Open Compliance jobs across governance, risk, and compliance, refreshed continuously.
Governance risk compliance jobs sit where policy meets proof. A GRC compliance team writes the rules an organization operates under, then evidences that the organization actually follows them — to regulators, to auditors, to customers running vendor due diligence, and increasingly to anyone asking how the company governs its AI.
The work splits along a few well-worn lines. IT security compliance manager jobs map security controls to frameworks like SOC 2, ISO 27001, PCI DSS and NIST, then run the evidence collection that proves those controls operate. Information security and privacy roles handle the data side. Internal audit provides the independent check on all of it, and a compliance governance and oversight lead owns the program end to end — risk register, policy lifecycle, regulator relationships and board reporting.
What has changed is scope. The same teams that certified against ISO 27001 are now being handed ISO/IEC 42001, the NIST AI Risk Management Framework and the EU AI Act, because AI governance is a controls-and-evidence discipline and these are the people who already know how to run one. That is why GRC compliance jobs have moved from cost centre to the fastest-growing seat in risk management.
Below are the open compliance jobs on the board now, from analyst through director and chief compliance officer.
Compliance jobs: what the market looks like right now
A snapshot built from the 167 Compliance roles currently on this page.
What these roles pay by level
Median advertised midpoint, by seniority band. Bars are to scale.
Median advertised salary midpoint by seniority level
Level
Median midpoint
Postings
Mid-level
$102k
32
Senior / lead / manager
$168k
37
Director
$214k
13
How these figures were calculated, and sources
Primary source: our own board. Every figure above is the median midpoint of the salary ranges published in the live postings on this page. Nothing is estimated, modelled, or carried over from a previous month. It is recalculated each time the board refreshes.
What is included. Only postings that publish a salary range. Hourly, weekly and monthly rates are annualised (2,080 hours, 52 weeks, 12 months). Ranges below $20,000 a year are excluded as data-entry placeholders. A seniority band is shown only when at least five postings support it; executive / c-suite is present on this page but below that threshold, so no median is published for that band.
What this is not. These are advertised ranges, not accepted offers. Advertised ranges tend to run wider than what is actually paid, and roles that do not publish a range are missing from the calculation entirely, which can bias the result upward.
For an independent benchmark, compare against the U.S. Bureau of Labor Statistics Occupational Employment and Wage Statistics for SOC 13-1041 — Compliance Officers, published annually at bls.gov/oes. BLS reports actual wages across all employers rather than advertised ranges, so its medians normally sit below job-board figures.
Where the work is
Work mode: 26 remote, 15 hybrid, 126 on-site or unstated.
Seniority mix: mid (66), senior (65), director (22), executive (14)
Employers hiring more than one: OKX (11), KPMG (10), SEI (9), Coinbase (9), Anduril Industries (6), Stripe (6)
Skills these postings ask for
policy and procedure writing
control testing and evidence collection
regulatory change management
SOX and SOC 2 readiness
issue management and remediation tracking
How to get a compliance job — the full career guide for this field: entry routes, transferable backgrounds, certifications and salary by level.
Certifications that come up most
None of these are universally required, but they appear often enough in Compliance postings to be worth knowing: CCEP, CRCM, CAMS, CIPP/US, AIGP. The certification academy covers what each one actually tests and who it is for.
Compliance jobs: tools, skills and workflows
What tools do compliance jobs use?
A compliance function runs on a small stack that barely changes between industries: a policy library with version control and attestation tracking, a control library mapped to whichever frameworks apply, an issues and findings tracker with owners and due dates, a training and attestation system, and an evidence repository the auditors can be pointed at. Larger programs put a GRC platform over the top of all of it. What separates a strong candidate is not naming the vendor, it is knowing what belongs in each record and what breaks when a regulation changes. Our guide to GRC tools and automation skills goes through the configuration work in detail.
What skills do compliance jobs require?
Reading a regulation and turning it into a control someone can actually perform, then testing whether they did. Around that: writing that survives legal review, evidence discipline, stakeholder management with people who see you as overhead, data work in spreadsheets and increasingly SQL, and enough platform skill to configure a workflow rather than file a ticket and wait. The cybersecurity and IT GRC career guides break this down job by job, and the how to become a compliance analyst roadmap lays out the entry path.
What does a compliance workflow actually look like?
A requirement arrives, from a regulator, a contract, or a new framework the company adopted. Someone maps it to controls that already exist and flags the gaps. The gaps become work with owners and dates. Controls get tested on a schedule, testing produces evidence and findings, findings get remediated or accepted with a documented rationale, and the whole loop is reported upward. Then the requirement changes and it runs again. Designing that loop so it survives contact with a busy business is most of the job.
How do I prove compliance skills without the title?
Pick one regulation and build the artifact: a control matrix mapping its clauses to testable controls, with owners, test procedures, evidence requirements and a sample test result. It is a weekend of work and it answers more of an interview than a certificate does. If you are studying at the same time, the 592 free certification practice questions cover CISA, CISM, CRISC and the AIGP.
Related GRC compliance roles
Compliance is one lane inside governance, risk and compliance. These neighbouring hubs share the same hiring managers and, often, the same shortlists:
We have 167 open Compliance roles on the board right now. Reach candidates who are already searching for this role, not a general audience. Your posting appears on this page, in the job alerts, and across the GRC Careers network.
We use only essential cookies to run this site. Analytics cookies stay off unless you turn them on. See our Cookie Notice.
Cookie preferences
We default to the minimum. Non-essential cookies stay off until you turn them on here, and we drop nothing before you do.
Essential cookies
Required for security and to operate the site, and they record no personal information. The only cookie we set is grc_sess, which keeps an employer signed in after login (expires in 30 days). Your choice here is saved in your browser's local storage, not a cookie. No tracking identifiers, and these are always active.
Analytics and usage cookies
Help us understand how the site is used. Off by default. Nothing analytics related loads unless you switch this on.
Your download is on the way
Want a new one every week? Join the AI governance brief: fresh jobs, guides, and reference sheets, straight to your inbox.
Your email stays confidential. Unsubscribing is one click. At most one email a week. Your download won't be interrupted.