1

Cybersecurity Governance Risk Compliance Jobs in California

Cybersecurity Director

San Francisco, CA ยท On-site

$230 - $245/hr

About the Role The Cybersecurity Director is responsible for providing strategic leadership across ... Manage a comprehensive Governance, Risk, and Compliance program in support of corporate audits ...

Posted today

About the Role The Cybersecurity Director is responsible for providing strategic leadership across ... Manage a comprehensive Governance, Risk, and Compliance program in support of corporate audits ...

New

Cybersecurity Consultant

Roseville, CA ยท On-site

$118 - $133/hr

Provide subjectโ€‘matter expertise across governance, risk, compliance, and core cybersecurity domains, including identity and access management, vulnerability management, cloud security, endpoint ...

Cybersecurity Consultant

Roseville, CA ยท On-site

$118K - $133K/yr

Provide subject-matter expertise across governance, risk, compliance, and core cybersecurity domains, including identity and access management, vulnerability management, cloud security, endpoint and ...

AI Governance

Pasadena, CA ยท On-site

$130K/yr

Partner with business, technology, data, legal, risk, compliance, cybersecurity, and audit teams to ensure AI initiatives align with enterprise governance standards and regulatory expectations.

Cybersecurity Consultant

Roseville, CA ยท On-site

$118K - $133K/yr

Provide subject-matter expertise across governance, risk, compliance, and core cybersecurity domains, including identity and access management, vulnerability management, cloud security, endpoint and ...

Cybersecurity Consultant

Roseville, CA ยท On-site

$118K - $133K/yr

Provide subject-matter expertise across governance, risk, compliance, and core cybersecurity domains, including identity and access management, vulnerability management, cloud security, endpoint and ...

Partner with business, technology, data, legal, risk, compliance, cybersecurity, and audit teams to ensure AI initiatives align with enterprise governance standards and regulatory expectations.

Cyber Security Program Manager

Sunnyvale, CA ยท On-site +1

$130K - $176K/yr

Lead coordination efforts with Information Security and Governance Risk & Compliance (GRC) leadership to strategically plan, execute, and oversee cybersecurity initiatives, ensuring alignment with ...

Showing results 21-40

Cybersecurity Governance Risk Compliance information

What is the difference between Cybersecurity Governance Risk Compliance vs Cybersecurity Analyst?

AspectCybersecurity Governance Risk ComplianceCybersecurity Analyst
CertificationsCISA, CISSP, CISMCompTIA Security+, CISSP, CEH
Work EnvironmentPolicy development, audits, compliance frameworksMonitoring security systems, incident response
Employer & Industry UsageOrganizations with compliance needs, regulatory bodiesIT security teams, cybersecurity firms

While Cybersecurity Governance Risk Compliance focuses on establishing policies, ensuring regulatory adherence, and managing risks, Cybersecurity Analysts primarily monitor security systems, analyze threats, and respond to incidents. Both roles are essential in a comprehensive cybersecurity strategy but differ in scope and daily responsibilities.

What are the key skills and qualifications needed to thrive as a cybersecurity governance, risk, and compliance (GRC) professional?

To thrive as a Cybersecurity GRC professional, you need a solid understanding of information security frameworks, risk management principles, and regulatory compliance, often supported by a degree in cybersecurity or related fields. Familiarity with tools like GRC platforms (e.g., Archer, ServiceNow), and certifications such as CISSP, CISM, or CRISC are highly valued. Strong analytical thinking, attention to detail, and effective communication skills help you interpret regulations and collaborate with stakeholders. These skills ensure organizations can manage cybersecurity risks proactively while meeting regulatory and industry standards.

What are some typical challenges faced by professionals in cybersecurity governance, risk, and compliance (GRC) roles?

