IT Governance Risk & Compliance (GRC) Analyst
Trustmark
Overview The IT GRC Analyst operates within the enterprise Cybersecurity Operations function and supports the Information Technology, Information Systems, and other technology teams aligned under the Chief Information Officer. This role executes governance, risk, and compliance activities aligned with regulatory frameworks and internal policies. Core responsibilities include ensuring operational alignment with frameworks such as GLBA, FFIEC, SOX, NIST CSF, and the Computer Risk Institute (CRI) Profile; conducting IT assessments and Risk Control Self Assessments (RCSAs); maintaining control libraries; and supporting recurring testing, reporting, and metrics analysis and response. The analyst contributes to recurring reporting cycles, supports departmental risk remediation and response efforts associated with findings and risks, and helps drive continuous improvement of governance practices through collaboration, documentation, and control maturity efforts. The analyst collaborates with Enterprise Risk, Audit (internal and external), Compliance, and Policy Management teams to execute these activities effectively. Day-to-day responsibilities include control documentation, testing coordination, assistance with reviewing and updating policies, standards, and control libraries, and policy lifecycle support. Familiarity with GRC platforms (e.g., AuditBoard), ITSM tools (e.g., ServiceNow), and regulatory compliance in financial services is strongly preferred. The analyst also contributes to the development and maintenance of IT policies and procedures and supports the definition and tracking of key performance indicators (KPIs) and key risk indicators (KRIs). Success in this role requires strong technical writing skills, cross-functional engagement, and a focus on building and maintaining automation to streamline control testing and reporting processes. The role demands a self-driven desire to continuously learn and improve along with a collaborative mindset and a willingness to meet teammates and coworkers where they are in their processes. The analyst must be committed to helping develop, strengthen, and sustain a resilient and effective IT GRC program across the organization. This position may be filled as a Level I, II or III. Additional responsibilities and qualifications apply. Responsibilities
- Serve as liaison between internal IT/IS/Cyber teams and Enterprise Risk and Audit to facilitate compliance efforts and assessments (GLBA, FFIEC, SOX, CRI/NIST CSF).
- Coordinate the collection of sufficient, appropriate evidence for assessments, including facilitating questionnaires and direct engagement with engineers and operational personnel.
- Execute and document testing procedures in spreadsheets and GRC platforms; draft reports based on results and environmental context.
- Utilize GRC tools to manage questionnaires, evidence collection, assessment documentation, and asset definitions.
- Track, document, and support remediation of findings, risk exceptions, and issues identified through audits, assessments, or operational testing, escalating unresolved items as appropriate.
- Collaborate with internal IT/IS teams to maintain and review policy/standards documentation.
- Research, implement, and monitor compliance initiatives to protect organizational assets.
- Assess systems for compliance gaps and oversee sustainable remediation efforts.
- Manage new and recurring compliance initiatives by conducting control assessments and recommending remediation or compensating controls.
- Collaborate with peers and leadership to review and refine assessment work.
- Stay current on regulatory changes and industry best practices to maintain alignment with standards.
- Facilitate cross-functional collaboration (IT, Engineering, Legal, HR) to address security risks.
- Advise IT and IS leadership on risk impacts and governance priorities.
- Assist with the design and monitoring of KPIs and KRIs aligned to operational objectives.
- Support timely execution of user access reviews and associated remediation efforts.
- Perform other duties commensurate with responsibilities of an IT GRC department.
- Associates are expected to perform all additional duties as assigned.
- Bachelor's degree in information security, Information Systems/Technology, Risk Management, Cybersecurity, or a similar discipline.
- 1 year of experience in IT GRC, IT audit, or a closely related compliance or risk function.
- Ability to coordinate with operational and IT/IS personnel to gather evidence, clarify processes, and support control implementation.
- Proficiency with Microsoft Office 365, including Excel and SharePoint for documentation and collaboration.
- Strong written and verbal communication skills, including drafting audit findings and control narratives.
- Familiarity with enterprise infrastructure components such as operating systems, directory services, and security technologies.
- External-facing project experience (e.g., consulting, public accounting) is a plus.
- Strong Preference for candidates located within commuting distance of Ridgeland, MS or willing to work hybrid/remote with occasional in-person sessions.
- 3 years of experience in IT GRC, IT audit, or a closely related compliance or risk function.
- Demonstrated ability to work independently with minimal oversight.
- Experience documenting control testing results in GRC platforms or structured formats.
- Working knowledge of GRC platforms (e.g., Archer, AuditBoard, ServiceNow).
- At least one relevant certification (e.g., CISSP, CISM, CISA, CIA, CRISC, CGRC).
- Experience translating regulatory requirements into detailed policies, standards, and control procedures, with the ability to explain technical and regulatory concepts clearly to non-GRC stakeholders.
- Understanding of cybersecurity infrastructure (e.g., firewalls, vulnerability management, IDS/IPS).
- Proactively identifies tasks and next steps rather than waiting for work to be assigned.Approaches problems from a solution oriented perspective and brings proposed options when raising issues.
