GOVERNANCE, RISK, AND COMPLIANCE ANALYST

Posted 13 days ago

access data consultingPhoenix (AZ)
Compliance ManagersOther Management Consulting Services

SENIORITY

Lead

Apply

About the role

Job Title: Governance, Risk, and Compliance Analyst (GRC) Location: Phoenix - Hybrid (within a one hour commute) Due to Government restrictions this position is open only to US citizens and Green Card Holders. No C2C or third parties will be considered. Our client is an organization dedicated to protecting enterprise data and modernizing digital systems. We are seeking a Governance, Risk, and Compliance Analyst to join their security team. In this role, you will bridge the gap between technical infrastructure and regulatory frameworks, ensuring digital services remain secure and fully compliant. Here’s What You’ll Be Doing Evaluating and analyzing technology environments across Windows and Unix platforms to perform risk assessments, control reviews, and compliance audits. Designing and mapping data models, operational data flows, and detailed system activity diagrams to track enterprise information dependencies. Formulating and documenting comprehensive audit findings, remediation strategies, and structured Plans of Action and Milestones (POA&Ms) in alignment with regulatory standards. Partnering and communicating with cross-functional business units and technical project managers to translate security requirements into scalable operational workflows and user adoption materials. Researching and updating institutional information security plans, internal control policies, and system authorization strategies to proactively mitigate compliance risks. Here’s What Our Ideal Candidate Has Framework mastery utilizing NIST 800-53 (Revision 5) to build, assess, and audit institutional risk management structures. Proven background in the Risk Management Framework (RMF), specifically guiding complex information systems through formal security control selection, verification, and approval cycles. Strong multi-platform technical literacy, including practical experience auditing or navigating Windows and Unix operating environments, databases, or network architectures. Excellent communication skills, with a track record of translating cybersecurity regulations (such as HIPAA, CJIS, or similar frameworks) into quality documentation for senior leadership. Preferred: Active security certifications (such as CISSP, CCSP, CAP, GSNA, or GSTRT) and previous exposure to technical project management methodologies. #J-18808-Ljbffr

Before you apply

Applying takes about a minute. These four things decide how fast it moves after that.

Your profile is current

It's what we read first. Occupations, seniority and locations matter more than a long history.

Two examples you can talk through

Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.

A number in mind

What you're on now and what would make you move. We negotiate better when we know both.

Your notice period

Employers plan around it, and it's the question that stalls offers most often.

Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.

More like this

GOVERNANCE, RISK, AND COMPLIANCE ANALYST Jobs at access data...