1

Cisa Grc Jobs (NOW HIRING)

CISSP * CISA * CRISC * CISM * CGEIT Behavioral Competencies: * Collaborates * Communicates ... GRC Platforms * Policy Management * Compliance Automation Tools * IT Risk Assessment * Control ...

CISSP * CISA * CRISC * CISM * CGEIT Behavioral Competencies: * Collaborates * Communicates ... GRC Platforms * Policy Management * Compliance Automation Tools * IT Risk Assessment * Control ...

THE POSITION NMC² is looking for a detail-oriented GRC Compliance Auditor to join the Information ... CISA, ISO 27001 Lead Auditor or Lead Implementer, CISM, CISSP, or CRISC. It is impossible to list ...

CISA, CRISC, CISM, Security+, ISO 27001 Foundation/Lead Implementer, or similar professional ... GRC or trust-management platforms such as Vanta, Archer, ServiceNow GRC, OneTrust, Drata, or ...

GRC Analyst II

Colorado Springs, CO · On-site

$73K - $100K/yr

The Governance, Risk, and Compliance (GRC) Analyst II configures, implements, and manages security ... Industry certifications such as CISA, CRISC, Security+, or similar credentials * Strong written and ...

CISA, CRISC, CISM, Security+, ISO 27001 Foundation/Lead Implementer, or similar professional ... GRC or trust-management platforms such as Vanta, Archer, ServiceNow GRC, OneTrust, Drata, or ...

IT GRC Specialist

Tucson, AZ · On-site

$100 - $125/hr

Professional certifications such as CISSP, CISA, CRISC, CGEIT, ISO 27001 Lead Implementer, or ... Experience with GRC platforms, audit management tools, and compliance automation solutions. Key ...

Security GRC Analyst

San Francisco, CA · On-site

$100 - $125/hr

## Security GRC AnalystApplyremote type: Office Tech-Flexiblelocations: California - San Franciscotime ... You hold one or more relevant certifications such as CISA (Certified Information Systems Auditor ...

Showing results 41-60

Cisa Grc information

See salary details

$4.9K

$8.7K

$13.4K

How much do cisa grc jobs pay per month?

As of Sep 9, 2026, the average monthly pay for cisa grc in the United States is $8,731.92, according to ZipRecruiter salary data. Most workers in this role earn between $5,208.33 and $12,250.00 per month, depending on experience, location, and employer.

What is a CISA GRC professional?

A CISA GRC professional is an expert who holds the Certified Information Systems Auditor (CISA) credential and specializes in Governance, Risk, and Compliance (GRC). These professionals help organizations manage risks, ensure compliance with regulations, and establish effective IT governance practices. They conduct audits, assess controls, and provide recommendations to improve security and operational processes. Their role is critical in protecting organizational assets and ensuring that IT systems support business objectives while complying with legal and regulatory requirements.

What are the key skills and qualifications needed to thrive as a CISA GRC professional?

To excel as a CISA GRC (Governance, Risk, and Compliance) professional, you need expertise in IT auditing, risk assessment, compliance frameworks, and a CISA certification. Familiarity with GRC platforms (such as RSA Archer or ServiceNow), audit management tools, and knowledge of regulations like SOX or GDPR are typically required. Critical thinking, attention to detail, and strong communication skills help manage risk and ensure organizational compliance. These competencies are crucial for safeguarding information assets, meeting regulatory requirements, and supporting business objectives.

What are some common challenges faced by professionals in CISA GRC roles, and how can they be addressed?

CISA GRC (Governance, Risk, and Compliance) professionals often encounter challenges such as keeping up with constantly changing regulations, managing risk across multiple business units, and ensuring organization-wide compliance. Navigating these complexities requires strong communication skills to coordinate with various departments and a proactive approach to staying updated on regulatory changes. Leveraging automated GRC tools and maintaining continuous professional development can help mitigate these challenges and enhance efficiency in fulfilling compliance and audit responsibilities.

What is the difference between Cisa Grc vs Cisa Auditor?

AspectCisa GrcCisa Auditor
CertificationsCISA, CRISC, CISSPCISA, CPA, CIA
Work EnvironmentRisk management, compliance, governanceAudit, assessment, controls testing
Industry UsageIT governance, risk, compliance rolesAudit firms, internal audit departments

Both Cisa Grc and Cisa Auditor roles require CISA certification, but Cisa Grc focuses on risk management and compliance, while Cisa Auditor emphasizes audit and controls testing. Understanding these differences helps professionals choose the right career path in cybersecurity and IT audit fields.

Is CISA still in demand?

