GRC Analyst

Massachusetts Bay Transportation AuthorityBoston, MA
Onsite

About The Position

The Governance, Risk, and Compliance (GRC) Analyst is responsible for identifying, assessing, monitoring, and mitigating organizational risks while ensuring compliance with applicable regulatory requirements, industry standards, and internal policies. This role works closely with business units, Information Technology (IT), cybersecurity, audit, and leadership to strengthen the organization's governance, risk management, and compliance framework.

Requirements

  • Bachelor's degree in Information Technology, Cybersecurity, Information Systems, Business, Finance, Risk Management, or a related field.
  • Two (2) years of experience in Governance, Risk, Compliance, Information Security, Internal Audit, or Enterprise Risk Management.
  • Experience performing risk assessments and documenting findings.
  • Knowledge of risk management methodologies and control frameworks.
  • Familiarity with regulatory and compliance standards (e.g., NIST CSF/800-53, ISO 27001, SOC 2, PCI DSS, HIPAA GDPR, SOX).
  • Strong analytical, organizational, and problem-solving skills.
  • Excellent written and verbal communication skills.
  • Ability to work cross-functionally with technical and non-technical stakeholders.
  • A high school diploma or GED with an additional seven (7) years of directly related experience substitutes for the bachelor’s degree requirement.
  • An associate’s degree from an accredited institution and an additional three (3) years of directly related experience substitutes for the bachelor’s degree requirement.
  • A master’s degree in a related subject substitutes for two (2) years of general experience.
  • A nationally recognized certification, or statewide/professional certification in a related field substitutes for one (1) year of experience.
  • Ability to effectively read, comprehend, communicate, and respond to instructions, orders, signs, notices, inquiries, etc. in English.
  • Be at least eighteen (18) years of age, except if participating in an approved high school internship / co-op program.
  • Ability to commute to assigned work locations in the Boston, MA metro area, as required by the role.
  • Ability to provide internal and external customers with courteous and professional experiences.
  • Ability to work effectively, independently, and as part of a diverse workforce team (or supervise, if required).
  • Ability to uphold the rights and interests of the MBTA while building and maintaining effective relationships with employees and co-workers.
  • Ability to adhere to rules, regulations, collective bargaining agreements (if applicable), and policies of the MBTA, including the EEO, anti-discrimination, anti-harassment, and anti-retaliation policies.
  • Have a satisfactory work record for the two (2) years immediately prior to the closing date of this posting (unless if current student or recent graduate), including overall employment, job performance, discipline, and safety records (infractions and/or offenses occurring after the closing of the posting and before the filling of a vacancy may preclude a candidate from consideration for selection).
  • Ability to pass a Criminal Offender Record Information (CORI) check, comprehensive background screening, and / or medical Clinic screening, potentially including physical examination and drug and alcohol screenings.
  • Ability to work all shifts and / or locations assigned, directed, or necessary for this position, including (for some transit / operations roles) up to twenty-four (24) hours per day, seven (7) days per week as necessary to accommodate severe weather conditions, emergencies, or any other circumstances that may potentially impact service or the safety of service.
  • Intern / co-op staff must be enrolled full or part-time in an accredited educational program and maintain a cumulative GPA of at least 2.5 for the entire duration of the internship / co-op.
  • Additionally, interns / co-ops must have valid work authorization and U.S. Social Security Number prior to starting pre-employment screenings / pre-boarding, working in their positions, and throughout the duration of their program.
  • All employees must be legally authorized to work in the United States and on an unrestricted basis.
  • The MBTA does not have an employer work sponsorship program.
  • However, if you have unrestricted work authorization, or are sponsored by a separate entity, you are welcome to apply.
  • Further, all persons hired will require a U.S. Social Security Number prior to starting the position and employees will be required to complete a Form I-9 to verify their identity and eligibility to work in the U.S.
  • Candidates should ensure they arrive on time, are prepared, can remain for the duration, and if remote, are in a quiet place without distraction, for the interview.
  • Candidates who do not attend their interview without advance authorization, including an email confirmation of a rescheduled time/date from Human Resources, will be considered a no-show and disqualified from consideration for the position.
  • In addition, Human Resources may require documentation supporting the request.
  • However, should you need to reschedule, you will need to contact your Recruiter directly by email.

