20 grc analyst jobs at 20 companies in Concord, CA

2w
Save
Mark Applied
Hide
GRC Analyst
San Francisco, California, United States
$95k-$150k/yr HybridFull Time
Zip
Zip: AI-powered intake-to-procure platform for enterprise spend management
2+ YOEBachelor's degree,2+ years GRC or security risk/audit experience,knowledge of SOC/ISO/PCI/FedRAMP/WCAG frameworks,strong written and verbal communication.
SOC 1, SOC 2, ISO 27001, ISO 42001, PCI DSS, WCAG, FedRAMP
1mo
Save
Mark Applied
Hide
Security GRC Analyst
San Francisco, California, United States
$116k-$160k/yr OnsiteFull Time
Salesforce
SalesforceNYSE: CRM: Sells cloud-based customer relationship management and business software solutions.
2+ YOE2–4 years GRC/compliance/audit or information security experience; working knowledge of at least two of SOC 2, HIPAA, ISO 27001, or GxP; proficiency with GRC/audit tools and Microsoft Office or Google Workspace; strong communication skills.
SOC 2, HIPAA, ISO 27001, GxP, Microsoft Office Suite, Google Workspace, Drata, Vanta, OneTrust, ServiceNow GRC
3w
Save
Mark Applied
Hide
Senior Security GRC Analyst
San Mateo, California, United States
$224k-$272k/yr HybridFull Time
Roblox
RobloxNYSE: RBLX: Platform for creating and playing user-generated 3D digital experiences.
4+ YOE4+ years GRC experience, risk assessment and policy development, ability to work with engineers, knowledge of compliance frameworks and security controls.
Factor Analysis of Information Risk (FAIR), Roblox Studio
4w
Save
Mark Applied
Hide
Information Security GRC Analyst 4
San Jose or Seattle or Lehi or New York City
$113k-$229k/yr OnsiteFull Time
Adobe
AdobeNASDAQ: ADBE: Provides software for digital media creation and marketing analytics
5+ YOE5+ years GRC/InfoSec experience, knowledge of SOC/ISO/HIPAA/FedRAMP/NIST frameworks, program and audit leadership, strong communication and analytical skills.
AWS, Azure, GCP, Adobe Common Controls Framework (CCF)
2mo
Save
Mark Applied
Hide
Governance, Risk & Compliance (GRC) Analyst
San Francisco, California, United States
$125k-$150k/yr OnsiteFull Time
Ivo
Ivo: AI-powered contract review and intelligence platform for legal teams.
3+ YOE3–5 years GRC/InfoSec/IT audit experience; hands-on SOC 2 Type II, ISO 27001, CSA STAR, ISO/IEC 42001; experience with Vanta, audits, evidence management, risk assessments, policy maintenance, and strong communication skills.
Vanta, GCP, AWS, Azure
2w
Save
Mark Applied
Hide
Third Party Risk Analyst, Security GRC
San Francisco, California, United States
$255k-$270k/yr HybridFull Time
Anthropic
Anthropic: Developing safe and reliable artificial intelligence systems.
Experience running end-to-end third-party/vendor risk assessments at a technology company; knowledge of risk fundamentals; ability to assess security, privacy, compliance, and operational risk; experience with LLM-backed workflows and procurement/GRC platforms.
LLM, RapidRatings, CreditSafe, LSEG
3w
Save
Mark Applied
Hide
Senior Information Security Analyst, GRC/Responsible AI
Irvine or Milpitas
$125k-$207k/yr OnsiteFull Time
Sandisk
SandiskNasdaq: SNDK: Designs and manufactures flash memory and data storage products.
6+ YOE6+ years information security experience with GRC and AI risk management, bachelor's or equivalent, technical proficiency in threat modeling and risk assessment, familiarity with NIST AI RMF and ISO/IEC 42001, and strong cross‑functional communication.
