1

Cybersecurity Governance Risk Compliance Jobs in California

About the Role The Cybersecurity Director is responsible for providing strategic leadership across ... Manage a comprehensive Governance, Risk, and Compliance program in support of corporate audits ...

Posted today

next page

Showing results 1-20

Cybersecurity Governance Risk Compliance information

What is the difference between Cybersecurity Governance Risk Compliance vs Cybersecurity Analyst?

AspectCybersecurity Governance Risk ComplianceCybersecurity Analyst
CertificationsCISA, CISSP, CISMCompTIA Security+, CISSP, CEH
Work EnvironmentPolicy development, audits, compliance frameworksMonitoring security systems, incident response
Employer & Industry UsageOrganizations with compliance needs, regulatory bodiesIT security teams, cybersecurity firms

While Cybersecurity Governance Risk Compliance focuses on establishing policies, ensuring regulatory adherence, and managing risks, Cybersecurity Analysts primarily monitor security systems, analyze threats, and respond to incidents. Both roles are essential in a comprehensive cybersecurity strategy but differ in scope and daily responsibilities.

What are the key skills and qualifications needed to thrive as a cybersecurity governance, risk, and compliance (GRC) professional?

To thrive as a Cybersecurity GRC professional, you need a solid understanding of information security frameworks, risk management principles, and regulatory compliance, often supported by a degree in cybersecurity or related fields. Familiarity with tools like GRC platforms (e.g., Archer, ServiceNow), and certifications such as CISSP, CISM, or CRISC are highly valued. Strong analytical thinking, attention to detail, and effective communication skills help you interpret regulations and collaborate with stakeholders. These skills ensure organizations can manage cybersecurity risks proactively while meeting regulatory and industry standards.

What are some typical challenges faced by professionals in cybersecurity governance, risk, and compliance (GRC) roles?

Professionals in Cybersecurity GRC roles often navigate the challenge of keeping up with rapidly changing regulatory requirements while ensuring company policies align with both business objectives and security best practices. Balancing the need for robust security controls with operational efficiency, educating non-technical stakeholders about risk, and managing audits are common aspects of the job. Additionally, GRC professionals frequently collaborate with IT, legal, and business teams to ensure a cohesive approach to risk management and compliance. This dynamic environment requires strong communication skills, adaptability, and a commitment to continuous learning.

Is cybersecurity governance risk compliance a good career?

Cybersecurity Governance, Risk, and Compliance (GRC) is a growing field that offers opportunities in managing organizational security policies, risk assessments, and regulatory compliance. It requires knowledge of security frameworks, certifications like CISSP or CISM, and strong analytical skills. The role is in demand across various industries due to increasing cybersecurity threats and regulatory requirements.

Is cybersecurity governance risk compliance a good job?

Cybersecurity Governance, Risk, and Compliance (GRC) roles are in high demand due to increasing cybersecurity threats and regulatory requirements. These jobs typically require knowledge of security frameworks, risk management, and compliance standards, offering opportunities for career growth and specialization. They often involve collaboration across departments and may require certifications like CISSP or CISA.

What is cybersecurity governance, risk, and compliance (GRC)?

Cybersecurity Governance, Risk, and Compliance (GRC) refers to a framework used by organizations to align their IT and security strategies with business objectives, manage risks, and ensure compliance with laws and regulations. Governance involves setting policies and procedures, risk focuses on identifying and addressing threats, and compliance ensures adherence to required standards. Professionals in this field help organizations protect sensitive data, avoid regulatory penalties, and build trust with stakeholders. GRC is essential for maintaining effective cybersecurity and demonstrating due diligence.
What are popular job titles related to Cybersecurity Governance Risk Compliance jobs in California? For Cybersecurity Governance Risk Compliance jobs in California, the most frequently searched job titles are:
What job categories do people searching Cybersecurity Governance Risk Compliance jobs in California look for? The top searched job categories for Cybersecurity Governance Risk Compliance jobs in California are:
What cities in California are hiring for Cybersecurity Governance Risk Compliance jobs? Cities in California with the most Cybersecurity Governance Risk Compliance job openings:
Infographic showing various Cybersecurity Governance Risk Compliance job openings in California as of August 2026, with employment types broken down into 1% As Needed, 84% Full Time, 11% Part Time, and 4% Contract. Highlights an 93% Physical, 3% Hybrid, and 4% Remote job distribution.

