1

Cgrc Jobs in California (NOW HIRING)

Showing results 41-60

Cgrc information

What is a CGRC professional?

CGRC professionals, or Certified in Governance, Risk and Compliance, are experts who help organizations manage risk, ensure regulatory compliance, and establish effective governance frameworks. They analyze processes, identify potential risks, and develop policies to maintain compliance with laws and industry standards. CGRC certification, previously known as CAP (Certified Authorization Professional), is offered by (ISC)² and validates knowledge in governance, risk management, and compliance best practices. These professionals often work in cybersecurity, IT, or regulatory roles across various industries.

What are the key skills and qualifications needed to thrive as a Cybersecurity Governance, Risk, and Compliance (CGRC) professional?

To thrive as a CGRC professional, you need a solid understanding of cybersecurity frameworks, risk management, and regulatory compliance, typically supported by a relevant degree and certifications such as CISSP, CISA, or CGRC (formerly CAP). Familiarity with GRC platforms like Archer, ServiceNow GRC, or RSA, as well as knowledge of NIST, ISO, or HIPAA standards, is commonly required. Strong analytical skills, attention to detail, and effective communication are crucial soft skills for interpreting regulations and collaborating across teams. These competencies ensure organizations remain secure and compliant, minimizing risk and avoiding costly penalties.

What are some common challenges CGRC professionals face when managing compliance across multiple frameworks?

CGRC (Cybersecurity Governance, Risk, and Compliance) professionals often encounter the challenge of aligning organizational policies with the requirements of various regulatory frameworks, such as NIST, ISO 27001, and GDPR. This can involve interpreting overlapping or conflicting controls and ensuring consistent documentation and reporting. Additionally, they must facilitate communication and collaboration between IT, legal, and business teams to ensure all stakeholders understand and meet compliance obligations. Keeping up with the evolving regulatory landscape and adapting internal processes accordingly is also a key aspect of the role.

What is the difference between Cgrc vs Compliance Analyst?

AspectCgrcCompliance Analyst
CertificationsCertifications like CFE, CISA, or CMMC often preferredCertifications such as CCEP, CISA, or CIA common
Work EnvironmentTypically in cybersecurity, risk management, or compliance teams within organizationsUsually in corporate compliance departments, auditing firms, or regulatory agencies
Industry UsageUsed in industries like finance, healthcare, and government for cybersecurity and risk managementCommon across various industries for regulatory compliance and risk assessment

The Cgrc (Certified Government Risk Compliance) focuses on government-specific regulations and cybersecurity risk management, while a Compliance Analyst generally handles broader regulatory compliance across industries. Both roles require understanding of compliance frameworks, but Cgrc emphasizes government standards and cybersecurity, making it more specialized in those areas.

What cities in California are hiring for Cgrc jobs?

Cities in California with the most Cgrc job openings:

Infographic showing various Cgrc job openings in California as of August 2026, with employment types broken down into 88% Full Time, 9% Part Time, and 3% Contract. Highlights an 76% Physical, 5% Hybrid, and 19% Remote job distribution.

Power BI Administrator / Security Reporting & Analytics Engineer

Anvaya Solutions

Rancho Cordova, CA • Remote

Full-time

Posted 5 days ago


Key responsibilities

  • Build and administer Power BI reports and dashboards, including exporting data from operational and security tools and transforming it using Power Query.

  • Develop and administer content within SIEM platforms, including creating dashboards, scheduled searches, reports, and KPI reporting.

  • Write search and query languages to build reports and detection content related to security operations.


Job description

1-YEAR BASE TERM, WITH POTENTIAL 1-YEAR EXTENSION.  WORK WILL BE PERFORMED REMOTELY.

 

Mandatory Requirements

  • At least five (5) years within the last seven (7) years of professional experience building and administering Power BI reports and dashboards, including exporting data from operational and security tools, transforming it using Power Query, and generating reports.
  • At least five (5) years within the last seven (7) years of professional experience administering and developing content within SIEM platforms, custom dashboards, scheduled searches, reports, and KPI reporting.
  • At least five (5) years within the last seven (7) years of professional experience writing search and query languages used to build reports and detection content.
  • At least five (5) years within the last seven (7) years of professional experience with Security Orchestration, Automation and Response (SOAR) tools, including building playbooks and custom automation scripts in Python.
  • At least five (5) years within the last seven (7) years of professional experience with data ingestion and data onboarding from Windows, Linux, and syslog sources into reporting and analytics platforms, including configuring indexes, routing, and retention policies.
  • At least five (5) years within the last seven (7) years of professional experience architecting and operating reporting/analytics infrastructure in AWS, including automated CI/CD deployment using GitLab and Terraform (and/or Jenkins and CloudFormation).
  • At least five (5) years within the last seven (7) years of professional experience administering Identity and Access Management (IAM) and Single Sign-On (SSO) (e.g., Okta, Centrify), including role-based access control (RBAC) and user provisioning for reporting/analytics and security applications.
  • At least five (5) years within the last seven (7) years of professional experience integrating and reporting against Governance, Risk and Compliance (GRC) platforms (such as RSA Archer) and ticketing/service-management tools (such as ServiceNow or Remedy).
  • Working knowledge of the MITRE ATT&CK framework and NIST standards, and the ability to translate security data into executive-ready dashboards and reports.

Desirable Requirements

  • Any professional experience conducting risk assessments for an IT environment with business units to support a diverse set of infrastructure and services.
  • Working knowledge of the National Institute of Standards and Technology (NIST) Standards, the NIST Cybersecurity Framework, and NIST Special Publication (SP) 800-53 and other regulatory security standards and frameworks.
  • Possession of one or more of the following information technology industry certifications:
    • Security Operations & Engineering (Microsoft):  Microsoft Security Operations Analyst (SC-200), Azure Security Engineer Associate (AZ-500), Cybersecurity Architect Expert (SC-100), Identity and Access Administrator Associate (SC-300), Azure Administrator Associate (AZ-104), or Security, Compliance, and Identity Fundamentals (SC-900);
    • Governance, Risk & Audit:  CISM, CISSP, CISA, CRISC, or CGRC (Certified in Governance, Risk, and Compliance / formerly CAP);
    • Cloud Security:  CCSP (Certified Cloud Security Professional), AWS Certified Solutions Architect, or AWS Certified Security – Specialty;
    • SOC / Blue-Team / Incident Response:  Any GIAC certification (e.g., GSEC, GCIH, GCDA, GMON, or GCFA), CompTIA Security+, or CompTIA CySA+.
    • SIEM / SOAR Platforms:  Splunk certifications (e.g., Core Certified Power user or Enterprise Security Certified Admin), or Palo Alto Networks Certified XSIAM Engineer;
    • Project & Agile Delivery:  PMP, PMI-ACP, or SAFe Scrum Master (SSM).
  • Ten (10) years within the last fifteen (15) years of experience supporting statewide cybersecurity operations and modernization initiatives within a California State agency.
  • Ten (10) years within the last fifteen (15) years of experience with Agile/Scrum delivery and tools such as Azure DevOps (ADO).
  • Demonstrated leadership experience establishing and leading technical teams and overseeing the delivery of multiple (two or more) enterprise identity and access management (IAM) and cybersecurity initiatives from concept through implementation and ongoing operations, including at least one initiative incorporating AI/automation or other emerging technologies.  Experience should include cross-functional stakeholder coordination and full-lifecycle delivery at an enterprise or public-sector scale.
  • Depth operating a Microsoft-native SOC at scale – Sentinel + Defender XDR in a multi-tenant / MSSIP or enterprise environment.
  • AI/GenAI applied to security operations SOC automation, detection engineering, or LLM triage.
  • Zero Trust and identity governance (IGA) delivery Entra ID Governance, SailPoint, or Saviynt implementations.
  • Security automation / SOAR playbook development (Azure Logic Apps, XSIAM, Splunk, SOAR).
  • Public-sector compliance depth StateRAMP/FedRAMP, CJIS, or California SAM/SIMM 5300 experience.
  • Knowledge transfer / mentoring of State staff.

Applications that do not complete the Prescreen Survey will not be considered.

Anvaya Solutions, Inc. is an equal opportunity employer. All employment decisions, including hiring, promotions, and compensation, are made without regard to race, color, religion, sex, national origin, or any other protected characteristic.  We are committed to a merit-based workplace where every individual is treated with respect and has equal access to opportunities based solely on their qualifications and performance.