- Recognizes and corrects gaps or weaknesses in own work prior to submission.
- Produces well structured, professionally formatted reports, presentations, and spreadsheets suitable for executive, audit, and regulatory audiences, with minimal need for substantive review, rework, or edits.
- 5 years of experience in IT GRC, IT audit, or a closely related compliance or risk function.
- Proven ability to manage cross-functional collaboration across IT, Engineering, Legal, HR, and other stakeholders.
- Advanced analytical skills with experience using tools like Alteryx, Tableau, Power BI, or Python for reporting and automation.
- Independently identifies, prioritizes, and drives work with minimal direction, proactively voicing and coordinating areas where effort is needed.
- Provides guidance, instruction, and informal training to Analyst I and Analyst II team members.
- Leads project execution by bringing structure, ideas, and recommended solutions, and translating detailed analysis into clear direction.
- Reviews the work of others constructively, identifying weaknesses and improvement opportunities.
- Produces work requiring minimal review and demonstrates sound judgment in improving overall team output beyond personal deliverables.
Vacancy posted 4 days ago
Similar jobs that could be interesting for youBased on the IT Governance Risk & Compliance (GRC) Analyst in United States vacancy
- Yamaha Motor Corporation, USA is seeking a Governance and Risk Compliance Analyst in Marietta, GA to partner with privacy and website teams. You will support... ...consent controls, GPC activities, and broader Cyber GRC initiatives while contributing to information security...Suggested
$80k - $100k
...Cybersecurity Compliance Analyst – Orlando, FL Salary: $80,000–$100,00... ...Compliance Analyst to support governance, risk, compliance, and audit... ...infrastructure, development, MDR/SOC, IT, leadership, and business... ...in cybersecurity, GRC, IT compliance, cyber risk,...SuggestedRelocation packageShift work$138k - $173k
...your name on itFanDuel is seeking a Senior Technology Governance, Risk & Compliance (GRC) Analyst to join its Technology GRC team as a strategic specialist... ...to risk appetite.In-depth understanding of various IT platform and systems including but not limited to AWS,...SuggestedTemporary workWork at officeLocal areaWorldwideShift work- Job Summary:The IT Governance, Risk, and Compliance (GRC) Lead Analyst serves as a subject matter expert responsible for leading the design, implementation, maturity, and continuous improvement of the organization’s IT governance, risk management, and compliance programs...SuggestedFull timeWork at office3 days per week
- ...Governance, Risk & Compliance (GRC) Analyst Client is seeking a GRC Analyst to lead our governance, risk, and compliance initiatives. This role will be... ...ensuring regulatory compliance, and supporting strategic IT goals. Key Responsibilities: Develop and...Suggested
- ...Governance, Risk & Compliance (GRC) Analyst (AI Training) About the Role We're partnering with the world's leading AI research labs to build smarter, more reliable AI systems - and we need practitioners who know how GRC actually works in the real world. If you've...Hourly payOngoing contractContract workFreelanceRemote workFlexible hours
- ...Governance, Risk, and Compliance (GRC) Analyst Schaumburg About Fulcrum We operate at the intersection of technology and law, in an industry that demands... ...Partner with cross-functional teams including IT, Legal, and Business Development to advance compliance...Full timeFlexible hours
- ...Governance, Risk & Compliance (GrC) Analyst We're partnering with the world's leading AI research labs to build smarter, more trustworthy AI — and we need practitioners who know how GRC actually works in the real world. Your expertise in security policies, compliance...Hourly payOngoing contractContract workFreelanceRemote workFlexible hours
- ...Governance, Risk & Compliance (GRC) Analyst Job Category : Information Technology Requisition Number : GOVER001449 Posted : July 1, 2026 Full-Time Hybrid... ...Analyst and play a key role in regulatory compliance, IT risk management, security. You'll assess risks, support...Full timeCasual workWork at officeWork from homeHome officeNight shiftWeekend work
$99k - $225k
Enterprise Cybersecurity GRC Governance AnalystThe Opportunity: The Enterprise Cybersecurity (ECS) Governance, Risk, and Compliance (GRC) team is seeking an experienced Information System Security Officer (ISSO) to bridge the gap between high-level policy and technical...Full timeContract workPart timeWork at officeLocal areaRemote work- ...IT Security Manager Key Responsibilities: Governance Develop, maintain, and enforce IT security... ...programs. Risk Management Identify... ...remediation efforts. Compliance Ensure compliance... ...Strong experience in GRC, IT audit, or cybersecurity...
