A GRC Analyst spends their day identifying risks, checking whether controls and policies are actually being followed, gathering evidence for audits, and translating regulations into practical steps the rest of the business can follow. They sit between security, legal, and business teams — not writing code or configuring firewalls, but making sure what those teams do can be shown to work and to satisfy whatever rules apply.
What the work actually looks like, week to week
- Maintaining the risk register — logging new risks, re-scoring old ones, and following up on whether agreed fixes actually happened.
- Control testing and evidence collection — pulling screenshots, logs, and configuration exports that prove a control (like MFA or offboarding access removal) is working, ahead of an internal or external audit.
- Policy work — drafting or updating policies (access control, acceptable use, incident response) and running a policy gap analysis against what the organization actually does, not just what looks good on paper.
- Vendor risk reviews — sending and reviewing security questionnaires before the business signs a new vendor, and flagging the ones with real gaps. This is third-party risk management (TPRM), and at many organizations it's specialized enough to be its own dedicated role.
- Reporting — turning all of the above into something a non-technical leadership team or board can actually act on.
Skills that actually matter
Analytical thinking (can you spot what's actually missing in a policy, not just what's there), clear writing (most GRC output is a document someone else has to read and act on), attention to detail, and enough working knowledge of the relevant frameworks (ISO 27001, NIST CSF, SOC 2) to know what "good" looks like. Coding is not on this list.
Where GRC Analysts sit in an organization
It depends on the company. Some GRC Analysts report into the security team under a CISO; others sit under legal or a dedicated compliance function reporting to a Chief Risk Officer or Chief Compliance Officer. Either way, the role is inherently cross-functional — you'll spend real time talking to engineering, legal, HR, and vendors, not just one team.
Career path
Typical progression: GRC Analyst → Senior GRC Analyst → GRC Manager or Compliance Manager → Head of GRC / Chief Risk Officer, or CISO for people who lean toward the security side — though see how realistic that CISO path actually is before treating it as the default plan. Career switchers most often enter at the Analyst level after building a portfolio of practical work — see how this compares to a cybersecurity career track, which certifications are worth pursuing at which stage, and a realistic step-by-step path in if you're starting from zero. Related roles worth knowing about: Compliance Analyst and IT Auditor.