Professionals in Cybersecurity GRC roles often navigate the challenge of keeping up with rapidly changing regulatory requirements while ensuring company policies align with both business objectives and security best practices. Balancing the need for robust security controls with operational efficiency, educating non-technical stakeholders about risk, and managing audits are common aspects of the job. Additionally, GRC professionals frequently collaborate with IT, legal, and business teams to ensure a cohesive approach to risk management and compliance. This dynamic environment requires strong communication skills, adaptability, and a commitment to continuous learning.

Is cybersecurity governance risk compliance a good career?

Cybersecurity Governance, Risk, and Compliance (GRC) is a growing field that offers opportunities in managing organizational security policies, risk assessments, and regulatory compliance. It requires knowledge of security frameworks, certifications like CISSP or CISM, and strong analytical skills. The role is in demand across various industries due to increasing cybersecurity threats and regulatory requirements.

Is cybersecurity governance risk compliance a good job?

Cybersecurity Governance, Risk, and Compliance (GRC) roles are in high demand due to increasing cybersecurity threats and regulatory requirements. These jobs typically require knowledge of security frameworks, risk management, and compliance standards, offering opportunities for career growth and specialization. They often involve collaboration across departments and may require certifications like CISSP or CISA.

What is cybersecurity governance, risk, and compliance (GRC)?

Cybersecurity Governance, Risk, and Compliance (GRC) refers to a framework used by organizations to align their IT and security strategies with business objectives, manage risks, and ensure compliance with laws and regulations. Governance involves setting policies and procedures, risk focuses on identifying and addressing threats, and compliance ensures adherence to required standards. Professionals in this field help organizations protect sensitive data, avoid regulatory penalties, and build trust with stakeholders. GRC is essential for maintaining effective cybersecurity and demonstrating due diligence.
What are popular job titles related to Cybersecurity Governance Risk Compliance jobs in California? For Cybersecurity Governance Risk Compliance jobs in California, the most frequently searched job titles are:
What job categories do people searching Cybersecurity Governance Risk Compliance jobs in California look for? The top searched job categories for Cybersecurity Governance Risk Compliance jobs in California are:
What cities in California are hiring for Cybersecurity Governance Risk Compliance jobs? Cities in California with the most Cybersecurity Governance Risk Compliance job openings:
Infographic showing various Cybersecurity Governance Risk Compliance job openings in California as of August 2026, with employment types broken down into 1% As Needed, 84% Full Time, 11% Part Time, and 4% Contract. Highlights an 93% Physical, 3% Hybrid, and 4% Remote job distribution.

Cybersecurity Director

Medium

San Francisco, CA โ€ข On-site

$230 - $245/hr

Other

Medical, Retirement, PTO

Posted 14 hours ago

Posted today


Job description

Business Wire, a Berkshire Hathaway company, is the global market leader in press release distribution and regulatory disclosure. We are on a mission to redefine how organizations connect with their audiences - and thatโ€™s just the beginning!

Organizations, large and small, depend on us to accurately publicize market-moving news and multimedia, and generate social engagements that develop interactions with their target audiences.

About the Role

The Cybersecurity Director is responsible for providing strategic leadership across Business Wireโ€™s cybersecurity function, providing strategy, overseeing security architecture and infrastructure, guiding cybersecurity-related risk decisions across the organization, and advancing and managing a comprehensive Governance, Risk, and Compliance (GRC) program.

This role works collaboratively with all areas of the business to ensure that we maintain a robust and highly effective Information Security program for our existing solutions while also supporting the buildout of new client solutions hosted in our data centers and the cloud. This role provides oversight of our external cyber defense partner and drives efforts in cloud security, application security, identity and access strategies, Zero Trust, vulnerability management, email security, data protection, privacy requirements, and emerging technology risksโ€”including AI.

This role is additionally responsible for establishing a robust security governance framework, ensuring compliance with internal and external audit requirements, fostering a security-first culture across the organization, and collaborating with cross-functional teams to integrate risk management practices into all business operations.

