IT Governance Risk & Compliance (GRC) Analyst
Trustmark
Overview The IT GRC Analyst operates within the enterprise Cybersecurity Operations function and supports the Information Technology, Information Systems, and other technology teams aligned under the Chief Information Officer. This role executes governance, risk, and compliance activities aligned with regulatory frameworks and internal policies. Core responsibilities include ensuring operational alignment with frameworks such as GLBA, FFIEC, SOX, NIST CSF, and the Computer Risk Institute (CRI) Profile; conducting IT assessments and Risk Control Self Assessments (RCSAs); maintaining control libraries; and supporting recurring testing, reporting, and metrics analysis and response. The analyst contributes to recurring reporting cycles, supports departmental risk remediation and response efforts associated with findings and risks, and helps drive continuous improvement of governance practices through collaboration, documentation, and control maturity efforts. The analyst collaborates with Enterprise Risk, Audit (internal and external), Compliance, and Policy Management teams to execute these activities effectively. Day-to-day responsibilities include control documentation, testing coordination, assistance with reviewing and updating policies, standards, and control libraries, and policy lifecycle support. Familiarity with GRC platforms (e.g., AuditBoard), ITSM tools (e.g., ServiceNow), and regulatory compliance in financial services is strongly preferred. The analyst also contributes to the development and maintenance of IT policies and procedures and supports the definition and tracking of key performance indicators (KPIs) and key risk indicators (KRIs). Success in this role requires strong technical writing skills, cross-functional engagement, and a focus on building and maintaining automation to streamline control testing and reporting processes. The role demands a self-driven desire to continuously learn and improve along with a collaborative mindset and a willingness to meet teammates and coworkers where they are in their processes. The analyst must be committed to helping develop, strengthen, and sustain a resilient and effective IT GRC program across the organization. This position may be filled as a Level I, II or III. Additional responsibilities and qualifications apply. Responsibilities
- Serve as liaison between internal IT/IS/Cyber teams and Enterprise Risk and Audit to facilitate compliance efforts and assessments (GLBA, FFIEC, SOX, CRI/NIST CSF).
- Coordinate the collection of sufficient, appropriate evidence for assessments, including facilitating questionnaires and direct engagement with engineers and operational personnel.
- Execute and document testing procedures in spreadsheets and GRC platforms; draft reports based on results and environmental context.
- Utilize GRC tools to manage questionnaires, evidence collection, assessment documentation, and asset definitions.
- Track, document, and support remediation of findings, risk exceptions, and issues identified through audits, assessments, or operational testing, escalating unresolved items as appropriate.
- Collaborate with internal IT/IS teams to maintain and review policy/standards documentation.
- Research, implement, and monitor compliance initiatives to protect organizational assets.
- Assess systems for compliance gaps and oversee sustainable remediation efforts.
- Manage new and recurring compliance initiatives by conducting control assessments and recommending remediation or compensating controls.
- Collaborate with peers and leadership to review and refine assessment work.
- Stay current on regulatory changes and industry best practices to maintain alignment with standards.
- Facilitate cross-functional collaboration (IT, Engineering, Legal, HR) to address security risks.
- Advise IT and IS leadership on risk impacts and governance priorities.
- Assist with the design and monitoring of KPIs and KRIs aligned to operational objectives.
- Support timely execution of user access reviews and associated remediation efforts.
- Perform other duties commensurate with responsibilities of an IT GRC department.
- Associates are expected to perform all additional duties as assigned.
- Bachelor's degree in information security, Information Systems/Technology, Risk Management, Cybersecurity, or a similar discipline.
- 1 year of experience in IT GRC, IT audit, or a closely related compliance or risk function.
- Ability to coordinate with operational and IT/IS personnel to gather evidence, clarify processes, and support control implementation.
- Proficiency with Microsoft Office 365, including Excel and SharePoint for documentation and collaboration.
- Strong written and verbal communication skills, including drafting audit findings and control narratives.
- Familiarity with enterprise infrastructure components such as operating systems, directory services, and security technologies.
- External-facing project experience (e.g., consulting, public accounting) is a plus.
- Strong Preference for candidates located within commuting distance of Ridgeland, MS or willing to work hybrid/remote with occasional in-person sessions.
- 3 years of experience in IT GRC, IT audit, or a closely related compliance or risk function.
- Demonstrated ability to work independently with minimal oversight.
- Experience documenting control testing results in GRC platforms or structured formats.
- Working knowledge of GRC platforms (e.g., Archer, AuditBoard, ServiceNow).
- At least one relevant certification (e.g., CISSP, CISM, CISA, CIA, CRISC, CGRC).
- Experience translating regulatory requirements into detailed policies, standards, and control procedures, with the ability to explain technical and regulatory concepts clearly to non-GRC stakeholders.
- Understanding of cybersecurity infrastructure (e.g., firewalls, vulnerability management, IDS/IPS).
- Proactively identifies tasks and next steps rather than waiting for work to be assigned.Approaches problems from a solution oriented perspective and brings proposed options when raising issues.
- Recognizes and corrects gaps or weaknesses in own work prior to submission.
