The Governance, Risk, and Compliance (GRC) Analyst is responsible for identifying, assessing, monitoring, and mitigating organizational risks while ensuring compliance with applicable regulatory requirements, industry standards, and internal policies. This role works closely with business units, Information Technology (IT), cybersecurity, audit, and leadership to strengthen the organization's governance, risk management, and compliance framework.
Position Duties
Enterprise & Information Security Risk Management Conduct comprehensive enterprise and information security risk assessments to identify threats and vulnerabilities across IT, Operational Technology (OT), and business processes. Maintain and continuously update the MBTA's risk register, ensuring timely tracking of remediation actions and residual risk. Evaluate business processes, technical controls, and governance workflows to ensure they effectively mitigate identified risks and align with MBTA’s centralized compliance strategy. Support the maturation of risk methodologies, including development of risk scoring models, prioritization frameworks, and automated reporting feeds. Governance, Compliance & Regulatory Alignment Support the development, implementation, and continuous improvement of governance, risk, and compliance programs and procedures. Monitor and report compliance against regulatory requirements, industry standards, and internal policies, including International Organization for Standardization (ISO) 27001, National Institute of Standards and Technology Cybersecurity Framework (NIST CSF)/800-53, Service Organization Control (SOC) 2, Payment Card Industry Data Security Standard (PCI DSS), Transportation Security Administration (TSA) Surface Directives, United States Coast Guard (USCG) requirements, General Data Protection Regulation (GDPR), Health Insurance Portability and Accountability Act (HIPAA), Sarbanes-Oxley Act (SOX), and other MBTA-applicable mandates. Assist with maintaining authoritative policy and standards documentation; participate in policy review cycles and support enterprise-wide enforcement. Third-Party & Supply-Chain Risk Perform detailed third-party/vendor security assessments covering onboarding, due-diligence, SOC 2/Federal Risk and Authorization Management Program (FedRAMP)/ISO attestation reviews, contractual security clauses, and ongoing monitoring. Track vendor remediation activities and partner with Procurement, Legal, and business owners to ensure sustained compliance. Audit Support & Evidence Management Assist with internal and external audits by gathering documentation, coordinating evidence collection, validating controls, and supporting remediation plans. Serve as a liaison between business units, auditors, and Information Security to ensure timely and accurate audit responses. Analytics, Reporting & Executive Dashboards Develop risk dashboards, status reports, metrics, and executive-level summaries for leadership, including trends, Key Performance Indicators (KPIs), Key Risk Indicators (KRIs), and compliance performance indicators. Maintain high-quality data integrity within GRC platforms (e.g., ServiceNow GRC, Archer) by ensuring accuracy of control catalogs, assessments, exceptions, and workflow automation. Cross-Functional Collaboration & Advisory Support Partner with IT, Cybersecurity, Operations, Legal, Finance, and business teams to identify control gaps and recommend actionable mitigation strategies. Support enterprise roadmaps by providing risk insights that influence technology, process, and operational decisions. Assist team leaders and stakeholders in understanding risk exposure, obligations, and governance expectations. Policy Governance & Awareness In collaboration with the GRC Policy Analyst, support policy development, review cycles, distribution, and enforcement efforts across the enterprise. Promote risk awareness, compliance practices, and security-first principles through communications, targeted training, and awareness campaigns. Continuous Monitoring & Professional Development Stay informed of emerging cybersecurity threats, regulatory changes, industry frameworks, and best practices relevant to MBTA operations. Evaluate opportunities for process improvements, automation, and enhanced risk analysis techniques. Additional Responsibilities Provide risk assessment and compliance support for OT environments and transit-related systems. Assist the team's Deputy Director or other leadership in executing enterprise-level initiatives related to centralized compliance, regulatory coordination, and risk governance. Stakeholder Engagement & Communication Prepare briefing materials for executive committees, regulatory inquiries, and cross-department collaborations. Perform all other duties and projects that may be assigned. Additional responsibilities may include focus on one or more departments or locations. See applicable addendum for department or location specific functions. Supervision No direct reports.
Apply for this job in 1 click
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
Conduct comprehensive enterprise and information security risk assessments to identify threats and vulnerabilities across IT, Operational Technology (OT), and business processes.
Maintain and continuously update the MBTA's risk register, ensuring timely tracking of remediation actions and residual risk. Evaluate business processes, technical controls, and governance workflows to ensure they effectively mitigate identified risks and align with MBTA’s centralized compliance strategy.
Support the maturation of risk methodologies, including development of risk scoring models, prioritization frameworks, and automated reporting feeds.
