    Full time
    Temporary work
    Work at office
    Local area
    Flexible hours

    CISCO Systems

    Research Triangle Park, NC
    3 days ago
  • $160k - $200k

     ...OpportunityThe Director, Head of Compliance Technology, is accountable...  ...enable regulatory, governance, and operational objectives.The...  ...architecture, information security, risk management, operations, and external...  ...product managers, business analysts, engineers, and delivery... 
    Suggested
    Full time
    Contract work
    Temporary work
    Work at office
    Local area
    Worldwide
    Relocation package
    3 days per week

    Metropolitan Life Insurance Company

    Cary, NC
    2 days ago
  • Join us at Towne Insurance! Your Career. Your Future. Your Towne. Towne Insurance is hiring a Commercial Lines Risk Advisor to join our Raleigh, NC team. This is a sales oriented position, requiring advanced communication skills, a thorough knowledge of the insurance products... 
    Full time
    Work at office

    TowneBank

    Raleigh, NC
    13 hours ago
  •  ...controls and influencing risk outcomes at enterprise...  ...Technology Risk Analyst, you will play a critical...  ...across technology, risk, compliance, and audit organizations...  ...Azure, SaaS, PaaS) and GRC platforms such as Archer...  ...Fidelity’s business is governed by the provisions of the... 
    Full time

    Fidelity Investments

    Durham, NC
    5 hours ago
  • $136k - $170k

     ...following job description:The Operational Risk Management Programs Risk Officer II-Fraud...  ...monitor fraud issue remediations using GRC tools and report status updates to management...  ...rigor and discipline focused on risk and compliance awareness, ethical business practices,... 
    Full time
    Part time
    Work at office
    Shift work
    Day shift

    Truist

    Raleigh, NC
    5 hours ago
  • $91k - $202.8k

     ...the company’s success. As a(n) Technology Risk Advisor within PNC's Technology Risk...  ...Information Security, Operational Risk, Audit, Compliance, Finance, and Enterprise Risk Management...  ...· Regulatory expectations for model governance and risk measurement· Industry... 
    Full time
    Temporary work
    Part time
    Work experience placement
    Work at office

    The PNC Financial Services Group

    Raleigh, NC
    3 days ago
  •  ...description:First line of defense risk professional within the...  ...: Credit, Market, Liquidity, Compliance, Operational, Reputation and...  ...change.Strong quantitative, governance, and analytic abilities.Ability...  ...Manager (FRM)/Certified Financial Analyst (CFA) or equivalent advanced... 
    Full time
    Part time
    Work at office
    Shift work
    Night shift
    Day shift

    Truist

    Raleigh, NC
    2 days ago
  •  ...highly skilled Senior Identity Governance & Administration (IGA) Analyst to lead the administration...  ...) processes, and ensuring compliance with multiple regulatory...  ...solutions that reduce risk while improving operational...  ...privacy, and other relevant GRC areas.All applicants must... 
    Full time
    Part time
    Work experience placement
    Relocation
    Visa sponsorship
    Flexible hours

    Black & Veatch

    Cary, NC
    4 days ago
  • $87.5k - $202.8k

     ...contribute to the company’s success. As a Credit Risk Review Advisor within PNC's Independent...  ...quality, ongoing monitoring, and policy compliance; identifying emerging risks and trends;...  ..., Loan Review, Organizational Governance, Regulatory Environment - Financial ServicesWork... 
    Full time
    Temporary work
    Part time
    Work experience placement
    Work at office

    The PNC Financial Services Group

    Raleigh, NC
    3 days ago
  •  ...Residents ONLY Job Title: Product Analyst II Job Location (Onsite, NO...  ..., process efficiency, and risk mitigation are met and continuously...  ...effectiveness of the data governance tool/function, measuring its...  ...in Risk Mitigation and Compliance. Develop metrics to monitor the... 
    Permanent employment
    Work experience placement
    Remote work

    TekLead

    Cary, NC
    13 hours ago
  •  ...Risk Analyst The experienced Risk Analyst role executes the VA Enterprise Risk Analysis process using a custom ERA tool...  ...or Internet of Things (IoT) Experience with Governance, Risk, and Compliance (GRC) Experience with Assessment and Authorization (A&A)... 
    For contractors
    Work experience placement

    RIT Solutions

    Durham, NC
    13 hours ago
  • DescriptionPosition Overview:The Compliance Operations Manager executes the day-to-day operations of Mayne Pharma's Compliance & Risk Program. Working closely with business stakeholders...  ...national, state and local laws governing nondiscrimination in employment as well... 
    Casual work
    Local area

    MAYNE PHARMA

    Raleigh, NC
    3 days ago
  • $82.6k - $162.8k

    Position Summary Cyber Security & Risk Strategy Consultant Our Deloitte Cyber...  ...models, including organizational structure, governance, roles and responsibilities, and process...  ...with governance, risk, and compliance tools, identity and access management solutions... 
    Local area
    Visa sponsorship