Governance Risk & Compliance Analyst Senior

Cottage Health

Santa Barbara, CA • On-site

$49.87 - $76.05/hr

Full-time

This job post has expired 6 days ago. Applications are no longer accepted.


Cottage Health rating

8.0

Company rating: 8.0 out of 10

Based on 22 frontline employees who took The Breakroom Quiz


Job description


Cottage Health seeks a Governance Risk & Compliance Analyst Senior for their CH ITS Security department. This position will lead security governance, risk management, and compliance activities across the organization. This role partners with IT, business, and vendor stakeholders to identify security risks, ensure regulatory compliance, and strengthen Cottage Health's overall security program and risk management capabilities. Key responsibilities include:
  • Lead and maintain security governance, risk, and compliance initiatives.
  • Conduct security risk assessments and manage the enterprise Security Risk Register.
  • Support HIPAA, PCI, and other regulatory compliance activities.
  • Assess third-party vendors and monitor compliance with security requirements.
  • Develop security metrics and report risk and compliance status to leadership.
  • Create and maintain security policies, standards, and governance processes.
  • Recommend risk mitigation strategies and drive remediation efforts.

Qualifications
All job qualifications listed indicate the minimum level necessary to perform this job proficiently.
LEVEL OF EDUCATION
Minimum: Bachelor's Degree in Computer Science or related field; or equivalent experience (8 years)
CERTIFICATIONS, LICENSES, REGISTRATIONS
Minimum: One or more of the following industry certifications: Certified Information Security Auditor (CISA), Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP),Certified in Risk and Information Systems Control (CRISC), SANS Security Awareness Professional, CompTIA Security+, CompTIA CySA+ Certified Ethical Hacker (CEH), Offensive Security Certified Professional (OSCP), GIAC Security Essentials (GSEC), Certified Cloud Security Professional (CCSP), Systems Security Certified Practitioner (SSCP), Advanced in AI Audit (AAIA), Certified Data Privacy Solutions Engineer (CDPSE), Certified in the Governance of Enterprise IT (CGEIT), Certified Cybersecurity Operations Analyst (CCOA)
TECHNICAL REQUIREMENTS
Minimum: Working knowledge of HIPAA, PCI, and cybersecurity governance frameworks
YEARS OF RELATED WORK EXPERIENCE
Minimum: 3-5 years of IT audit, risk management, or information security compliance experience, operating independently with limited supervision
About Us
Cottage Health is a leading acute care hospital system, located on the central coast of California, widely known for our superior patient care, innovation, medical research and education. Our health system operates primarily in Santa Barbara, CA, since 1888, and consists of three acute care hospitals, a Rehabilitation Hospital, multiple clinics and a multi-site Urgent Care system. Our mission is to serve the central coast communities with excellence, integrity, and compassion. Every day we touch thousands of lives in many different ways, resolute in our mission to put patients first. We take pride in helping our patients get back to living their lives - in the places they love.
Cottage Health is an Equal Opportunity Employer. Cottage Health applicants are considered solely based on their qualifications, without regard to race, color, ethnicity, religion, age, gender, transgender, gender expression and identity, national origin, ancestry, disability, sexual orientation, marital status, military status or any other classification protected by law. This policy applies to all aspects of the relationship between Cottage Health and an applicant or employee. Cottage Health is committed to upholding discrimination-free hiring practices. We strive to cultivate an environment where exceptional people bring diverse perspectives and find belonging, support and connection to their work.
Any Cottage Health applicants who require assistance or reasonable accommodations during the application process may request the need for accommodation with the Recruiter.
*Pay for non-physician positions is determined based on related years of experience and internal equity. Eligible employees may also receive additional forms of compensation, including shift differentials, on-call pay, incentive pay, and bonus opportunities, where applicable. Manager and above positions may participate in Cottage Health's annual management incentive program. Physician compensation is determined based upon specialty and may include bonus potential. For more information on our comprehensive Total Rewards offerings, please visit https://cottagehealth.org/careers/total-rewards.
If you're already a Cottage Health employee, please apply on this link only.

What Cottage Health employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom