Experience with governance, risk, and compliance (GRC) programs, risk management, control testing, or compliance strategy * Experience with data protection laws or online safety regulations such as ...
Experience with governance, risk, and compliance (GRC) programs, risk management, control testing, or compliance strategy * Experience with data protection laws or online safety regulations such as ...
Cyber Security Grc information
See Rochester, NY salary details
$40K - $52.5K
0% of jobs
$52.5K - $65K
0% of jobs
$65K - $77.5K
4% of jobs
$77.5K - $90K
9% of jobs
$102K is the 25th percentile. Wages below this are outliers.
$90K - $102.5K
13% of jobs
$102.5K - $115K
20% of jobs
The median wage is $118.4K / yr.
$115K - $127.5K
16% of jobs
$137.3K is the 75th percentile. Wages above this are outliers.
$127.5K - $140.1K
17% of jobs
$140.1K - $152.6K
12% of jobs
$152.6K - $165.1K
6% of jobs
$165.1K - $177.6K
3% of jobs
$40K
$121.3K
$177.6K
How much do cyber security grc jobs pay per year?
Is cyber security GRC a good job?
What are some common challenges faced by Cyber Security GRC professionals, and how do they typically overcome them?
Cyber Security GRC professionals often face the challenge of keeping up with evolving regulations, adapting controls for new technologies, and coordinating between security teams and business units. To overcome these challenges, professionals stay current with industry standards, participate in ongoing training, and actively communicate policy changes and risk assessments to stakeholders across the organization. They also leverage robust GRC tools to streamline compliance processes and documentation. Working collaboratively with IT, legal, and compliance teams allows them to better identify risks and implement effective, practical security controls. This approach ensures a well-integrated and proactive risk management posture for the organization.
What is a Cyber Security GRC?
A Cyber Security GRC (Governance, Risk, and Compliance) job focuses on ensuring an organization's security policies, risk management strategies, and regulatory compliance. Professionals in this role develop and enforce security policies, assess risks, and ensure adherence to industry regulations like GDPR, HIPAA, or ISO 27001. They collaborate with different teams to mitigate cybersecurity threats while aligning security practices with business goals. This role is critical for maintaining an organization's security posture and reducing potential risks.
Is cyber security GRC in high demand?
What are the key skills and qualifications needed to thrive in the Cyber Security GRC position?
To thrive as a Cyber Security GRC professional, a solid understanding of information security frameworks, risk management, and regulatory compliance is essential, often supported by a degree in information security or a related field. Familiarity with GRC platforms (such as Archer, ServiceNow, or LogicGate), and certifications like CISSP, CISM, or CRISC, are highly valued. Excellent analytical skills, attention to detail, and the ability to communicate complex risks to non-technical stakeholders are critical soft skills. These capabilities ensure organizations remain secure, compliant, and able to effectively manage evolving cyber risks.

Other
Re-posted 6 days ago
Deloitte rating
8.2
Based on 92 frontline employees who took The Breakroom Quiz
46th of 150 rated financial services
Job description
The Digital Trust & Online Protection Professional will advise clients in developing, managing, and implementing policies, procedures, and strategies to ensure a safe, compliant, and trustworthy environment for our users. This individual will scale and mature digital trust and safety processes, including content compliance, user protection, and regulatory adherence across our platforms for our clients. Working closely with cross-functional stakeholders, this role will monitor regulatory changes, manage risks, and enhance our organization's approach to content safety, user trust, and online integrity.
Recruiting for this role ends on 12/31/3026.
Work you'll do
As a Senior Consultant, Strategy, Growth, and Transformation on the Deloitte Cyber team, you will be responsible for:
- Leading the development and execution of trust and safety compliance programs aligned to regulatory requirements and online safety practices
- Creating, refining, and enforcing policies, procedures, and training that support content moderation, user protection, and platform safety
- Monitoring regulatory developments, interpreting new requirements, and integrating updates into existing policies, procedures, and compliance activities
- Conducting risk assessments, identifying content and user safety risks, and leading incident response for trust and safety matters
- Collaborating with legal, policy, product, operations, data protection, and engineering stakeholders to implement solutions and improve program effectiveness
A successful candidate would possess these skills:
- Ability to work independently and collaborate as part of a team
- Effective written and verbal communication skills
- Meticulous attention to detail and quality of work product
- Ability to build and sustain professional relationships
- Ability to lead projects or workstreams
- Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
- Strong interpersonal skills and professional demeanor
- Ability to meet deadlines
- Ability to provide clear guidance to others
The team
Enables trust and safety of online communications and digital products, protecting users, consumers, and patients from harm. Enables clients to provide consumer confidence in knowing with whom they are dealing and ensuring the integrity of access to data.
