Governance, Risk, and Compliance (GRC) Analyst
Ardent Services
Governance, Risk, and Compliance (GRC) / Compliance Analyst
Ardent is seeking a Governance, Risk, and Compliance (GRC) / Compliance Analyst to join our team. This is a remote position with expected travel to Tallahassee, FL.
Position Description:
Ardent is seeking a Governance, Risk, and Compliance (GRC) / Compliance Analyst that integrates technical evidence with governance, risk, compliance, and internal-audit support requirements. The role maintains traceability among agency documentation, Rule 60GG-2, NIST CSF, approved procedures, factual findings, remediation actions, and deliverable acceptance criteria while protecting confidential and exempt information across a potentially broad multi-agency environment.
Responsibilities and Duties:
- Lead ingestion and analysis of agency documentation, including risk assessments, remediation plans, prior findings, corrective actions, inventories, and strategic plans.
- Direct development of the Agency Risk Understanding Memorandum, including environmental summaries, agency-specific risks, assumptions, documentation gaps, and impacts on testing priorities.
- Design the Ground-Truth and Ad Hoc Testing Strategies and approve detailed procedures defining objectives, systems, controls, access points, tools, sampling, scripts, evidence, thresholds, stop conditions, and escalation paths.
- Map procedures and results to NIST CSF DE.AE, DE.DP, PR.AC; Rule 60GG-2, F.A.C.; and the applicable approved criteria.
- Ensure testing remains within written OCIG authorization, avoids duplication of operational testing, and complies with agency-specific Rules of Engagement.
- Review evidence for relevance, reliability, sufficiency, attribution, timestamps, chain of custody, and reproducibility.
- Validate that reports accurately state procedures performed and factual results without an audit opinion; ensure advisory recommendations are distinctly labeled.
- Conduct independent QA reviews of technical deliverables not authored solely by the reviewer and document sign-off.
- Lead technical briefings, workshops, job aids, and knowledge transfer so OCIG and OIG staff can understand and reuse procedures.
- Support urgent analysis of logs, timelines, after-action reports, remediation evidence, and incident-specific control issues when directed.
Requirements:
- Bachelor's degree in cybersecurity, information assurance, audit, information systems, or related discipline.
- Proof of relevant professional certifications such as CISSP, CISA, PMP, CEH, or other relevant certifications.
- 10 years of progressive cybersecurity experience, including security operations, incident response, vulnerability management, intrusion analysis, adversary simulation, technical assessment, or audit support.
- 5 years supporting or conducting audits, compliance reviews, independent assessments, or assurance work in government or similarly regulated environments.
- Demonstrated ability to design defensible test procedures, evaluate control performance, distinguish fact from opinion, and communicate technical results to senior stakeholders.
- Working knowledge of professional auditing or assurance standards and evidence requirements.
Preferred Qualifications:
- Purple-team or adversary-emulation leadership using MITRE ATT&CK and threat-informed kill chains.
- Government incident-command experience.
- CISA, CIA, or other audit credential.
- Experience with Active Directory, cloud platforms, APIs, web applications, databases, endpoints, SIEM/EDR, vulnerability scanners, and evidence repositories.
Due to the nature of the work we support, all candidates in consideration for this role must be willing to undergo the government issued background investigation process.
Ardent is an equal opportunity employer. We will not discriminate in employment, recruitment, advertisements for employment, compensation, termination, upgrading, promotions, and other conditions of employment against any employee or job applicant on the bases of race, color, gender, national origin, age, religion, creed, disability, veteran's status, sexual orientation, gender identity, gender expression, or any other basis protected by state, local, or federal law.
$165k - $190k
...degree in Information Security, Risk, Business or equivalent.... ...~ Experience engaging with government agencies or federal sector stakeholders... ...objectives with regulatory/compliance requirements and security... ...and drive improvements to the GRC program accordingly. Job...SuggestedDaily paidTemporary workLive outRelocation package- ...Governance, Risk & Compliance (GRC) Analyst (AI Training) About the Role We're looking for experienced GRC professionals to help evaluate and improve AI systems being trained on real-world security, compliance, and risk scenarios. Your practitioner knowledge will...SuggestedHourly payOngoing contractContract workFreelanceRemote workFlexible hours
- ...Description Job Description Join our team as a GRC Analyst and play a key role in regulatory compliance, IT risk management, security. You'll assess risks,... ...incident response team. • Assist in the maintenance, governance, and execution of Threat and Vulnerability...SuggestedCasual workWork at officeWork from homeHome officeNight shiftWeekend work
$138k - $173k
THE POSITIONOur roster has an opening with your name on itFanDuel is seeking a Senior Technology Governance, Risk & Compliance (GRC) Analyst to join its Technology GRC team as a strategic specialist supporting our first line of defense (1LOD) function. This role offers...SuggestedTemporary workWork at officeLocal areaWorldwideShift work- Information Security Risk Analyst Job Summary Our client is seeking an Information Security... ...utilizing ServiceNow IRM to support governance and compliance processes. Key Responsibilities... ...with Governance, Risk and Compliance (GRC). Experience preparing technical documentation...SuggestedInternshipWork at office
- Governance, Risk, and Compliance (GRC) Analyst About Fulcrum We operate at the intersection of technology and law, in an industry that demands agility and innovation. Our team is dedicated to developing advanced solutions for legal professionals. Our daily work involves...Full time
- Governance, Risk & Compliance (GRC) Analyst Washington D.C. CHAOS Industries is redefining modern defense with a multi-product portfolio that gives the ultimate advantage domain dominance. The company's products are powered by Coherent Distributed Networks (CDN), empowering...Contract workFor subcontractorCasual workRelocation package
$135k - $165k
...foundational to our platform and customer relationships. As we continue to scale, we are looking for a highly motivated Governance, Risk & Compliance (GRC) Analyst to support and mature Ivo's security compliance and risk management programs. Role Overview Ivo is seeking a...Contract workFlexible hours- Job Title: Cyber Security - Governance Risk Compliance (GRC) Analyst-Only locals Location: Boca Raton, FL Talent must reside at location on submission? Primary Skills Risk Management Job Description Job Summary: The management, assessment, and mitigation of risks are...Work experience placementLocal area
- Governance, Risk, & Compliance (GRC) Analyst Washington, DC Remote Full-Time About This Role As a GRC Analyst, you will help organizations navigate the complex landscape of cybersecurity compliance and risk management. You will work directly with clients to assess their...Full timeRemote work
- ...Beacon Hill was founded to set a new standard in search, career placement and flexible staffing. Governance, Risk & Compliance (GRC) Specialist Location: Houston, TX (Hybrid: 3 days onsite, 2 remote) OR Chicago, IL (Remote) Duration: 6-Month Contract (Strong Extension...Contract workRemote workFlexible hours
- ...Overview The Technology Risk Assessor is an entry-level role focused on identifying,... ...This role supports the Technology Risk and Governance function by evaluating technology... ...technology, IT risk, cybersecurity, audit, compliance, or governance. Bachelor’s degree in Information...
- ...The Senior IT GRC Analyst leads policy development and audit execution within CMG's IT Governance, Risk, and Compliance program, with particular emphasis on CMG's upcoming SOC 2 readiness effort. This role works closely with the GRC team and the broader IT department to...Work at officeRemote work
- ...Own hands-on execution of governance, risk, and compliance operations for Socure’s public sector business Coordinate third-party assessment organization assessments and respond to auditor evidence and documentation requests Maintain FedRAMP and GovRAMP controls and documentation...Permanent employment
$115k - $125k
...TechnologyReference ID: Job record: a1qPL IyU9YAKValid through: Senior GRC Analyst Industry: Professional Services / Information... ...professional services organization, is seeking a Senior Governance, Risk & Compliance (GRC) Analyst to help build and mature its internal...Contract workTemporary workLocal areaFlexible hours- ...Job Description Job Description JUNIOR GRC ANALYST ROCKVILLE, MD - HYBRID LONG TERM CONTRACT SEEKING SOMEONE WHO HAS... ...Analyst supports the administration of Information Security Governance, Risk, and Compliance programs, including policy exception management and...Long term contractInternship
- ...Junior-Level GRC Analysts Department: Governance, Risk & Compliance (GRC) Reports To: Compliance Manager Location: Hybrid (St.Petersburg, Florida Applicants Only) Working Hours: U.S. Eastern Time (ET) business hours Employment Type: Full-Time Level:...Full timeWork at office
$65k - $75k
...The University of Maine System is seeking a Cybersecurity Governance, Risk & Compliance (GRC) Analyst to join our Information Security team. This position plays an important role in protecting the information, systems, and data that support Maine's public universities...Casual workWork at officeImmediate startRemote workMonday to FridayFlexible hoursAfternoon shift- UT Southwestern Medical Center seeks a Senior Governance Risk Compliance Analyst to lead information security governance, risk management, and compliance for the Texas Behavioral Health Center program. This role applies NIST, HIPAA, PCI standards and coordinates enterprise...
