1

Cybersecurity Analyst Grc Jobs (NOW HIRING)

The GRC Cybersecurity Analyst III is a senior level contributor responsible for leading ICCU's Governance, Risk, and Compliance (GRC) initiatives within the scope of the IT domain. This role provides ...

The GRC Cybersecurity Analyst III is a senior level contributor responsible for leading ICCU's Governance, Risk, and Compliance (GRC) initiatives within the scope of the IT domain. This role provides ...

The GRC Cybersecurity Analyst III is a senior level contributor responsible for leading ICCU's Governance, Risk, and Compliance (GRC) initiatives within the scope of the IT domain. This role provides ...

Cybersecurity GRC Analyst (Remote) Location: 100% Remote Rate: $51/hour (No PTO) Overview We are seeking a Cybersecurity GRC Analyst to support enterprise-wide cybersecurity risk management ...

A Cybersecurity Analyst is part of a team that consults with clients about cybersecurity related ... Participate in the on-boarding of clients into GRC tools like Apptega. * Provide training and ...

Senior Analyst, Cybersecurity GRC, Washington, DC The Senior Analyst, Cybersecurity GRC will administer the completion of compliance-related client requests to assess security policies and procedures.

Senior Analyst, Cybersecurity GRC, Washington, DC The Senior Analyst, Cybersecurity GRC will administer the completion of compliance-related client requests to assess security policies and procedures.

The Cybersecurity GRC Analyst works closely with IT, Internal Audit, Compliance, Procurement, and business stakeholders to help ensure cybersecurity requirements are defined, documented, assessed ...

We're looking for a highly motivated and detail-oriented Senior Cybersecurity Risk Analyst to join our Governance, Risk, and Compliance (GRC) organization. Focused on technical risk management, you ...

We are seeking an experienced Cybersecurity GRC Analyst for a 6-month engagement to support our ongoing security compliance and governance initiatives. The ideal candidate will have strong hands-on ...

We are seeking an experienced Cybersecurity GRC Analyst for a 6-month engagement to support our ongoing security compliance and governance initiatives. The ideal candidate will have strong hands-on ...

next page

Showing results 1-20

Cybersecurity Analyst Grc information

See salary details

$43K

$99.4K

$150K

How much do cybersecurity analyst grc jobs pay per year?

As of Sep 11, 2026, the average yearly pay for cybersecurity analyst grc in the United States is $99,400.00, according to ZipRecruiter salary data. Most workers in this role earn between $79,500.00 and $115,500.00 per year, depending on experience, location, and employer.

What is a cybersecurity analyst GRC?

A Cybersecurity Analyst GRC (Governance, Risk, and Compliance) is a professional responsible for ensuring that an organization’s cybersecurity policies, procedures, and systems comply with regulations and industry standards. They assess risks, monitor security controls, and help implement frameworks like ISO 27001 or NIST. Their work involves conducting audits, identifying vulnerabilities, and advising on best practices to strengthen the organization’s security posture. This role bridges the gap between IT security and business compliance requirements.

What are the key skills and qualifications needed to thrive as a cybersecurity analyst GRC?

To thrive as a Cybersecurity Analyst GRC, you need a solid understanding of risk management, compliance frameworks (such as NIST, ISO 27001), and information security principles, often supported by a degree in cybersecurity, IT, or a related field. Familiarity with governance, risk, and compliance (GRC) tools, security assessment platforms, and certifications like CISSP, CISM, or CRISC is highly valued. Strong analytical thinking, attention to detail, and effective communication skills enable you to interpret regulations and collaborate across the organization. These competencies are essential for ensuring that security policies align with business objectives and regulatory requirements, effectively minimizing organizational risk.

How does a cybersecurity analyst GRC typically collaborate with other departments to ensure compliance and manage risk?

A Cybersecurity Analyst GRC (Governance, Risk, and Compliance) frequently works cross-functionally with IT, legal, and business units to develop and enforce security policies, conduct risk assessments, and ensure regulatory compliance. They often lead or participate in meetings to interpret compliance requirements and translate them into actionable security controls. Regular communication and coordination are essential, as these analysts must balance security needs with business objectives, making collaboration a key aspect of daily work. This role also involves educating staff about compliance protocols and responding to audits or incidents alongside other teams.

What is the difference between Cybersecurity Analyst Grc vs Cybersecurity Analyst?

AspectCybersecurity Analyst GrcCybersecurity Analyst
CertificationsCompTIA Security+, CISSP, CISACompTIA Security+, CISSP, CEH
Work EnvironmentFocus on governance, risk management, complianceBroader security operations, incident response
Employer & Industry UsageFinancial, healthcare, regulated industriesVarious sectors including tech, finance, government

Cybersecurity Analyst Grc primarily concentrates on governance, risk, and compliance activities, ensuring organizations adhere to security standards. In contrast, a Cybersecurity Analyst has a broader role, including monitoring security threats, incident response, and technical security measures. Both roles require similar certifications but differ in focus and daily tasks, with Grc roles emphasizing policy and compliance, and general analyst roles focusing on security operations.

Is cybersecurity analyst GRC a good job?

A cybersecurity analyst specializing in Governance, Risk, and Compliance (GRC) is a valuable role that focuses on managing security policies, regulatory requirements, and risk assessments. It often requires knowledge of frameworks like ISO 27001 or NIST and may involve certifications such as CISSP or CISA. The role offers steady employment prospects and opportunities for advancement in the cybersecurity field.