- ...Governance, Risk & Compliance (GRC) Analyst (AI Training) About the Role We partner with the world's leading AI research labs to build smarter, safer AI systems - and we need practitioners who know how compliance and risk management actually work in the real world...Hourly payOngoing contractContract workFreelanceRemote workWorldwideFlexible hours
$120k - $150k
...Industries cybersecurity GRC program by establishing governance structure, policies, standards... ...You'll report to the IT/Cybersecurity Program Director... ...and manage cybersecurity risk processes, including risk... ...beyond minimum mandatory compliance, building genuine security...Contract workWork experience placementFor subcontractorCasual workRelocation package- ...programs.This role helps drive enterprise-wide cybersecurity governance, risk, compliance, and assurance activities that strengthen control quality,... ...experience in cybersecurity governance, risk, compliance (GRC), IT audit, risk management, control assurance, or related...Permanent employmentFor contractors
- ...a detail-oriented and proactive GRC Analyst to support the company's compliance, risk management, and security assurance... ...cross-functionally with engineering, IT, legal, HR, and business... ...standards, and procedures. Support AI governance and responsible AI compliance...Contract workWork at officeRemote workVisa sponsorshipRelocation packageFlexible hours
$135k - $165k
...continue to scale, we are looking for a highly motivated Governance, Risk & Compliance (GRC) Analyst to support and mature Ivo's security compliance and... ...procedures, and partnering cross-functionally with engineering, IT, legal, HR, and business stakeholders. This is a fully...Contract workFlexible hours- ...Governance, Risk & Compliance (GRC) Analyst (AI Training) About the Role We're looking for experienced GRC professionals to help evaluate and improve AI systems being trained on real-world security, compliance, and risk scenarios. Your practitioner knowledge will...Hourly payOngoing contractContract workFreelanceRemote workFlexible hours
$30 - $55 per hour
...Governance, Risk & Compliance (GRC) Analyst $30-55/hr Remote Freelance CODING About the Role We're looking for experienced GRC professionals to help train and evaluate cutting-edge AI systems. At Alignerr, we partner with the world's leading AI research labs —...Ongoing contractFreelanceRemote workFlexible hours- ...assessment, and mitigation of risks are fundamental components of... .... This position leads the IT security risk and audit program... ...Maintain IT security risk and compliance matrix and performs... ...IT best practices. GRC Risk Analyst Skills & Requirements:...Work experience placement
- Apply For This Job *indicates a required field FanDuel
- Description The Senior IT GRC Analyst leads policy development and audit execution within CMG's IT Governance, Risk, and Compliance program, with particular emphasis on CMG's upcoming SOC 2 readiness effort. This role works closely with the GRC team and the broader...Work at officeRemote work
- ...Infrastructure Consultant 2 to strengthen risk governance and controls programs within the... ...controls documentation, and coordinating IT infrastructure projects across teams. The... ...stakeholders to drive process improvements, ensure compliance, and support audits while contributing...
- Trustmark in Ridgeland, MS is seeking an IT GRC Analyst to oversee governance, risk, and compliance activities. The role includes coordinating compliance efforts, executing IT assessments, and developing policies. The ideal candidate will hold a Bachelor's in information...Remote job
- ...community. Description JOB DESCRIPTION: The Senior IT GRC (Governance, Risk, and Compliance) Analyst oversees technical design, implementation, maintenance,... ..., risk remediation, continuous monitoring, and IT compliance documentation and reporting efforts. Coordinates...Work experience placementRemote workWork from homeFlexible hours
- ...Third Party Governance, Risk and Compliance Analyst We are conducting a search for an experienced Third Party Governance, Risk and Compliance (GRC) Analyst with a minimum of three years' experience... ...Management (TPRM), Client Compliance and IT Risk Management. This includes...
- ...Third Party Governance, Risk and Compliance (GRC) Analyst The Analyst will be a key player in overseeing third-party vendor risk, ensuring regulatory compliance, and supporting enterprise GRC initiatives. The ideal candidate brings hands-on experience with GRC processes...Contract work
- ...highly skilled and motivated Senior GRC Analyst to join our Security and Privacy team... ..., you will own and grow RainFocus's governance, risk, and compliance program — maintaining our control framework... .... Identify and help close Shadow IT / unmanaged SaaS visibility gaps in...Full time
- ...Job Description Job Description Governance, Risk & Compliance (GRC) Analyst – State Agency – $40-46/hr W2 – Phoenix Hybrid – Contract-to-Hire SunSoftOnline is hiring a GRC / Information Security Analyst for an Arizona state agency's technology division, a 4-month...Permanent employmentFull timeContract workRemote workVisa sponsorshipMonday to Friday
- ASSYST is seeking an Information Security Governance, Risk & Compliance (GRC) Analyst to support our client in administering and maintaining an established... ..., documentation, and risk management activities. It does not involve performing security assessments, penetration...Work at officeLocal area
- Governance, Risk, & Compliance (GRC) Analyst Washington, DC Remote Full-Time About This Role As a GRC Analyst, you will help organizations navigate the complex landscape of cybersecurity compliance and risk management. You will work directly with clients to assess their...Full timeRemote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to IT Governance Risk & Compliance (GRC) Analyst. Be the first to apply!
Related searches
- quantitative risk analyst United States
- third party risk analyst United States
- operational risk specialist United States
- risk officer United States
- junior risk analyst United States
- senior quantitative risk analyst United States
- risk analyst intern United States
- transaction risk analyst United States
- information risk analyst United States
- market risk analyst United States


