1

Cyber Security Grc Analyst Jobs (NOW HIRING)

Cybersecurity GRC Analyst (Remote) Location: 100% Remote Rate: $51/hour (No PTO) Overview We are seeking a Cybersecurity GRC Analyst to support enterprise-wide cybersecurity risk management ...

We are seeking an experienced Cybersecurity GRC Analyst for a 6-month engagement to support our ongoing security compliance and governance initiatives. The ideal candidate will have strong hands-on ...

The Cybersecurity GRC Analyst works closely with IT, Internal Audit, Compliance, Procurement, and business stakeholders to help ensure cybersecurity requirements are defined, documented, assessed ...

Senior Analyst, Cybersecurity GRC

Washington, DC ยท On-site

$113K - $146K/yr

Senior Analyst, Cybersecurity GRC, Washington, DC The Senior Analyst, Cybersecurity GRC will administer the completion of compliance-related client requests to assess security policies and procedures.

Senior Analyst, Cybersecurity GRC

Washington, DC ยท On-site

$113K - $146K/yr

Senior Analyst, Cybersecurity GRC, Washington, DC The Senior Analyst, Cybersecurity GRC will administer the completion of compliance-related client requests to assess security policies and procedures.

$90K/yr

Cybersecurity GRC Analyst I, II, or III (Depending on experience) Salary: Starting at $90,000/year+ D.O.E *Actual compensation may vary from posting based on geographic location, work experience ...

next page

Showing results 1-20

Cyber Security Grc Analyst information

See salary details

$43K

$99.4K

$150K

How much do cyber security grc analyst jobs pay per year?

As of Sep 13, 2026, the average yearly pay for cyber security grc analyst in the United States is $99,400.00, according to ZipRecruiter salary data. Most workers in this role earn between $79,500.00 and $115,500.00 per year, depending on experience, location, and employer.

What is a Cyber Security GRC analyst?

Cyber Security GRC (Governance, Risk, and Compliance) Analysts are professionals who help organizations protect their digital assets by ensuring security policies, procedures, and controls comply with legal and regulatory requirements. They assess risks, develop security frameworks, conduct audits, and recommend improvements to minimize vulnerabilities. Their work ensures that organizations not only stay compliant but also proactively manage and mitigate security threats.

What skills and qualifications are needed to thrive as a Cyber Security GRC analyst?

To thrive as a Cyber Security GRC Analyst, you need a solid understanding of information security principles, risk management, compliance frameworks (such as NIST, ISO 27001), and typically a degree in cybersecurity or a related field. Familiarity with GRC platforms (like RSA Archer), risk assessment tools, and certifications such as CISSP, CISA, or CRISC are highly valued. Strong analytical thinking, attention to detail, and effective communication skills are essential for translating technical risks into business terms and collaborating across departments. These skills ensure robust security governance, effective risk mitigation, and regulatory compliance within an organization.

How does a Cyber Security GRC analyst typically collaborate with other departments to ensure compliance and mitigate risks?

A Cyber Security GRC Analyst works closely with various departments such as IT, legal, and business units to identify risks, implement controls, and ensure compliance with regulations and policies. They often facilitate risk assessments, coordinate audits, and communicate findings, helping teams understand security requirements and best practices. Collaboration is key, as GRC Analysts must translate complex security concepts into actionable steps for non-technical stakeholders, ensuring organization-wide alignment and effective risk management.

What is the difference between Cyber Security Grc Analyst vs Cyber Security Risk Analyst?

AspectCyber Security Grc AnalystCyber Security Risk Analyst
CertificationsISO 27001, CISSP, CISACISSP, CISA, CRISC
Work EnvironmentPolicy development, compliance, auditsRisk assessment, vulnerability analysis
Employer & Industry UsageFinancial, healthcare, governmentTech, finance, consulting

The Cyber Security Grc Analyst focuses on governance, risk management, and compliance frameworks, ensuring organizations adhere to security policies. In contrast, the Cyber Security Risk Analyst primarily assesses and analyzes security risks to inform mitigation strategies. Both roles require similar certifications and often work within the same industries, but their core responsibilities differ in scope and focus.

Are cyber security GRC analysts in demand?