Support the development, implementation, and continuous improvement of governance, risk, and compliance programs and procedures.
Monitor and report compliance against regulatory requirements, industry standards, and internal policies, including International Organization for Standardization (ISO) 27001, National Institute of Standards and Technology Cybersecurity Framework (NIST CSF)/800-53, Service Organization Control (SOC) 2, Payment Card Industry Data Security Standard (PCI DSS), Transportation Security Administration (TSA) Surface Directives, United States Coast Guard (USCG) requirements, General Data Protection Regulation (GDPR), Health Insurance Portability and Accountability Act (HIPAA), Sarbanes-Oxley Act (SOX), and other MBTA-applicable mandates.
Assist with maintaining authoritative policy and standards documentation; participate in policy review cycles and support enterprise-wide enforcement.
Perform detailed third-party/vendor security assessments covering onboarding, due-diligence, SOC 2/Federal Risk and Authorization Management Program (FedRAMP)/ISO attestation reviews, contractual security clauses, and ongoing monitoring.
Track vendor remediation activities and partner with Procurement, Legal, and business owners to ensure sustained compliance.
Assist with internal and external audits by gathering documentation, coordinating evidence collection, validating controls, and supporting remediation plans.
Serve as a liaison between business units, auditors, and Information Security to ensure timely and accurate audit responses.
Develop risk dashboards, status reports, metrics, and executive-level summaries for leadership, including trends, Key Performance Indicators (KPIs), Key Risk Indicators (KRIs), and compliance performance indicators.
Maintain high-quality data integrity within GRC platforms (e.g., ServiceNow GRC, Archer) by ensuring accuracy of control catalogs, assessments, exceptions, and workflow automation.
Partner with IT, Cybersecurity, Operations, Legal, Finance, and business teams to identify control gaps and recommend actionable mitigation strategies.
Support enterprise roadmaps by providing risk insights that influence technology, process, and operational decisions.
Assist team leaders and stakeholders in understanding risk exposure, obligations, and governance expectations.
In collaboration with the GRC Policy Analyst, support policy development, review cycles, distribution, and enforcement efforts across the enterprise.
Promote risk awareness, compliance practices, and security-first principles through communications, targeted training, and awareness campaigns.
Stay informed of emerging cybersecurity threats, regulatory changes, industry frameworks, and best practices relevant to MBTA operations.
Evaluate opportunities for process improvements, automation, and enhanced risk analysis techniques.
Provide risk assessment and compliance support for OT environments and transit-related systems.
Assist the team's Deputy Director or other leadership in executing enterprise-level initiatives related to centralized compliance, regulatory coordination, and risk governance. Stakeholder Engagement & Communication
Prepare briefing materials for executive committees, regulatory inquiries, and cross-department collaborations.
Perform all other duties and projects that may be assigned.
No direct reports.
Minimum Qualifications
Bachelor's degree in Information Technology, Cybersecurity, Information Systems, Business, Finance, Risk Management, or a related field. Two (2) years of experience in Governance, Risk, Compliance, Information Security, Internal Audit, or Enterprise Risk Management. Experience performing risk assessments and documenting findings. Knowledge of risk management methodologies and control frameworks. Familiarity with regulatory and compliance standards (e.g., NIST CSF/800-53, ISO 27001, SOC 2, PCI DSS, HIPAA GDPR, SOX). Strong analytical, organizational, and problem-solving skills. Excellent written and verbal communication skills. Ability to work cross-functionally with technical and non-technical stakeholders. Substitutions A high school diploma or GED with an additional seven (7) years of directly related experience substitutes for the bachelor’s degree requirement. An associate’s degree from an accredited institution and an additional three (3) years of directly related experience substitutes for the bachelor’s degree requirement. A master’s degree in a related subject substitutes for two (2) years of general experience. A nationally recognized certification, or statewide/professional certification in a related field substitutes for one (1) year of experience.
Bachelor's degree in Information Technology, Cybersecurity, Information Systems, Business, Finance, Risk Management, or a related field.
Two (2) years of experience in Governance, Risk, Compliance, Information Security, Internal Audit, or Enterprise Risk Management.
Experience performing risk assessments and documenting findings.
Knowledge of risk management methodologies and control frameworks.
Familiarity with regulatory and compliance standards (e.g., NIST CSF/800-53, ISO 27001, SOC 2, PCI DSS, HIPAA GDPR, SOX).
Strong analytical, organizational, and problem-solving skills.
Excellent written and verbal communication skills.
Ability to work cross-functionally with technical and non-technical stakeholders.
A high school diploma or GED with an additional seven (7) years of directly related experience substitutes for the bachelor’s degree requirement.