Qualifications
Required:
- Bachelor's degree in Law, Business, Information Security, Compliance, or Public Policy
- 5+ years of experience in trust and safety, compliance, content moderation, or online safety programs
- Experience developing or implementing trust and safety, compliance, or content moderation policies and procedures
- Experience conducting risk assessments or compliance reviews for digital platforms or online services
- Experience interpreting or applying regulatory requirements such as General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), Children's Online Privacy Protection Act (COPPA), or Digital Services Act (DSA)
- Ability to travel 25-50%, on average, based on the work you do and the clients and industries/sectors you serve
- Limited immigration sponsorship may be available.
Preferred:
- Master's degree in Law, Business, Information Security, Compliance, or Public Policy
- Certification such as Certified Information Privacy Professional (CIPP), Certified Information Privacy Manager (CIPM), or Certified Information Systems Security Professional (CISSP)
- Experience with governance, risk, and compliance (GRC) programs, risk management, control testing, or compliance strategy
- Experience with data protection laws or online safety regulations such as GDPR, COPPA, Digital Services Act, or Online Safety Act
- Experience using trust and safety tools, content filtering tools, monitoring tools, or user protection technologies
- Experience supporting responses to regulatory inquiries or requests for information
For individuals assigned and/or hired to work in Colorado, Deloitte is required by law to include a reasonable estimate of the compensation range for this role. This compensation range is specific to Colorado and takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $105,400 to $207,800.
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
The Digital Trust & Online Protection Professional will advise clients in developing, managing, and implementing policies, procedures, and strategies to ensure a safe, compliant, and trustworthy environment for our users. This individual will scale and mature digital trust and safety processes, including content compliance, user protection, and regulatory adherence across our platforms for our clients. Working closely with cross-functional stakeholders, this role will monitor regulatory changes, manage risks, and enhance our organization's approach to content safety, user trust, and online integrity.
Recruiting for this role ends on 12/31/3026.
Work you'll do
As a Senior Consultant, Strategy, Growth, and Transformation on the Deloitte Cyber team, you will be responsible for:
- Leading the development and execution of trust and safety compliance programs aligned to regulatory requirements and online safety practices
- Creating, refining, and enforcing policies, procedures, and training that support content moderation, user protection, and platform safety
- Monitoring regulatory developments, interpreting new requirements, and integrating updates into existing policies, procedures, and compliance activities
- Conducting risk assessments, identifying content and user safety risks, and leading incident response for trust and safety matters
- Collaborating with legal, policy, product, operations, data protection, and engineering stakeholders to implement solutions and improve program effectiveness
A successful candidate would possess these skills:
- Ability to work independently and collaborate as part of a team
- Effective written and verbal communication skills
- Meticulous attention to detail and quality of work product
- Ability to build and sustain professional relationships
- Ability to lead projects or workstreams
- Ability to manage and prioritize multiple tasks in a fast-paced and dynamic environment
- Strong interpersonal skills and professional demeanor
- Ability to meet deadlines
- Ability to provide clear guidance to others
The team
Enables trust and safety of online communications and digital products, protecting users, consumers, and patients from harm. Enables clients to provide consumer confidence in knowing with whom they are dealing and ensuring the integrity of access to data.
Qualifications
Required:
- Bachelor's degree in Law, Business, Information Security, Compliance, or Public Policy
- 5+ years of experience in trust and safety, compliance, content moderation, or online safety programs
- Experience developing or implementing trust and safety, compliance, or content moderation policies and procedures
- Experience conducting risk assessments or compliance reviews for digital platforms or online services
- Experience interpreting or applying regulatory requirements such as General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), Children's Online Privacy Protection Act (COPPA), or Digital Services Act (DSA)
- Ability to travel 25-50%, on average, based on the work you do and the clients and industries/sectors you serve
- Limited immigration sponsorship may be available.
Preferred:
- Master's degree in Law, Business, Information Security, Compliance, or Public Policy
- Certification such as Certified Information Privacy Professional (CIPP), Certified Information Privacy Manager (CIPM), or Certified Information Systems Security Professional (CISSP)
- Experience with governance, risk, and compliance (GRC) programs, risk management, control testing, or compliance strategy
- Experience with data protection laws or online safety regulations such as GDPR, COPPA, Digital Services Act, or Online Safety Act
- Experience using trust and safety tools, content filtering tools, monitoring tools, or user protection technologies
- Experience supporting responses to regulatory inquiries or requests for information
For individuals assigned and/or hired to work in Colorado, Deloitte is required by law to include a reasonable estimate of the compensation range for this role. This compensation range is specific to Colorado and takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $105,400 to $207,800.
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.