What You'll Do
  • Develop and maintain cybersecurity and GRC strategy and long-term roadmap, with the goal of enhancing overall strategy in alignment with business objectives.
  • Make continuous improvements to our security strategies to protect critical assets and data.
  • Provide strategic decision-making and problem-solving to navigate complex security and regulatory landscapes.
  • Manage a comprehensive Governance, Risk, and Compliance program in support of corporate audits, client assessments, and regulatory standards such as PCI DSS, SOC 2, and ISO 27001; ensure that our company meets all internal and external audit requirements.
  • Conduct regular risk assessments and periodic penetration testing and vulnerability assessments to identify and mitigate potential threats to the organization's infrastructure, applications, and data.
  • Manage the timely creation and dissemination of security-related communications including security awareness and training announcements, security compliance policies and processes, security alerts, and event messaging.
  • Provide oversight in maintaining a successful collaborative relationship with our external cyber defense partner, including evaluation of service delivery performance and in alignment with BWโ€™s cybersecurity priorities.
  • Provide strategic leadership during cybersecurity incidents, coordinating with IT, Legal, HR, Privacy, Communications, and other stakeholders, and act as executive-level point-of-contact.
  • Offer senior-level guidance in developing and improving cybersecurity governance programs, policies, standards, and secure architecture guidelines.
  • Oversee enterprise cybersecurity risk assessments and ensure corrective actions are prioritized and implemented effectively; provide direction for privacy and data protection initiatives.
  • Provide leadership, guidance, and mentorship to cybersecurity and GRC team members, drive strong performance across all initiatives and support individual and team development.
  • Act as a trusted advisor to senior leadership on cybersecurity risk, architecture decisions, and strategic measures.
  • Use metrics to evaluate and track effectiveness of security, governance, and compliance initiatives.
  • Leverage exceptional communication skills to translate technical requirements into actionable business solutions.
What You'll Need
  • Ability to work in the San Francisco office an average of twice a week.
  • Bachelor's or Master's degree in Computer Science, Information Security, or a related field.
  • 10+ years of relevant industry experience in Information Security, with 5+ years of managerial and strategic leadership experience.
  • Knowledge of data protection, privacy regulations, and cybersecurity governance frameworks.
  • Expertise in cloud security, including AWS and Azure, as well as cybersecurity architecture, application security, identity management, and Zero Trust.
  • Experience in data encryption, access controls, code reviews, and secure coding practices.
  • Expertise in building and implementing GRC frameworks and risk management processes.
  • Familiarity with regulatory compliance requirements, including PCI DSS, SOC 2, and ISO 27001.
  • Certified Information Systems Security Professional (CISSP) or equivalent certification is a plus.
  • Strong leadership and team-building skills.
  • Excellent written and verbal communication skills with external and internal stakeholders and executives, and the ability to simplify complex cybersecurity topics. Ability to deliver constructive & encouraging feedback.
  • Proactive, organized, analytical, detail-oriented, and persistent.
  • Experience managing and overseeing external security service providers or technology partners.

Business Wire will not sponsor a new applicant for employment authorization for this position.

What We Offer

The base salary range for this position is $230K to $245K/year. Offered salary will be determined by several factors, including but not limited to: applicantโ€™s education, experience, knowledge, skills and abilities, as well as internal equity and alignment with geographic market data. Business Wire reserves the right to modify this salary range at any time.

Business Wireโ€™s total rewards include:

  • Ability to work remotely
  • Excellent health benefits that begin on your first day of employment
  • $100 monthly fitness allotment, a tuition reimbursement program, and enhanced mental health resources
  • 401(k) plan with generous company match, and annual profit sharing contribution (subject to company performance)
  • PTO, Floating Holidays, Wellness Day Off, Birthday Day Off, and more!

A pre-employment background check will be required after the acceptance of an offer. Business Wire is proud to be an equal opportunity workplace. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status. Pursuant to the San Francisco Fair Chance Ordinance and other similar state laws and local ordinances, and its internal policy, Business Wire will also consider for employment qualified applicants with arrest and conviction records.

#J-18808-Ljbffr