- Security Compliance Support Role Provides direct support to the Director Security Governance, Risk and Compliance and security shared service team by assuring information system... ...security solutions. Experience in working with GRC systems/modules. Experience in working...
- Job Description: Senior Information Security GRC Analyst Department: Information Security Job Title: Senior Information Security Governance, Risk, and Compliance (GRC) Analyst Reports To: Information Security GRC Manager / Head of Information Security Location: Remote,...Contract workWork at officeRemote work
- Nordstrom is seeking a Senior Analyst for the Governance, Risk and Compliance (GRC) program. You will own the Common Control Framework (CCF) from inception, mature it, run it, and test control effectiveness in a scalable, AI-enabled environment. This role requires cross...Work at office
- NorthMark Strategies LLC is hiring a GRC Analyst to join the Information Security team in Dallas, TX. You will drive governance processes, risk assessments, policy library management,... ...the enterprise risk register, ensuring compliance and effective risk mitigation across...
- ...is not a remote position. The GRC Senior Regulatory Compliance Analyst, who has proficient knowledge in regulatory... ...annual regulatory compliance risk assessments, reviewing contracts... ...processes such as Security and IT governance, risk, and compliance activities to...Contract workWork at office1 day per week
- Ruleset Security is offering an exciting internship opportunity for a Governance, Risk, and Compliance (GRC) Analyst. This role is perfect for students or recent graduates looking to gain hands-on experience in cybersecurity, compliance, and risk management. The internship...Full timeInternship
- Ruleset Security is offering an exciting internship opportunity for a Governance, Risk, and Compliance (GRC) Analyst. This role is perfect for students or recent graduates looking to gain hands‑on experience in cybersecurity, compliance, and risk management. The internship...Remote jobFull timeInternship
- ## GRC AnalystApplylocations: Clemmons, NCtime type: Full timeposted on: Posted Yesterdayjob requisition id: R26... ...well as Canada, Spain, France, Australia, and China. **Governance, Risk, and Compliance (GRC) Analyst - SOX & Data Security Focus**Location: Clemmons, NC...Full time
- Governance Analyst The Governance Analyst will be responsible for assisting... ...executing the security framework compliance/governance activities and... ...of governance, risk, compliance Knowledge of security... ...assessment statuses Utilize GRC tools to effectively manage...ApprenticeshipWork experience placementLocal area
- Metropolis is seeking a Governance, Risk, and Compliance (GRC) Analyst to join our Security team in Los Angeles. You will mature information security policies, drive employee training, and pioneer our AI governance framework across Legal, Tech, and Procurement. You will...Work at office
- BWH Hotels is seeking an information security compliance professional to support governance, risk, and compliance across the organization. You will coordinate evidence with stakeholders and auditors, maintain control documentation, and help ensure audit readiness for PCI...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Governance, Risk, and Compliance (GRC) Analyst. Be the first to apply!
- market risk analyst United States
- risk consultant United States
- risk analyst intern United States
- governance risk & compliance analyst United States
- it risk analyst United States
- operational risk specialist United States
- information risk analyst United States
- risk analyst United States
- third party risk analyst United States
- risk officer United States


