Source Job

$70,000–$77,000/yr
US

  • Perform enterprise risk assessments using NIST CSF, SOC 2, and CIS frameworks.
  • Develop and execute security awareness programs including training and phishing simulations.
  • Support governance and control management by maintaining policies and control libraries.

Cybersecurity Risk Management Compliance GRC Vendor Risk Management

20 jobs similar to Security GRC Analyst

Jobs ranked by similarity.

$120,000–$140,000/yr
US

  • Conduct IT and cybersecurity risk assessments across systems, applications, and business processes.
  • Lead audit readiness activities for frameworks like SOC 2, HIPAA, and NYDFS.
  • Manage security policies, third-party vendor assessments, and develop risk dashboards.

Jobgether uses an AI-powered matching process to connect candidates with hiring companies. They focus on efficient, objective application review and are a remote-first organization.

US

  • Monitor security alerts, vulnerabilities, and incidents across enterprise systems and assist in incident response.
  • Maintain compliance with standards such as NIST CSF, ISO 27001, and SOC 2 through audits and policy development.
  • Conduct security risk assessments, evaluate controls, and track remediation plans.

Mission Critical Group is an end-to-end power solutions and services provider that accelerates time-to-power for mission critical environments. With over 1.5 million square feet of U.S. manufacturing capacity, they support data centers, healthcare, and industrial facilities.

$150,000–$170,000/yr
US Unlimited PTO

  • Lead the governance, risk, and compliance function across security policies, standards, risk management, audits, and third-party risk.
  • Own audit readiness and ongoing compliance programs across frameworks such as SOC 2, ISO 27001, GovRAMP, PCI DSS, HIPAA, NIST CSF, and more.
  • Manage third-party and supply chain risk management, including vendor security reviews, due diligence, and remediation tracking.

Accela provides government software solutions to improve efficiency, increase citizen engagement, and enable thriving communities. They have been an industry leader for nearly 20 years and are committed to diversity, equity, and inclusion.

US

  • Lead the design and governance of control frameworks and risk workflows within the GRC platform, ensuring alignment with compliance requirements like HIPAA, HITRUST, and NIST.
  • Oversee risk assessments, control testing, and vendor evaluations to identify and mitigate security risks.
  • Manage policy lifecycle, audit coordination, and reporting on control effectiveness and risk indicators.

USAP is a healthcare organization focused on providing anesthesia services and patient safety. It is a growing company with a culture of security, compliance, and collaboration.

$105,000–$130,000/yr
US

  • Consult onsite and remotely with customers to collect and analyze data related to policies, infrastructure, and compliance requirements.
  • Perform gap analyses of current environments and recommend remediation steps.
  • Assist with sales and marketing activities as a subject matter expert and prepare industry presentations.

CampusGuard provides information security and privacy consulting and compliance services for campus-based organizations. It is a full-service firm leveraging industry standards to deliver world-class security and compliance services.

$110,100–$143,100/yr
North America

  • Defines program goals, governance frameworks, and measurable objectives for cyber risk and compliance programs.
  • Manages user attestations, third-party risk, cyber contract negotiation, and coordination of IT audits/assessments.
  • Implements GRC tooling and monitors program effectiveness through KPIs, QA reviews, and control testing.

Velera is a credit union service organization providing fintech solutions to over 4,000 financial institutions. The company fosters a remote-first, inclusive culture with a focus on employee wellbeing and belonging.

$115,000–$145,000/yr
Global

  • Serve as a hands-on GRC advisor for customers, guiding them through risk assessments, audit preparation, and control rollouts.
  • Help customers navigate audits like SOC 2, ISO 27001, HIPAA, PCI-DSS, and NIST, translating requirements into practical steps.
  • Spot GRC complexity early and partner with Support and Customer Success to own escalations requiring real GRC expertise.

Compyl is a GRC and automated security compliance platform built by security practitioners. Backed by Venture Guides, Contour Venture Partners, and Armory Square Ventures, it is a high-growth Series A company.

US Unlimited PTO

  • Manage and implement complex controls frameworks for large systems consisting of Cloud infrastructure and SaaS services.
  • Design and develop automation solutions for evidence collection across Cloud infrastructure, endpoints, and SaaS services.
  • Conduct risk assessments across business units and processes, identifying risk findings and recommending remediation strategies.

Virtru is a data protection platform that enables secure sharing without sacrificing security or privacy. Backed by top venture capital firms, the company helps Fortune 500 companies and government agencies achieve true data security with freedom to share.

Canada United States

  • Execute the security architecture process for business initiatives, from engagement through to implementation.
  • Support the Information Security Architect across analysis, reviews, and outputs as needed.
  • Act as a point of contact for InfoSec queries and use security tooling to identify and analyze risks.

StackAdapt is a leading technology company that provides an AI-powered marketing platform for programmatic advertising. The company has a diverse, remote-first culture with a supportive workplace.

$198,238–$233,221/yr
US

  • Own and manage the compliance program including SOC 2 and ISO 27001 readiness and audits.
  • Lead risk assessments, control testing, and enterprise risk management processes.
  • Partner with Engineering, Security, Product, Legal, HR, and Operations to embed compliance into business processes.

Calendly is a scheduling platform used by millions to automate meetings and streamline time management. They are a rapidly growing SaaS company fostering a culture of learning and high performance.

$120,000–$140,000/yr
US Unlimited PTO

  • Define and enforce security requirements for software products, features, and components.
  • Design, perform, and maintain security analysis on commercial products throughout the product lifecycle.
  • Collaborate with cross-functional teams to perform vulnerability management and implement mitigation strategies.

symplr is revolutionizing healthcare operations with a platform that drives effective, efficient, and connected workflows. The company is remote-first with employees across the US, India, and the Netherlands, and values teamwork, customer focus, and integrity.

US 5w PTO

  • Take ownership of building and scaling comprehensive security, privacy, and compliance programs that protect customer data.
  • Lead compliance initiatives such as SOC 2 Type 2 audits and evaluate additional frameworks like ISO 27001 and HIPAA.
  • Build scalable automated security processes by replacing manual tasks with scripts, APIs, and AI-powered solutions.

Our partner is a technology company focused on building secure, scalable systems. They operate with a remote, collaborative culture emphasizing ownership, transparency, and continuous improvement, with around 50–300 employees.

US

  • Lead ISSO activities to ensure confidentiality, integrity, availability, and compliance of enterprise applications and information systems.
  • Manage RMF processes including ATO packages, continuous monitoring, risk assessments, and accreditation documentation within eMASS.
  • Implement and maintain compliance with DISA STIGs, NIST 800-53 controls, and federal cybersecurity requirements.

Jobgether is a platform that uses AI-powered matching to connect candidates with job opportunities. The company facilitates the hiring process by sharing top-fitting candidate shortlists with partner companies, focusing on efficiency and objectivity.

$130,000–$145,000/yr
US Unlimited PTO 20w maternity 12w paternity

  • Support and scale the Assurance & Compliance function through an engineering-driven, automation-first approach.
  • Partner with Engineering, Security, Legal, and other teams to support compliance programs and audit readiness.
  • Help transform compliance into a continuous, measurable capability embedded into operations.

Flock builds technology that reduces crime and protects privacy, partnering with cities, businesses, schools, and neighborhoods. With over $1B in funding and an $8.3B valuation, the company is a high-performance team united by urgency, ownership, and a shared commitment to meaningful impact.

$55,000–$55,000/yr
US

  • Perform project tasks independently while contributing to cybersecurity assessment engagements and client deliverables.
  • Collect, organize, and analyze documentation, evidence, and technical artifacts required for security reviews.
  • Support assessments related to cybersecurity, compliance, and information security programs.

Our partner is a company focused on helping organizations strengthen their security posture and maintain compliance with industry standards. They offer a dynamic and collaborative work environment with career growth opportunities in cybersecurity.

Spain 5w PTO

  • Bolster Auctane's global engineering and operations within the Information Security Group, reporting to the CISO.
  • Lead security programs defining technology and processes for cybersecurity, focusing on Enterprise and Cloud Infrastructures.
  • Manage core security operations, incident response, and vulnerability management while promoting security by design.

Auctane provides mailing and shipping software products that enable businesses of all sizes to send billions of items annually, worth over $200 billion, to recipients worldwide. The company, with a family of brands including ShipStation and Stamps.com, values a flat and open engineering culture and emphasizes teamwork, customer delight, and delivering great outcomes.

US

  • Act as a trusted consultant guiding clients through complex security and compliance challenges.
  • Develop security strategies aligned with frameworks like CMMC, NIST 800-171, and NIST 800-53.
  • Design and implement AWS and/or GCP security tools with deep expertise in cloud security.

Aprio is a Top 20 CPA and advisory firm that provides compliance and advisory services to fast-growing industries. With over 3,200 team members across 40 US and international offices, they foster a top-rated culture and collaborative environment.

US 24w maternity 24w paternity

  • Own the end-to-end GRC strategy and roadmap, driving compliance maturity and reducing audit risk.
  • Design and implement policy-as-code systems, translating compliance frameworks into enforceable code.
  • Lead full audit cycles, manage evidence collection, and architect GRC platform strategy for continuous compliance.

Smartsheet empowers teams to manage work and scale solutions, now uniting human teams with AI agents to automate tasks and uncover insights. With a history of over 20 years, the company fosters a culture of inclusion, creativity, and big thinking, offering professional growth and a supportive environment.

$80,900–$137,600/yr

  • Monitors, investigates, and responds to cybersecurity events and alerts across various security platforms.
  • Manages data loss prevention and insider risk alerts, collaborating with IT and business stakeholders.
  • Supports continuous improvement of detection capabilities through alert tuning and process optimization.

USAP is a company that safeguards organizational data and technology assets through cybersecurity operations. The size and culture are not specified, but the job emphasizes collaboration, continuous improvement, and a secure technology environment.

$132,000–$165,000/yr
US Unlimited PTO

  • Manage and support compliance certifications including SOC 2, HITRUST, and ISO 27001 audits across the audit lifecycle.
  • Serve as the subject matter expert across the company on compliance frameworks and primary point of contact for external auditors.
  • Maintain the risk register, drive risk identification and reporting, and scale GRC function with AI and automation.

Garner transforms the healthcare economy by partnering with employers to redesign healthcare benefits using data-driven insights. It is a fast-growing healthcare technology company with a mission-driven team focused on making healthcare more affordable and high-quality.