Cyber security GRC (Governance, Risk, and Compliance) analysts are in high demand due to increasing cybersecurity threats and regulatory requirements. Organizations seek professionals with skills in risk management, compliance frameworks, and security policies, often requiring certifications like CISSP or CISA. The role offers strong job growth prospects across various industries, including finance, healthcare, and technology.

What cities are hiring for Cyber Security Grc Analyst jobs?

Cities with the most Cyber Security Grc Analyst job openings:

What states have the most Cyber Security Grc Analyst jobs?

States with the most job openings for Cyber Security Grc Analyst jobs include:

What are popular job titles related to Cyber Security Grc Analyst jobs?

For Cyber Security Grc Analyst jobs, the most frequently searched job titles are:

Infographic showing various Cyber Security Grc Analyst job openings in the United States as of August 2026, with employment types broken down into 88% Full Time, 10% Part Time, and 2% Contract. Highlights an 93% Physical, 2% Hybrid, and 5% Remote job distribution, with an average salary of $99,400 per year, or $47.8 per hour.

Cybersecurity GRC Analyst

Owings Mills, MD โ€ข Remote

System One
Business Consulting Servicesย โ€ขย 5 - 10K employees

$51/hr

Contractor

PTO

Re-posted 3 days ago


Job description

Cybersecurity GRC Analyst (Remote)

Location: 100% Remote Rate: $51/hour (No PTO)

Overview

We are seeking a Cybersecurity GRC Analyst to support enterprise-wide cybersecurity risk management, governance, and compliance initiatives. This role is responsible for conducting risk assessments, enhancing security practices, evaluating controls, and helping protect organizational data from unauthorized access, disclosure, or misuse.

The ideal candidate will have experience in cybersecurity governance, risk management, compliance, IT audit, and security controls, along with exposure to ServiceNow and database environments.

Key Responsibilities

  • Conduct cybersecurity risk assessments and control evaluations.
  • Develop and enhance organization-wide security policies, standards, and best practices.
  • Research emerging threats, vulnerabilities, and security trends, providing recommendations to leadership.
  • Support governance, risk, and compliance (GRC) initiatives and regulatory requirements.
  • Assess, plan, and implement layered security measures to strengthen the organization's security posture.
  • Partner with IT, Audit, Compliance, and business teams to address security risks and improve controls.
  • Maintain security-related documentation, reporting, and compliance evidence.
  • Utilize ServiceNow and other tools to support risk and compliance processes.

Required Qualifications

  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
    • Additional relevant experience may be considered in lieu of a degree.
  • 3+ years of experience in cybersecurity, with a focus on:
    • Cybersecurity GRC
    • IT Risk Management
    • Information Security Compliance
    • Security Governance
    • IT Audit and Controls
  • Experience with ServiceNow, databases, risk assessments, and Microsoft Office applications.
  • Strong understanding of cybersecurity frameworks, risk management methodologies, and industry best practices.
  • Excellent communication skills with the ability to work effectively with technical and non-technical stakeholders.
  • Ability to manage multiple priorities in a fast-paced environment.

Preferred Certifications

  • CISSP (Certified Information Systems Security Professional)
  • CEH (Certified Ethical Hacker)
  • CTIA (Certified Threat Intelligence Analyst)
  • CAP (Certification and Accreditation Professional)
  • EnCase Certified Examiner

Ideal Backgrounds

  • Cybersecurity GRC Analyst
  • Information Security Analyst (Governance/Risk)
  • IT Risk Analyst
  • Information Security Compliance Analyst
  • IT Auditor with cybersecurity experience
  • Security Governance Analyst

Nice-to-Have Backgrounds

  • Internal Auditor focused on IT controls
  • IAM Governance Analyst
  • Third-Party Risk Analyst
  • Security Consultant performing risk and control assessments
Ref: #851-Rockville-S1


System One logo

About System One

Sourced by ZipRecruiter

System One helps employers get work done more efficiently and economically without compromising quality. Over our 35+ year history, we've helped connect thousands of talented people with innovative companies. The excitement of a perfect fit motivates us every single day.

Industry

Business consulting services and recruiting and staffing services

Company size

5,001 - 10,000 Employees

Headquarters location

Pittsburgh, PA, US