1

Cybersecurity Governance Risk Compliance Jobs in California

next page

Showing results 1-20

Cybersecurity Governance Risk Compliance information

What is cybersecurity governance, risk, and compliance (GRC)?

Cybersecurity Governance, Risk, and Compliance (GRC) refers to a framework used by organizations to align their IT and security strategies with business objectives, manage risks, and ensure compliance with laws and regulations. Governance involves setting policies and procedures, risk focuses on identifying and addressing threats, and compliance ensures adherence to required standards. Professionals in this field help organizations protect sensitive data, avoid regulatory penalties, and build trust with stakeholders. GRC is essential for maintaining effective cybersecurity and demonstrating due diligence.

What are the key skills and qualifications needed to thrive as a cybersecurity governance, risk, and compliance (GRC) professional?

To thrive as a Cybersecurity GRC professional, you need a solid understanding of information security frameworks, risk management principles, and regulatory compliance, often supported by a degree in cybersecurity or related fields. Familiarity with tools like GRC platforms (e.g., Archer, ServiceNow), and certifications such as CISSP, CISM, or CRISC are highly valued. Strong analytical thinking, attention to detail, and effective communication skills help you interpret regulations and collaborate with stakeholders. These skills ensure organizations can manage cybersecurity risks proactively while meeting regulatory and industry standards.

What are some typical challenges faced by professionals in cybersecurity governance, risk, and compliance (GRC) roles?

Professionals in Cybersecurity GRC roles often navigate the challenge of keeping up with rapidly changing regulatory requirements while ensuring company policies align with both business objectives and security best practices. Balancing the need for robust security controls with operational efficiency, educating non-technical stakeholders about risk, and managing audits are common aspects of the job. Additionally, GRC professionals frequently collaborate with IT, legal, and business teams to ensure a cohesive approach to risk management and compliance. This dynamic environment requires strong communication skills, adaptability, and a commitment to continuous learning.

What is the difference between Cybersecurity Governance Risk Compliance vs Cybersecurity Analyst?

AspectCybersecurity Governance Risk ComplianceCybersecurity Analyst
CertificationsCISA, CISSP, CISMCompTIA Security+, CISSP, CEH
Work EnvironmentPolicy development, audits, compliance frameworksMonitoring security systems, incident response
Employer & Industry UsageOrganizations with compliance needs, regulatory bodiesIT security teams, cybersecurity firms

While Cybersecurity Governance Risk Compliance focuses on establishing policies, ensuring regulatory adherence, and managing risks, Cybersecurity Analysts primarily monitor security systems, analyze threats, and respond to incidents. Both roles are essential in a comprehensive cybersecurity strategy but differ in scope and daily responsibilities.

What are popular job titles related to Cybersecurity Governance Risk Compliance jobs in California?

For Cybersecurity Governance Risk Compliance jobs in California, the most frequently searched job titles are:

What job categories do people searching Cybersecurity Governance Risk Compliance jobs in California look for?

The top searched job categories for Cybersecurity Governance Risk Compliance jobs in California are:

What cities in California are hiring for Cybersecurity Governance Risk Compliance jobs?

Cities in California with the most Cybersecurity Governance Risk Compliance job openings:

Infographic showing various Cybersecurity Governance Risk Compliance job openings in California as of August 2026, with employment types broken down into 1% As Needed, 79% Full Time, 15% Part Time, and 5% Contract. Highlights an 88% Physical, 3% Hybrid, and 9% Remote job distribution.

GRC, Cyber Security Architect

San Francisco, CA โ€ข On-site

TekisHub Consulting Services
201 - 500 employees

Other

Posted 28 days ago


Job description

GRC, Cyber Security Data Architect
San Francisco, CA
 
Lead the delivery of cybersecurity gap and maturity assessment for a global enterprise program, covering assessment planning, stakeholder engagement, evidence review, maturity scoring, risk based gap prioritization, executive reporting, and development of a practical improvement roadmap.
 
10 to 15 years in cybersecurity, GRC, risk management, audit, security consulting, or cybersecurity program assessment.
Strong hands on experience with NIST CSF, preferably NIST CSF 2.0 maturity assessments.
Experience mapping controls across NIST CSF, ISO 27001, NIST 800 53, CIS Controls, SOC 2, or similar frameworks.
Proven experience conducting enterprise wide cybersecurity maturity, gap, risk, or control assessments.
Ability to conduct interviews/workshops with senior security, risk, compliance, technology, and business stakeholders.
Strong experience creating leadership ready cybersecurity reports, maturity dashboards, and roadmap presentations.
Experience working in consulting/advisory environments with structured methodology, governance, and client facing deliverables.
Ability to convert control gaps into risk ranked remediation recommendations and practical roadmaps.

Required Skills
Strong expertise in NIST CSF 2.0, cybersecurity governance, risk management, compliance, control maturity models, and ISO 27001 / ISMS.
Ability to map controls across NIST CSF, ISO 27001, NIST 800 53, CIS Controls, SOC 2, and similar frameworks.
Experience in evidence based assessment, maturity scoring, risk based gap prioritization, and remediation roadmap development.
 
 
Suresh
suresh.b@tekishub.com

TekisHub, an EEO Employer

We value diversity and are dedicated to fostering an inclusive workplace of Equal Employment Opportunity where everyone is empowered to succeed. All employment decisions are based on qualifications, merit, and business needs.