Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

IT Governance Risk & Compliance (GRC) Analyst

Trustmark

Overview

The IT GRC Analyst operates within the enterprise Cybersecurity Operations function and supports the Information Technology, Information Systems, and other technology teams aligned under the Chief Information Officer. This role executes governance, risk, and compliance activities aligned with regulatory frameworks and internal policies. Core responsibilities include ensuring operational alignment with frameworks such as GLBA, FFIEC, SOX, NIST CSF, and the Computer Risk Institute (CRI) Profile; conducting IT assessments and Risk Control Self Assessments (RCSAs); maintaining control libraries; and supporting recurring testing, reporting, and metrics analysis and response. The analyst contributes to recurring reporting cycles, supports departmental risk remediation and response efforts associated with findings and risks, and helps drive continuous improvement of governance practices through collaboration, documentation, and control maturity efforts.

The analyst collaborates with Enterprise Risk, Audit (internal and external), Compliance, and Policy Management teams to execute these activities effectively. Day-to-day responsibilities include control documentation, testing coordination, assistance with reviewing and updating policies, standards, and control libraries, and policy lifecycle support. Familiarity with GRC platforms (e.g., AuditBoard), ITSM tools (e.g., ServiceNow), and regulatory compliance in financial services is strongly preferred.

The analyst also contributes to the development and maintenance of IT policies and procedures and supports the definition and tracking of key performance indicators (KPIs) and key risk indicators (KRIs). Success in this role requires strong technical writing skills, cross-functional engagement, and a focus on building and maintaining automation to streamline control testing and reporting processes. The role demands a self-driven desire to continuously learn and improve along with a collaborative mindset and a willingness to meet teammates and coworkers where they are in their processes. The analyst must be committed to helping develop, strengthen, and sustain a resilient and effective IT GRC program across the organization.

This position may be filled as a Level I, II or III. Additional responsibilities and qualifications apply.

Responsibilities

  • Serve as liaison between internal IT/IS/Cyber teams and Enterprise Risk and Audit to facilitate compliance efforts and assessments (GLBA, FFIEC, SOX, CRI/NIST CSF).
  • Coordinate the collection of sufficient, appropriate evidence for assessments, including facilitating questionnaires and direct engagement with engineers and operational personnel.
  • Execute and document testing procedures in spreadsheets and GRC platforms; draft reports based on results and environmental context.
  • Utilize GRC tools to manage questionnaires, evidence collection, assessment documentation, and asset definitions.
  • Track, document, and support remediation of findings, risk exceptions, and issues identified through audits, assessments, or operational testing, escalating unresolved items as appropriate.
  • Collaborate with internal IT/IS teams to maintain and review policy/standards documentation.
  • Research, implement, and monitor compliance initiatives to protect organizational assets.
  • Assess systems for compliance gaps and oversee sustainable remediation efforts.
  • Manage new and recurring compliance initiatives by conducting control assessments and recommending remediation or compensating controls.
  • Collaborate with peers and leadership to review and refine assessment work.
  • Stay current on regulatory changes and industry best practices to maintain alignment with standards.
  • Facilitate cross-functional collaboration (IT, Engineering, Legal, HR) to address security risks.
  • Advise IT and IS leadership on risk impacts and governance priorities.
  • Assist with the design and monitoring of KPIs and KRIs aligned to operational objectives.
  • Support timely execution of user access reviews and associated remediation efforts.
  • Perform other duties commensurate with responsibilities of an IT GRC department.
  • Associates are expected to perform all additional duties as assigned.
Qualifications
  • Bachelor's degree in information security, Information Systems/Technology, Risk Management, Cybersecurity, or a similar discipline.
  • 1 year of experience in IT GRC, IT audit, or a closely related compliance or risk function.
  • Ability to coordinate with operational and IT/IS personnel to gather evidence, clarify processes, and support control implementation.
  • Proficiency with Microsoft Office 365, including Excel and SharePoint for documentation and collaboration.
  • Strong written and verbal communication skills, including drafting audit findings and control narratives.
  • Familiarity with enterprise infrastructure components such as operating systems, directory services, and security technologies.
  • External-facing project experience (e.g., consulting, public accounting) is a plus.
  • Strong Preference for candidates located within commuting distance of Ridgeland, MS or willing to work hybrid/remote with occasional in-person sessions.
Additional qualifications required for Level II:
  • 3 years of experience in IT GRC, IT audit, or a closely related compliance or risk function.
  • Demonstrated ability to work independently with minimal oversight.
  • Experience documenting control testing results in GRC platforms or structured formats.
  • Working knowledge of GRC platforms (e.g., Archer, AuditBoard, ServiceNow).
  • At least one relevant certification (e.g., CISSP, CISM, CISA, CIA, CRISC, CGRC).
  • Experience translating regulatory requirements into detailed policies, standards, and control procedures, with the ability to explain technical and regulatory concepts clearly to non-GRC stakeholders.
  • Understanding of cybersecurity infrastructure (e.g., firewalls, vulnerability management, IDS/IPS).
  • Proactively identifies tasks and next steps rather than waiting for work to be assigned.Approaches problems from a solution oriented perspective and brings proposed options when raising issues.
  • Recognizes and corrects gaps or weaknesses in own work prior to submission.
  • Produces well structured, professionally formatted reports, presentations, and spreadsheets suitable for executive, audit, and regulatory audiences, with minimal need for substantive review, rework, or edits.
Additional qualifications required for Level III:
  • 5 years of experience in IT GRC, IT audit, or a closely related compliance or risk function.
  • Proven ability to manage cross-functional collaboration across IT, Engineering, Legal, HR, and other stakeholders.
  • Advanced analytical skills with experience using tools like Alteryx, Tableau, Power BI, or Python for reporting and automation.
  • Independently identifies, prioritizes, and drives work with minimal direction, proactively voicing and coordinating areas where effort is needed.
  • Provides guidance, instruction, and informal training to Analyst I and Analyst II team members.
  • Leads project execution by bringing structure, ideas, and recommended solutions, and translating detailed analysis into clear direction.
  • Reviews the work of others constructively, identifying weaknesses and improvement opportunities.
  • Produces work requiring minimal review and demonstrates sound judgment in improving overall team output beyond personal deliverables.

