1

Cyber Grc Jobs (NOW HIRING)

Cyber GRC Risk Analyst At BNY, our culture allows us to run our company better and enables employees' growth and success. As a leading global financial services company at the heart of the global ...

next page

Showing results 1-20

Cyber Grc information

See salary details

$38.5K

$58.2K

$87K

How much do cyber grc jobs pay per year?

As of May 28, 2026, the average yearly pay for cyber grc in the United States is $58,171.00, according to ZipRecruiter salary data. Most workers in this role earn between $48,000.00 and $64,500.00 per year, depending on experience, location, and employer.

What are the key skills and qualifications needed to thrive as a Cyber GRC (Governance, Risk, and Compliance) professional, and why are they important?

To thrive as a Cyber GRC professional, you need expertise in risk assessment, compliance frameworks (such as ISO 27001, NIST, or GDPR), and a solid understanding of cybersecurity principles, often backed by a degree in information security or related fields. Familiarity with GRC tools like Archer, ServiceNow GRC, or MetricStream, as well as certifications such as CISA, CISSP, or CRISC, is typically required. Strong analytical thinking, attention to detail, and effective communication are crucial soft skills for managing policies and engaging stakeholders. These skills ensure organizations can identify, manage, and mitigate cyber risks while maintaining regulatory compliance and protecting sensitive information.

What are some common challenges faced by professionals in Cyber GRC roles and how can they be addressed?

Professionals in Cyber GRC (Governance, Risk, and Compliance) roles often encounter challenges such as keeping up with constantly evolving regulations, ensuring company-wide compliance, and effectively communicating risk to stakeholders. To address these challenges, it's important to stay updated on industry standards, leverage automated GRC tools to streamline processes, and develop strong communication skills to translate technical risks into business terms. Collaboration with IT, legal, and business teams is also essential for creating a robust compliance culture.

What is Cyber GRC?

Cyber GRC stands for Cyber Governance, Risk, and Compliance. It refers to the integrated collection of capabilities that enable an organization to reliably achieve objectives, address uncertainty, and act with integrity when managing cybersecurity risks. Professionals in Cyber GRC help organizations develop policies, assess risks, comply with regulations, and ensure ongoing security governance. Their work is essential for building strong cybersecurity frameworks and maintaining compliance with laws such as GDPR, HIPAA, or PCI DSS.

What is the difference between Cyber Grc vs Cyber Security Analyst?

AspectCyber GrcCyber Security Analyst
CertificationsISO 27001 Lead Implementer, CISSP, CISACompTIA Security+, CISSP, CEH
Work EnvironmentPolicy development, risk management, compliance teamsSecurity monitoring, incident response, vulnerability assessment
Employer & Industry UsageFinancial, healthcare, government sectors focusing on governanceIT security teams across various industries

Cyber Grc professionals focus on establishing policies, managing risks, and ensuring compliance within organizations. In contrast, Cyber Security Analysts primarily monitor security systems, respond to incidents, and identify vulnerabilities. While both roles require certifications like CISSP, their daily tasks and focus areas differ significantly, with Grc emphasizing governance and analysts focusing on technical security operations.

More about Cyber Grc jobs
What cities are hiring for Cyber Grc jobs? Cities with the most Cyber Grc job openings:
What states have the most Cyber Grc jobs? States with the most job openings for Cyber Grc jobs include:
Infographic showing various Cyber Grc job openings in the United States as of May 2026, with employment types broken down into 98% Full Time, and 2% Contract. Highlights an 34% Physical, 24% Hybrid, and 42% Remote job distribution, with an average salary of $58,171 per year, or $28 per hour.

Vice President, Information Security

BNY

Pittsburgh, PA โ€ข On-site

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 11 days ago


Job description

Cyber GRC Risk Analyst

At BNY, our culture allows us to run our company better and enables employees' growth and success.ย As a leading global financial services company at the heart of the global financial system, we influence nearly 20% of the world's investible assets. Every day, our teams harness cutting-edge AI and breakthrough technologies to collaborate with clients, driving transformative solutions that redefine industries and uplift communities worldwide.

Recognized as a top destination for innovators, BNY is where bold ideas meet advanced technology and exceptional talent. Together, we power the future of finance - and this is what #LifeAtBNY is all about. Join us and be part of something extraordinary.

We're seeking a future team member for the role of Cyber GRC Risk Analyst to join our Cyber Security team. This role is located in Pittsburgh, PA.

Position Summary

The Cyber GRC Risk Analyst role is responsible for overseeing the identification, analysis, escalation, tracking, and remediation of cybersecurity and technology control risks. This position supports governance, risk, and compliance activities by ensuring control deficiencies, risk findings, and remediation actions are managed effectively, reported accurately, and resolved in a timely manner.

The role partners closely with the Cyber Security teams, Enterprise Issue Management, Engineering, Audit, Risk, Compliance, and business stakeholders to drive issue resolution, improve cyber hygiene, strengthen control effectiveness, and support audit and regulatory readiness. This position requires a strong blend of data analysis, risk management, governance discipline, and stakeholder coordination.

