27 grc risk analyst jobs at 23 companies in California
3d
Save
Mark Applied
Hide
3d
Governance, Risk & Compliance (GRC) Analyst
El Segundo or Los Angeles or Washington or San Francisco or San Diego or Seattle or London
$120k-$150k/yrHybridFull Time
CHAOS Industries: Redefining modern defense with a multi-product portfolio.
5+ YOEBachelor's degree or equivalent experience, 5+ years of GRC or compliance experience, DoD or military experience, audit support, risk assessment, GRC tooling, and knowledge of major security frameworks.
2+ YOEBachelor's degree,2+ years GRC or security risk/audit experience,knowledge of SOC/ISO/PCI/FedRAMP/WCAG frameworks,strong written and verbal communication.
SOC 1, SOC 2, ISO 27001, ISO 42001, PCI DSS, WCAG, FedRAMP
ViasatNASDAQ: VSAT: Global communications providing satellite connectivity and defense solutions.
5+ YOE5+ years in IT audit/compliance or IT risk; bachelor’s or equivalent; SOX/ITGC expertise; experience with control design/testing; strong communication; U.S. citizenship required; CISA/CRISC/CISSP/CPA preferred.
ViasatNASDAQ: VSAT: Global communications providing satellite connectivity and defense solutions.
5+ YOE5+ years in IT audit/compliance/risk, bachelor’s in related field or equivalent, SOX/ITGC expertise, experience designing/testing IT controls, strong communication, CISA/CRISC/CISSP/CPA preferred, U.S. citizenship required.
Senior GRC / Third-Party Risk / Data Protection Analyst
California, United States
$104k-$166k/yrRemoteFull Time
Peraton Labs: Private applied research organization developing cybersecurity, communications, electronic-warfare, mobility, and analytics technologies for government and commercial customers.
8+ YOEBachelor's degree or equivalent experience, 8+ years in security GRC, third-party risk, or data protection, active CISA or CGRC, NIST control testing, POA&M management, DLP, GRC, U.S. citizenship, and California clearance.
Ivo: AI-powered contract intelligence platform serving in-house legal and procurement teams at enterprise companies.
3+ YOE3–5 years GRC/InfoSec/IT audit experience; hands-on SOC 2 Type II, ISO 27001, CSA STAR, ISO/IEC 42001; experience with Vanta, audits, evidence management, risk assessments, policy maintenance, and strong communication skills.
RobloxNYSE: RBLX: Global platform for user-created immersive digital experiences.
4+ YOE4+ years GRC experience, risk assessment and policy development, ability to work with engineers, knowledge of compliance frameworks and security controls.
Factor Analysis of Information Risk (FAIR), Roblox Studio
Scottsdale or Chicago or San Francisco or New York City
$84k-$105k/yrHybridFull Time
Early Warning Services: U.S. bank-owned fintech and consumer reporting agency providing identity, fraud-risk, and real-time payment solutions to financial institutions.
5+ YOEBachelor's degree in Accounting/Finance/Risk, 5+ years risk experience (3+ in financial services), advanced Microsoft Excel and PowerPoint skills, three-lines-of-defense experience, KRI/GRC familiarity, strong communication.
Karman Space & DefenseNYSE: KRMN: Provider of mission-critical aerospace and defense system solutions.
5+ YOEBachelor's degree or equivalent experience and 5+ years in cybersecurity GRC, IT audit, risk management, or control assurance. Requires control assessment expertise, regulated-framework knowledge, analytical skills, and stakeholder management.
Microsoft 365, Microsoft Excel, Microsoft PowerPoint, Microsoft Word, Microsoft Teams, Microsoft SharePoint, Microsoft Outlook, ServiceNow, Jira, Archer, AuditBoard, Drata, Vanta, Hyperproof
San Francisco or Denver or New York City or Scottsdale or San Jose
$183k-$205k/yrHybridFull Time
Gusto: Gusto is a payroll, benefits, and human-resources software platform serving small and medium-sized businesses.
8+ YOE8+ years in governance, risk, and compliance within SaaS; bachelor's degree required; SOC 2 Type 2 experience; strong communication, analytics, and compliance platform skills; relevant certification preferred.
