141 grc security analyst jobs at 121 companies in United States
2d
Save
Mark Applied
Hide
2d
Security GRC Analyst
United States
$70k-$77k/yrRemoteFull Time
Protective: Provides life insurance, annuities, and retirement protection solutions
1+ YOEExecute GRC functions including risk assessments, vendor risk, compliance, security awareness, reporting, and audit readiness; 1+ years GRC or risk experience; bachelor\u0002s degree in related field.
ServiceNow, Archer, Microsoft SharePoint, Microsoft Power BI, UpGuard, Azure, AWS
SalesforceNYSE: CRM: Sells cloud-based customer relationship management and business software solutions.
2+ YOE2–4 years GRC/compliance/audit or information security experience; working knowledge of at least two of SOC 2, HIPAA, ISO 27001, or GxP; proficiency with GRC/audit tools and Microsoft Office or Google Workspace; strong communication skills.
SOC 2, HIPAA, ISO 27001, GxP, Microsoft Office Suite, Google Workspace, Drata, Vanta, OneTrust, ServiceNow GRC
RobloxNYSE: RBLX: Platform for creating and playing user-generated 3D digital experiences.
4+ YOE4+ years GRC experience, risk assessment and policy development, ability to work with engineers, knowledge of compliance frameworks and security controls.
Factor Analysis of Information Risk (FAIR), Roblox Studio
Essential UtilitiesNYSE: WTRG: Provides regulated water, wastewater, and natural gas utility services.
3+ YOE3+ years GRC or information security experience; bachelor’s in IT-related field; risk, vulnerability, and compliance assessment experience; familiarity with ISO/NIST/COBIT/CIS; must obtain one listed security certification within 12 months.
Qualys Policy Compliance, CIS-CAT, Qualys, RSA Archer, Microsoft Active Directory, Microsoft Office 365, Microsoft Azure
Clear Capital: AI-driven real estate valuation and property data solutions.
3+ YOE5+ years GRC/risk/compliance experience with Bachelor’s (or 3+ years with Master’s) or equivalent; deep knowledge of NIST, ISO, SOC 2, GLBA/CCPA/GDPR; relevant certifications (CISSP, CISM, CISA, CRISC, AIGP); familiarity with Vanta, Drata, OneTrust, cloud and DevOps; strong analytics and communication.
NIST CSF, NIST RMF, ISO 27001, ISO 27002, ISO 42001, SOC 2, GLBA, CCPA, GDPR, Vanta, Drata, OneTrust, DevOps, cloud computing
MACOMNASDAQ: MTSI: Designs and manufactures semiconductor products for communications infrastructure.
1+ YOEBachelor's in relevant field (or equivalent), 1–3 years information security/risk/compliance experience, knowledge of security frameworks, strong analytical and communication skills, and willingness to learn ServiceNow GRC.
ServiceNow GRC, NIST, ISO 27001, SOC2, CIS, ISO9001, ISO14001
Zip: AI-powered intake-to-procure platform for enterprise spend management
2+ YOEBachelor's degree,2+ years GRC or security risk/audit experience,knowledge of SOC/ISO/PCI/FedRAMP/WCAG frameworks,strong written and verbal communication.
SOC 1, SOC 2, ISO 27001, ISO 42001, PCI DSS, WCAG, FedRAMP
4+ YOE4+ years GRC or information security governance experience; hands-on change management, risk assessment, policy management; familiarity with ISO 27001/SOC 2/NIST CSF; stakeholder engagement and strong written communication.
Ease: Mobile software for manufacturing plant floor audits and inspections.
3+ YOE3+ years in GRC/security compliance or IT audit; hands-on SOC 2/ISO 27001/HIPAA work; cloud (AWS/Azure/GCP) familiarity; vendor assessments; Jira; strong written communication; authorized to access CUI (US citizen or permanent resident).
SOC 2, CMMC, ISO 27001, HIPAA, NIST 800-171, DFARS 252.204-7012, FedRAMP, NIST AI RMF, System Security Plan (SSP), C3PAO, Drata, Vanta, Hyperproof, Secureframe, Jira, AWS, Azure, GCP, EASE
News CorpNASDAQ: NWSA: Provides global news, information, and digital media services.
3+ YOE3+ years in cyber security/GRC, experience with PCI DSS, NIST CSF, ISO 27001, AWS; supports audits, risk assessments, and third‑party security reviews; professional security certifications preferred.
AdobeNASDAQ: ADBE: Provides software for digital media creation and marketing analytics
5+ YOE5+ years GRC/InfoSec experience, knowledge of SOC/ISO/HIPAA/FedRAMP/NIST frameworks, program and audit leadership, strong communication and analytical skills.
AWS, Azure, GCP, Adobe Common Controls Framework (CCF)
Morgan & Morgan: Provides legal representation for personal injury and consumer litigation.
4+ YOE4+ years in GRC/IT audit/compliance/information security; hands-on GRC platform experience (Vanta preferred); strong knowledge of ISO 27001, NIST CSF, CIS v8.1; ISC2 or ISACA certification required; experience leading audits and vendor risk assessments.
7+ YOE7+ years GRC or related experience, experience with HITRUST/ISO 27001/SOC 2/NIST, third-party risk assessments, strong documentation and stakeholder skills, bachelor's degree in related field required.
HITRUST, ISO 27001, SOC 2, NIST CSF, PCI DSS, UK Cyber Essentials, NIS2, HIPAA, FDA
Benepass: Platform for distributing and managing flexible employee benefits.
5+ YOE5+ years in GRC, information security, IT audit or risk management; hands-on SOC 2, ISO 27001/HITRUST; policy, evidence & audit readiness; strong communication.
PSEGNYSE: PEG: Investor-owned electric and gas utility.
4+ YOEBachelor's in related field or 8+ years' equivalent; 4+ years cybersecurity GRC/IT audit experience; proficiency with Cyber GRC tools; experience with risk and control assessments, audit coordination, and remediation tracking; DOE 10 CFR 810 eligibility.
DoorDashNASDAQ: DASH: On-demand delivery platform connecting consumers with local merchants.
6+ YOE6+ years in security compliance/GRC with 3+ years implementing HIPAA programs in technology or regulated environments; strong HIPAA Security Rule knowledge, multi-framework experience, technical fluency with cloud/IAM/CI/CD, and stakeholder communication skills.
Rogo: Provides a generative AI platform for financial institutions.
Experience supporting customer-facing security/compliance in SaaS/cloud; translate security concepts into written responses; manage multiple requests; strong written and stakeholder communication; knowledge of cloud security, incident response; drive continuous improvement.