1

Cyber Grc Analyst Jobs (NOW HIRING)

Cyber GRC Specialist

Baltimore, MD · On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

Cyber Risk / Compliance Analyst work, ISO and risk-platform support, evidence coordination, client ... GRC or trust-management platforms such as Vanta, Archer, ServiceNow GRC, OneTrust, Drata, or ...

Cyber GRC Specialist

Washington, DC

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

Cyber Risk / Compliance Analyst work, ISO and risk-platform support, evidence coordination, client ... GRC or trust-management platforms such as Vanta, Archer, ServiceNow GRC, OneTrust, Drata, or ...

Cyber GRC Specialist

Baltimore, MD · On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

Cyber Risk / Compliance Analyst work, ISO and risk-platform support, evidence coordination, client ... GRC or trust-management platforms such as Vanta, Archer, ServiceNow GRC, OneTrust, Drata, or ...

Cyber GRC Specialist

Baltimore, MD · On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

Cyber Risk / Compliance Analyst work, ISO and risk-platform support, evidence coordination, client ... GRC or trust-management platforms such as Vanta, Archer, ServiceNow GRC, OneTrust, Drata, or ...

Analyst-Cyber GRC, Sr.

Lakewood, CO · On-site

$100K - $129K/yr

  • Medical

  • Life

  • Retirement

  • PTO

The Senior Analyst, Cyber GRC supports the continued improvement of Tallgrass Energy's cybersecurity posture by assessing risk, evaluating controls, supporting compliance obligations, and ...

Analyst-Cyber GRC, Sr.

Lakewood, CO · On-site

$99K - $128K/yr

  • Medical

  • Life

  • Retirement

  • PTO

The Senior Analyst, Cyber GRC supports the continued improvement of Tallgrass Energy's cybersecurity posture by assessing risk, evaluating controls, supporting compliance obligations, and ...

Analyst-Cyber GRC, Sr.

Lakewood, CO · On-site

$100K - $129K/yr

  • Medical

  • Life

  • Retirement

  • PTO

The Senior Analyst, Cyber GRC supports the continued improvement of Tallgrass Energy's cybersecurity posture by assessing risk, evaluating controls, supporting compliance obligations, and ...

Experience selling into or supporting GRC, security compliance, cyber risk, or security reporting/analytics use cases and comfortable engaging with both practitioners and executives. * Practical data ...

Senior GRC Analyst

Boston, MA · On-site

$130K - $170K/yr

... Analyst to lead the day-to-day execution and support the ongoing operation of the GRC program in a ... Lead cyber, AI, and technology risk assessments across systems, cloud environments, business ...

GRC Analyst

New York, NY · On-site

$150K - $200K/yr

The Role Rogo is hiring a GRC Analyst to support our customer trust, security assurance, and ... AI Act, UK Cyber Essentials, and GDPR, including evidence collection and audit readiness.

As a Cyber & AI Risk Analyst, you will play a critical role in strengthening Alpaca's security ... Working closely with the Cyber GRC Lead, you will support the identification, assessment, and ...

Overview The IT GRC Analyst operates within the enterprise Cybersecurity Operations function and ... Serve as liaison between internal IT/IS/Cyber teams and Enterprise Risk and Audit to facilitate ...

Senior Director - GRC Engineer

Indianapolis, IN · On-site

$101K - $138K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

... synthesizing GRC Analyst outputs, KRI/KPI performance data, and assessment findings, into a ... This role also serves as the DLO's peer-level liaison to Cyber Engineering and Security ...

Senior Director - GRC Engineer

Indianapolis, IN · On-site

$101K - $138K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

... synthesizing GRC Analyst outputs, KRI/KPI performance data, and assessment findings, into a ... This role also serves as the DLO's peer-level liaison to Cyber Engineering and Security ...

Governance, Risk and Compliance Analyst

Reston, VA · On-site

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

The GRC Analyst will assist in maintaining compliance with the NIST Cybersecurity Framework (NIST CSF), Cybersecurity Maturity Model Certification (CMMC), Cyber Essentials Plus, SOC 2, and ISO/IEC ...

next page

Showing results 1-20

Cyber Grc Analyst information

See salary details

$34K

$112.9K

$176K

How much do cyber grc analyst jobs pay per year?

As of Aug 15, 2026, the average yearly pay for cyber grc analyst in the United States is $112,871.00, according to ZipRecruiter salary data. Most workers in this role earn between $91,500.00 and $130,000.00 per year, depending on experience, location, and employer.

What is a Cyber GRC Analyst?