What cities are hiring for Cybersecurity Analyst Grc jobs?

Cities with the most Cybersecurity Analyst Grc job openings:

What states have the most Cybersecurity Analyst Grc jobs?

States with the most job openings for Cybersecurity Analyst Grc jobs include:

What are popular job titles related to Cybersecurity Analyst Grc jobs?

For Cybersecurity Analyst Grc jobs, the most frequently searched job titles are:

GRC Cybersecurity Analyst III

Chubbuck, ID • On-site

Full-time

Re-posted 22 days ago


Job description

The GRC Cybersecurity Analyst III is a senior level contributor responsible for leading ICCU's Governance, Risk, and Compliance (GRC) initiatives within the scope of the IT domain. This role provides strategic oversight of cyber and IT operational risk assessments, regulatory compliance, IT audit coordination, and IT policy development. GRC Cybersecurity Analyst III serves as a subject matter expert, mentor to junior staff, and liaison to executive leadership and external stakeholders while advancing ICCU's mission of Helping Members Achieve Financial Success.
Duties & Responsibilities
  • Lead and execute enterprisewide cyber and information security risk assessments and audits.
  • A primary contributor to setting strategy and direction in strengthening and reinforcing ICCUs technology defenses and identifying and remedying weaknesses and control gaps within the ICCU environment.
  • Manage third-party cyber risk assessments, vendor reviews, and remediation tracking.
  • Oversee compliance frameworks including NIST CSF, FFIEC, PCI-DSS, CIS Controls, FedLine, and SWIFT.
  • Develop and maintain IT policies, standards, and procedures aligned with regulatory mandates.
  • Act as lead liaison and coordinator of internal and external IT audits.
  • Build and maintain IT GRC dashboards, risk registers, and executive reports.
  • Scope and draft statements of work and proposals for new IT GRC initiatives.
  • Lead tabletop exercises, Pen Test reviews, and incident response planning in partnership with stakeholders.
  • Provide mentorship and guidance to junior GRC Cybersecurity analysts.
  • Collaborate with IT, Compliance, and Risk teams to align GRC efforts.
  • Serve as a primary IT point of contact for auditors, regulators, and certification bodies.
  • Monitor and report on compliance gaps, risk mitigation plans, and audit readiness.
  • Stay current on regulatory developments, compliance frameworks, and emerging governance risks impacting cybersecurity programs.
  • Support strategic planning and budgeting for GRC tools and capabilities.
  • Other duties as assigned.

Qualifications:
Education & Certifications
  • A bachelor's degree in Information Assurance, Cyber Security, Computer Science, Computer Information Technology, or similar field of study, or equivalent work experience is required.
  • A master's degree or equivalent certificate in information assurance or computer related fields such as Computer Science, Computer Security or Software Development is strongly preferred. A masters degree may substitute for 1 year of required experience.
  • One Level I certification, One Level II, and One Level III certification from the DoD 8140 (8570) Cyber Workforce Qualification Matrix pertaining to GRC (eg, SSCP, CISSP, CISM, CISA, CRISC, GSEC, CGRC, CCSP, CSSLP, GSE, or equivalent).

Experience
  • 9+ years of work experience in roles with significant Information Security duties.
  • 6+ years of work experience in senior level IT technical roles in Security, Infrastructure, Application Development, Operations, Cloud Management, Ecommerce, or similar areas.
  • 3+ years of experience in senior roles with cyber / infosec GRC projects or teams.
  • Proven experience with regulatory compliance and certification programs.
  • Experience in regulated industries such as financial services or healthcare.
  • Familiarity with enterprise risk management (ERM) frameworks.

Tools & Technologies
  • Security Information and Event Management (SIEM) tools for log aggregation, monitoring, and analysis.
  • Vulnerability Scanning Platforms for identifying, reporting, and tracking security weaknesses.
  • Enterprise GRC systems (or equivalent) for assessment distribution and tracking.
  • Internal dashboards (for metrics, assessments, audit readiness, and executive reporting).
  • Familiarity with project management tools.
  • Microsoft Office Suite (Excel, Word).
  • Understanding of cloud technologies and SaaS platforms.

Skills & Competencies
  • Strong leadership, communication, and stakeholder management skills.
  • Ability to manage complex projects and cross-functional teams.
  • Strategic thinking with strong attention to detail.
  • Ability to simplify complexity and drive results.
  • High sense of urgency and initiative.
  • Ability to work independently and collaboratively.

Physical & Operational Requirements
This role is primarily office-based and requires extended periods of sitting, computer use, and interaction with standard office equipment. Occasional lifting of up to 15 pounds may be required. The employee must have sufficient vision to read documents and screens, and hearing ability to communicate effectively in person and via telephone. Flexibility may be required during organizational changes or high-priority audit cycles.
The above statements reflect the general details considered necessary to describe the essential functions of the job and should not be construed as a detailed description of all the work requirements that may be inherent of the job.
Must be eligible for membership at ICCU to obtain employment.
ICCU is an Equal Opportunity Employer. Employment decisions are made without regard to race, color, religion, national or ethnic origin, sex, age, disability, protected veteran status or other characteristics protected by law.
Equal Opportunity Employer
This employer is required to notify all applicants of their rights pursuant to federal employment laws.
For further information, please review the Know Your Rights notice from the Department of Labor.