OWASP Top 10 for LLM Applications, NIST AI RMF, ISO/IEC 42001, STRIDE, PASTA, attack tree analysis, CI/CD
1w
Save
Mark Applied
Hide
Security Analyst
San Francisco, California, United States
$144k-$162k/yr HybridFull Time
Discord
Discord: A platform providing voice, video, and text communication services.
4+ YOE4+ years in security compliance/GRC or related fields; familiarity with ISO 27001/27002,SOC 2,PCI DSS,GDPR/CPRA; hands-on compliance processes; automation-first mindset; strong writing and cross-team collaboration skills.
ISO 27001, ISO 27002, SOC 2, PCI DSS, GDPR, CPRA, GRC platform, ticketing, docs and wikis
1w
Save
Mark Applied
Hide
Sr. Risk Analyst
Scottsdale or Chicago or San Francisco or New York City
$84k-$105k/yr HybridFull Time
Early Warning Services
Early Warning Services: Operates payment and risk solutions for the financial industry.
5+ YOEBachelor's degree in Accounting/Finance/Risk, 5+ years risk experience (3+ in financial services), advanced Microsoft Excel and PowerPoint skills, three-lines-of-defense experience, KRI/GRC familiarity, strong communication.
Microsoft Excel, Microsoft PowerPoint, GRC
2mo
Save
Mark Applied
Hide
Principal Cybersecurity Compliance Analyst
Roseville or Sacramento or Oakland
$150k-$200k/yr HybridFull Time
GFT (Gannett Fleming)
GFT (Gannett Fleming): Provides infrastructure engineering, design, and construction management services.
10+ YOEBachelor's degree, 10+ years in power utility GRC/cybersecurity/OT, deep knowledge of NERC CIP and FERC, experience with audits and compliance documentation, and certification such as CISSP/CISM/RIMS-CRMP required.
GRC, FERC, NERC CIP, SCADA/ICS, NIST CSF, NIST SP 800-53, ISO 27001
1w
Save
Mark Applied
Hide
Staff Security Analyst
Palo Alto, California, United States
$131k-$291k/yr OnsiteFull Time
Navan
NavanNasdaq: NAVN: Integrated platform for corporate travel and expense management.
6+ YOE6+ years in security GRC/auditing, hands-on ISMS management, experience with PCI, SOX, ISO 27001/42001, SOC 1/2, control automation, auditor coordination, and cloud security.
Vanta, Drata, OneTrust, Hyperproof, ServiceNow GRC, Archer, AWS, Azure, GCP, SIEM
1mo
Save
Mark Applied
Hide
Senior Analyst, IT Internal Controls & SOX Compliance
San Francisco or Salt Lake City or Phoenix or Los Angeles or Chicago or Boston or Austin or New York City or Miami or Tampa or Atlanta or Columbus or Boise or San Diego or Minneapolis or Houston or Raleigh or Nashville or Kansas City or Charlotte or Portland or Philadelphia or Dallas or Washington D.C. or Seattle
$113k-$148k/yr RemoteFull Time
Circle
CircleNYSE: CRCL: Digital currency issuer and blockchain financial infrastructure provider.
4+ YOE4+ years Big 4 IT audit/controls experience, Bachelor's in related field, CPA/CISA/CIA/CISSP required; strong SOX/ITGC knowledge, cloud/SaaS/SDLC/IAM experience, ERP/GRC familiarity, and stakeholder communication skills.
Slack, Apple MacOS, Google Workspace, ERP, GRC, AI
2w
Save
Mark Applied
Hide
Customer Trust Analyst
Santa Clara, California, United States
$126k-$189k/yr OnsiteFull Time
Pure Storage
Pure StorageNYSE: PSTG: Provides all-flash enterprise data storage and management solutions.
2+ YOE2–5 years in customer trust/GRC/security assurance; knowledge of SOC 2, ISO/IEC 27001, NIST CSF, GDPR; strong technical writing, cross-functional collaboration, and problem-solving; generative AI or automation experience desirable.
