1

Cgrc Jobs in Arizona (NOW HIRING)

SecurityX / CASP+, CGRC/CAP, CISSO, Cloud+, FITSP-A, GCSA, GSEC, PenTest+, Security+ * Install and Configure ACAS: Deploy and configure ACAS components (Nessus scanners, Security Center, etc.) to ...

Cgrc information

What is a CGRC professional?

CGRC professionals, or Certified in Governance, Risk and Compliance, are experts who help organizations manage risk, ensure regulatory compliance, and establish effective governance frameworks. They analyze processes, identify potential risks, and develop policies to maintain compliance with laws and industry standards. CGRC certification, previously known as CAP (Certified Authorization Professional), is offered by (ISC)² and validates knowledge in governance, risk management, and compliance best practices. These professionals often work in cybersecurity, IT, or regulatory roles across various industries.

What are the key skills and qualifications needed to thrive as a Cybersecurity Governance, Risk, and Compliance (CGRC) professional?

To thrive as a CGRC professional, you need a solid understanding of cybersecurity frameworks, risk management, and regulatory compliance, typically supported by a relevant degree and certifications such as CISSP, CISA, or CGRC (formerly CAP). Familiarity with GRC platforms like Archer, ServiceNow GRC, or RSA, as well as knowledge of NIST, ISO, or HIPAA standards, is commonly required. Strong analytical skills, attention to detail, and effective communication are crucial soft skills for interpreting regulations and collaborating across teams. These competencies ensure organizations remain secure and compliant, minimizing risk and avoiding costly penalties.

What are some common challenges CGRC professionals face when managing compliance across multiple frameworks?

CGRC (Cybersecurity Governance, Risk, and Compliance) professionals often encounter the challenge of aligning organizational policies with the requirements of various regulatory frameworks, such as NIST, ISO 27001, and GDPR. This can involve interpreting overlapping or conflicting controls and ensuring consistent documentation and reporting. Additionally, they must facilitate communication and collaboration between IT, legal, and business teams to ensure all stakeholders understand and meet compliance obligations. Keeping up with the evolving regulatory landscape and adapting internal processes accordingly is also a key aspect of the role.

What is the difference between Cgrc vs Compliance Analyst?

AspectCgrcCompliance Analyst
CertificationsCertifications like CFE, CISA, or CMMC often preferredCertifications such as CCEP, CISA, or CIA common
Work EnvironmentTypically in cybersecurity, risk management, or compliance teams within organizationsUsually in corporate compliance departments, auditing firms, or regulatory agencies
Industry UsageUsed in industries like finance, healthcare, and government for cybersecurity and risk managementCommon across various industries for regulatory compliance and risk assessment

The Cgrc (Certified Government Risk Compliance) focuses on government-specific regulations and cybersecurity risk management, while a Compliance Analyst generally handles broader regulatory compliance across industries. Both roles require understanding of compliance frameworks, but Cgrc emphasizes government standards and cybersecurity, making it more specialized in those areas.

Infographic showing various Cgrc job openings in Arizona as of August 2026, with employment types broken down into 34% Part Time, and 66% Contract. Highlights an 100% In-person job distribution.

GRC Analyst / Onsite in Downtown Phoenix

Motion Recruitment Partners, LLC

Phoenix, AZ • On-site

Other

Posted 14 days ago


Job description

A large enterprise organization is seeking a GRC Analyst to support a high-visibility security initiative in a onsite role based in downtown Phoenix, AZ. This is a contract position focused on governance, risk, and compliance activities across technology projects, with exposure to security frameworks, audit processes, and enterprise risk management tools such as ServiceNow, Azure DevOps, Jira, and SharePoint.
This is an excellent opportunity for someone who thrives in structured environments and enjoys bringing order to complex security processes. The key value of this role is ownership of the risk register and approval lifecycle - you'll be the central point ensuring risks, decisions, documentation, and approvals are clearly tracked and audit-ready. If you're looking to deepen your GRC experience while working closely with security architects, engineering teams, and stakeholders across a large organization, this role offers strong exposure to enterprise-scale governance practices and real-world security decision-making.
Contract Duration: 12 - 24 Months
Required Skills & Experience
  • Experience supporting governance, risk, compliance, audit readiness, security documentation, risk management, or approval tracking for technology projects
  • Ability to maintain a project risk register with clear risk descriptions, owners, impacts, likelihood, mitigation plans, residual risk, decisions, and status updates
  • Working knowledge of security governance and risk management concepts, including control mapping, risk acceptance, evidence collection, approval workflows, and issue remediation tracking
  • Familiarity with security frameworks such as NIST Cybersecurity Framework, NIST SP 800-53, CIS Controls, ISO 27001, or equivalent
  • Ability to understand technical project context well enough to accurately document risks, controls, approvals, dependencies, and evidence requirements
  • Strong documentation discipline, attention to detail, follow-up skills, and ability to keep records audit-ready
  • Proficiency with Microsoft Office, Excel, SharePoint, Teams, and tools such as ServiceNow, Azure DevOps, Jira, Archer, or OneTrust
  • Ability to coordinate across security, architecture, engineering, project delivery, compliance, operations, and stakeholder groups
  • Strong written communication skills and ability to clearly summarize risk and approval status
Desired Skills & Experience
  • Security+, CGRC, CISA, CRISC, CISM, or similar certifications
  • Experience supporting public sector, regulated, or high-governance environments
  • Experience with authorization, exception, risk acceptance, audit, or compliance evidence processes
  • Experience building dashboards, trackers, approval matrices, or evidence repositories
  • Familiarity with Azure cloud, infrastructure delivery, DevOps, and security review processes
What You Will Be Doing
Tech Breakdown
  • 50% GRC Platforms and Documentation
  • 30% Security Frameworks and Risk Management
  • 20% Collaboration and Reporting Tools
Daily Responsibilities
  • 60% Risk and Compliance Tracking
  • 15% Process Coordination and Follow-Ups
  • 25% Cross-Team Collaboration