Nice To Haves

  • Certified Information Systems Auditor (CISA).
  • Certified in Risk and Information Systems Control (CRISC).
  • Certified Information Systems Security Professional (CISSP).
  • Certified Information Security Manager (CISM).
  • Project Management Professional (PMP).

Responsibilities

  • Conduct comprehensive enterprise and information security risk assessments to identify threats and vulnerabilities across IT, Operational Technology (OT), and business processes.
  • Maintain and continuously update the MBTA's risk register, ensuring timely tracking of remediation actions and residual risk.
  • Evaluate business processes, technical controls, and governance workflows to ensure they effectively mitigate identified risks and align with MBTA’s centralized compliance strategy.
  • Support the maturation of risk methodologies, including development of risk scoring models, prioritization frameworks, and automated reporting feeds.
  • Support the development, implementation, and continuous improvement of governance, risk, and compliance programs and procedures.
  • Monitor and report compliance against regulatory requirements, industry standards, and internal policies, including International Organization for Standardization (ISO) 27001, National Institute of Standards and Technology Cybersecurity Framework (NIST CSF)/800-53, Service Organization Control (SOC) 2, Payment Card Industry Data Security Standard (PCI DSS), Transportation Security Administration (TSA) Surface Directives, United States Coast Guard (USCG) requirements, General Data Protection Regulation (GDPR), Health Insurance Portability and Accountability Act (HIPAA), Sarbanes-Oxley Act (SOX), and other MBTA-applicable mandates.
  • Assist with maintaining authoritative policy and standards documentation; participate in policy review cycles and support enterprise-wide enforcement.
  • Perform detailed third-party/vendor security assessments covering onboarding, due-diligence, SOC 2/Federal Risk and Authorization Management Program (FedRAMP)/ISO attestation reviews, contractual security clauses, and ongoing monitoring.
  • Track vendor remediation activities and partner with Procurement, Legal, and business owners to ensure sustained compliance.
  • Assist with internal and external audits by gathering documentation, coordinating evidence collection, validating controls, and supporting remediation plans.
  • Serve as a liaison between business units, auditors, and Information Security to ensure timely and accurate audit responses.
  • Develop risk dashboards, status reports, metrics, and executive-level summaries for leadership, including trends, Key Performance Indicators (KPIs), Key Risk Indicators (KRIs), and compliance performance indicators.
  • Maintain high-quality data integrity within GRC platforms (e.g., ServiceNow GRC, Archer) by ensuring accuracy of control catalogs, assessments, exceptions, and workflow automation.
  • Partner with IT, Cybersecurity, Operations, Legal, Finance, and business teams to identify control gaps and recommend actionable mitigation strategies.
  • Support enterprise roadmaps by providing risk insights that influence technology, process, and operational decisions.
  • Assist team leaders and stakeholders in understanding risk exposure, obligations, and governance expectations.
  • In collaboration with the GRC Policy Analyst, support policy development, review cycles, distribution, and enforcement efforts across the enterprise.
  • Promote risk awareness, compliance practices, and security-first principles through communications, targeted training, and awareness campaigns.
  • Stay informed of emerging cybersecurity threats, regulatory changes, industry frameworks, and best practices relevant to MBTA operations.
  • Evaluate opportunities for process improvements, automation, and enhanced risk analysis techniques.
  • Provide risk assessment and compliance support for OT environments and transit-related systems.
  • Assist the team's Deputy Director or other leadership in executing enterprise-level initiatives related to centralized compliance, regulatory coordination, and risk governance.
  • Prepare briefing materials for executive committees, regulatory inquiries, and cross-department collaborations.
  • Perform all other duties and projects that may be assigned.
  • Additional responsibilities may include focus on one or more departments or locations.
  • See applicable addendum for department or location specific functions.

Benefits

  • Accrued paid sick leave
  • Monthly transportation pass
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service