SOC 2, ISO/IEC 27001, NIST CSF, GDPR, generative AI
3w
Save
Mark Applied
Hide
SENIOR RISK ASSESSMENT ANALYST
Oakland, California, United States
$160k-$184k/yr RemoteFull Time
University of California, Davis
University of California, Davis: A public research university providing higher education and healthcare.
8+ YOE8+ years of relevant experience overseeing enterprise cyber risk assessments; knowledge of NIST, ISO, HIPAA, PCI-DSS; GRC platform familiarity; strong communication, presentation, and project management skills.
ServiceNow, Archer
2mo
Save
Mark Applied
Hide
Security Compliance Analyst, Privacy
San Francisco or New York
$175k-$220k/yr OnsiteFull Time
LangChain
LangChain: Tools for building and deploying production-ready AI agents.
5+ YOE5+ years in privacy/GRC/security compliance; hands-on experience with GDPR, HIPAA, CCPA, SOC 2, ISO frameworks; DPAs/BAAs experience; technical fluency (can read code, validate data flows); strong writing skills.
Python
1mo
Save
Mark Applied
Hide
Governance, Risk & Compliance Analyst
San Francisco, California, United States
$200k-$220k/yr OnsiteFull Time
Perplexity
Perplexity: AI-powered search engine providing conversational answers with citations.
6+ YOE6+ years leading audit and compliance engagements; experience with SOC2/ISO27001/HIPAA, GDPR/CCPA/CPRA; building GRC tooling and automation; strong communication and cross-functional collaboration skills.
1mo
Save
Mark Applied
Hide
Senior Security Analyst, Customer Assurance
New York City or Seattle or Raleigh or San Francisco or Washington or London or Amsterdam
$134k-$214k/yr HybridFull Time
Plaid
Plaid: Provides financial data connectivity and payment infrastructure via APIs.
6+ YOE6+ years in security assurance/GRC with ownership of customer-facing security workflows; experience reviewing security contract provisions; familiarity with SOC 2, ISO 27001, NIST frameworks, PCI, GLBA, GDPR/CCPA; program design, metrics ownership, and AI-assisted workflow experience.
SOC 2, ISO 27001, NIST CSF, PCI DSS, GLBA, GDPR, CCPA, NIST 800-53
1mo
Save
Mark Applied
Hide
Compliance Analyst, Enterprise Compliance Office
Menlo Park, California, United States
$144k-$200k/yr HybridFull Time
Moloco
Moloco: AI-powered programmatic advertising and commerce media platform.
6+ YOE6+ years in compliance/legal operations/risk/audit or related fields; bachelor’s degree in a related field; experience with compliance programs, evidence coordination, documentation, analytics, and cross-functional collaboration.
Jira, Confluence, GRC platforms, Claude, Co-work, Microsoft Excel, Sheets, SQL, BI dashboards
1mo
Save
Mark Applied
Hide
Governance, Risk, Compliance & Trust Analyst
Oakland, California, United States
$140k-$178k/yr HybridFull Time
Everlaw
Everlaw: Provides a cloud-based litigation platform for legal teams.
5+ YOE5+ years GRC experience; strong knowledge of FedRAMP, SOC 2, ISO frameworks; audit readiness, vendor reviews, customer security questionnaires, trust portals, and producing clear, audit-ready deliverables.
FedRAMP, SOC 2, ISO 27001, ISO 27017, ISO 27018, Covey, Covey Scout, Modern Health
1w
Save
Mark Applied
Hide
Senior Analyst, Third-Party Risk Management (TPRM)
Milwaukee or Chicago or New York City or San Francisco or Phoenix or Austin or United States
$133k-$195k/yr RemoteFull Time
DoorDash
DoorDashNYSE: DASH: Local food delivery and on-demand logistics platform.
7+ YOERequires 7+ years in security-focused TPRM, a bachelor's or master's degree, risk assessment and remediation experience, cloud and AI vendor expertise, GRC framework experience, and excellent communication skills.
AWS, Azure, GCP, Covey