GOVERNANCE, RISK, AND COMPLIANCE ANALYST

Access Data Consulting Corporation

Phoenix (AZ)

Hybrid

USD 80,000 - 100,000

Full time

14 days+
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Access Data Consulting Corporation seeks a Governance, Risk, and Compliance Analyst to join their security team in a hybrid work environment in Phoenix. The role involves ensuring compliance with security regulations while bridging technical infrastructure and regulatory frameworks.

The ideal candidate must demonstrate mastery of the NIST 800-53 framework and possess strong skills in risk management, as well as effective communication abilities to translate complex cybersecurity guidelines into quality documentation.

Qualifications

  • NIST 800-53 framework mastery for risk management.
  • Experience in guiding complex information systems through security control cycles.
  • Technical literacy with Windows and Unix operating environments.

Responsibilities

  • Evaluate technology environments to perform risk assessments.
  • Design data models and system activity diagrams for information tracking.
  • Document audit findings and remediation strategies.
  • Translate security requirements into operational workflows.
  • Update security plans and internal control policies.

Skills

Framework mastery utilizing NIST 800-53
Proven background in Risk Management Framework (RMF)
Strong multi-platform technical literacy
Excellent communication skills
Active security certifications (e.g., CISSP, CCSP)

Job description

Job Title: Governance, Risk, and Compliance Analyst (GRC)

Location: Phoenix - Hybrid (within a one hour commute)

Due to Government restrictions this position is open only to US citizens and Green Card Holders. No C2C or third parties will be considered.

Our client is an organization dedicated to protecting enterprise data and modernizing digital systems. We are seeking a Governance, Risk, and Compliance Analyst to join their security team. In this role, you will bridge the gap between technical infrastructure and regulatory frameworks, ensuring digital services remain secure and fully compliant.

Here’s What You’ll Be Doing
  • Evaluating and analyzing technology environments across Windows and Unix platforms to perform risk assessments, control reviews, and compliance audits.
  • Designing and mapping data models, operational data flows, and detailed system activity diagrams to track enterprise information dependencies.
  • Formulating and documenting comprehensive audit findings, remediation strategies, and structured Plans of Action and Milestones (POA&Ms) in alignment with regulatory standards.
  • Partnering and communicating with cross-functional business units and technical project managers to translate security requirements into scalable operational workflows and user adoption materials.
  • Researching and updating institutional information security plans, internal control policies, and system authorization strategies to proactively mitigate compliance risks.
Here’s What Our Ideal Candidate Has
  • Framework mastery utilizing NIST 800-53 (Revision 5) to build, assess, and audit institutional risk management structures.
  • Proven background in the Risk Management Framework (RMF), specifically guiding complex information systems through formal security control selection, verification, and approval cycles.
  • Strong multi-platform technical literacy, including practical experience auditing or navigating Windows and Unix operating environments, databases, or network architectures.
  • Excellent communication skills, with a track record of translating cybersecurity regulations (such as HIPAA, CJIS, or similar frameworks) into quality documentation for senior leadership.
  • Preferred: Active security certifications (such as CISSP, CCSP, CAP, GSNA, or GSTRT) and previous exposure to technical project management methodologies.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

GRC Analyst: Risk, Compliance & Audit Lead
GRC Analyst: Risk, Compliance & Audit Lead

Access Data Consulting Corporation • Phoenix (AZ)

Hybrid
USD 80,000 - 100,000
Governance, Risk & Compliance (GRC) Analyst
Governance, Risk & Compliance (GRC) Analyst

Delta-Denta • St. Louis (MO)

On-site
USD 75,000 - 110,000
GRC Analyst
GRC Analyst

The Emery Company, LLC • Houston (TX)

On-site
USD 85,000 - 110,000
Governance, Risk and Compliance Analyst Senior
Governance, Risk and Compliance Analyst Senior

Cone Health • Greensboro (NC)

On-site
USD 90,000 - 130,000
IT GRC Lead Analyst
IT GRC Lead Analyst

Westfield Insurance • Westfield Center (OH)

On-site
USD 90,000 - 120,000
Governance, Risk & Compliance Analyst (Third-Party Risk Analyst)
Governance, Risk & Compliance Analyst (Third-Party Risk Analyst)

recruit22 • Chicago (IL)

On-site
USD 65,000 - 90,000
Governance, Risk, & Compliance (GRC) Analyst
Governance, Risk, & Compliance (GRC) Analyst

Districttechgroup • Washington

On-site
USD 80,000 - 100,000
Fully remote work environment
Competitive salary and performance bonuses
Health, dental, and vision insurance
+2
Senior GRC Analyst
Senior GRC Analyst

Averity • New York (NY)

On-site
USD 90,000 - 140,000
CyberSecurity Specialist - GRC - W2 Only
CyberSecurity Specialist - GRC - W2 Only

Saransh Inc • Phoenix (AZ)

Hybrid
USD 110,000 - 160,000
GRC (Governance, Risk, and Compliance) Consultant
GRC (Governance, Risk, and Compliance) Consultant

Zoho • United States

Remote
USD 120,000 - 180,000