    Deloitte

    Raleigh, NC
    3 days ago
  • $74.9k - $147.6k

     ...s Human Capital practice as an Actuarial Analyst and help clients address complex challenges...  ...benefit managers, and federal and state government clients. You will contribute to actuarial...  ...using statistical methods to quantify risk and assess complex business issuesContributing... 
    Work at office
    Local area
    Visa sponsorship

    Deloitte

    Raleigh, NC
    5 hours ago
  •  ...experience level and expertise. The Ipas Network Risk Service Node is responsible for...  ...and ethics. The Enterprise Risk Management Analyst plays a critical role in strengthening organizational...  ...risks affecting program delivery, donor compliance, safeguarding commitments, and strategic... 
    Work at office
    Local area
    Remote work

    Ipas

    Raleigh, NC
    13 hours ago
  • $82.24k - $133.64k

     ...confirm models continue to perform as intended, and elevate emerging risks. Assess model change requests, including methodology changes,...  ...criticality, and track remediation through to closure. AI Governance & Emerging Technology: Test, evaluate, and independently review... 
    Work experience placement

    Live Oak Bank

    Raleigh, NC
    2 days ago
  • $102.7k - $164.6k

     ...contain a comprehensive inventory of all duties, responsibilities, and qualifications required of employees to do this job.* ***Compliance Requirement:*** *This job adheres to the ethical and legal standards and behavioral expectations as set forth in the code of business... 
    Work at office
    Remote work
    Work from home
    Shift work

    Highmark Health

    Raleigh, NC
    1 day ago
  •  ...purposeful work and meaningful impact every day. Learn more about what makes us different and how you can make your mark as an Actuarial Analyst at MMA. A day in the life As our Actuarial Analyst on the Employee Health & Benefits team, you’ll be responsible for analytical... 
    Permanent employment
    Work at office
    Local area
    Flexible hours
    Night shift

    Marsh McLennan Agency

    Raleigh, NC
    1 day ago
  •  ...Senior Actuarial Analyst Our not-so-secret sauce. Award-winning, inclusive, top workplace culture doesn't happen overnight. It's a result of hard work by extraordinary people. The industry's brightest talent drive our efforts to deliver purposeful work and meaningful... 
    Permanent employment
    Work at office
    Local area
    Flexible hours
    Night shift

    Mercer France

    Raleigh, NC
    3 days ago
  • $100.4k - $197.9k

     ...is $100,400 to $197,900. You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational... 
    Local area
    Visa sponsorship

    Deloitte

    Raleigh, NC
    1 day ago
  • $81.07k - $129.71k

     ...new and existing plans of insurance. Provides support to senior analysts or actuaries as required. Retrieves and validates data for rate...  ...and anomalies. Executes control activities to support Enterprise Risk Management. Provides analytic support for corporate and departmental... 
    Work at office
    Local area
    Remote work
    Flexible hours
    2 days per week

    Blue Cross and Blue Shield of North Carolina

    Raleigh, NC
    13 hours ago
  • About UsBased in Parma, Italy, Chiesi is an international research-focused biopharmaceutical group with 90 years’ experience, operating in 31 countries. More than 8,000 employees across the group are united by a singular purpose: promoting a healthier world for our people...
    Hourly pay
    Work at office
    Local area
    Remote work
    Relocation package
    Flexible hours

    Chiesi

    Cary, NC
    2 days ago
  •  ...is looking for an experienced analyst to manage the software...  ...requirements specifications, risk assessments, traceability matrices...  ...validation) with appropriate governance.World-class benefits Highlights...  ...solely for trade law compliance purposes and does not use it... 
    Full time
    Local area
    Work visa
    Shift work

    SAS Institute

    Cary, NC
    6 hours ago
  •  ...Senior Compliance Analyst CAPTRUST is seeking a Senior Compliance Analyst to join our Compliance Team. You will work with the Director of...  ...transactions, and other data to identify potential compliance risks and develop testing and action plans. Assist in drafting,... 
    Temporary work
    Local area
    Flexible hours

    CAPTRUST

    Raleigh, NC
    2 days ago
  •  ...providing clear guidance on their obligations, label use, and compliance responsibilities. \n Cascade changes from the basic registrations...  ...distribution, providing early warning to the business on risks, restrictions, and opportunities. \n Drive process efficiency... 
    Permanent employment

    Envu

    Cary, NC
    3 days ago
  • $75.8k - $164.1k

    Zurich’s Risk Engineering Property South Team is seeking a Property Field Risk Engineering Consultant with large property highly protected risk (HPR) experience. This is a work from home role positioned in North Carolina within the Raleigh, Greensboro, or Charlotte areas... 
    Temporary work
    Local area
    Remote work
    Work from home

    Zurich Insurance Group

    Raleigh, NC
    2 days ago
  • Associate Vice President, Actuary, Management Liability About the Company Globally recognized insurance company Industry Insurance Type Privately Held Employees 501-1000 Specialties commercial auto reinsurance commercial inland marine ...
    For contractors
    Work experience placement
    Relocation

    Confidential

    Raleigh, NC
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Governance, Risk & Compliance (GRC) Analyst. Be the first to apply!