1

Cyber Security Grc Jobs (NOW HIRING)

Senior Cybersecurity GRC

Manhattan, NY ยท On-site

$110K - $142K/yr

Senior Cybersecurity GRC & Third Party Risk Consultant Location: New York, NY (Onsite/Hybrid) Duration: Long-Term Contract(W2) We are seeking an experienced Senior Cybersecurity GRC & Third Party ...

We are seeking an experienced Cybersecurity GRC Analyst for a 6-month engagement to support our ongoing security compliance and governance initiatives. The ideal candidate will have strong hands-on ...

We are seeking an experienced Cybersecurity GRC Analyst for a 6-month engagement to support our ongoing security compliance and governance initiatives. The ideal candidate will have strong hands-on ...

We are seeking an experienced Cybersecurity GRC Analyst for a 6-month engagement to support our ongoing security compliance and governance initiatives. The ideal candidate will have strong hands-on ...

OR ยท Hybrid

JOB SUMMARY The Cybersecurity GRC Analyst II plays a key role in supporting the organization's governance, risk, compliance, and audit programs while contributing to day-to-day cybersecurity ...

OR ยท Hybrid

JOB SUMMARY The Cybersecurity GRC Analyst II plays a key role in supporting the organization's governance, risk, compliance, and audit programs while contributing to day-to-day cybersecurity ...

The Cybersecurity GRC Analyst works closely with IT, Internal Audit, Compliance, Procurement, and business stakeholders to help ensure cybersecurity requirements are defined, documented, assessed ...

next page

Showing results 1-20

Cyber Security Grc information

See salary details

$40.5K

$122.9K

$180K

How much do cyber security grc jobs pay per year?

As of Jul 27, 2026, the average yearly pay for cyber security grc in the United States is $122,890.00, according to ZipRecruiter salary data. Most workers in this role earn between $102,000.00 and $142,000.00 per year, depending on experience, location, and employer.

What are some common challenges faced by Cyber Security GRC professionals, and how do they typically overcome them?

Cyber Security GRC professionals often face the challenge of keeping up with evolving regulations, adapting controls for new technologies, and coordinating between security teams and business units. To overcome these challenges, professionals stay current with industry standards, participate in ongoing training, and actively communicate policy changes and risk assessments to stakeholders across the organization. They also leverage robust GRC tools to streamline compliance processes and documentation. Working collaboratively with IT, legal, and compliance teams allows them to better identify risks and implement effective, practical security controls. This approach ensures a well-integrated and proactive risk management posture for the organization.

Is GRC in high demand?

Cyber Security GRC (Governance, Risk, and Compliance) professionals are in high demand due to increasing cybersecurity regulations and the need for organizations to manage risk effectively. Employers seek candidates with knowledge of compliance frameworks, risk management tools, and relevant certifications like CISA or CISSP, making GRC roles a growing area within cybersecurity careers.

What is a Cyber Security GRC job?

A Cyber Security GRC (Governance, Risk, and Compliance) job focuses on ensuring an organization's security policies, risk management strategies, and regulatory compliance. Professionals in this role develop and enforce security policies, assess risks, and ensure adherence to industry regulations like GDPR, HIPAA, or ISO 27001. They collaborate with different teams to mitigate cybersecurity threats while aligning security practices with business goals. This role is critical for maintaining an organization's security posture and reducing potential risks.

What are the key skills and qualifications needed to thrive in the Cyber Security Grc position, and why are they important?

To thrive as a Cyber Security GRC professional, a solid understanding of information security frameworks, risk management, and regulatory compliance is essential, often supported by a degree in information security or a related field. Familiarity with GRC platforms (such as Archer, ServiceNow, or LogicGate), and certifications like CISSP, CISM, or CRISC, are highly valued. Excellent analytical skills, attention to detail, and the ability to communicate complex risks to non-technical stakeholders are critical soft skills. These capabilities ensure organizations remain secure, compliant, and able to effectively manage evolving cyber risks.

What is GRC in cyber security?

