1

Cissp Grc Jobs (NOW HIRING)

Active certifications such as CISA, CRISC, CISM, CISSP, or ISO 27001 Lead Auditor * Experience with GRC platforms such as ServiceNow GRC, Archer, OneTrust, or equivalent * Familiarity with CMMC, NERC ...

About the Role As a member of the Information Security team, the IS GRC - Risk & Compliance Senior ... CISSP (Preferred) * CISA (Preferred) * CRISC (Nice to have) * Willingness to pursue security ...

New

next page

Showing results 1-20

Cissp Grc information

See salary details

$68K

$126.8K

$191.5K

How much do cissp grc jobs pay per year?

As of Aug 1, 2026, the average yearly pay for cissp grc in the United States is $126,833.00, according to ZipRecruiter salary data. Most workers in this role earn between $105,000.00 and $145,000.00 per year, depending on experience, location, and employer.

How does a CISSP GRC professional typically collaborate with IT, legal, and business teams within an organization?

A CISSP GRC (Governance, Risk, and Compliance) professional often acts as a bridge between technical, legal, and business stakeholders. They work closely with IT teams to ensure security controls align with organizational policies, coordinate with legal departments to interpret regulatory requirements, and advise business leaders on risk management strategies. Regular cross-functional meetings, risk assessments, and policy reviews are common, making strong communication skills essential. This collaborative approach ensures that security and compliance initiatives support both regulatory standards and business objectives.

What is the difference between Cissp Grc vs Cissp Security Analyst?

AspectCissp GrcCissp Security Analyst
CertificationsCissp, GRC-focused certificationsCissp, Security certifications
Work EnvironmentGovernance, risk management, compliance teamsSecurity operations, incident response teams
Employer & IndustryOrganizations with compliance and risk needsOrganizations focusing on security monitoring

The Cissp Grc role primarily focuses on governance, risk management, and compliance, working closely with organizational policies. In contrast, a Cissp Security Analyst concentrates on security operations, monitoring, and incident response. While both roles require Cissp certification, their daily tasks and focus areas differ significantly, making each suitable for different career paths within cybersecurity.

What is a CISSP GRC professional?

A CISSP GRC professional is an expert who combines the Certified Information Systems Security Professional (CISSP) certification with knowledge and experience in Governance, Risk, and Compliance (GRC) practices. These professionals help organizations align their security programs with business objectives, manage risks, and ensure compliance with relevant regulations and standards. They are responsible for developing, implementing, and monitoring security policies, procedures, and controls, while also conducting risk assessments and audits. Their work is critical for maintaining an organization's information security posture and meeting regulatory requirements.

What are the key skills and qualifications needed to thrive as a CISSP GRC professional, and why are they important?

To thrive as a CISSP GRC (Governance, Risk, and Compliance) professional, you need deep knowledge of information security principles, risk management frameworks, and regulatory compliance, typically validated by the CISSP certification. Familiarity with tools such as GRC platforms (e.g., RSA Archer, ServiceNow GRC), risk assessment software, and compliance tracking systems is essential. Strong analytical thinking, attention to detail, and effective communication skills help you interpret complex regulations and collaborate with diverse stakeholders. These skills are critical to ensuring organizations meet regulatory requirements, manage risks proactively, and maintain a robust security posture.
More about Cissp Grc jobs
What cities are hiring for Cissp Grc jobs? Cities with the most Cissp Grc job openings:
What states have the most Cissp Grc jobs? States with the most job openings for Cissp Grc jobs include:
Infographic showing various Cissp Grc job openings in the United States as of July 2026, with employment types broken down into 91% Full Time, 4% Part Time, and 5% Contract. Highlights an 78% Physical, 8% Hybrid, and 14% Remote job distribution, with an average salary of $126,833 per year, or $61 per hour.

GRC Manager

Merci Technologies - Talent

Atlanta, GA โ€ข Remote

Full-time

Re-posted 7 days ago


Job description

About the Role

Merci Technologies is seeking an experienced GRC Manager to lead governance, risk, and compliance initiatives for one of our enterprise clients on a remote contract engagement. In this role, you will serve as the primary driver of the organization's GRC program — overseeing policy development, risk assessments, audit readiness, and regulatory compliance across a complex technology environment.

The GRC Manager will work closely with legal, IT security, operations, and executive leadership to ensure the organization maintains a strong and defensible compliance posture while enabling business objectives.

Responsibilities

  • Lead the design, implementation, and ongoing management of the enterprise GRC program including policies, standards, and procedures
  • Conduct and oversee enterprise risk assessments, identify control gaps, and develop risk treatment plans aligned to business priorities
  • Manage audit and assessment activities including SOC 2, ISO 27001, NIST CSF, CMMC, or equivalent frameworks
  • Develop and maintain the organization's risk register, tracking remediation progress and reporting status to senior leadership
  • Collaborate with IT, legal, and business teams to ensure compliance with applicable regulations including GDPR, CCPA, HIPAA, or industry-specific requirements
  • Oversee third-party vendor risk management activities including assessments, due diligence, and ongoing monitoring
  • Develop and deliver security awareness and compliance training programs for internal stakeholders
  • Prepare executive-level reports, dashboards, and presentations on risk posture, compliance status, and program maturity
  • Mentor and guide junior GRC analysts and contribute to team capability development
  • Stay current on emerging regulatory developments and industry best practices and translate them into actionable program updates

Required Qualifications

  • 7–10 years of experience in GRC, information security, or risk management roles with at least 2 years in a leadership or management capacity
  • Deep knowledge of GRC frameworks and standards including NIST CSF, NIST 800-53, ISO 27001, SOC 2, and CIS Controls
  • Hands-on experience managing compliance programs across regulated industries such as healthcare, finance, energy, or government
  • Strong understanding of third-party and vendor risk management practices
  • Experience leading internal and external audit engagements from preparation through closure
  • Excellent written and verbal communication skills with demonstrated ability to present to executive and board-level audiences
  • Strong project management skills with ability to manage multiple concurrent initiatives in a remote environment
  • Must be legally authorized to work in the United States without employer sponsorship

Preferred Qualifications

  • Active certifications such as CISA, CRISC, CISM, CISSP, or ISO 27001 Lead Auditor
  • Experience with GRC platforms such as ServiceNow GRC, Archer, OneTrust, or equivalent
  • Familiarity with CMMC, NERC CIP, or FedRAMP compliance requirements
  • Experience supporting M&A security due diligence or post-merger integration activities
  • Background working in a managed services or consulting environment