A Cyber GRC (Governance, Risk, and Compliance) Analyst is a cybersecurity professional who helps organizations manage and reduce information security risks while ensuring adherence to regulatory and industry standards. They are responsible for developing, implementing, and maintaining security policies, conducting risk assessments, monitoring compliance, and preparing reports for management or auditors. Their work ensures the organization’s data and systems are protected, and that the company meets requirements such as GDPR, HIPAA, or ISO 27001.

What are the key skills and qualifications needed to thrive as a Cyber GRC Analyst, and why are they important?

To thrive as a Cyber GRC Analyst, you need a solid understanding of risk management, cybersecurity frameworks (like NIST, ISO 27001), and compliance requirements, often supported by a degree in IT, cybersecurity, or related fields. Familiarity with GRC tools (such as Archer or ServiceNow), security monitoring systems, and certifications like CISSP, CISA, or CRISC is typically expected. Strong analytical thinking, attention to detail, and communication skills help you identify risks and effectively report findings to stakeholders. These competencies ensure organizations can proactively manage cyber risks, maintain regulatory compliance, and protect critical assets.

What is the difference between Cyber Grc Analyst vs Cyber Security Analyst?

AspectCyber Grc AnalystCyber Security Analyst
CertificationsISO 27001, CISSP, CISACISSP, CEH, Security+
Work EnvironmentPolicy, compliance, risk managementThreat detection, incident response
Employer & Industry UsageFinancial, healthcare, governmentTech, finance, retail

Cyber Grc Analysts focus on governance, risk, and compliance, ensuring organizations meet security standards. Cyber Security Analysts primarily handle threat detection and incident response. While both roles require security certifications and work in related environments, their core responsibilities differ, with GRC analysts emphasizing policies and compliance, and security analysts focusing on technical security measures.

How does a Cyber GRC Analyst typically collaborate with other departments to manage organizational risk?

As a Cyber GRC Analyst, collaboration with other departments is a key aspect of the role. Analysts often work closely with IT, legal, compliance, and business units to assess risks, implement controls, and ensure adherence to regulations and policies. This involves facilitating risk assessments, coordinating audits, and communicating findings or recommendations in a clear, actionable way. Effective teamwork and communication skills are essential to bridge technical and non-technical stakeholders and foster a culture of security and compliance across the organization.
More about Cyber Grc Analyst jobs

What cities are hiring for Cyber Grc Analyst jobs?

Cities with the most Cyber Grc Analyst job openings:

What states have the most Cyber Grc Analyst jobs?

States with the most job openings for Cyber Grc Analyst jobs include:

Infographic showing various Cyber Grc Analyst job openings in the United States as of August 2026, with employment types broken down into 1% Internship, 86% Full Time, 6% Part Time, and 7% Contract. Highlights an 81% Physical, 9% Hybrid, and 10% Remote job distribution, with an average salary of $112,871 per year, or $54.3 per hour.

Cyber GRC Specialist

Brown Advisory Incorporated

Baltimore, MD • On-site

Full-time

Medical, Dental, Vision, Life, Retirement

Posted 6 days ago


Job description

Company Overview
Every firm has a culture - the values, beliefs, methodology, attitudes and standards that reflect an organization's DNA. But the truly inspiring firms - the game-changers, the industry leaders and the disruptors - have cultures that propel them to innovate and stand out. At Brown Advisory, we aim to be one of those inspired firms. Over the years, we have purposefully built and nurtured our client-first culture.
Brown Advisory is an independent investment management and strategic advisory firm committed to delivering a combination of first-class performance, strategic advice and the highest level of client service. The firm's clients-including individuals, families, family offices, endowments, foundations, charities, institutions, consultants, and financial intermediaries-are served by over 1,000 colleagues worldwide, all of whom are equity owners of the firm.
Brown Advisory is currently seeking a Cyber GRC Specialist to support and mature the firm's governance, risk, compliance, and control-management routines. This blended role is designed for someone who can translate security requirements into practical business processes, drive evidence and accountability, and communicate clearly with technical and non-technical stakeholders.
As part of a lean Information Security team within a mid-sized financial services organization, this individual will serve as a central coordinator for cyber risk, policy management, control testing, audit readiness, client and regulatory response support, and vulnerability remediation governance. The role is not intended to be a hands-on vulnerability engineering role; rather, it ensures the process, ownership, exceptions, reporting, and governance routines are working.
Blended Role Coverage
Primary emphasis: Cyber GRC support for policies, controls, cyber risk tracking, audit coordination, exceptions, and governance routines.
Blended coverage: Cyber Risk / Compliance Analyst work, ISO and risk-platform support, evidence coordination, client/regulatory response support, communications, and vulnerability governance.
Duties and Responsibilities
  • Support and mature core cyber governance routines, including policy management, control ownership, risk acceptance, exception handling, standards maintenance, and periodic leadership reporting.
  • Maintain the cyber risk register and partner with technology and business owners to document risk decisions, remediation plans, due dates, dependencies, and residual risk.
  • Serve as a key administrator and process contributor for ISO and security-risk management platforms such as Vanta or similar tools.
  • Coordinate evidence collection, control testing, audit requests, client due diligence responses, regulatory requests, and recurring compliance deliverables.
  • Translate ISO 27001, regulatory, client, and internal security expectations into practical controls and operating procedures appropriate for Brown Advisory's size and risk profile.
  • Facilitate cross-functional communications for security change, SaaS inventory, policy enforcement, control adoption, and risk remediation.
  • Coordinate vulnerability management governance, including scan-result intake, prioritization routines, remediation tracking, exception handling, and reporting.
  • Partner with security engineers, infrastructure teams, application owners, Compliance, Legal, Operations, and Client Service to close control gaps in a business-aligned manner.
  • Develop clear metrics for control effectiveness, audit readiness, exceptions, overdue remediation, and recurring governance activities.
  • Identify process improvements that make security governance more repeatable, transparent, and useful without creating unnecessary bureaucracy.

Preferred Qualifications
  • Bachelor's degree in cyber security, information systems, risk management, business, or a relevant field preferred; equivalent professional experience will be considered.
  • 3-6 years of experience in cyber GRC, information security, technology risk, IT audit, compliance, or related control-management work preferred.
  • Working knowledge of ISO 27001, SOC 2, NIST CSF, CIS Controls, SEC/FINRA expectations, privacy requirements, or comparable control frameworks.
  • Experience supporting audits, evidence collection, control testing, policy updates, issue tracking, or risk-register maintenance in a regulated environment; financial services experience preferred.
  • CISA, CRISC, CISM, Security+, ISO 27001 Foundation/Lead Implementer, or similar professional designation preferred but not required.

Technical Skills
  • Cyber risk registers, exception management, control testing, evidence management, policy lifecycle management, and audit coordination.
  • GRC or trust-management platforms such as Vanta, Archer, ServiceNow GRC, OneTrust, Drata, or similar tools.
  • Vulnerability management governance, including prioritization, remediation tracking, aging analysis, exception workflows, and executive reporting.
  • Strong knowledge of cyber security controls across identity, endpoint, cloud, network, data protection, application security, and third-party risk.
  • Excellent writing, facilitation, and stakeholder-management skills, including the ability to turn technical risk into clear business language.
  • Practical judgment about when to enforce, when to escalate, and when to help the business find a workable control path.
  • Demonstrates curiosity and a continuous improvement mindset by identifying opportunities to enhance processes, improve efficiency, and thoughtfully leverage new technologies and tools, including AI-enabled productivity solutions

Personal Attributes
  • Take ownership and move initiatives forward without constant oversight.
  • Balance technical depth, process discipline, and sound business judgment.
  • Approach risk management pragmatically rather than theoretically.
  • Thrive in collaborative, high-accountability environments.
  • Communicate clearly with technical and non-technical colleagues.
  • Bring an entrepreneurial mindset to building and improving security capabilities.

Applicants must be authorized to work in the United States without the need for current or future employer-sponsored work authorization (e.g., H-1B , O-1, F-1 (OPT), TN, or any other non-immigrant visa classifications that require employer support or sponsorship).
MD Salary: $95-$115k. Commensurate with experience and location. Does not include bonus or long term incentive eligibility (if applicable).
DC Salary: $104.5K-$126.5K. Commensurate with experience and location. Does not include bonus or long-term incentive eligibility (if applicable).
Benefits
At Brown Advisory we offer a competitive compensation package, including full benefits.
• Medical
• Dental
• Vision
• Wellness program participation incentive
• Financial wellness program
• Fitness event fee reimbursement
• Gym membership discounts
• Colleague Assistance Program
• Telemedicine Program (for those enrolled in Medical)
• Adoption Benefits
• Daycare late pick-up fee reimbursement
• Basic Life & Accidental Death & Dismemberment Insurance
• Voluntary Life & Accidental Death & Dismemberment Insurance
• Short Term Disability
• Paid parental leave
• Group Long Term Disability
• Pet Insurance
• 401(k) (50% employer match up to IRS limit, 4 year vesting)
Brown Advisory is an Equal Employment Opportunity Employer.