1

Cybersecurity Governance Risk Compliance Jobs in Seattle, WA

Director of Cybersecurity

Bothell, WA · On-site

$160 - $210/hr

Formalize and maintain governance, risk, and compliance frameworks including SOC2 alignment * Lead ... Represent cybersecurity in executive forums and client discussions in partnership with the CISO and ...

Director of Cybersecurity

Bothell, WA · Remote

$160K - $210K/yr

Formalize and maintain governance, risk, and compliance frameworks including SOC2 alignment * Lead ... Represent cybersecurity in executive forums and client discussions in partnership with the CISO and ...

Director of Cybersecurity

Bothell, WA · On-site

$160K - $210K/yr

Formalize and maintain governance, risk, and compliance frameworks including SOC2 alignment * Lead ... Represent cybersecurity in executive forums and client discussions in partnership with the CISO and ...

Director of Cybersecurity

Bothell, WA · On-site

$160K - $210K/yr

... governance, risk management, and compliance * Strong leadership, communication, client engagement ... Experience leading cybersecurity teams within a growth-oriented, service-driven organization ...

Cyber Manager - Cloud DevSecOps

Seattle, WA

$126K - $170K/yr

... Cybersecurity, Engineering, Cloud, Application Development, Risk, Compliance, and Technology ... Establish secure AI/Agentic AI governance and guardrails, AI threat Modeling, identity and data ...

next page

Showing results 1-20

Cybersecurity Governance Risk Compliance information

See Seattle, WA salary details

$26.2K

$129.4K

$171.3K

How much do cybersecurity governance risk compliance jobs pay per year?

As of Aug 28, 2026, the average yearly pay for cybersecurity governance risk compliance in Seattle, WA is $129,398.00, according to ZipRecruiter salary data. Most workers in this role earn between $113,800.00 and $146,800.00 per year, depending on experience, location, and employer.

What is cybersecurity governance, risk, and compliance (GRC)?

Cybersecurity Governance, Risk, and Compliance (GRC) refers to a framework used by organizations to align their IT and security strategies with business objectives, manage risks, and ensure compliance with laws and regulations. Governance involves setting policies and procedures, risk focuses on identifying and addressing threats, and compliance ensures adherence to required standards. Professionals in this field help organizations protect sensitive data, avoid regulatory penalties, and build trust with stakeholders. GRC is essential for maintaining effective cybersecurity and demonstrating due diligence.

What are the key skills and qualifications needed to thrive as a cybersecurity governance, risk, and compliance (GRC) professional?

To thrive as a Cybersecurity GRC professional, you need a solid understanding of information security frameworks, risk management principles, and regulatory compliance, often supported by a degree in cybersecurity or related fields. Familiarity with tools like GRC platforms (e.g., Archer, ServiceNow), and certifications such as CISSP, CISM, or CRISC are highly valued. Strong analytical thinking, attention to detail, and effective communication skills help you interpret regulations and collaborate with stakeholders. These skills ensure organizations can manage cybersecurity risks proactively while meeting regulatory and industry standards.

What are some typical challenges faced by professionals in cybersecurity governance, risk, and compliance (GRC) roles?

Professionals in Cybersecurity GRC roles often navigate the challenge of keeping up with rapidly changing regulatory requirements while ensuring company policies align with both business objectives and security best practices. Balancing the need for robust security controls with operational efficiency, educating non-technical stakeholders about risk, and managing audits are common aspects of the job. Additionally, GRC professionals frequently collaborate with IT, legal, and business teams to ensure a cohesive approach to risk management and compliance. This dynamic environment requires strong communication skills, adaptability, and a commitment to continuous learning.

What is the difference between Cybersecurity Governance Risk Compliance vs Cybersecurity Analyst?

AspectCybersecurity Governance Risk ComplianceCybersecurity Analyst
CertificationsCISA, CISSP, CISMCompTIA Security+, CISSP, CEH
Work EnvironmentPolicy development, audits, compliance frameworksMonitoring security systems, incident response
Employer & Industry UsageOrganizations with compliance needs, regulatory bodiesIT security teams, cybersecurity firms

While Cybersecurity Governance Risk Compliance focuses on establishing policies, ensuring regulatory adherence, and managing risks, Cybersecurity Analysts primarily monitor security systems, analyze threats, and respond to incidents. Both roles are essential in a comprehensive cybersecurity strategy but differ in scope and daily responsibilities.

