1

Cybersecurity Governance Risk Compliance Jobs in Austin, TX

Be Seen First

GRC Cybersecurity Specialist

Austin, TX · On-site

$115K - $144K/yr

While compliance is an important component of the position, the strongest emphasis is on Governance and Risk . Candidates should be comfortable discussing how cybersecurity decisions are made, how ...

What can set you apart * 3+ years of applicable experience in IT compliance, governance, risk and compliance (GRC), IT audit, information security, technology risk, or a related field preferred.

New

next page

Showing results 1-20

Cybersecurity Governance Risk Compliance information

See Austin, TX salary details

$22.8K

$112.7K

$149.2K

How much do cybersecurity governance risk compliance jobs pay per year?

As of Aug 26, 2026, the average yearly pay for cybersecurity governance risk compliance in Austin, TX is $112,704.00, according to ZipRecruiter salary data. Most workers in this role earn between $99,100.00 and $127,900.00 per year, depending on experience, location, and employer.

What is cybersecurity governance, risk, and compliance (GRC)?

Cybersecurity Governance, Risk, and Compliance (GRC) refers to a framework used by organizations to align their IT and security strategies with business objectives, manage risks, and ensure compliance with laws and regulations. Governance involves setting policies and procedures, risk focuses on identifying and addressing threats, and compliance ensures adherence to required standards. Professionals in this field help organizations protect sensitive data, avoid regulatory penalties, and build trust with stakeholders. GRC is essential for maintaining effective cybersecurity and demonstrating due diligence.

What are the key skills and qualifications needed to thrive as a cybersecurity governance, risk, and compliance (GRC) professional?

To thrive as a Cybersecurity GRC professional, you need a solid understanding of information security frameworks, risk management principles, and regulatory compliance, often supported by a degree in cybersecurity or related fields. Familiarity with tools like GRC platforms (e.g., Archer, ServiceNow), and certifications such as CISSP, CISM, or CRISC are highly valued. Strong analytical thinking, attention to detail, and effective communication skills help you interpret regulations and collaborate with stakeholders. These skills ensure organizations can manage cybersecurity risks proactively while meeting regulatory and industry standards.

What are some typical challenges faced by professionals in cybersecurity governance, risk, and compliance (GRC) roles?

Professionals in Cybersecurity GRC roles often navigate the challenge of keeping up with rapidly changing regulatory requirements while ensuring company policies align with both business objectives and security best practices. Balancing the need for robust security controls with operational efficiency, educating non-technical stakeholders about risk, and managing audits are common aspects of the job. Additionally, GRC professionals frequently collaborate with IT, legal, and business teams to ensure a cohesive approach to risk management and compliance. This dynamic environment requires strong communication skills, adaptability, and a commitment to continuous learning.

What is the difference between Cybersecurity Governance Risk Compliance vs Cybersecurity Analyst?

AspectCybersecurity Governance Risk ComplianceCybersecurity Analyst
CertificationsCISA, CISSP, CISMCompTIA Security+, CISSP, CEH
Work EnvironmentPolicy development, audits, compliance frameworksMonitoring security systems, incident response
Employer & Industry UsageOrganizations with compliance needs, regulatory bodiesIT security teams, cybersecurity firms

While Cybersecurity Governance Risk Compliance focuses on establishing policies, ensuring regulatory adherence, and managing risks, Cybersecurity Analysts primarily monitor security systems, analyze threats, and respond to incidents. Both roles are essential in a comprehensive cybersecurity strategy but differ in scope and daily responsibilities.

What are popular job titles related to Cybersecurity Governance Risk Compliance jobs in Austin, TX?

For Cybersecurity Governance Risk Compliance jobs in Austin, TX, the most frequently searched job titles are:

What job categories do people searching Cybersecurity Governance Risk Compliance jobs in Austin, TX look for?

The top searched job categories for Cybersecurity Governance Risk Compliance jobs in Austin, TX are:

What cities near Austin, TX are hiring for Cybersecurity Governance Risk Compliance jobs?

Cities near Austin, TX with the most Cybersecurity Governance Risk Compliance job openings:

Infographic showing various Cybersecurity Governance Risk Compliance job openings in Austin, TX as of August 2026, with employment types broken down into 100% Full Time. Highlights an 100% In-person job distribution, with an average salary of $112,704 per year, or $54.2 per hour.

GRC Cybersecurity Specialist

We Place People Executive Search Firm

Austin, TX • On-site

$115K - $144K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 11 days ago

Be Seen First

After you apply to this job, you can share why you’re interested to jump to the top of the candidate list.


Job description

Location: Austin, TX
Employment Type: Direct Hire / Full-Time
Work Arrangement: Onsite
Work Authorization: U.S. Citizen or Green Card Holder required


Our client is seeking an experienced Cybersecurity Governance, Risk & Compliance (GRC) Specialist II to join its Information Security organization in Austin.


This position is ideal for a cybersecurity professional who has done more than participate in audits, complete compliance checklists, or respond to security questionnaires. The successful candidate will have hands-on experience with cybersecurity governance and risk management and will understand how security programs are structured, governed, measured, and improved within a complex organization.


While compliance is an important component of the position, the strongest emphasis is on Governance and Risk. Candidates should be comfortable discussing how cybersecurity decisions are made, how accountability and ownership are established, how risk is identified and evaluated, and how policies, standards, exceptions, and risk-treatment decisions are managed across an organization.


