113 information security grc analyst jobs at 99 companies in United States
1w
Save
Mark Applied
Hide
1w
Information Security GRC Analyst 4
San Jose or Seattle or Lehi or New York City
$113k-$229k/yrOnsiteFull Time
AdobeNASDAQ: ADBE: Provides software for digital media creation and marketing analytics
5+ YOE5+ years GRC/InfoSec experience, knowledge of SOC/ISO/HIPAA/FedRAMP/NIST frameworks, program and audit leadership, strong communication and analytical skills.
AWS, Azure, GCP, Adobe Common Controls Framework (CCF)
Chatham Financial: Independent finance firm focused on capital markets and risk management.
3+ YOE3-5+ years IT audit/risk experience; bachelor’s in Information Security/CS/Risk; SOC 2 experience; knowledge of NIST/ISO; CRISC, CDPSE, CISA, CISSP, ISO 27001 lead auditor/implementer preferred; strong analytical/written skills.
NIST SP 800-30, ISO 27005, NIST CSF, NIST 800-53, ISO 27001, CIS, SOC 2 Trust Services Criteria, Cloud Control Matrix (CCM), Risk Management tools
7+ YOE7+ years GRC or related experience, experience with HITRUST/ISO 27001/SOC 2/NIST, third-party risk assessments, strong documentation and stakeholder skills, bachelor's degree in related field required.
HITRUST, ISO 27001, SOC 2, NIST CSF, PCI DSS, UK Cyber Essentials, NIS2, HIPAA, FDA
Protective: Provides life insurance, annuities, and retirement protection solutions
1+ YOEExecute GRC functions including risk assessments, vendor risk, compliance, security awareness, reporting, and audit readiness; 1+ years GRC or risk experience; bachelor\u0002s degree in related field.
ServiceNow, Archer, Microsoft SharePoint, Microsoft Power BI, UpGuard, Azure, AWS
SalesforceNYSE: CRM: Sells cloud-based customer relationship management and business software solutions.
2+ YOE2–4 years GRC/compliance/audit or information security experience; working knowledge of at least two of SOC 2, HIPAA, ISO 27001, or GxP; proficiency with GRC/audit tools and Microsoft Office or Google Workspace; strong communication skills.
SOC 2, HIPAA, ISO 27001, GxP, Microsoft Office Suite, Google Workspace, Drata, Vanta, OneTrust, ServiceNow GRC
Centennial or Decatur or Cape Canaveral or Vandenberg AFB
$104k-$173k/yrOnsiteFull Time
United Launch Alliance: Aerospace providing space launch services for satellites.
4+ YOEBachelor in STEM or equivalent experience, 4+ years related experience, working knowledge of CNSSI 1253/NIST/ISO frameworks, experience in regulated A&D/DoD environments, strong analytical and communication skills.
Essential UtilitiesNYSE: WTRG: Provides regulated water, wastewater, and natural gas utility services.
3+ YOE3+ years GRC or information security experience; bachelor’s in IT-related field; risk, vulnerability, and compliance assessment experience; familiarity with ISO/NIST/COBIT/CIS; must obtain one listed security certification within 12 months.
Qualys Policy Compliance, CIS-CAT, Qualys, RSA Archer, Microsoft Active Directory, Microsoft Office 365, Microsoft Azure
WHSmithLondon Stock Exchange: SMWH: Global travel retailer operating stores in airports and resorts.
1+ YOEBachelor's in cybersecurity or equivalent experience,1+ years cybersecurity/GRC/IT experience,knowledge of NIST CSF/CIS/ISO27001/PCI DSS,EDR exposure,vulnerability and access management,training and communication skills.
WHSmith North AmericaLondon Stock Exchange: SMWH: Specialty travel retailer operating stores in airports and resorts.
1+ YOEBachelor's in cybersecurity or equivalent experience,1+ year cybersecurity/GRC/IT experience,knowledge of NIST CSF/CIS/ISO27001/PCI DSS,EDR and vulnerability concepts,strong communication and training skills,English fluency.
Senior Information Security Analyst, GRC/Responsible AI
Irvine or Milpitas
$125k-$207k/yrOnsiteFull Time
SandiskNasdaq: SNDK: Designs and manufactures flash memory and data storage products.
6+ YOE6+ years information security experience with GRC and AI risk management, bachelor's or equivalent, technical proficiency in threat modeling and risk assessment, familiarity with NIST AI RMF and ISO/IEC 42001, and strong cross‑functional communication.
OWASP Top 10 for LLM Applications, NIST AI RMF, ISO/IEC 42001, STRIDE, PASTA, attack tree analysis, CI/CD
Meritrust Credit Union: Offers personal and business banking services to its members.
0+ YOEAssociate's or Bachelor's in IT/cybersecurity or equivalent experience; 0–2 years IT/cybersecurity experience; familiarity with security frameworks, Windows/Linux, networking; strong analytical and communication skills.
Microsoft Windows, Linux, PCI DSS, NIST 800-53, FedRAMP, ISO 27001, CIS, MITRE ATT&CK, OWASP Top 10
MACOMNASDAQ: MTSI: Designs and manufactures semiconductor products for communications infrastructure.
1+ YOEBachelor's in relevant field (or equivalent), 1–3 years information security/risk/compliance experience, knowledge of security frameworks, strong analytical and communication skills, and willingness to learn ServiceNow GRC.
ServiceNow GRC, NIST, ISO 27001, SOC2, CIS, ISO9001, ISO14001
Rutgers University: Providing higher education degrees and conducting academic research.
5+ YOEBachelor's in a related field and 5+ years information security experience; knowledge of HIPAA, GLBA, PCI DSS, NIST CSF; experience with GRC/VRM; strong communication and risk assessment skills.
HIPAA, GLBA, PCI DSS, NIST CSF, NIST 800-171, ISO 27001, ISO 27002, GRC, VRM
Intercontinental ExchangeNYSE: ICE: Operates global financial exchanges, clearing houses, and mortgage platforms.
Governance, risk, and compliance in information security; degree in information security or related field; CISSP or equivalent; experience with policies, metrics, audits; strong technical writing.
Information Security Governance, Risk & Compliance (GRC) Analyst
Rockville, Maryland, United States
OnsiteFull Time
ASSYST: An award-winning IT firm that delivers digital transformation, DevSecOps, cyber security, and AI integration for government agencies.
Experience in information security governance, risk management, or compliance; strong analytical, written and verbal communication, organizational skills; ability to learn new technologies and work independently.
ServiceNow Integrated Risk Management (IRM), Microsoft Office 365
4+ YOE4+ years GRC or information security governance experience; hands-on change management, risk assessment, policy management; familiarity with ISO 27001/SOC 2/NIST CSF; stakeholder engagement and strong written communication.
Victaulic: Manufacturer of mechanical pipe joining and flow control systems.
0+ YOE0–2 years in information security, IT audit, or risk; familiarity with NIST CSF, ISO/IEC 27001, CMMC, and NIS2; experience with risk assessments, third-party audits, cloud/DevOps/application security; CompTIA Security+ or equivalent; CISA preferred.
Benepass: Platform for distributing and managing flexible employee benefits.
5+ YOE5+ years in GRC, information security, IT audit or risk management; hands-on SOC 2, ISO 27001/HITRUST; policy, evidence & audit readiness; strong communication.