Physical Requirements & Working Conditions:

Must be able to sit for long periods of time and use computer keyboard and/or mouse requiring hand and wrist manipulation, while viewing computer screens.

Disclaimer:

Management retains the right to add, delete or modify the responsibilities and qualifications of the position at any time.

Trustmark Bank does not accept unsolicited resumes from agencies and/or search firms for any job postings on this site. Resumes submitted to any Trustmark Bank employee by a third-party agency and/or search firm without a valid, written search agreement signed by Trustmark, will become the sole property of Trustmark Bank. No fee will be paid if a candidate is hired for a position as a result of an unsolicited agency or search firm referral.
Vacancy posted 3 days ago
Similar jobs that could be interesting for youBased on the IT Governance Risk & Compliance (GRC) Analyst in United States vacancy
  •  ...environment supporting enterprise governance, policy, compliance, and audit readiness across a...  ...closely with Information Security, Risk, Compliance, Legal, Audit, IT, application owners, and business...  ...and effective use of ServiceNow GRC/IRM and ITSM capabilities. What'... 
    Suggested
    Contract work
    Remote work

    Axiom-Path

    Richmond, VA
    1 day ago
  • $80k - $100k

     ...Cybersecurity Compliance Analyst – Orlando, FL Salary: $80,000–$100,00...  ...Compliance Analyst to support governance, risk, compliance, and audit...  ...infrastructure, development, MDR/SOC, IT, leadership, and business...  ...in cybersecurity, GRC, IT compliance, cyber risk,... 
    Suggested
    Relocation package
    Shift work
    Orlando, FL
    4 days ago
  •  ...IT Security Manager Key Responsibilities: Governance Develop, maintain, and enforce IT security...  ...programs. Risk Management Identify...  ...remediation efforts. Compliance Ensure compliance...  ...Strong experience in GRC, IT audit, or cybersecurity... 
    Suggested

    Yochana

    Austin, TX
    3 days ago
  •  ...Governance, Risk & Compliance (GRC) Analyst (AI Training) About the Role We're partnering with the world's leading AI research labs to build smarter, safer AI - and we need practitioners who know how compliance and risk management actually work inside real organizations... 
    Suggested
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work
    Worldwide
    Flexible hours

    Alignerr

    Seattle, WA
    4 days ago
  •  ...Governance, Risk & Compliance (GRC) Analyst (AI Training) About the Role We partner with the world's leading AI research labs to build smarter, safer AI systems - and we need practitioners who know how compliance and risk management actually work in the real world... 
    Suggested
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work
    Worldwide
    Flexible hours

    Alignerr

    Chicago, IL
    4 days ago
  •  ...Applications Development and Maintenance IT service provider headquartered in...  ...complex challenges faced by our federal government clients. Our focus is on enabling our...  ...Decisions is seeking a Governance, Risk & Compliance (GRC) Analyst to support a cybersecurity program... 
    Contract work
    Remote work

    SkyePoint Decisions

    Bethesda, MD
    1 day ago
  • $8.22k - $10.48k

     ...how often (in days) to receive an alert: Cyber Security Governance, Risk, and Compliance (GRC) Analyst Columbus, NE, US, 68602-0499 Cyber Security Governance,...  ...degree and a minimum of three (3) years technical IT experience, including specific experience as listed below... 
    Permanent employment
    Full time
    Contract work
    Temporary work
    Work at office
    Relocation package

    Nebraska Public Power District

    Columbus, NE
    4 days ago
  •  ...Governance, Risk & Compliance (GRC) Analyst Client is seeking a GRC Analyst to lead our governance, risk, and compliance initiatives. This role will be...  ...ensuring regulatory compliance, and supporting strategic IT goals. Key Responsibilities: Develop and... 

    Group Nine LLC

    Middleton, WI
    1 day ago
  •  ...Governance, Risk, and Compliance (GRC) Analyst We operate at the intersection of technology and law, in an industry that demands agility and innovation....  ...Collaboration Partner with cross-functional teams including IT, Legal, and Business Development to advance compliance... 
    Full time
    Flexible hours

    Fulcrum Global Technologies

    Schaumburg, IL
    3 days ago
  •  ...Governance, Risk & Compliance (GRC) Analyst (AI Training) About the Role We're partnering with the world's leading AI research labs to build smarter, safer AI - and we need practitioners who know how GRC actually works in the real world. If you've spent time... 
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work
    10 hours per week
    Flexible hours

    Alignerr

    Denver, CO
    4 days ago
  •  ...Governance, Risk & Compliance (GRC) Analyst (AI Training) About the Role We're partnering with the world's leading AI research labs to build smarter, more trustworthy AI - and we need practitioners who know how GRC actually works in the real world. Your expertise... 
    Hourly pay
    Ongoing contract
    Contract work
    Freelance
    Remote work
    Flexible hours

    Alignerr

    Dallas, TX
    4 days ago
  •  ...GRC Analyst Join our team as a GRC Analyst and play a key role in regulatory compliance, IT risk management, security. You'll assess risks, support audits, and develop policies...  ...team. • Assist in the maintenance, governance, and execution of Threat and Vulnerability... 
    Casual work
    Work at office
    Work from home
    Home office
    Night shift
    Weekend work

    Delta Dental of Missouri

    Saint Louis, MO
    1 day ago
  •  ...Governance, Risk, & Compliance (GRC) Analyst Washington, DC Remote Full-Time About This Role As a GRC Analyst, you will help organizations navigate the complex landscape of cybersecurity compliance and risk management. You will work directly with clients to assess their... 
    Full time
    Remote work

    Districttechgroup

    Washington DC
    20 hours ago
  • $135k - $165k

     ...a detail-oriented and proactive GRC Analyst to support the company's compliance, risk management, and security assurance...  ...cross-functionally with engineering, IT, legal, HR, and business...  ...standards, and procedures. Support AI governance and responsible AI compliance... 
    Contract work
    Flexible hours

    IVO Inc

    San Francisco, CA
    3 days ago
  • Trustmark in Ridgeland, MS is seeking an IT GRC Analyst to oversee governance, risk, and compliance activities. The role includes coordinating compliance efforts, executing IT assessments, and developing policies. The ideal candidate will hold a Bachelor's in information... 
    Remote job

    Trustmark

    Ridgeland, MS
    1 day ago
  • Senior Governance, Risk, Compliance (GRC) Analyst job at Oura. New York, NY. At Oura, our mission is to empower every person to own their inner potential....  ...our team if you have: Experience: 6+ years leading GRC, IT compliance, security, risk management projects.... 
    Work at office
    Local area
    Remote work
    Flexible hours

    Itlearn360

    New York, NY
    20 hours ago
  • $70k - $80k

    As a GRC Cybersecurity Analyst (CA), you will play a pivotal role securing our clients’ infrastructure...  ...cybersecurity leadership in Governance, Risk, and Compliance (GRC) directly to our clients. You...  ...remediator, technical auditor, IT administrator with security responsibilities... 
    Full time
    Work at office

    Fractional CISO

    Newton, MA
    1 day ago
  •  ...Job Description The Information Security Governance, Risk & Compliance Analyst II will ensure information technology processes meet defined security...  ...and processes with industry standards. Lead IT Risk Assessment projects. Perform ongoing monitoring... 
    Full time
    Live in

    Saint Luke's Health System

    Kansas City, MO
    2 days ago
  •  ...Job description Risk and Compliance Analyst Houston, TX(5 days onsite) Monitor...  ...user environments. Support cyber governance activities, compliance tracking, and mitigation...  ...planning. Lead or coordinate IT related projects including planning,... 