What You'll Be Doing


Cybersecurity Governance

  • Help operate and mature the organization's cybersecurity governance program.
  • Develop, maintain, and improve information security policies, standards, procedures, and governance documentation.
  • Work with security, technology, business, and leadership teams to establish clear ownership and accountability for cybersecurity requirements.
  • Help ensure security policies and standards translate into practical controls and operating processes.
  • Provide guidance to stakeholders on security requirements, governance processes, and appropriate security practices.
  • Identify gaps between established security requirements and actual business or technology practices and help drive appropriate remediation.


Cybersecurity Risk Management

  • Perform and support cybersecurity risk assessments across technology, business processes, vendors, applications, and services.
  • Identify security risks, assess their potential business impact, and communicate findings clearly to both technical and non-technical stakeholders.
  • Work with risk owners to determine appropriate remediation, mitigation, acceptance, transfer, or other risk-treatment strategies.
  • Manage and evaluate security exception requests and help ensure accepted risks have appropriate ownership, documentation, approvals, and expiration or review dates.
  • Track identified risks and remediation activities through resolution.
  • Help leadership understand cybersecurity risk so informed business decisions can be made.


Third-Party & Client Security

  • Conduct security reviews and risk assessments of vendors and third-party service providers.
  • Manage remediation and follow-up activities associated with identified vendor risks.
  • Support the ongoing third-party security risk management lifecycle.
  • Lead or coordinate responses to client security questionnaires, assessments, and security-related inquiries.
  • Gather and validate evidence demonstrating the effectiveness of security controls.
  • Participate in client and third-party discussions as an Information Security subject matter expert.


Security Controls & Frameworks

  • Evaluate technology environments and security programs against established cybersecurity frameworks, standards, and internal requirements.
  • Work with frameworks and assessment methodologies including NIST, ISO 27001, SOC, and SIG.
  • Assess whether controls are appropriately designed, implemented, documented, and operating as intended.
  • Partner with technology and security teams to address control gaps and strengthen the organization's overall security posture.


AI Governance & Risk

  • Support governance and risk management associated with Artificial Intelligence technologies and use cases.
  • Evaluate AI-related security, governance, privacy, and technology risks.
  • Help establish appropriate controls, standards, and risk-management practices for responsible AI adoption.
  • Work with stakeholders to evaluate new AI capabilities from a cybersecurity and risk perspective.


Security Awareness & GRC Operations

  • Support and help manage the organization's Security Awareness program, including planning, training evaluation, measurement, and continuous improvement.
  • Support administration and optimization of GRC platforms, workflows, reporting, and risk records.
  • Maintain accurate documentation and reporting related to risks, controls, exceptions, assessments, and remediation activities.
  • Help improve GRC processes as the cybersecurity program continues to mature.


What We're Looking For


Education & Experience

  • Bachelor's degree or equivalent combination of education and experience.
  • Approximately 5+ years of IT Security experience, including meaningful experience within cybersecurity governance, risk, or GRC.
  • At least 4 years of Information Security experience with exposure to technical security environments.
  • Hands-on cybersecurity experience is strongly preferred.


Governance & Risk Experience – Critical

Candidates should be able to clearly explain their experience with:

  • Cybersecurity governance structures and processes.
  • Security policy and standards development.
  • Roles, responsibilities, ownership, and accountability within a security program.
  • Cybersecurity risk identification and assessment.
  • Risk scoring, prioritization, remediation, and treatment.
  • Risk acceptance and security exception processes.
  • Translating technical security findings into business risk.
  • Working with risk and control owners to drive issues through resolution.


We are particularly interested in candidates who understand why governance processes exist and how they influence cybersecurity decision-making, rather than candidates whose GRC experience has primarily consisted of compliance testing or audit support.


Additional Qualifications

  • Strong working knowledge of NIST, ISO 27001, SOC, and SIG or comparable security frameworks and assessment methodologies.
  • Experience performing third-party/vendor security assessments.
  • Experience responding to client security questionnaires and security reviews.
  • Experience with AI governance, AI security, or AI risk management.
  • Strong technical writing skills with the ability to develop clear policies, standards, risk documentation, and executive-level communications.
  • Experience working with GRC platforms and related workflow technologies.
  • Understanding of role-based access controls and identity/security concepts.
  • Working knowledge of security technologies and concepts such as authentication, encryption, firewalls, SIEM, IDS/IPS, vulnerability management, privileged access management, and mobile security.
  • Ability to communicate cybersecurity risk effectively to both technical teams and business stakeholders.
  • Strong analytical, organizational, project-management, and problem-solving skills.


Preferred certifications may include


CISSP, CISA, CISM, or relevant AI governance, audit, risk, or security credentials.


The Candidate We're Looking For

The right person will not view GRC as simply an audit or compliance function. We are looking for someone who understands that strong cybersecurity governance establishes how security decisions are made, who owns those decisions, how accountability is maintained, and how risk is evaluated and addressed.


You should be comfortable discussing real examples of situations where you identified a cybersecurity risk, worked with stakeholders to determine an appropriate response, documented or communicated that risk, and followed the issue through remediation or formal acceptance.


This is a highly collaborative position requiring the ability to work effectively with cybersecurity professionals, engineers, technology teams, business leaders, vendors, and clients.


This is a full-time, direct-hire position requiring onsite work in Austin. Candidates must be U.S. Citizens or Green Card holders.

How to Apply:

Our client has hired us to help facilitate the initial interview and recruiting process. Please attach your current version of your resume and make sure you complete our initial pre-screening questions that will be used for determining which applicants will be considered at this time. Thank you for your interest.

Company Description

We Place People is a premiere Executive Search Firm working with leading companies nationwide. We have a direct relationship with our clients and a 95% hire rate! We differentiate ourselves from other firms & work closely with our candidates throughout the interview process. WE PLACE PEOPLE is what we do best!