GRC in cybersecurity stands for Governance, Risk Management, and Compliance. It involves establishing policies, assessing risks, and ensuring adherence to regulations to protect organizational information assets. Cybersecurity professionals working in GRC often use frameworks like ISO 27001 or NIST to guide their efforts.

Is GRC cybersecurity a good job?

Cyber Security GRC (Governance, Risk, and Compliance) roles are in demand due to increasing cybersecurity regulations and organizational needs for risk management. These positions often require knowledge of compliance frameworks, risk assessment, and security policies, and can offer stable employment with opportunities for advancement. The job can be rewarding for those interested in policy, audit, and security governance aspects of cybersecurity.

Can you make $200,000 in cyber security?

Cyber Security GRC professionals can earn $200,000 or more annually, especially with extensive experience, advanced certifications like CISSP or CISA, and leadership roles such as GRC manager or director. Salaries vary based on industry, location, and company size, with senior positions often reaching or exceeding this level. Developing expertise in risk management, compliance, and security frameworks can help achieve higher compensation in this field.
What cities are hiring for Cyber Security Grc jobs? Cities with the most Cyber Security Grc job openings:
What are the most commonly searched types of Cyber Security Grc jobs? The most popular types of Cyber Security Grc jobs are:
What states have the most Cyber Security Grc jobs? States with the most job openings for Cyber Security Grc jobs include:
What job categories do people searching Cyber Security Grc jobs look for? The top searched job categories for Cyber Security Grc jobs are:
Infographic showing various Cyber Security Grc job openings in the United States as of July 2026, with employment types broken down into 94% Full Time, 3% Part Time, and 3% Contract. Highlights an 89% Physical, 4% Hybrid, and 7% Remote job distribution, with an average salary of $122,890 per year, or $59.1 per hour.

Senior Cybersecurity GRC

BIGDATAAPPTECH LLC

Manhattan, NY โ€ข On-site

$110K - $142K/yr

Other

Posted 13 days ago


Job description

Job Title: Senior Cybersecurity GRC & Third Party Risk Consultant
Location: New York, NY (Onsite/Hybrid)
Duration: Long-Term Contract(W2)

Job Description
We are seeking an experienced Senior Cybersecurity GRC & Third Party Risk Consultant to support the implementation and enhancement of Third Party and Fourth Party Risk Management programs. The ideal candidate will have strong expertise in vendor risk management, information security governance, regulatory compliance, and Archer GRC solutions within the banking or financial services industry.

Key Responsibilities
Gather and define business requirements for Third Party and Fourth Party Risk Management initiatives.
Lead the implementation and alignment of SIG 2027 questionnaires, risk domains, and assessment frameworks.
Design and maintain risk taxonomy, risk assessment methodologies, and risk scoring models.
Configure and support RSA Archer TPRM workflows and related GRC processes.
Collaborate with business and technical teams to implement vendor risk workflows, questionnaires, and data models.
Support vendor onboarding, security due diligence, risk assessments, continuous monitoring, and remediation activities.
Ensure compliance with regulatory, governance, audit, and information security requirements.
Participate in User Acceptance Testing (UAT), data validation, issue resolution, and governance approvals.
Develop executive dashboards, KPIs, and risk analytics for vendor risk reporting.
Recommend improvements to Third Party Risk Management processes and governance practices.
Required Skills
10+ years of experience in Third Party Risk Management (TPRM), Vendor Risk Management (VRM), Information Security Risk, or Governance, Risk & Compliance (GRC).
Strong expertise in Third Party and Fourth Party Risk Management frameworks and operating models.
Deep understanding of SIG (Standardized Information Gathering) questionnaires, including SIG 2027.
Experience defining risk taxonomy, risk assessment methodologies, and risk scoring models.
Hands-on experience with RSA Archer TPRM or similar GRC platforms.
Strong knowledge of the vendor lifecycle, including onboarding, due diligence, continuous monitoring, and offboarding.
Experience working with cybersecurity governance, regulatory compliance, and audit frameworks.
Excellent communication, stakeholder management, and documentation skills.