> Markdown version of [/jobs/ext/2601468-grc-analyst-onsite-in-downtown-phoenix](https://www.wearedevelopers.com/jobs/ext/2601468-grc-analyst-onsite-in-downtown-phoenix). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # GRC Analyst / Onsite in Downtown Phoenix - **Company:** Motion Recruitment - **Location:** Phoenix, AZ, United States - **Contract:** Temporary contract - **Skills:** Microsoft Excel, JIRA, Microsoft Azure, Cyber Security, DevOps, Microsoft Office, Microsoft SharePoint, RSA Archer Platform, Tools for Reporting, CIS Benchmarks, Servicenow - **Published:** August 6, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=1b37d64ea477c291 ## About the Role * Experience supporting governance, risk, compliance, audit readiness, security documentation, risk management, or approval tracking for technology projects * Ability to maintain a project risk register with clear risk descriptions, owners, impacts, likelihood, mitigation plans, residual risk, decisions, and status updates * Working knowledge of security governance and risk management concepts, including control mapping, risk acceptance, evidence collection, approval workflows, and issue remediation tracking * Familiarity with security frameworks such as NIST Cybersecurity Framework, NIST SP 800-53, CIS Controls, ISO 27001, or equivalent * Ability to understand technical project context well enough to accurately document risks, controls, approvals, dependencies, and evidence requirements * Strong documentation discipline, attention to detail, follow-up skills, and ability to keep records audit-ready * Proficiency with Microsoft Office, Excel, SharePoint, Teams, and tools such as ServiceNow, Azure DevOps, Jira, Archer, or OneTrust * Ability to coordinate across security, architecture, engineering, project delivery, compliance, operations, and stakeholder groups * Strong written communication skills and ability to clearly summarize risk and approval status Desired Skills & Experience * Security+, CGRC, CISA, CRISC, CISM, or similar certifications * Experience supporting public sector, regulated, or high-governance environments * Experience with authorization, exception, risk acceptance, audit, or compliance evidence processes * Experience building dashboards, trackers, approval matrices, or evidence repositories * Familiarity with Azure cloud, infrastructure delivery, DevOps, and security review processes ## Description A large enterprise organization is seeking a GRC Analyst to support a high-visibility security initiative in a onsite role based in downtown Phoenix, AZ. This is a contract position focused on governance, risk, and compliance activities across technology projects, with exposure to security frameworks, audit processes, and enterprise risk management tools such as ServiceNow, Azure DevOps, Jira, and SharePoint. This is an excellent opportunity for someone who thrives in structured environments and enjoys bringing order to complex security processes. The key value of this role is ownership of the risk register and approval lifecycle - you'll be the central point ensuring risks, decisions, documentation, and approvals are clearly tracked and audit-ready. If you're looking to deepen your GRC experience while working closely with security architects, engineering teams, and stakeholders across a large organization, this role offers strong exposure to enterprise-scale governance practices and real-world security decision-making., Tech Breakdown * 50% GRC Platforms and Documentation * 30% Security Frameworks and Risk Management * 20% Collaboration and Reporting Tools Daily Responsibilities * 60% Risk and Compliance Tracking * 15% Process Coordination and Follow-Ups * 25% Cross-Team Collaboration ## Related Videos - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [From DevOps to Scaled DevOps: How We’re Rebuilding Continuous Delivery as a Platform](https://www.wearedevelopers.com/videos/100018-from-devops-to-scaled-devops-how-we-re-rebuilding-continuous-delivery-as-a-platform) - [Improving quality with Agentic AI with Rovo Dev and Xray](https://www.wearedevelopers.com/videos/2005-improving-quality-with-agentic-ai-with-rovo-dev-and-xray) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [AI in Production: applied AI & enterprise use cases](https://www.wearedevelopers.com/videos/100130-ai-in-production-applied-ai-enterprise-use-cases) - [DevOps Maturity Check – a way to balance autonomy and alignment](https://www.wearedevelopers.com/videos/58-devops-maturity-check-a-way-to-balance-autonomy-and-alignment) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Top HR Tech Conferences in 2024](https://www.wearedevelopers.com/magazine/303-top-hr-tech-conferences-in-2024) - [Dev Digest 121 - AI goes offline](https://www.wearedevelopers.com/magazine/456-dev-digest-121-ai-goes-offline) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers)