23 cyber grc analyst jobs at 19 companies in United States
1mo
Save
Mark Applied
Hide
1mo
Cyber GRC Analyst
Austin, Texas, United States
$80k-$110k/yrHybridFull Time
News CorpNASDAQ: NWSA: Provides global news, information, and digital media services.
3+ YOE3+ years in cyber security/GRC, experience with PCI DSS, NIST CSF, ISO 27001, AWS; supports audits, risk assessments, and third‑party security reviews; professional security certifications preferred.
PSEGNYSE: PEG: Investor-owned electric and gas utility.
4+ YOEBachelor's in related field or 8+ years' equivalent; 4+ years cybersecurity GRC/IT audit experience; proficiency with Cyber GRC tools; experience with risk and control assessments, audit coordination, and remediation tracking; DOE 10 CFR 810 eligibility.
Black & Veatch: Provides engineering, procurement, and construction services for global infrastructure.
2+ YOEBachelor's in IT/CS or equivalent experience; 2+ years in GRC; experience with risk assessment frameworks (NIST CSF, ISO 27001, SOC), ServiceNow Risk Management, and enterprise cyber/compliance risk practices; CRISC/CISSP preferred.
WHOOP: Wearable technology for personalized health and performance tracking.
6+ YOE6+ years in cybersecurity or enterprise risk; experience conducting structured cyber/IT risk assessments, maintaining risk registers, familiarity with security frameworks and AI risk; strong communication and analysis skills.
NIST CSF, ISO 27001, PCI DSS, GDPR, HIPAA, NIST AI RMF, ISO/IEC 42001, FAIR
WHOOP: Providing wearable health trackers and physiological performance analytics.
6+ YOE6+ years in cybersecurity or enterprise risk management, experience conducting structured cyber/IT and AI risk assessments, maintaining risk registers, familiarity with NIST/ISO/PCI/GDPR/HIPAA, and strong communication skills.
NIST CSF, ISO 27001, PCI DSS, GDPR, HIPAA, NIST AI RMF, ISO/IEC 42001, FAIR
SpaceX: Designs and launches advanced rockets and satellite internet constellations.
1+ YOEBachelor's degree or 3+ years managing cyber assurance for classified systems; 1+ years cyber assurance; RMF A&A lifecycle experience; familiarity with Nessus, Splunk, Security Center, ServiceNow, eMASS, and GRC tools; active TS/SCI clearance and CI polygraph or ability to obtain.
RMF, Nessus, Splunk, Security Center, ServiceNow (SNOW), eMASS, GRC, NRO A&A, JSIG A&A
Sr Director Analyst, Cyber GRC Tools and Technology (Remote US)
United States or Texas
$172k-$203k/yrRemoteFull Time
GartnerNYSE: IT: Provides research and advisory services for business leaders.
12+ YOE5+ Mgmt12+ years in Cyber GRC/InfoSec/ERM with 5+ years leadership, expertise in Cyber GRC tools, strong research, writing, presentation and client engagement skills; willingness to travel up to 25%.
General Atomics Aeronautical Systems: Designs and manufactures unmanned aircraft and radar systems.
5+ YOEActive Top Secret/SCI clearance, US citizenship, bachelor\u0002s or equivalent, ~5+ years security experience, knowledge of CMMC/DFARS/NIST, RMF/IC directives, security assessments, and strong analytical and communication skills.
FlagstarNYSE: FLG: Provides personal banking, mortgage lending, and commercial financial services.
6+ YOE Undergraduate degree in Computer Science, Information Technology, Cybersecurity or related field; 6+ years in IT/cyber/risk/compliance; strong risk management and communication skills.
Pittsburgh or Bécancour or Montréal or Baie-Comeau or Deschambault
OnsiteFull Time
AlcoaNYSE: AA: Produces aluminum through bauxite mining, refining, and smelting.
6+ YOE6+ years in cybersecurity or IT risk; experience assessing IT and OT risk; knowledge of ISO/NIST/CIS frameworks, GRC activities and tools; strong written/verbal communication and facilitation skills; bachelor's degree or equivalent experience.
Governance, Risk, and Compliance (GRC), SIEM, ISO 27001, NIST CSF, NIST 800-53, CIS Controls, SOX
Invenergy: Develops and operates utility-scale renewable and clean energy projects.
2+ YOEBachelor's in cybersecurity/IT or equivalent,2+ years cybersecurity/GRC experience,knowledge of security frameworks,experience with audits and control assessments,strong analytical and communication skills.
ServiceNow, Archer, Smartsheet, Microsoft 365, Azure
Invenergy: Develops, builds, and operates large-scale sustainable energy infrastructure projects.
2+ YOEBachelor's in cybersecurity/IT or equivalent,2+ years cybersecurity/GRC experience,knowledge of security frameworks,audit/compliance experience,strong analytical and communication skills.
ServiceNow, Archer, Smartsheet, Microsoft 365, Azure
Hyundai AutoEver AmericaKorea Exchange: 307950: Provides automotive software and IT services for mobility systems.
7+ YOE7+ years in technology/cyber/GRC risk with experience running risk assessments, issue/exception management, control libraries, GRC tooling, and executive reporting; Bachelor’s in related field required.
Enterprise Products PartnersNYSE: EPD: Provides midstream energy services for natural gas and crude oil.
2+ YOEAnalyzes cyber risks and threats; supports risk assessments, threat monitoring, vulnerability analysis; collaborates with IT security teams; 2–5 years in cyber security; familiar with SIEM, vulnerability scanners, threat intel; knowledge of NIST/MITRE; college degree preferred.
Booz Allen HamiltonNYSE: BAH: Consulting and technology services for government and commercial clients
5+ YOE5+ years supporting cyber/technology/enterprise risk, experience with GRC practices, knowledge of AI concepts and industry risk frameworks, HS diploma/GED, strong writing and cross-team collaboration skills.
NIST CSF, NIST AI RMF, NIST SP 800-53, NIST SP 800-171, ISO 27001, ISO 42001, MITRE ATLAS, CMMC, ServiceNow, Archer, Smartsheet, Jira
Analyst, Security Inquiry Response Center (SIRC) (Canada)
Canada or United States or Hermitage or Nashville or Tampa or Saint John or Halifax or Toronto
OnsiteFull Time
Deloitte: Global provider of audit, consulting, tax, and advisory services.
3+ YOEBachelor's degree or equivalent experience; 3+ years information security experience; knowledge of information systems security, cyber security, IT audit, IT risk, compliance and vendor security risk; working knowledge of ISO, NIST, COBIT, SOC2; familiarity with GRC tools (e.g., ServiceNow); strong analytical skills.