1

Cyber Grc Analyst Jobs (NOW HIRING)

$110 - $135/hr

Global Information Security GRC Analyst - Third-Party RiskThe Company CROWN Cork & Seal USA, Inc ... GRC, cyber risk, or third-party risk management. * Experience conducting security assessments and ...

New

$90 - $110/hr

Overview Position: Cybersecurity GRC Analyst I, II, or III (Depending on experience) Salary ... The role includes vendor cybersecurity assessments, continuous cyber monitoring, Security ...

New

Partnering with program owners, cyber/risk stakeholders, legal/compliance teams, and platform ... Mentor engineers and analysts through architecture standards, implementation playbooks, and design ...

Partnering with program owners, cyber/risk stakeholders, legal/compliance teams, and platform ... Mentor engineers and analysts through architecture standards, implementation playbooks, and design ...

Partnering with program owners, cyber/risk stakeholders, legal/compliance teams, and platform ... Mentor engineers and analysts through architecture standards, implementation playbooks, and design ...

Cyber GRC Schedule: Full-Time Shift: Day Job Travel: Yes - 10% of the time Minimum Clearance ... ORA_ON_SITE Description SAIC is seeking a Defensive Cyber Operations Analyst to support the ...

Showing results 41-60

Cyber Grc Analyst information

See salary details

$34K

$112.9K

$176K

How much do cyber grc analyst jobs pay per year?

As of Sep 3, 2026, the average yearly pay for cyber grc analyst in the United States is $112,871.00, according to ZipRecruiter salary data. Most workers in this role earn between $91,500.00 and $130,000.00 per year, depending on experience, location, and employer.

What is a Cyber GRC Analyst?

A Cyber GRC (Governance, Risk, and Compliance) Analyst is a cybersecurity professional who helps organizations manage and reduce information security risks while ensuring adherence to regulatory and industry standards. They are responsible for developing, implementing, and maintaining security policies, conducting risk assessments, monitoring compliance, and preparing reports for management or auditors. Their work ensures the organization’s data and systems are protected, and that the company meets requirements such as GDPR, HIPAA, or ISO 27001.

How does a Cyber GRC Analyst typically collaborate with other departments to manage organizational risk?

As a Cyber GRC Analyst, collaboration with other departments is a key aspect of the role. Analysts often work closely with IT, legal, compliance, and business units to assess risks, implement controls, and ensure adherence to regulations and policies. This involves facilitating risk assessments, coordinating audits, and communicating findings or recommendations in a clear, actionable way. Effective teamwork and communication skills are essential to bridge technical and non-technical stakeholders and foster a culture of security and compliance across the organization.

What are the key skills and qualifications needed to thrive as a Cyber GRC Analyst, and why are they important?

To thrive as a Cyber GRC Analyst, you need a solid understanding of risk management, cybersecurity frameworks (like NIST, ISO 27001), and compliance requirements, often supported by a degree in IT, cybersecurity, or related fields. Familiarity with GRC tools (such as Archer or ServiceNow), security monitoring systems, and certifications like CISSP, CISA, or CRISC is typically expected. Strong analytical thinking, attention to detail, and communication skills help you identify risks and effectively report findings to stakeholders. These competencies ensure organizations can proactively manage cyber risks, maintain regulatory compliance, and protect critical assets.

What is the difference between Cyber Grc Analyst vs Cyber Security Analyst?

AspectCyber Grc AnalystCyber Security Analyst
CertificationsISO 27001, CISSP, CISACISSP, CEH, Security+
Work EnvironmentPolicy, compliance, risk managementThreat detection, incident response
Employer & Industry UsageFinancial, healthcare, governmentTech, finance, retail

Cyber Grc Analysts focus on governance, risk, and compliance, ensuring organizations meet security standards. Cyber Security Analysts primarily handle threat detection and incident response. While both roles require security certifications and work in related environments, their core responsibilities differ, with GRC analysts emphasizing policies and compliance, and security analysts focusing on technical security measures.

Is GRC cybersecurity a good job?

A Cyber GRC (Governance, Risk, and Compliance) analyst plays a key role in managing cybersecurity policies, risk assessments, and compliance standards within organizations. The role offers steady employment, opportunities for certification such as CISA or CISSP, and the chance to work in various industries focused on protecting information assets.

What does a cybersecurity GRC analyst do?

A cybersecurity GRC (Governance, Risk, and Compliance) analyst is responsible for developing and implementing security policies, assessing risks, and ensuring compliance with industry standards and regulations. They often use tools like risk management frameworks and conduct audits to identify vulnerabilities and improve security posture.
More about Cyber Grc Analyst jobs

What cities are hiring for Cyber Grc Analyst jobs?

Cities with the most Cyber Grc Analyst job openings:

What states have the most Cyber Grc Analyst jobs?

States with the most job openings for Cyber Grc Analyst jobs include:

Infographic showing various Cyber Grc Analyst job openings in the United States as of August 2026, with employment types broken down into 89% Full Time, 6% Part Time, and 5% Contract. Highlights an 82% Physical, 7% Hybrid, and 11% Remote job distribution, with an average salary of $112,871 per year, or $54.3 per hour.

GRC Analyst (Attack Surface Mgmt) - Global Industrial

GPC - Genuine Parts Company

Atlanta, GA • On-site

Full-time

Medical, Retirement, PTO

Posted 2 days ago

New


Genuine Parts Company rating

7.3

Company rating: 7.3 out of 10

Based on 63 frontline employees who took The Breakroom Quiz

217th of 428 rated retail wholesalers


Job description

SUMMARY:

Under general supervision the Governance, Risk & Compliance (GRC) Analyst II will support Motion's Governance, Risk & Compliance functions, which may include Privacy, Compliance, Risk Management, Third-Party Risk, Governance, or Attack Surface Management. This role executes day-to-day GRC activities within their assigned domain, and reports to the GRC Lead.

JOB DUTIES

  • Monitors vulnerability scanning results and maintain visibility into Motion's external attack surface.
  • Tracks and prioritizes vulnerabilities for remediation, partnering with IT Operations and Application Development.
  • Owns vulnerability management reporting and metrics and scanning tool administration.
  • Drives remediation service level agreements and escalate cross-team blockers as needed.
  • Develops, maintains, and periodically reviews information security policies and standards.
  • Owns the IT Security Awareness program, including content updates and tracking participation amongst stakeholders.
  • Manages policy exceptions and the exception/acceptance process.
  • Represents Governance in cross-team initiatives and audits.
  • Supports compliance activities across pertinent platforms.
  • Supports Operational Technology (OT) compliance efforts in partnership with the Cyber Defense Engineering & Architecture team.
  • Manages privacy notices, cookie compliance, and consent/preference management across digital properties.
  • Supports privacy program operations, including gap identification and remediation tracking.
  • Assists with Privacy Impact Assessments (PIAs) and Data Privacy Impact Assessments (DPIAs).
  • Manages intake and processing of Data Subject Access Requests (DSARs).
  • Assist with compliance audits and assessments including evidence coordination.
  • Produces privacy and compliance metrics and reporting data for the Lead, and support development of privacy training and awareness content.
  • Maintains and update the cyber risk register and track security issues through the remediation lifecycle, following up with control owners on outstanding items.
  • Supports execution of IT risk assessments and third-party/vendor risk assessments including periodic reviews and quality assurance of risk documentation.
  • Tracks and communicate risk exceptions and remediation action plans to stakeholders.
  • Collaborates with business partners and vendor stakeholders to identify improvement opportunities in risk processes.
  • Maintains awareness of relevant risk frameworks and standards.

EDUCATION & EXPERIENCE

  • Typically requires a bachelor's degree in computer science, software engineering, or a related field and three (3) to five (5) years of related experience or equivalent combination.

KNOWLEDGE, SKILLS, ABILITIES

  • Strong analytical, organizational, and documentation skills.
  • Excellent written and verbal communication skills.
  • Ability to work independently in a lean team environment.
  • Detail-oriented and self-directed.
  • Relevant certification or progress toward certification.
  • Familiarity with GRC tooling/platforms.
  • Experience in a specific framework relevant to the functional area assigned.

PHYSICAL DEMANDS:

LICENSES & CERTIFICATIONS:

SUPERVISORY RESPONSIBILITY: No Supervisory Responsibility

BUDGET RESPONSIBILITY: No

COMPANY INFORMATION:

Motion offers an excellent benefits package which includes options for healthcare coverage, 401(k), tuition reimbursement, vacation, sick, and holiday pay.

DISCLAIMER:

This job description illustrates the general nature and level of work performed by employees within this job classification. It is not intended to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and skills required. Management retains the right to add or modify duties at any time.

Not the right fit? Let us know you're interested in a future opportunity by joining our Talent Community on jobs.genpt.com or create an account to set up email alerts as new job postings become available that meet your interest!

GPC conducts its business without regard to sex, race, creed, color, religion, marital status, national origin, citizenship status, age, pregnancy, sexual orientation, gender identity or expression, genetic information, disability, military status, status as a veteran, or any other protected characteristic. GPC's policy is to recruit, hire, train, promote, assign, transfer and terminate employees based on their own ability, achievement, experience and conduct and other legitimate business reasons.


What Genuine Parts Company employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom