39 grc analyst jobs at 34 companies in California

1w
Save
Mark Applied
Hide
GRC Analyst
San Mateo, California, United States
$160k-$170k/yr OnsiteFull Time
Fireworks AI
Fireworks AI: Private AI infrastructure serving developers and enterprises with model training and inference.
3+ YOERequires 3–5 years in GRC, IT audit, information security, or related work; security and privacy framework knowledge; GRC platform experience; access review and security awareness platform administration experience; cloud familiarity.
Adaptive Security, Anecdotes, Vanta, Drata, Secureframe, OneTrust, ServiceNow GRC, KnowBe4, Hoxhunt, Proofpoint, AWS, GCP, Azure, RBAC
2d
Save
Mark Applied
Hide
GRC Analyst
United States or Massachusetts or New York or California or Colorado
$70k-$88k/yr RemoteFull Time
Coretelligent
Coretelligent: Managed IT and cybersecurity services provider serving small, midsized, and highly regulated businesses across the United States.
3+ YOERequires 3+ years in GRC focused on IT or cybersecurity controls, or 3+ years in IT with a cybersecurity focus, plus analytical, organizational, communication, and project management skills.
1mo
Save
Mark Applied
Hide
GRC Analyst
San Francisco, California, United States
$95k-$150k/yr HybridFull Time
ZipHQ
ZipHQ: AI platform for enterprise procurement.
2+ YOEBachelor's degree,2+ years GRC or security risk/audit experience,knowledge of SOC/ISO/PCI/FedRAMP/WCAG frameworks,strong written and verbal communication.
SOC 1, SOC 2, ISO 27001, ISO 42001, PCI DSS, WCAG, FedRAMP
2mo
Save
Mark Applied
Hide
Security GRC Analyst
San Francisco, California, United States
$116k-$160k/yr OnsiteFull Time
Salesforce
SalesforceNYSE: CRM: The #1 AI CRM driving customer success together.
2+ YOE2–4 years GRC/compliance/audit or information security experience; working knowledge of at least two of SOC 2, HIPAA, ISO 27001, or GxP; proficiency with GRC/audit tools and Microsoft Office or Google Workspace; strong communication skills.
SOC 2, HIPAA, ISO 27001, GxP, Microsoft Office Suite, Google Workspace, Drata, Vanta, OneTrust, ServiceNow GRC
1mo
Save
Mark Applied
Hide
GRC Analyst II
Los Angeles or Chicago or Nashville or New York or Seattle
$100k-$135k/yr HybridFull Time
Metropolis Technologies
Metropolis Technologies: Building AI for the real world with a computer vision platform for checkout-free payment and mobility services.
3+ YOE3+ years in information security GRC or technology compliance; experience managing security awareness programs; knowledge of SOC 2 and PCI-DSS; familiarity with AI/data security and training platforms; bachelor\u0002s degree required.
SOC 2, PCI-DSS, automated employment decision tool (AEDT)
1mo
Save
Mark Applied
Hide
Senior Security GRC Analyst
San Mateo, California, United States
$224k-$272k/yr HybridFull Time
Roblox
RobloxNYSE: RBLX: Global platform for user-created immersive digital experiences.
4+ YOE4+ years GRC experience, risk assessment and policy development, ability to work with engineers, knowledge of compliance frameworks and security controls.
Factor Analysis of Information Risk (FAIR), Roblox Studio
2mo
Save
Mark Applied
Hide
Senior IT GRC Analyst
Hillsboro or Irvine or Phoenix or Tacoma or Utah or San Diego or Denver or Liberty Lake or Los Angeles or Las Vegas or Seattle
$80k-$165k/yr OnsiteFull Time
Columbia Bank
Columbia BankNASDAQ: COLB: Regional financial institution providing banking and wealth management services.
7+ YOE7+ years in information security/IT audit/operations; ServiceNow IRM/GRC experience; knowledge of NIST, FFIEC, CIS, ITIL, COBIT; familiarity with PCI DSS, GLBA, HIPAA; bachelor’s preferred.
ServiceNow IRM/GRC, NIST CSF, FFIEC, CIS, ITIL, COBIT, ISO 27002, NIST 800, PCI DSS, GLBA, HIPAA, Cybersecurity Assessment Tool (CAT)
5d
Save
Mark Applied
Hide
Senior Cybersecurity GRC Analyst
Huntington Beach or Mukilteo
$120k-$136k/yr OnsiteFull Time
Karman Space & Defense
Karman Space & DefenseNYSE: KRMN: Provider of mission-critical aerospace and defense system solutions.
5+ YOEBachelor's degree or equivalent experience and 5+ years in cybersecurity GRC, IT audit, risk management, or control assurance. Requires control assessment expertise, regulated-framework knowledge, analytical skills, and stakeholder management.
Microsoft 365, Microsoft Excel, Microsoft PowerPoint, Microsoft Word, Microsoft Teams, Microsoft SharePoint, Microsoft Outlook, ServiceNow, Jira, Archer, AuditBoard, Drata, Vanta, Hyperproof
3d
Save
Mark Applied
Hide
Senior GRC Analyst
San Francisco or Denver or New York City or Scottsdale or San Jose
$183k-$205k/yr HybridFull Time
Gusto
Gusto: Gusto is a payroll, benefits, and human-resources software platform serving small and medium-sized businesses.
8+ YOE8+ years in governance, risk, and compliance within SaaS; bachelor's degree required; SOC 2 Type 2 experience; strong communication, analytics, and compliance platform skills; relevant certification preferred.
Optro, Vanta, Drata, Viso Trust
1mo
Save
Mark Applied
Hide
Information Security GRC Analyst 4
San Jose or Seattle or Lehi or New York City
$113k-$229k/yr OnsiteFull Time
Adobe
AdobeNASDAQ: ADBE: Empowering everyone to create through innovative digital experiences.
5+ YOE5+ years GRC/InfoSec experience, knowledge of SOC/ISO/HIPAA/FedRAMP/NIST frameworks, program and audit leadership, strong communication and analytical skills.
AWS, Azure, GCP, Adobe Common Controls Framework (CCF)
2w
Save
Mark Applied
Hide
Senior GRC / Third-Party Risk / Data Protection Analyst
California, United States
$104k-$166k/yr RemoteFull Time
Peraton Labs
Peraton Labs: Private applied research organization developing cybersecurity, communications, electronic-warfare, mobility, and analytics technologies for government and commercial customers.
8+ YOEBachelor's degree or equivalent experience, 8+ years in security GRC, third-party risk, or data protection, active CISA or CGRC, NIST control testing, POA&M management, DLP, GRC, U.S. citizenship, and California clearance.
NIST SP 800-53 Rev. 5, SIG, CAIQ, Microsoft Purview, Netskope, Forcepoint, GRC platform, DLP, POA&M, ARC-AMPE, IRS Publication 1075, HIPAA, HITECH, CCPA, CMS, SAWs
4d
Save
Mark Applied
Hide
Governance, Risk & Compliance (GRC) Analyst
El Segundo or Los Angeles or Washington or San Francisco or San Diego or Seattle or London
$120k-$150k/yr HybridFull Time
CHAOS Industries
CHAOS Industries: Redefining modern defense with a multi-product portfolio.
5+ YOEBachelor's degree or equivalent experience, 5+ years of GRC or compliance experience, DoD or military experience, audit support, risk assessment, GRC tooling, and knowledge of major security frameworks.
NIST CSF, NIST RMF, ISO/IEC 27000, UK Cyber Essentials, CMMC, NIST 800-171, NIST 800-53, GRC tooling, OT/ICS
1mo
Save
Mark Applied
Hide
Senior Analyst, IT Risk & GRC
Carlsbad or Duluth or Tempe
$91k-$143k/yr OnsiteFull Time
Viasat
ViasatNASDAQ: VSAT: Global communications providing satellite connectivity and defense solutions.
5+ YOE5+ years in IT audit/compliance or IT risk; bachelor’s or equivalent; SOX/ITGC expertise; experience with control design/testing; strong communication; U.S. citizenship required; CISA/CRISC/CISSP/CPA preferred.
SAP, Oracle, Workday, GCP, Tableau
1mo
Save
Mark Applied
Hide
Senior Analyst, IT Risk & GRC
Carlsbad or Duluth or Tempe
$91k-$143k/yr HybridFull Time
Viasat
ViasatNASDAQ: VSAT: Global communications providing satellite connectivity and defense solutions.
5+ YOE5+ years in IT audit/compliance/risk, bachelor’s in related field or equivalent, SOX/ITGC expertise, experience designing/testing IT controls, strong communication, CISA/CRISC/CISSP/CPA preferred, U.S. citizenship required.
SAP, Oracle, Workday, GCP, Tableau
1mo
Save
Mark Applied
Hide
Senior Technology Governance, Risk & Compliance (GRC) Analyst
New York City or Atlanta or Los Angeles or Jersey City or Canada or United Kingdom or Ireland or Portugal or Romania or Australia or Puerto Rico
$138k-$173k/yr HybridFull Time
FanDuel
FanDuel: American sports-tech gaming offering sports betting, daily fantasy, horse racing, casino, and sports media to fans.
5+ YOE5+ years technology/cybersecurity GRC experience, hands-on control lifecycle, technology risk assessments, policy development, audit and regulatory assessment experience, strong communication skills.
NIST CSF, GLI-GSF, PCI, SOC2, SOX, NIST 800-53, FAIR, AWS, Okta, GitHub, Atlassian, Microsoft Office, Optro, Anecdotes, Jira, Sharepoint
2mo
Save
Mark Applied
Hide
Governance, Risk & Compliance (GRC) Analyst
San Francisco, California, United States
$125k-$150k/yr OnsiteFull Time
Ivo
Ivo: AI-powered contract intelligence platform serving in-house legal and procurement teams at enterprise companies.
3+ YOE3–5 years GRC/InfoSec/IT audit experience; hands-on SOC 2 Type II, ISO 27001, CSA STAR, ISO/IEC 42001; experience with Vanta, audits, evidence management, risk assessments, policy maintenance, and strong communication skills.
Vanta, GCP, AWS, Azure
1mo
Save
Mark Applied
Hide
Senior Information Security Analyst, GRC/Responsible AI
Irvine or Milpitas
$125k-$207k/yr OnsiteFull Time
SanDisk
SanDiskNASDAQ: SNDK: Specialist in NAND flash memory and data storage solutions.
6+ YOE6+ years information security experience with GRC and AI risk management, bachelor's or equivalent, technical proficiency in threat modeling and risk assessment, familiarity with NIST AI RMF and ISO/IEC 42001, and strong cross‑functional communication.
OWASP Top 10 for LLM Applications, NIST AI RMF, ISO/IEC 42001, STRIDE, PASTA, attack tree analysis, CI/CD
4w
Save
Mark Applied
Hide
Sr. Risk Analyst
Scottsdale or Chicago or San Francisco or New York City
$84k-$105k/yr HybridFull Time
Early Warning Services
Early Warning Services: U.S. bank-owned fintech and consumer reporting agency providing identity, fraud-risk, and real-time payment solutions to financial institutions.
5+ YOEBachelor's degree in Accounting/Finance/Risk, 5+ years risk experience (3+ in financial services), advanced Microsoft Excel and PowerPoint skills, three-lines-of-defense experience, KRI/GRC familiarity, strong communication.
Microsoft Excel, Microsoft PowerPoint, GRC
1w
Save
Mark Applied
Hide
Senior Governance Risk and Compliance (GRC) Analyst
San Francisco, California, United States
$165k-$190k/yr HybridFull Time
IREN
IRENNASDAQ: IREN: Vertically integrated AI cloud and data center infrastructure provider.
5+ YOEBachelor's or master's degree in a relevant field, 5–7 years in cybersecurity or IT program management, FedRAMP authorization leadership, NIST 800-53 expertise, audit experience, and strong analytical and communication skills.
FedRAMP, NIST 800-53, SOC 2, ISO 27001, HITRUST, System Security Plan (SSP)
2mo
Save
Mark Applied
Hide
Classified Cyber Assurance Analyst
Hawthorne, California, United States
$85k-$135k/yr OnsiteFull Time
SpaceX
SpaceXNasdaq: SPCX: Designing, manufacturing, and launching advanced rockets and spacecraft.
1+ YOEBachelor's degree or 3+ years managing cyber assurance for classified systems; 1+ years cyber assurance; RMF A&A lifecycle experience; familiarity with Nessus, Splunk, Security Center, ServiceNow, eMASS, and GRC tools; active TS/SCI clearance and CI polygraph or ability to obtain.
RMF, Nessus, Splunk, Security Center, ServiceNow (SNOW), eMASS, GRC, NRO A&A, JSIG A&A