13 security grc analyst jobs at 12 companies in New York City, NY

3w
Save
Mark Applied
Hide
GRC Analyst II
Los Angeles or Chicago or Nashville or New York or Seattle
$100k-$135k/yr HybridFull Time
Metropolis
Metropolis: Computer vision technology for checkout-free parking and retail payments.
3+ YOE3+ years in information security GRC or technology compliance; experience managing security awareness programs; knowledge of SOC 2 and PCI-DSS; familiarity with AI/data security and training platforms; bachelor\u0002s degree required.
SOC 2, PCI-DSS, automated employment decision tool (AEDT)
1mo
Save
Mark Applied
Hide
Information Security GRC Analyst 4
San Jose or Seattle or Lehi or New York City
$113k-$229k/yr OnsiteFull Time
Adobe
AdobeNASDAQ: ADBE: Provides software for digital media creation and marketing analytics
5+ YOE5+ years GRC/InfoSec experience, knowledge of SOC/ISO/HIPAA/FedRAMP/NIST frameworks, program and audit leadership, strong communication and analytical skills.
AWS, Azure, GCP, Adobe Common Controls Framework (CCF)
1mo
Save
Mark Applied
Hide
Cyber Security GRC Analyst (82464)
Bethpage, New York, United States
$94k-$148k/yr HybridFull Time
PSEG
PSEGNYSE: PEG: Investor-owned electric and gas utility.
4+ YOEBachelor's in related field or 8+ years' equivalent; 4+ years cybersecurity GRC/IT audit experience; proficiency with Cyber GRC tools; experience with risk and control assessments, audit coordination, and remediation tracking; DOE 10 CFR 810 eligibility.
ServiceNow, Archer, RSAM
2w
Save
Mark Applied
Hide
Senior Analyst, GRC
White Plains, New York, United States
$140k-$180k/yr OnsiteFull Time
Veterinary Emergency Group
Veterinary Emergency Group: Operates a network of 24/7 emergency veterinary hospitals.
3+ YOERequires 3+ years in GRC, IT audit, compliance, or related security work; knowledge of a security or compliance framework; GRC platform experience; and strong documentation and communication skills.
PCI DSS, NIST, SOC 2, ISO 27001, Hyperproof, Archer, OneTrust
2d
Save
Mark Applied
Hide
Security & Compliance Analyst
New York City, New York, United States
$90k-$110k/yr OnsiteFull Time
OTG
OTG: Operates dining and retail locations in airport terminals.
3+ YOEBachelor’s degree or equivalent experience, 3–5 years in IT security, compliance, or audit, and hands-on PCI DSS experience. Knowledge of AWS, network security, GRC tools, and payment environments preferred.
PCI DSS, Governance, Risk, and Compliance (GRC), AWS, IAM, CloudWatch, Secrets Manager, VPC, ServiceNow, POS
2w
Save
Mark Applied
Hide
Senior Analyst, Tech GRC M&A
Long Island City, New York, United States
$90k-$135k/yr OnsiteFull Time
The Estée Lauder Companies
The Estée Lauder CompaniesNYSE: EL: Manufactures and markets prestige skincare, makeup, and fragrance products.
Experienced application security professional versed in SDLC/DevSecOps, vulnerability assessment (SAST/DAST/IAST), threat modeling, CI/CD and cloud/container security; strong programming/scripting skills and ability to mentor teams.
C#, C/C++, Java, JavaScript, PowerShell, Python, REST, SOAP, SAST, DAST, IAST, Bitbucket, Jenkins, JIRA, Artifactory, Nexus, git, Ansible, DeMisto, Docker, Kubernetes
1d
Save
Mark Applied
Hide
Governance, Risk, Complaince (GRC) Analyst
New York City, New York, United States
OnsiteFull Time
Aaru
Aaru: AI platform for predictive human behavior simulation.
3+ YOERequires 3–5 years in GRC, security compliance, or IT audit; SOC 2 knowledge; familiarity with ISO 27001 and related frameworks; GRC platform experience; and strong communication and process-building skills.
