1

Cyber Grc Analyst Jobs (NOW HIRING)

Showing results 41-60

Cyber Grc Analyst information

See salary details

$34K

$112.9K

$176K

How much do cyber grc analyst jobs pay per year?

As of Aug 16, 2026, the average yearly pay for cyber grc analyst in the United States is $112,871.00, according to ZipRecruiter salary data. Most workers in this role earn between $91,500.00 and $130,000.00 per year, depending on experience, location, and employer.

What is a Cyber GRC Analyst?

A Cyber GRC (Governance, Risk, and Compliance) Analyst is a cybersecurity professional who helps organizations manage and reduce information security risks while ensuring adherence to regulatory and industry standards. They are responsible for developing, implementing, and maintaining security policies, conducting risk assessments, monitoring compliance, and preparing reports for management or auditors. Their work ensures the organization’s data and systems are protected, and that the company meets requirements such as GDPR, HIPAA, or ISO 27001.

What are the key skills and qualifications needed to thrive as a Cyber GRC Analyst, and why are they important?

To thrive as a Cyber GRC Analyst, you need a solid understanding of risk management, cybersecurity frameworks (like NIST, ISO 27001), and compliance requirements, often supported by a degree in IT, cybersecurity, or related fields. Familiarity with GRC tools (such as Archer or ServiceNow), security monitoring systems, and certifications like CISSP, CISA, or CRISC is typically expected. Strong analytical thinking, attention to detail, and communication skills help you identify risks and effectively report findings to stakeholders. These competencies ensure organizations can proactively manage cyber risks, maintain regulatory compliance, and protect critical assets.

What is the difference between Cyber Grc Analyst vs Cyber Security Analyst?

AspectCyber Grc AnalystCyber Security Analyst
CertificationsISO 27001, CISSP, CISACISSP, CEH, Security+
Work EnvironmentPolicy, compliance, risk managementThreat detection, incident response
Employer & Industry UsageFinancial, healthcare, governmentTech, finance, retail

Cyber Grc Analysts focus on governance, risk, and compliance, ensuring organizations meet security standards. Cyber Security Analysts primarily handle threat detection and incident response. While both roles require security certifications and work in related environments, their core responsibilities differ, with GRC analysts emphasizing policies and compliance, and security analysts focusing on technical security measures.

How does a Cyber GRC Analyst typically collaborate with other departments to manage organizational risk?

As a Cyber GRC Analyst, collaboration with other departments is a key aspect of the role. Analysts often work closely with IT, legal, compliance, and business units to assess risks, implement controls, and ensure adherence to regulations and policies. This involves facilitating risk assessments, coordinating audits, and communicating findings or recommendations in a clear, actionable way. Effective teamwork and communication skills are essential to bridge technical and non-technical stakeholders and foster a culture of security and compliance across the organization.
More about Cyber Grc Analyst jobs

What cities are hiring for Cyber Grc Analyst jobs?

Cities with the most Cyber Grc Analyst job openings:

What states have the most Cyber Grc Analyst jobs?

States with the most job openings for Cyber Grc Analyst jobs include:

Infographic showing various Cyber Grc Analyst job openings in the United States as of August 2026, with employment types broken down into 1% Internship, 86% Full Time, 6% Part Time, and 7% Contract. Highlights an 81% Physical, 9% Hybrid, and 10% Remote job distribution, with an average salary of $112,871 per year, or $54.3 per hour.

Job Opportunity as GRC ANALYST in Phoenix, AZ

vTech Solution

Phoenix, AZ • On-site

Contractor

Re-posted 20 days ago


Job description

Position Details

Position:               GRC ANALYST 
Location :              Phoenix, Arizona. 85007
Duration:             04 Months 
Interview:            In person interview
Work Mode:        Hybrid
Position Description:

Seeking an experienced and highly motivated individual to join our team as a Information Security Analyst, (ISA) contractor. This position will work on the Governance Risk and Compliance (GRC) Team to communicate and engage with business units to develop a strong understanding of their reporting, data, and product needs. The team member will work with other personnel across departments to define requirements for projects, identify data dependencies and relationships to develop logical and physical data models, data flows and system activity diagrams, and write specifications for managing enterprise information policies. The team member will help develop plans and materials to support user adoption, training, and customer service, working through direct and regular contact with users from other divisions, programs, and service units to provide regular insight and guidance in prioritizing enhancements for the data systems. The team member will also support technical project managers to ensure that all aspects of the information analysis and requirements gathering process are completed with the highest degree of accuracy and quality, which includes developing and socializing key project artifacts.

Job Duties:

  • Perform risk assessments, audit reviews, generate findings reports, and make appropriate recommendations for improvement and track outcomes from those activities for DES reporting requirements. Develop and formulate comprehensive reports detailing the findings, areas of non-compliance, required POA&Ms (Plan of Action and Milestones), environmental observations, and incident reports.
  • Review, update, and manage security related audit plans, security plans and risk plan documentation for accuracy and consistency, proactively solves problems.
  • Evaluate data and formulate comprehensive reports detailing the findings, areas of non-compliance, required action plans, and environmental observations. Generates incident reports and investigates suspicious network activity.
  • Preparing audit documentation that supports audit results, drafting and editing audit findings to adhere to the standards and the agency's writing style.
  • Research agency and industry IT security practices standards, best practices, laws and regulations, and other applicable resources, ensures compliance with standards

 Knowledge, Skills & Abilities (Not incompassing):

  • Knowledge of security principles, policies, and procedures, and be able to develop effective security policies.
  • Knowledge of Information Security Risk Management.
  • Knowledge of laws, regulations, policies, principles, and ethics as they relate to cybersecurity and privacy. (Required: NIST 800-53 R5, IRS Pub1075, IPAA/HITRUST, CJIS and MARS-E)
  • Expert knowledge of internal auditing, internal controls, and risk management practices and methods.
  • Knowledge of Selection/Approval, Implementation, and Assessment/Audit of Security and Privacy Controls.
  • Knowledge of Risk Management Framework (RMF) requirements.
  • Knowledge of Authorization/Approval of Information Systems.
  • Knowledge in conducting audits or reviews of technical systems.
  • Knowledge in comprehensive understanding of internal control environments within the IT function.
  • Knowledge in multiple technology domains including aspects of Windows, Unix and/or database administration, software development and networking.
  • Knowledge in identifying cybersecurity and privacy issues that stem from connections with internal and external customers and partner organizations.
  • Ability to produce high quality work products for both the IT groups and Senior Management.
  • Ability to perform excellent interpersonal, written and oral communication skills.
  • Ability to assess, manage, and improve security policies and procedures.
  • Ability to work collaboratively in teams and across organizations.
  • Ability to synthesize feedback and adjust plans accordingly, build strong relationships inside and outside the organization and manage large teams.
  • Ability to ensure security practices are followed throughout all phases of the life cycle of every aspect of business and IT processes.
  • Ability to develop policy, plans, and strategy in compliance with laws, regulations, 
  • policies, and standards in support of organizational cyber activities.
  • Ability to exercise judgment when policies are not well-defined.
  • Ability to ensure information security management processes are integrated with strategic and operational planning processes.
  • Ability to ensure that senior officials within the organization provide information security for the information and systems that support the operations and assets under their control.
  • Ability to understand technology, management, and leadership issues related to organization processes and problem solving.
  • Ability to understand the basic concepts and issues related to cyber and its organizational impact.
  • Develop plans and materials to support user adoption, training, and customer service.
  • Ability to work collaboratively in teams and across organizations.
  • Develop plans and materials to support user adoption, training, and customer service.
  • Work directly with users from other divisions, programs, and service units to provide insight and guidance.
  • Identify risks and suggest improvements to information systems and processes.
  • Support technical project managers to fulfill information analysis requirements with the highest degree of accuracy and quality.
  • Develop and maintain key project artifacts.

Skills Required:

  • NIST 800-53R5
  • RMF
  • Windows/ Unix Experience

Skills Preferred:

  • Project Management experience 
  • CISSP, CCSP, GSTRT, GSNA, or CAP Certification
 

vTech Solution Inc. is a Managed IT Services firm headquartered in Washington, DC. They specialize in a range of services including cloud computingmanaged network security, and cybersecurity. Their primary focus is on providing human-centered IT solutions for government and business sectors, including federal, state, local, and education (SLED) groups, as well as commercial organizations.

vTech Solution offers services such as:

  • Managed Security Services: Implementing zero-trust security frameworks to prevent cyber threats in real-time.
  • Multi-cloud Management Services: Helping businesses digitally transform with smart cloud technologies.
  • Infrastructure Managed Services: Creating resilient and secure infrastructure management.
  • Professional Services: Providing expertise for mission-critical programs.
  • Productivity and Communications: Ensuring secure and confident business connectivity from anywhere

vTech Solution logo

About vTech Solution

Sourced by ZipRecruiter

vTech is a Managed IT Services firm based out of Washington DC with a primary focus on Cloud Computing and Managed Network Security.

Industry

It services

Company size

51 - 200 Employees

Headquarters location

Washington, DC, US

Year founded

2006

Social media