    VDart

    Houston, TX
    2 days ago
  • Overview Information Security Governance, Risk and Compliance (GRC) Analyst – Risk and Policy focus. Responsibilities Assist in the execution of the organization...  ..., or a related field. 3‑5+ years of experience in IT audit, IT risk management, executing security assessments... 
    Contract work

    CFC- Chatham Financial Corporation

    Kennett Square, PA
    1 day ago
  • $117k - $151k

     ...Sr. Cyber Governance, Risk & Compliance Analyst The Senior Cyber Governance, Risk & Compliance Analyst is a...  ...cyber governance, risk and compliance (GRC), and security operations. This role...  ...Party Risk Management program, evolving it from a reactive, compliance driven... 
    Contract work
    Flexible hours

    Vuori

    Carlsbad, CA
    1 day ago
  • Tire Rack is seeking a Senior Information Security GRC Analyst to support and advance our Information Security Governance, Risk, and Compliance (GRC) program. In this role, you will assess and strengthen IT and security controls across the organization while ensuring alignment... 
    Monday to Friday

    Tire Rack

    Mishawaka, IN
    20 hours ago
  • Honda is seeking an IT risk quantification analyst in Cybersecurity Governance, Risk, and Compliance to evaluate potential threats and measure impact using FAIR, MITRE, and NIST frameworks. The role prioritizes risks by likelihood and loss, collaborating with cybersecurity... 

    Honda South Carolina Manufacturing

    Marysville, OH
    4 days ago
  •  ...HCL Global Systems Inc. in Mississippi seeks an IT Governance Risk & Compliance (GRC) Analyst for a contract role. You’ll help drive security governance and compliance initiatives at the associate level, coordinating controls and assessments to support regulatory alignment... 
    Contract work

    HCL Global Systems

    Jackson, MS
    4 days ago
  • $95k - $105k

     ...Job Description Sr. GRC Analyst About Subsplash Subsplash...  ...'t take our word for it—head to Glassdoor and...  ...advance security and risk operations. In this...  ...building an AI-first compliance function, and this role...  ...cadence. 2. Access Governance & Identity Management... 
    Temporary work
    Currently hiring
    Remote work
    Relocation

    Subsplash

    Indianapolis, IN
    20 days ago
  • Description The Senior IT GRC Analyst leads policy development and audit execution within CMG's IT Governance, Risk, and Compliance program, with particular emphasis on CMG's upcoming SOC 2 readiness effort. This role works closely with the GRC team and the broader... 
    Work at office
    Remote work

    CMG Financial

    United States
    5 days ago
  •  ...Description Job Description Job Summary: As a Senior Governance Risk and Compliance (GRC) Analyst at C2 Labs you will lead a team of security analysts...  .... Qualifications: Minimum 8 years’ experience in IT consulting specializing in Governance, Risk, and... 

    C2 Labs, Inc.

    Knoxville, TN
    26 days ago
  •  ...! UCT is looking for a talented Analyst III, IT Infosec to join us in Austin, TX!...  ...enterprise. Role Overview The UCT GRC Specialist will support the design, execution, and maturity of UCT’s IT governance, risk, and compliance program. This role is responsible... 
    Contract work
    Local area

    Ultra Clean Technology Systems & Svc Inc

    Manor, TX
    2 days ago
  •  ...Ruleset Security is offering an exciting internship opportunity for a Governance, Risk, and Compliance (GRC) Analyst. This role is perfect for students or recent graduates looking to gain hands-on experience in cybersecurity, compliance, and risk management. The internship... 
    Full time
    Internship

    Ruleset Security

    Arlington, VA
    1 day ago
  •  ...evolving industry. Job Summary The IT Risk Associate will support the...  ...management and cybersecurity compliance programs. Reporting to the...  ...cybersecurity risk analysis, governance activities, issue management,...  ...learn and use risk management or GRC software and other security... 
    Internship
    Local area

    AmeriLife

    Clearwater, FL
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to IT Governance Risk & Compliance (GRC) Analyst. Be the first to apply!