- Produces well structured, professionally formatted reports, presentations, and spreadsheets suitable for executive, audit, and regulatory audiences, with minimal need for substantive review, rework, or edits.
- 5 years of experience in IT GRC, IT audit, or a closely related compliance or risk function.
- Proven ability to manage cross-functional collaboration across IT, Engineering, Legal, HR, and other stakeholders.
- Advanced analytical skills with experience using tools like Alteryx, Tableau, Power BI, or Python for reporting and automation.
- Independently identifies, prioritizes, and drives work with minimal direction, proactively voicing and coordinating areas where effort is needed.
- Provides guidance, instruction, and informal training to Analyst I and Analyst II team members.
- Leads project execution by bringing structure, ideas, and recommended solutions, and translating detailed analysis into clear direction.
- Reviews the work of others constructively, identifying weaknesses and improvement opportunities.
- Produces work requiring minimal review and demonstrates sound judgment in improving overall team output beyond personal deliverables.
Vacancy posted 12 hours ago
Similar jobs that could be interesting for youBased on the IT Governance Risk & Compliance (GRC) Analyst in United States vacancy
$80k - $100k
...Cybersecurity Compliance Analyst - Orlando, FL Salary: $80,000-$100,00... ...Compliance Analyst to support governance, risk, compliance, and audit... ...infrastructure, development, MDR/SOC, IT, leadership, and business... ...in cybersecurity, GRC, IT compliance, cyber risk,...SuggestedRelocation packageShift work- .... About the Role We are seeking an experienced Governance, Risk, and Compliance (GRC) Senior Analyst to join our InfoSec team. This role will be instrumental... ...~ Partner with cross-functional teams including IT, Legal, and Business Development to advance compliance...SuggestedFull timeFlexible hours
- ...various locations. Purpose: Athene is seeking a Sr. Governance, Risk & Compliance (GRC) Analyst to help strengthen and evolve enterprise technology... ...with meaningful enterprise impact. Accountabilities: IT Risk Management & Governance * Conduct technology and...SuggestedLocal area
- ...Governance, Risk & Compliance (GRC) Analyst Location: Middleton, Wisconsin Hybrid: Travel to client office might be required on case basis. Client... ...regulatory compliance, and supporting strategic IT goals. Key Responsibilities: Develop and maintain...SuggestedWork at office
- ...Governance, Risk & Compliance (GRC) Analyst We're looking for experienced GRC professionals to help build and evaluate AI systems that reason about security, risk, and compliance. At Alignerr, we partner with the world's leading AI research labs — and your real-world...SuggestedHourly payOngoing contractContract workFreelanceRemote workFlexible hours
- ...Governance, Risk & Compliance (GRC) Analyst We're looking for experienced GRC professionals to help build and evaluate AI systems that reason about security, compliance, and risk. At Alignerr, we partner with the world's leading AI research labs to create high-quality...Hourly payOngoing contractContract workFreelanceRemote workFlexible hours
$60k - $75k
...solving problems, managing compliance, and helping keep cybersecurity and government contract requirements on... ...Staffing is seeking a GRC Analyst for our client in Macon,... ...compliance, risk management, audit readiness... ...efforts Work closely with IT, HR, Operations, Contracts...Contract workRelocationRelocation packageMonday to Thursday- Governance, Risk & Compliance (GRC) Analyst (AI Training) About the Role We're partnering with the world's leading AI research labs to build smarter, more trustworthy AI - and we need practitioners who know how GRC actually works in the real world. Your expertise...Hourly payOngoing contractContract workFreelanceRemote workFlexible hours
- ...Governance, Risk & Compliance (GRC) Analyst (AI Training) About the Role We partner with the world's leading AI research labs to build smarter, safer AI systems - and we need practitioners who know how compliance and risk management actually work in the real world...Hourly payOngoing contractContract workFreelanceRemote workWorldwideFlexible hours
$135k - $165k
...continue to scale, we are looking for a highly motivated Governance, Risk & Compliance (GRC) Analyst to support and mature Ivo's security compliance and... ...procedures, and partnering cross-functionally with engineering, IT, legal, HR, and business stakeholders. This is a fully...Contract workFlexible hours- Brown-Forman is hiring an IT Governance/Risk/Compliance Analyst in Louisville, KY. This role involves developing and maintaining IT governance frameworks, supporting risk management programs, and ensuring compliance with internal policies and external regulations. The ideal...
- A community-focused healthcare organization in California is seeking a Senior Analyst for IT Governance, Risk & Compliance. This role involves managing the Information Security GRC program, ensuring compliance with various regulations including HIPAA and PCI. Candidates...
$84.5k - $109.85k
...and professionally, so our benefits and perks support that mindset. About the Role: As a Senior Consultant - Governance, Risk and Compliance (GRC) Analyst within NYSTEC's Cybersecurity and Data Privacy practice area, you will support governance, compliance, and...Local areaVisa sponsorship- Brown-Forman is seeking an IT Governance/Risk/Compliance Analyst to support risk management initiatives and ensure compliance with internal policies and regulations. The ideal candidate will have over 3 years of experience, strong analytical and communication skills, and...
$80k - $110k
Job Description : Governance, Risk and Compliance (GRC) Analyst Location - Austin Texas Hybrid - 3 Days in office The Governance, Risk and Compliance (GRC) Analyst will have a good understanding of security and privacy principles as well as a sound understanding of regulatory...Work at officeLocal areaFlexible hours- Governance, Risk, & Compliance (GRC) Analyst Washington, DC Remote Full-Time About This Role As a GRC Analyst, you will help organizations navigate the complex landscape of cybersecurity compliance and risk management. You will work directly with clients to assess their...Full timeRemote work
$130k - $180k
...building a cutting‑edge security compliance program aligned with FedRAMP,... ..., and other frameworks. As a GRC Analyst you’ll help manage these... ..., and SaaS services. Conduct risk assessments across business units... ...in information security, IT audit, IT risk management, or...Local areaFlexible hours- Insight Global is seeking a Senior Analyst to focus on AI compliance, risk assessment, and governance activities. The role involves working closely with various departments to review third-party AI tools and support client-facing requests. This position requires strong...
$32.21 - $40.26 per hour
Governance, Risk and Compliance (GRC) Analyst job at Provident Bank. Iselin, NJ. How would you like to join one of the most highly regarded financial institutions... ..., Sarbanes Oxley (SOX) compliance requirements and IT General Controls (ITGC) Information Security...Hourly payWork at officeLocal areaFlexible hours- Senior Governance, Risk, Compliance (GRC) Analyst job at Oura. New York, NY. At Oura, our mission is to empower every person to own their inner potential.... ...our team if you have: Experience: 6+ years leading GRC, IT compliance, security, risk management projects....Work at officeLocal areaRemote workFlexible hours
- The Vanguard Group is seeking a Governance, Risk & Compliance Analyst, Specialist in Dallas, Texas. This role focuses on delivering GRC modernization initiatives, conducting risk assessments, and shaping security policies across the enterprise. The ideal candidate will...Visa sponsorship
$37.95 - $64.92 per hour
...Wisconsin, is seeking a Cybersecurity GRC Analyst, Training & Awareness professional to join the Cybersecurity Governance, Risk Management, and Compliance (GRC) team. This role is critical in... ...including clinicians, administrative staff, IT teams, and executives. •...Hourly payTemporary workRemote workFlexible hoursShift workWeekend workDay shift$125k
...University of Texas at Austin is seeking a Cybersecurity GRC Analyst to support governance, risk, and compliance for its Controlled Research Program. The role... ...programs, conducting assessments, and collaborating with IT and research stakeholders. Applicants should have a...Remote job- Spectraforce Technologies is seeking a Database Analyst III in San Francisco, CA. This hands-on role focuses on automating compliance workflows, data governance, and AI-driven automation. Key responsibilities include designing GRC workflows, building dashboards, and...
$117.9k - $160k
...seeking a detail-oriented and analytical Senior Governance, Risk, and Compliance ( GRC) Process Analyst to support governance, risk, and compliance initiatives... ...This role will partner with Information Security, IT&O, Internal Audit, Compliance, SOX, External Audit,...Permanent employmentWork experience placementRelocationVisa sponsorshipWork visaRelocation packageFlexible hoursShift workDay shift- ...IT GRC Analyst II The Cybersecurity GRC Analyst II will be a key member of our fast-paced, growing Cybersecurity Services team. This role is intensely focused on Governance, Risk, and Compliance (GRC) and serves as a primary point of contact for responding to external...Work at officeRemote work
$74.33k - $130.08k
...Cybersecurity GRC Analyst II (HYBRID) HUNT VALLEY, MD, US, 21031 McCormick employees... ...is a key member of the Cybersecurity Governance, Risk, and Compliance team and will report to the Senior... ...the execution of and response to IT audits. The ideal candidate has a...Permanent employmentImmediate start- ...Cybersecurity Senior GRC Analyst Location: Denver, PA, US, 17517 Workplace Environment... ...and services! Job Summary The Governance Risk & Compliance (GRC) Cybersecurity Senior Analyst... ...and reporting. Collaborate with IT stakeholders to monitor UGI Utilities...For contractors
- Synchrony Financial is seeking a detail-oriented Sr. Business Analyst to join its GRC Risk Management Systems team in Boston, Massachusetts. This role involves advocating for GRC technology and working closely with various stakeholders to manage organizational risks effectively...
- A leading automotive company is seeking a Senior Analyst for Cybersecurity Compliance in Austin, Texas. This role involves designing and operating control... ...oversee compliance program implementation and conduct risk assessments while collaborating cross-functionally to enhance...
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to IT Governance Risk & Compliance (GRC) Analyst. Be the first to apply!
Related searches
- it risk analyst United States
- risk officer United States
- risk compliance officer United States
- junior risk analyst United States
- information risk analyst United States
- third party risk analyst United States
- market risk analyst United States
- governance risk & compliance analyst United States
- quantitative risk analyst United States
- risk analyst United States