Cathay BankNASDAQ: CATY: Commercial bank providing financial services to individuals and businesses.
3+ YOE3+ Mgmt3-5 years risk or banking experience, bachelor's degree required (master's preferred), leadership experience, advanced Microsoft Office skills, experience with risk/GRC platforms and KRIs/RCSAs.
Microsoft Excel, Power BI, Tableau, Microsoft PowerPoint, Microsoft Visio
United States or Colorado or Hawaii or Illinois or Maryland or Massachusetts or Minnesota or Vermont or District of Columbia or New York or New Jersey or Washington or California or Connecticut or Pennsylvania
$129k-$189k/yrRemoteFull Time
TwilioNYSE: TWLO: Cloud communications platform for building personalized customer experiences.
5+ YOE5+ years security-focused risk management experience with industry risk frameworks, quantitative and qualitative risk analysis, automation and AI tooling, cross-functional collaboration, and strong communication skills.
Senior Governance Risk and Compliance (GRC) Analyst
San Francisco, California, United States
$165k-$190k/yrHybridFull Time
IRENNASDAQ: IREN: Vertically integrated AI cloud and data center infrastructure provider.
5+ YOEBachelor's or master's degree in a relevant field, 5–7 years in cybersecurity or IT program management, FedRAMP authorization leadership, NIST 800-53 expertise, audit experience, and strong analytical and communication skills.
FedRAMP, NIST 800-53, SOC 2, ISO 27001, HITRUST, System Security Plan (SSP)
Perplexity AI: Private American software offering an AI-powered conversational search engine with real-time web answers and citations.
6+ YOE6+ years leading audit and compliance engagements; experience with SOC2/ISO27001/HIPAA, GDPR/CCPA/CPRA; building GRC tooling and automation; strong communication and cross-functional collaboration skills.
San Francisco or New York City or Los Angeles or Seattle
$175k-$230k/yrHybridFull Time
Whatnot: Live shopping marketplace connecting buyers and sellers.
8+ YOERequires 8+ years of security GRC experience, bachelor's degree in computer science or information security, audit experience, cloud compliance expertise, and knowledge of ISO 27001, SOC2, PCI, GDPR, and CCPA.
Senior Information Security Governance, Risk & Compliance Analyst
Northridge or Georgia or Minnesota or Texas
$121k-$205k/yrOnsiteFull Time
MedtronicNYSE: MDT: Global leader in medical technology and healthcare solutions.
7+ YOEBachelor’s degree or equivalent experience, 7+ years in information security GRC, risk, SOX ITGC, audit, access governance, or internal controls; SAP GRC certifications and advanced governance expertise required.
SAP GRC Access Control, SAP GRC Process Control, SAP GRC Risk Management, SAP, Oracle, Workday, ServiceNow, SailPoint, Entra ID, NIST Cybersecurity Framework, NIST Risk Management Framework, NIST AI Risk Management Framework, ISO 27001, ISO 31000, ISO 42001, COBIT, COSO Internal Control Framework, SOX 404 IT General Controls, HIPAA
Milwaukee or Chicago or New York City or San Francisco or Phoenix or Austin or United States
$133k-$195k/yrRemoteFull Time
DoorDashNYSE: DASH: Technology enabling local on-demand delivery and commerce.
7+ YOERequires 7+ years in security-focused TPRM, a bachelor's or master's degree, risk assessment and remediation experience, cloud and AI vendor expertise, GRC framework experience, and excellent communication skills.
Senior Information Security Analyst, GRC/Responsible AI
Irvine or Milpitas
$125k-$207k/yrOnsiteFull Time
SanDiskNASDAQ: SNDK: Specialist in NAND flash memory and data storage solutions.
6+ YOE6+ years information security experience with GRC and AI risk management, bachelor's or equivalent, technical proficiency in threat modeling and risk assessment, familiarity with NIST AI RMF and ISO/IEC 42001, and strong cross‑functional communication.
OWASP Top 10 for LLM Applications, NIST AI RMF, ISO/IEC 42001, STRIDE, PASTA, attack tree analysis, CI/CD