1

Cybersecurity Grc Jobs (NOW HIRING)

Senior Cybersecurity GRC

Manhattan, NY · On-site

$110K - $142K/yr

Senior Cybersecurity GRC & Third Party Risk Consultant Location: New York, NY (Onsite/Hybrid) Duration: Long-Term Contract(W2) We are seeking an experienced Senior Cybersecurity GRC & Third Party ...

We are seeking an experienced Cybersecurity GRC Analyst for a 6-month engagement to support our ongoing security compliance and governance initiatives. The ideal candidate will have strong hands-on ...

We are seeking an experienced Cybersecurity GRC Analyst for a 6-month engagement to support our ongoing security compliance and governance initiatives. The ideal candidate will have strong hands-on ...

We are seeking an experienced Cybersecurity GRC Analyst for a 6-month engagement to support our ongoing security compliance and governance initiatives. The ideal candidate will have strong hands-on ...

We are looking for a Cybersecurity GRC Engineer who can bridge the gap between governance, risk, compliance, and technical security operations in a mission-driven healthcare environment. This role is ...

next page

Showing results 1-20

Cybersecurity GRC information

See salary details

$38.5K

$58.2K

$87K

How much do cybersecurity grc jobs pay per year?

As of Aug 8, 2026, the average yearly pay for cybersecurity grc in the United States is $58,171.00, according to ZipRecruiter salary data. Most workers in this role earn between $48,000.00 and $64,500.00 per year, depending on experience, location, and employer.

What are some common challenges faced by professionals in Cybersecurity GRC roles, and how can they be addressed?

Professionals in Cybersecurity GRC (Governance, Risk, and Compliance) often encounter challenges such as keeping up with evolving regulatory requirements, balancing business objectives with security mandates, and fostering collaboration between IT, legal, and business teams. These challenges can be addressed by staying current with industry standards, utilizing automated tools for compliance tracking, and building strong communication channels across departments. Proactively engaging stakeholders and fostering a culture of security awareness also play a crucial role in overcoming these obstacles and ensuring effective risk management.

What is Cybersecurity GRC?

Cybersecurity GRC stands for Governance, Risk, and Compliance in the context of cybersecurity. It involves establishing frameworks and processes to ensure an organization's information security aligns with business objectives, regulatory requirements, and risk management strategies. Professionals in this field help identify and manage security risks, create policies and controls, and ensure compliance with laws and standards such as GDPR, HIPAA, or ISO 27001. The goal of Cybersecurity GRC is to protect the organization’s digital assets while enabling responsible growth and innovation.

What are the key skills and qualifications needed to thrive as a Cybersecurity GRC professional?

To thrive as a Cybersecurity GRC professional, you need a solid understanding of cybersecurity frameworks, risk management principles, and regulatory compliance, often supported by a degree in information security or a related field. Familiarity with tools like GRC platforms (e.g., RSA Archer, ServiceNow), as well as certifications such as CISSP, CISM, or CRISC, is typically required. Strong analytical skills, attention to detail, and effective communication are crucial soft skills for collaborating with stakeholders and translating technical risks into business implications. These competencies ensure organizations can proactively manage cyber risks, meet regulatory requirements, and maintain trust with clients and partners.

What is the difference between Cybersecurity Grc vs Cybersecurity Analyst?

AspectCybersecurity GrcCybersecurity Analyst
CertificationsISO 27001, CISSP, CISACompTIA Security+, CEH, CISSP
Work EnvironmentPolicy development, risk management, complianceThreat detection, incident response, vulnerability assessment
Employer & Industry UsageOrganizations focusing on governance and complianceSecurity operations centers, IT departments

Cybersecurity Grc professionals focus on establishing policies, managing risks, and ensuring compliance with regulations. In contrast, Cybersecurity Analysts primarily monitor security systems, analyze threats, and respond to incidents. While both roles require similar certifications and work within the cybersecurity field, Grc roles are more strategic and policy-oriented, whereas Analysts are more technical and operational.

More about Cybersecurity GRC jobs
What cities are hiring for Cybersecurity Grc jobs? Cities with the most Cybersecurity Grc job openings:
What are the most commonly searched types of Cybersecurity Grc jobs? The most popular types of Cybersecurity Grc jobs are:
What states have the most Cybersecurity Grc jobs? States with the most job openings for Cybersecurity Grc jobs include:
What job categories do people searching Cybersecurity Grc jobs look for? The top searched job categories for Cybersecurity Grc jobs are:
Infographic showing various Cybersecurity Grc job openings in the United States as of August 2026, with employment types broken down into 91% Full Time, 4% Part Time, and 5% Contract. Highlights an 81% Physical, 6% Hybrid, and 13% Remote job distribution, with an average salary of $58,171 per year, or $28 per hour.

Senior Cybersecurity GRC

BIGDATAAPPTECH LLC

Manhattan, NY • On-site

$110K - $142K/yr

Other

Posted 24 days ago


Job description

Job Title: Senior Cybersecurity GRC & Third Party Risk Consultant
Location: New York, NY (Onsite/Hybrid)
Duration: Long-Term Contract(W2)

Job Description
We are seeking an experienced Senior Cybersecurity GRC & Third Party Risk Consultant to support the implementation and enhancement of Third Party and Fourth Party Risk Management programs. The ideal candidate will have strong expertise in vendor risk management, information security governance, regulatory compliance, and Archer GRC solutions within the banking or financial services industry.

Key Responsibilities
Gather and define business requirements for Third Party and Fourth Party Risk Management initiatives.
Lead the implementation and alignment of SIG 2027 questionnaires, risk domains, and assessment frameworks.
Design and maintain risk taxonomy, risk assessment methodologies, and risk scoring models.
Configure and support RSA Archer TPRM workflows and related GRC processes.
Collaborate with business and technical teams to implement vendor risk workflows, questionnaires, and data models.
Support vendor onboarding, security due diligence, risk assessments, continuous monitoring, and remediation activities.
Ensure compliance with regulatory, governance, audit, and information security requirements.
Participate in User Acceptance Testing (UAT), data validation, issue resolution, and governance approvals.
Develop executive dashboards, KPIs, and risk analytics for vendor risk reporting.
Recommend improvements to Third Party Risk Management processes and governance practices.
Required Skills
10+ years of experience in Third Party Risk Management (TPRM), Vendor Risk Management (VRM), Information Security Risk, or Governance, Risk & Compliance (GRC).
Strong expertise in Third Party and Fourth Party Risk Management frameworks and operating models.
Deep understanding of SIG (Standardized Information Gathering) questionnaires, including SIG 2027.
Experience defining risk taxonomy, risk assessment methodologies, and risk scoring models.
Hands-on experience with RSA Archer TPRM or similar GRC platforms.
Strong knowledge of the vendor lifecycle, including onboarding, due diligence, continuous monitoring, and offboarding.
Experience working with cybersecurity governance, regulatory compliance, and audit frameworks.
Excellent communication, stakeholder management, and documentation skills.