An associate’s degree from an accredited institution and an additional three (3) years of directly related experience substitutes for the bachelor’s degree requirement.
A master’s degree in a related subject substitutes for two (2) years of general experience.
A nationally recognized certification, or statewide/professional certification in a related field substitutes for one (1) year of experience.
Other Qualifications
Certified Information Systems Auditor (CISA). Certified in Risk and Information Systems Control (CRISC). Certified Information Systems Security Professional (CISSP). Certified Information Security Manager (CISM). Project Management Professional (PMP).
Certified Information Systems Auditor (CISA).
Certified in Risk and Information Systems Control (CRISC).
Certified Information Systems Security Professional (CISSP).
Certified Information Security Manager (CISM).
Project Management Professional (PMP).
Benefits
Employment Benefits at the MBTA Full-Time Employees: The MBTA offers comprehensive benefits packages. Types of benefits offered at the MBTA are subject to the union affiliation / Collective Bargaining Agreement (CBA) of the position to which you apply. Benefits that may apply to your position include the following: Insurance: Health, Dental, Vision, Life (basic and supplemental), and Long-Term Disability Paid Time Off (PTO): Vacation, Personal Days, Sick Leave, and Holidays Retirement: Pension or deferred compensation 401(a), plus MBTA contributions Complimentary pass for travel on the MBTA transit system (bus, train, ferry, and Commuter Rail) Tuition Reimbursement (up to $10,000 per year) Public Service Loan Forgiveness (PSLF) for student loans Commuter Choice Parking Program: Pre-tax benefits for parking Flexible Spending Account (FSA): Pre-tax benefits for healthcare-related expenses Discounted tickets for concerts, movies, travel / vacation, etc. via TicketsAtWork.com Shopping discounts via GovX.com Verizon and AT&T service discounts And more... Disclaimer: The above information is meant to be a general overview of the benefit programs offered by the MBTA, which may or may not apply to a specific position. This summary is not a contract and is not meant to change the provisions of union contracts or Authority policies and does not establish a binding practice. Please contact the assigned Recruiter directly or email hrstaffing@mbta.com for more information. The MBTA is an Affirmative Action/Equal Opportunity Employer
Employment Benefits at the MBTA
Full-Time Employees: The MBTA offers comprehensive benefits packages. Types of benefits offered at the MBTA are subject to the union affiliation / Collective Bargaining Agreement (CBA) of the position to which you apply. Benefits that may apply to your position include the following:
Insurance: Health, Dental, Vision, Life (basic and supplemental), and Long-Term Disability
Paid Time Off (PTO): Vacation, Personal Days, Sick Leave, and Holidays
Retirement: Pension or deferred compensation 401(a), plus MBTA contributions
Complimentary pass for travel on the MBTA transit system (bus, train, ferry, and Commuter Rail)
Tuition Reimbursement (up to $10,000 per year)
Public Service Loan Forgiveness (PSLF) for student loans
Commuter Choice Parking Program: Pre-tax benefits for parking
Flexible Spending Account (FSA): Pre-tax benefits for healthcare-related expenses
Discounted tickets for concerts, movies, travel / vacation, etc. via TicketsAtWork.com
Shopping discounts via GovX.com
Verizon and AT&T service discounts
And more...
Disclaimer: The above information is meant to be a general overview of the benefit programs offered by the MBTA, which may or may not apply to a specific position. This summary is not a contract and is not meant to change the provisions of union contracts or Authority policies and does not establish a binding practice. Please contact the assigned Recruiter directly or email hrstaffing@mbta.com for more information.
Supplemental Questions
I do not have a High School Diploma or GED Equivalent.
A High School Diploma or GED and nine (9) years of experience in Governance, Risk, Compliance, Information Security, Internal Audit, or Enterprise Risk Management.
An associate degree from an accredited institution and five (5) years of experience in Governance, Risk, Compliance, Information Security, Internal Audit, or Enterprise Risk Management.
A Bachelor's Degree in Information Technology, Cybersecurity, Information Systems, Business, Finance, Risk Management, or a related field and two (2) years of experience in Governance, Risk, Compliance, Information Security, Internal Audit, or Enterprise Risk Management.
A master’s degree in a related subject and general experience in Governance, Risk, Compliance, Information Security, Internal Audit, or Enterprise Risk Management.
A nationally recognized certification, or statewide/professional certification and one (1) year of experience in Governance, Risk, Compliance, Information Security, Internal Audit, or Enterprise Risk Management.
Yes
No
Required Question
About Massachusetts Bay Transportation Authority
Verified company details for this employer are not available yet.