263 grc analyst jobs at 221 companies in United States
1w
Save
Mark Applied
Hide
1w
GRC Analyst
San Mateo, California, United States
$160k-$170k/yrOnsiteFull Time
Fireworks AI: Private AI infrastructure serving developers and enterprises with model training and inference.
3+ YOERequires 3–5 years in GRC, IT audit, information security, or related work; security and privacy framework knowledge; GRC platform experience; access review and security awareness platform administration experience; cloud familiarity.
United States or Massachusetts or New York or California or Colorado
$70k-$88k/yrRemoteFull Time
Coretelligent: Managed IT and cybersecurity services provider serving small, midsized, and highly regulated businesses across the United States.
3+ YOERequires 3+ years in GRC focused on IT or cybersecurity controls, or 3+ years in IT with a cybersecurity focus, plus analytical, organizational, communication, and project management skills.
2+ YOEBachelor's degree,2+ years GRC or security risk/audit experience,knowledge of SOC/ISO/PCI/FedRAMP/WCAG frameworks,strong written and verbal communication.
SOC 1, SOC 2, ISO 27001, ISO 42001, PCI DSS, WCAG, FedRAMP
American TowerNYSE: AMT: Public U.S. REIT that owns, operates, and leases wireless towers, communications sites, and data centers to connectivity providers.
2+ YOERequires 2+ years in GRC or information security, strong project management and communication skills, Microsoft Office and Oracle proficiency, and knowledge of security standards and privacy regulations.
Microsoft Office, Oracle, ISO 27001, ISO 27002, ITIL, Identity and Access Management (IAM)
Allied Benefit Systems: Independent U.S. third-party administrator providing self-funded health-plan administration and care solutions to employers and members.
3+ YOEBachelor's degree or equivalent experience; 3+ years in governance, risk, and compliance; regulated-environment experience; HIPAA, HITECH, SOC 2, GRC platforms, and security frameworks knowledge.
Drata, NIST CSF, NIST SP 800 series, ISO/IEC 27000 series
Fluidstack: Building and operating civilization-scale data center infrastructure for AI.
Experienced in operating compliance controls and audits across SOC 2, ISO 27001, NIST 800-53 or FedRAMP; owning policy sets, evidence collection, and audit readiness on GRC platforms.
Vercel: Software providing developer infrastructure for teams building web applications and AI agents.
3+ YOE3+ years supporting audit lifecycle in cloud environments; manage ISO/SOC/HIPAA/PCI compliance, collaborate with engineering, strong project management and communication; familiarity with cloud and GRC tools.
Hayward HoldingsNYSE: HAYW: Publicly traded global manufacturer of residential and commercial pool, outdoor-living, and industrial flow-control equipment.
3+ YOEBachelor's degree in Accounting, Information Systems, Cybersecurity or related; 3+ years SOX-focused GRC/audit experience; hands-on Varonis and SailPoint experience; strong ITGC/ICFR and audit evidence knowledge.
Acadian Companies: Employee-owned U.S. group providing medical transport, home healthcare, safety, security, training, and charter aviation.
2+ YOEBachelor’s degree or equivalent experience; 2–5 years in GRC, IT audit, or cybersecurity risk management; experience with NIST CSF, NIST SP 800-53, or ISO/IEC 27001; HIPAA preferred.
NorthMark Compute & Cloud: Private U.S. high-performance computing infrastructure provider serving businesses with HPC, cloud, AI, and simulation capacity.
4+ YOE4+ years GRC or information security governance experience; hands-on change management, risk assessment, policy management; familiarity with ISO 27001/SOC 2/NIST CSF; stakeholder engagement and strong written communication.
Wolfe: Private Pittsburgh fintech providing personalized digital and physical gift cards to businesses and consumers.
7+ YOE7+ years in GRC, IT audit, or security compliance; 3+ years supporting PCI DSS in a Level 1 or equivalent payment environment; SOC 2, ITGC, third-party risk, and GRC platform experience.
SalesforceNYSE: CRM: The #1 AI CRM driving customer success together.
2+ YOE2–4 years GRC/compliance/audit or information security experience; working knowledge of at least two of SOC 2, HIPAA, ISO 27001, or GxP; proficiency with GRC/audit tools and Microsoft Office or Google Workspace; strong communication skills.
SOC 2, HIPAA, ISO 27001, GxP, Microsoft Office Suite, Google Workspace, Drata, Vanta, OneTrust, ServiceNow GRC
Sub-Zero Group, Inc.: Family-owned luxury kitchen-appliance manufacturer serving high-end homes with refrigeration, cooking, and dishwashing products.
0+ YOEAssociate's or bachelor's degree in a related field and 0–3 years of GRC, risk, compliance, auditing, or related experience; strong analytical, organizational, and communication skills.
NIST CSF, NIST AI RMF, ISO 27001, ISO 31000, ISO 22301, CCPA/CPRA, GDPR, PCI DSS
Blue Cross and Blue Shield of Louisiana: Policyholder-owned nonprofit health insurer providing medical, dental, Medicare, prescription and life coverage to Louisianians.
4+ YOEBachelor's in IT, audit, or related field, or four years equivalent experience; 4 years specialized GRC experience; knowledge of cybersecurity, IT infrastructure, cloud technologies, or application development.
Los Angeles or Chicago or Nashville or New York or Seattle
$100k-$135k/yrHybridFull Time
Metropolis Technologies: Building AI for the real world with a computer vision platform for checkout-free payment and mobility services.
3+ YOE3+ years in information security GRC or technology compliance; experience managing security awareness programs; knowledge of SOC 2 and PCI-DSS; familiarity with AI/data security and training platforms; bachelor\u0002s degree required.
YETINew York Stock Exchange: YETI: Public American outdoor-products designer, retailer, and distributor serving outdoor enthusiasts and everyday consumers.
6+ YOE5+ years experience in SAP GRC and SAP security, SoD risk analysis, SOX compliance knowledge, GRC module administration, strong communication and independent multitasking skills.
Protective Life: Private U.S. insurer providing life insurance, annuities, retirement, asset-protection, and employee-benefit solutions to consumers and businesses.
1+ YOEExecute GRC functions including risk assessments, vendor risk, compliance, security awareness, reporting, and audit readiness; 1+ years GRC or risk experience; bachelor\u0002s degree in related field.
ServiceNow, Archer, Microsoft SharePoint, Microsoft Power BI, UpGuard, Azure, AWS
Cleveland Brothers Equipment: Exclusive Caterpillar dealer serving Pennsylvania, West Virginia, and Maryland.
Bachelor's or equivalent experience in cybersecurity/IT, deep GRC knowledge, experience with security frameworks, policy development, audits, risk assessments, control tracking, and strong written/verbal communication.
Information Services Agency: A local government providing public services and technology solutions to Indianapolis and Marion County.
2+ YOEBachelor's degree or equivalent experience; 2–3 years in governance, risk, and compliance; knowledge of control frameworks and security standards; analytical, communication, and teamwork skills.