14 cybersecurity grc jobs at 13 companies in San Francisco, CA
2mo
Save
Mark Applied
Hide
2mo
Principal Cybersecurity Compliance Analyst
Roseville or Sacramento or Oakland
$150k-$200k/yrHybridFull Time
GFT (Gannett Fleming): Provides infrastructure engineering, design, and construction management services.
10+ YOEBachelor's degree, 10+ years in power utility GRC/cybersecurity/OT, deep knowledge of NERC CIP and FERC, experience with audits and compliance documentation, and certification such as CISSP/CISM/RIMS-CRMP required.
Airwallex: Global financial platform for business payments and money management.
5+ YOE5-7 years cybersecurity experience, Mexican Tax ID (RFC) or dual Mexican citizenship required, fluent English and Spanish, knowledge of PCI-DSS/ISO 27001/SOC2, fintech and cloud compliance experience, CISSP/CEH/CISA strong advantage.
Business Wire: Distributes press releases and regulatory disclosures to global media outlets.
10+ YOE5+ MgmtBachelor's or master's degree in computer science, information security, or related field; 10+ years in information security; 5+ years of managerial leadership; expertise in cloud security, GRC, risk, architecture, and compliance.
AWS, Azure, Zero Trust, PCI DSS, SOC 2, ISO 27001, AI
Tata Consultancy ServicesNational Stock Exchange of India: TCS: Global provider of IT services, consulting, and business solutions.
5+ YOERequires 5+ years in cybersecurity, TPRM, GRC, or supplier risk; knowledge of NIST CSF, ISO 27001, SOC 2, SIG/CAIQ; GRC tool experience and strong client-facing communication.
F5NASDAQ: FFIV: Provides application delivery networking and multi-cloud security solutions.
10+ YOEBachelor's degree required; 10+ years in cybersecurity/GRC with 3–5 years hands-on engineering; Python, API, and systems-integration experience; ServiceNow IRM and Agentic/LLM framework familiarity; professional certs preferred.
Strava: Fitness tracking and social networking app for athletes.
8+ YOEBachelor's degree,8-12 years in security or technical risk,security certification (CISSP or CISM) preferred,experience building GRC/risk programs,AI/automation in security,team management and executive reporting.
Tata Consultancy ServicesNational Stock Exchange of India: TCS: Global provider of IT services, consulting, and business solutions.
5+ years in cybersecurity/TPRM/GRC with hands-on experience running vendor assessments, managing CAPs, stakeholder escalation, and producing leadership reports.
Senior Governance Risk and Compliance (GRC) Analyst
San Francisco, California, United States
$165k-$190k/yrHybridFull Time
IRENNASDAQ: IREN: Operates renewable-powered data centers for AI and Bitcoin mining
5+ YOEBachelor's or master's degree in a relevant field, 5–7 years in cybersecurity or IT program management, FedRAMP authorization leadership, NIST 800-53 expertise, audit experience, and strong analytical and communication skills.
FedRAMP, NIST 800-53, SOC 2, ISO 27001, HITRUST, System Security Plan (SSP)
Anthropic: Developing safe and reliable artificial intelligence systems.
10+ YOE10+ years in security industry partnerships with a track record in complex multi-stakeholder deals; deep domain expertise in SIEM/SOAR, EDR, identity, cloud security, GRC; ability to work cross-functionally with research, product, engineering, policy and legal.
Dublin or London or San Francisco or New York City or Tel Aviv or Sydney
HybridFull Time
Vanta: Automated security compliance and trust management software for businesses.
5+ YOE5+ years customer-facing technical experience in pre-sales; full German proficiency; B2B SaaS experience; hands-on with AWS, Google Cloud, Microsoft Azure, Windows/MacOS/Linux; familiarity with Python, Ruby, Bash, JavaScript and REST APIs; strong project management and customer-facing skills; cybersecurity experience preferred.
AWS, Google Cloud, Microsoft Azure, Windows, MacOS, Linux, Python, Ruby, Bash, JavaScript, REST API
BlinkOps: Agentic security automation platform for enterprise workflows.
3+ YOE3+ years in sales/solutions engineering in cybersecurity, strong security operations knowledge, hands-on with APIs, JSON/YAML and jq, experience with SIEM/SOAR/EDR/IAM/GRC integrations, demo/POC and customer-facing skills.
TikTok: Global short-form video hosting and social media platform.
3+ YOEBachelor's degree in IT/Cybersecurity/Law/Business or related,3+ years GRC/privacy/compliance experience,experience with audits,project management skills,and professional proficiency in English and Mandarin.
Thinking Machines: Building AI systems to extend human will and judgment.
7+ YOE7+ years GRC experience in technology and cybersecurity; led SOC 2/ISO 27001/FedRAMP from scoping through audit close; hands-on evidence collection, control documentation, and recurring compliance processes; strong technical fluency.
Dolby LaboratoriesNYSE: DLB: Develops audio and video signal processing and compression technologies.
8+ YOE8+ years in information/cybersecurity or related roles; experience across security domains and frameworks; strong stakeholder engagement, risk management, and security integration skills.
SOX, GDPR, ISO 27001, TISAX, NIST CSF, NIST 800-53, NIST 800-171, SOC, IR, GRC