In this role, you'll make an impact in the following ways:

Manage the end-to-end lifecycle of cyber and technology control issues, including intake, assessment, prioritization, escalation, tracking, remediation, validation, and closure.

Review and analyze complex data sets to identify trends, insights, emerging risks, and actionable recommendations related to control deficiencies and remediation progress.

Support governance processes related to cyber risk, control management, audit findings, and regulatory commitments while helping ensure remediation activities align with internal standards and regulatory expectations.

Produce and interpret metrics, dashboards, trend analyses, and management reporting related to issue inventory, remediation status, control health, and cyber hygiene.

Partner closely with Information Security, Technology, Risk, Audit, Compliance, and business teams to strengthen control effectiveness, improve remediation practices, and support audit and regulatory readiness.

Support application teams in improving cyber hygiene by enhancing control management practices, identifying remediation opportunities, and driving timely resolution of control gaps to reduce operational and security risk.

To be successful in this role, we're seeking the following:

Bachelor's degree in Computer Science, Cybersecurity, Information Systems, Risk Management, or a related discipline, or equivalent work experience.

  • Typically 5-10 years of experience ย Experience in Governance, Risk, and Compliance, Information Security, Technology Risk, Cybersecurity, or a related field, including issue management, control remediation, audit support, risk analysis, or compliance oversight.

Strong analytical, problem-solving, and troubleshooting skills, with experience using business intelligence, data analysis, and reporting platforms such as SQL, DB2, Power BI, Business Objects, Qlik, Tableau, Excel, and PowerPoint.

Knowledge of cybersecurity controls, risk management principles, issue remediation practices, and an understanding of the System Development Life Cycle and technology risk implications across development and production environments.

Excellent written and verbal communication skills, strong time management, sound judgment, and the ability to work effectively both independently and collaboratively with technical and non-technical stakeholders.

Preferred qualifications include:

Degree in Cybersecurity, Information Systems, Business, or a related discipline.

Experience in the securities, banking, or financial services industry.

Experience supporting audit, regulatory examinations, or formal remediation programs.

Familiarity with industry control and risk frameworks such as NIST Cybersecurity Framework, NIST 800-53, Cyber Risk Institute Cyber Profile, ISO 27001, COBIT, FFIEC guidance, and PCI DSS, where applicable.

Experience with GRC platforms, issue tracking systems, control management tools, and integrated reporting workflows that aggregate vulnerability, control, audit, and self-identified findings.


At BNY, our culture speaks for itself, check out the latest BNY news at:

BNY Newsroom

BNY LinkedInย 

ย Here's a few of our recent awards:ย 

  • America's Most Innovative Companies, Fortune, 2025
  • World's Most Admired Companies, Fortune 2025
  • "Most Just Companies", Just Capital and CNBC, 2025


Our Benefits and Rewards:

BNY offers highly competitive compensation, benefits, and wellbeing programs rooted in a strong culture of excellence and our pay-for-performance philosophy. We provide access to flexible global resources and tools for your life's journey. Focus on your health, foster your personal resilience, and reach your financial goals as a valued member of our team, along with generous paid leaves, including paid volunteer time, that can support you and your family through moments that matter.ย 

BNY is an Equal Employment Opportunity/Affirmative Action Employer - Underrepresented racial and ethnic groups/Females/Individuals with Disabilities/Protected Veterans.

At BNY, our culture speaks for itself, check out the latest BNY news atย BNY Newsroomย &ย BNY LinkedIn

ย Here's a few of our recent awards:

  • America's Most Innovative Companies, Fortune, 2025
  • World's Most Admired Companies, Fortune 2025
  • "Most Just Companies", Just Capital and CNBC, 2025

    Our Benefits and Rewards:

    BNY offers highly competitive compensation, benefits, and wellbeing programs rooted in a strong culture of excellence and our pay-for-performance philosophy. We provide access to flexible global resources and tools for your life's journey. Focus on your health, foster your personal resilience, and reach your financial goals as a valued member of our team, along with generous paid leaves, including paid volunteer time, that can support you and your family through moments that matter.

    BNY is an Equal Employment Opportunity/Affirmative Action Employer - Underrepresented racial and ethnic groups/Females/Individuals with Disabilities/Protected Veterans.

    BNY assesses market data to ensure a competitive compensation package for our employees. The expected base salary for this position when employment commences can be found in the Job Info section at the bottom of the posting.ย 

    Base salary offered may vary depending on multiple individualized factors, including market location, job-related knowledge, skills, and experience. Base salary is only part of the total rewards package, which may include eligibility for an annual discretionary incentive award. Subject to the terms and conditions of the applicable plans then in effect, eligible employees may enroll in a 401(k) plan as well as participate in Company-sponsored medical, dental, vision, and basic life insurance plans for the employee and the employee's eligible dependents. Eligible employees also may receive other benefits (including various paid time off benefits, such as vacation and sick time), dependent on the position offered. Details of participation in these benefit plans will be provided if an employee receives an offer of employment.

    If hired, the employee will be in an "at will" position and the Company reserves the right to modify base salary (as well as any other discretionary payments or compensation programs) at any time, including for reasons related to individual performance, Company or individual department/team performance, and market factors.