CISA (Certified Information Systems Auditor) professionals are in high demand due to the ongoing need for cybersecurity governance, risk management, and compliance expertise. Organizations seek CISA-certified individuals to help secure information systems, ensure regulatory compliance, and manage IT audits, making the role consistently relevant across industries.
Infographic showing various Cisa Grc job openings in the United States as of September 2026, with employment types broken down into 1% As Needed, 88% Full Time, 7% Part Time, and 4% Contract. Highlights an 68% Physical, 7% Hybrid, and 25% Remote job distribution, with an average salary of $104,783 per year, or $50.4 per hour.

IT GRC Lead Analyst

Westfield Center, OH • On-site

Westfield
Insurance Services • 1 - 5K employees

Full-time

This job post has expired today. Applications are no longer accepted.


Key responsibilities

  • Lead the development, execution, and continuous improvement of the enterprise IT Governance, Risk, and Compliance (GRC) program, frameworks, and operating model.

  • Lead enterprise technology risk assessments and provide risk-based recommendations aligned with business objectives and risk appetite.

  • Oversee compliance with regulatory requirements, industry standards, and internal policies, ensuring effective implementation of controls and monitoring mechanisms.


Westfield Insurance rating

8.7

Company rating: 8.7 out of 10

Based on 12 frontline employees who took The Breakroom Quiz

72nd of 315 rated insurance


Job description


Job Summary:
The IT Governance, Risk, and Compliance (GRC) Lead Analyst serves as a subject matter expert responsible for leading the design, implementation, maturity, and continuous improvement of the organization's IT governance, risk management, and compliance programs.
This role provides strategic oversight of technology risk and control management, partners with business and technology leaders to ensure alignment with enterprise objectives and drives a proactive risk-aware culture across the organization. The GRC Lead Analyst serves as a trusted advisor to senior leadership, influencing risk-based decision-making and ensuring compliance with regulatory requirements, industry standards, and internal policies.
The ideal candidate possesses deep expertise in governance frameworks, regulatory compliance, IT controls, risk management, audit practices, and cybersecurity governance, along with demonstrated leadership in driving enterprise-wide initiatives and mentoring others.
Applicants must be currently authorized to work in the United States on a full-time basis without employer sponsorship.
Job Responsibilities:
  • Lead the development, execution, and continuous improvement of the enterprise IT Governance, Risk, and Compliance (GRC) program, frameworks, and operating model.
  • Serve as the organization's subject matter expert for IT governance, risk management, compliance, and control oversight.
  • Lead enterprise technology risk assessments and provide risk-based recommendations aligned with business objectives and risk appetite.
  • Drive the maturity of risk management practices through governance enhancements, process optimization, and industry best practices.
  • Oversee compliance with regulatory requirements, industry standards, and internal policies, ensuring effective implementation of controls and monitoring mechanisms.
  • Establish and maintain IT control frameworks, including ITGCs, cybersecurity controls, and key risk indicators (KRIs).
  • Lead control assessments, testing, continuous monitoring, and remediation efforts to strengthen the organization's control environment.
  • Serve as the primary liaison for internal and external audits, regulatory examinations, and issue remediation governance.
  • Lead third-party technology risk management activities, including vendor assessments and ongoing risk oversight.
  • Champion the implementation, optimization, and automation of GRC processes and technologies to improve efficiency and effectiveness.
  • Develop and deliver executive-level reporting, dashboards, and insights on risk, compliance, audit results, and remediation activities.
  • Lead cross-functional GRC initiatives, influence strategic decision-making, and mentor team members to foster a culture of risk awareness and continuous improvement.

Job Qualifications:
  • 7+ years of experience in IT Governance, Risk, and Compliance, Information Security, IT Audit, or related disciplines.
  • Bachelor's degree in Information Technology, Cybersecurity, Information Systems, Risk Management, Business, or related field.

Location
Hybrid defined as three (3) or more days per week in the office.
Licenses and Certifications:
  • CISSP
  • CISA
  • CRISC
  • CISM
  • CGEIT

Behavioral Competencies:
  • Collaborates
  • Communicates Effectively
  • Customer Focus
  • Decision Quality
  • Nimble Learning

Technical Skills:
  • Insurance Industry Knowledge
  • Regulatory Examinations
  • GRC Platforms
  • Policy Management
  • Compliance Automation Tools
  • IT Risk Assessment
  • Control Design
  • Security Testing

This job description describes the general nature and level of work performed in this role. It is not intended to be an exhaustive list of all duties, skills, responsibilities, knowledge, etc. These may be subject to change and additional functions may be assigned as needed by management.
About Us
Founded in 1848, Westfield is a global leader in property and casualty insurance, delivering superior risk insights and innovative solutions to customers through a diverse portfolio of insurance products. Westfield underwrites commercial, personal, surety, and specialty lines of coverage through a network of leading independent agents and brokers in the United States and specialty products through Lloyd's of London Syndicate 1200. As a mutual insurance company with more than 3,000 employees, Westfield has revenues in excess of $4 billion and more than $10 billion in assets.

What Westfield Insurance employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom