1

Cgrc Jobs in California (NOW HIRING)

Cybersecurity Program Manager

San Jose, CA · Remote

$151K - $184K/yr

PMP, CISSP, CISM, CGRC, or similar certifications are a plus Ideal Candidate * A structured, proactive program manager with strong cybersecurity instincts * Comfortable working with ambiguity and ...

Cybersecurity Program Manager

San Jose, CA · On-site +1

$151K - $184K/yr

PMP, CISSP, CISM, CGRC, or similar certifications are a plus Ideal Candidate * A structured, proactive program manager with strong cybersecurity instincts * Comfortable working with ambiguity and ...

next page

Showing results 1-20

Cgrc information

What is a CGRC professional?

CGRC professionals, or Certified in Governance, Risk and Compliance, are experts who help organizations manage risk, ensure regulatory compliance, and establish effective governance frameworks. They analyze processes, identify potential risks, and develop policies to maintain compliance with laws and industry standards. CGRC certification, previously known as CAP (Certified Authorization Professional), is offered by (ISC)² and validates knowledge in governance, risk management, and compliance best practices. These professionals often work in cybersecurity, IT, or regulatory roles across various industries.

What are the key skills and qualifications needed to thrive as a Cybersecurity Governance, Risk, and Compliance (CGRC) professional?

To thrive as a CGRC professional, you need a solid understanding of cybersecurity frameworks, risk management, and regulatory compliance, typically supported by a relevant degree and certifications such as CISSP, CISA, or CGRC (formerly CAP). Familiarity with GRC platforms like Archer, ServiceNow GRC, or RSA, as well as knowledge of NIST, ISO, or HIPAA standards, is commonly required. Strong analytical skills, attention to detail, and effective communication are crucial soft skills for interpreting regulations and collaborating across teams. These competencies ensure organizations remain secure and compliant, minimizing risk and avoiding costly penalties.

What are some common challenges CGRC professionals face when managing compliance across multiple frameworks?

CGRC (Cybersecurity Governance, Risk, and Compliance) professionals often encounter the challenge of aligning organizational policies with the requirements of various regulatory frameworks, such as NIST, ISO 27001, and GDPR. This can involve interpreting overlapping or conflicting controls and ensuring consistent documentation and reporting. Additionally, they must facilitate communication and collaboration between IT, legal, and business teams to ensure all stakeholders understand and meet compliance obligations. Keeping up with the evolving regulatory landscape and adapting internal processes accordingly is also a key aspect of the role.

What is the difference between Cgrc vs Compliance Analyst?

AspectCgrcCompliance Analyst
CertificationsCertifications like CFE, CISA, or CMMC often preferredCertifications such as CCEP, CISA, or CIA common
Work EnvironmentTypically in cybersecurity, risk management, or compliance teams within organizationsUsually in corporate compliance departments, auditing firms, or regulatory agencies
Industry UsageUsed in industries like finance, healthcare, and government for cybersecurity and risk managementCommon across various industries for regulatory compliance and risk assessment

The Cgrc (Certified Government Risk Compliance) focuses on government-specific regulations and cybersecurity risk management, while a Compliance Analyst generally handles broader regulatory compliance across industries. Both roles require understanding of compliance frameworks, but Cgrc emphasizes government standards and cybersecurity, making it more specialized in those areas.

What cities in California are hiring for Cgrc jobs?

Cities in California with the most Cgrc job openings:

Infographic showing various Cgrc job openings in California as of August 2026, with employment types broken down into 88% Full Time, 9% Part Time, and 3% Contract. Highlights an 76% Physical, 5% Hybrid, and 19% Remote job distribution.

Security Architect / Engineer - Zero Trust Architecture

WaveStrong, Inc.

Sacramento, CA

$69.25 - $89.50/hr

Contractor

Re-posted yesterday


Job description

Exciting Security Architect / Engineer - Zero Trust Architecture contract opportunity.

Requirements

  • 5 plus years of experience as a Security Architect / Engineer with expertise evaluating Zero Trust Architecture (ZTA).
  • ZTA implementation roadmap (Plan, Schedule, and Decks), Cybersecurity Program and Architecture Risk Review and architect and engineer support for Zero Trust Architecture (ZTA) implementation activities
  • Experience evaluating, recommending, and implementing commercial hardware and software security products to augment and enhance enterprise cybersecurity program.
  • Experience with system, device, and application-level hardening and assessing the cybersecurity posture of software, hardware, and firmware.
  • Experience with supporting an integrated, dynamic cyber defense and leveraging cybersecurity solutions to deliver cybersecurity operational services.
  • Experience researching emerging technology, requisite security requirements, and emerging threats to develop a way forward to meet organizational goals
  • B.S computer Science (CS), Management of Information Systems (MIS), Electrical Engineering (EE), or Cybersecurity from an accredited University.

DESIRABLE QUALIFICATIONS:

  • ISC2 Certified Information Systems Security Professional (CISSP), ISC2 Certified - Governance Risk and Compliance (CGRC) or Certified Authorization Professional (CAP), ISACA Certified Information Security Manager (CISM), ISACA Certified in Risk and Information Systems Control (CRISC), CompTIA Certified Advanced Security Practitioner (CASAP+), CompTIA Security+