Vanta, Drata, OneTrust, SOC 2, ISO 27001, NIST CSF, HIPAA, PCI-DSS, ISO 42001, NIST AI RMF, EU AI Act, GDPR, Python, JavaScript, CISA, CRISC, CISM
1mo
Save
Mark Applied
Hide
Senior Security Analyst, Customer Assurance
New York City or Seattle or Raleigh or San Francisco or Washington or London or Amsterdam
$134k-$214k/yr HybridFull Time
Plaid
Plaid: Provides financial data connectivity and payment infrastructure via APIs.
6+ YOE6+ years in security assurance/GRC with ownership of customer-facing security workflows; experience reviewing security contract provisions; familiarity with SOC 2, ISO 27001, NIST frameworks, PCI, GLBA, GDPR/CCPA; program design, metrics ownership, and AI-assisted workflow experience.
SOC 2, ISO 27001, NIST CSF, PCI DSS, GLBA, GDPR, CCPA, NIST 800-53
1w
Save
Mark Applied
Hide
Senior Security Assurance Analyst
New York City, New York, United States
$148k-$185k/yr HybridFull Time
Lyft
LyftNASDAQ: LYFT: Provides an on-demand ride-hailing and multimodal transportation platform.
5+ YOERequires 5+ years in security GRC, IT audit, or assurance; 5+ years with ISO 27001 and PCI DSS; knowledge of SOC 2, HIPAA, NIST CSF, global frameworks; strong technical, communication, and project leadership skills.
Jira, Confluence, AuditBoard CrossComply, Vanta, Drata, SafeBase, AWS, GCP, Azure, CAIQ, SIG, LLMs
2mo
Save
Mark Applied
Hide
Security Compliance Analyst, Privacy
San Francisco or New York
$175k-$220k/yr OnsiteFull Time
LangChain
LangChain: Tools for building and deploying production-ready AI agents.
5+ YOE5+ years in privacy/GRC/security compliance; hands-on experience with GDPR, HIPAA, CCPA, SOC 2, ISO frameworks; DPAs/BAAs experience; technical fluency (can read code, validate data flows); strong writing skills.
Python
2w
Save
Mark Applied
Hide
Senior Analyst, Tech GRC M&A (25878)
Long Island City, New York, United States
$90k-$135k/yr OnsiteFull Time
Estée Lauder Companies
Estée Lauder CompaniesNYSE: EL: Manufacturer and marketer of prestige beauty and skincare products.
Experience in application security, secure SDLC, vulnerability assessment (SAST/DAST/IAST), threat modeling, CI/CD and cloud/container security, strong programming/scripting skills, and ability to consult across technical teams.
C#, C/C++, Java, JavaScript, PowerShell, Python, REST, SOAP, SOA, Bitbucket, Jenkins, JIRA, Artifactory, Nexus, git, Application Engine, SQL, Ansible, DeMisto, Docker, Kubernetes, SAST, DAST, IAST
2d
Save
Mark Applied
Hide
Governance Risk & Compliance Analyst
San Francisco or New York City or Los Angeles or Seattle
$175k-$230k/yr HybridFull Time
Whatnot
Whatnot: Social marketplace for buying and selling via live streams
8+ YOERequires 8+ years of security GRC experience, bachelor's degree in computer science or information security, audit experience, cloud compliance expertise, and knowledge of ISO 27001, SOC2, PCI, GDPR, and CCPA.
Okta, Terraform, AWS, Lumos, Cloudflare, Github
2w
Save
Mark Applied
Hide
Senior Analyst, Third-Party Risk Management (TPRM)
Milwaukee or Chicago or New York City or San Francisco or Phoenix or Austin or United States
$133k-$195k/yr RemoteFull Time
DoorDash
DoorDashNYSE: DASH: Local food delivery and on-demand logistics platform.
7+ YOERequires 7+ years in security-focused TPRM, a bachelor's or master's degree, risk assessment and remediation experience, cloud and AI vendor expertise, GRC framework experience, and excellent communication skills.
AWS, Azure, GCP, Covey