What are popular job titles related to Cybersecurity Governance Risk Compliance jobs in Seattle, WA?

For Cybersecurity Governance Risk Compliance jobs in Seattle, WA, the most frequently searched job titles are:

What job categories do people searching Cybersecurity Governance Risk Compliance jobs in Seattle, WA look for?

The top searched job categories for Cybersecurity Governance Risk Compliance jobs in Seattle, WA are:

Infographic showing various Cybersecurity Governance Risk Compliance job openings in Seattle, WA as of June 2026, with employment types broken down into 1% As Needed, 87% Full Time, 10% Part Time, and 2% Contract. Highlights an 93% Physical, 3% Hybrid, and 4% Remote job distribution, with an average salary of $129,398 per year, or $62.2 per hour.

Senior Cybersecurity GRC Analyst

Mukilteo, WA • On-site

AMRO Fabricating Corporation
Manufacturing • 51 - 200 employees

$112K - $144K/yr

Full-time

Medical, Dental, Vision, Life, Retirement, PTO

Posted 2 days ago

New


Job description

Karman Space & Defense is a leader in the rapid design, development, and production of critical, next-generation system solutions that align with the U.S. Department of War and its allies’ core mission priorities, and meet the accelerating demand for access to space. Building on nearly 50 years of success, we deliver Payload & Protection Systems, Aero/Hydrodynamic Interstage Systems, and Propulsion & Launch Systems to more than 80 prime contractors supporting over 130 space and defense programs.

This role helps drive enterprise-wide cybersecurity governance, risk, compliance, and assurance activities that strengthen control quality, evidence readiness, and risk management across Karman. You will translate regulatory, contractual, and customer requirements into clear controls and reliable evidence; independently assess control effectiveness and risk; and partner with business and technology owners to embed sustainable practices that support audit, assessment, and operational readiness.

Responsibilities

  • Interprets and operationalizes cybersecurity, regulatory, contractual, and customer requirements with business, legal, and technology stakeholders.
  • Maintains cybersecurity governance artifacts including policies, standards, control documentation, mappings, ownership records, and assurance schedules.
  • Evaluates control design, operating effectiveness, evidence sufficiency, exceptions, and residual risk and recommends corrective actions or escalation.
  • Supports sustainable CMMC Level 2, NIST SP 800‑171, DFARS, and Controlled Unclassified Information (CUI) obligations through assessment, evidence validation, remediation, and monitoring.
  • Maintains the Enterprise System Security Plan (SSP), Controlled Site Addenda, system boundaries, inventories, and supporting evidence across regulated environments.
  • Coordinates contractual, regulatory, and CAGE-code traceability, ensuring accurate alignment among obligations, boundaries, sites, and assessment records.
  • Supports Sarbanes‑Oxley (SOX) Information Technology General Controls (ITGC) through narrative development, testing coordination, evidence quality, exception identification, and remediation tracking.
  • Governs cybersecurity risks, exceptions, remediation plans, compensating controls, and acceptance records and prepares leadership-ready materials that translate issues into decisions and business impact.
  • Oversees identity, access, and vulnerability governance, including coverage, aging, remediation performance, exceptions, and validation of closure across responsible teams.
  • Coordinates cybersecurity reviews for third-party services, Software-as-a-Service (SaaS), artificial intelligence (AI) tools, suppliers, and M &A activities, ensuring security, privacy, data-handling, and evidence requirements are met.

Required Qualifications

  • Bachelor’s degree in cybersecurity, information technology, information systems, business, risk management, accounting, audit, or a related field; equivalent relevant experience may be considered.
  • 5+ years of progressive experience in cybersecurity governance, risk, compliance (GRC), IT audit, risk management, control assurance, or related disciplines.
  • Experience assessing control design, operating effectiveness, and evidence sufficiency and translating findings into practical remediation and leadership reporting.
  • Working knowledge of CMMC Level 2, NIST SP 800‑171, DFARS, CUI, SOX ITGC, or comparable regulated control environments.
  • Experience maintaining cybersecurity policies, control narratives, SSPs or equivalent system documentation, evidence repositories, risk registers, Plans of Action and Milestones (POA &Ms), and remediation trackers.
  • Ability to exercise independent judgment, challenge unsupported conclusions, organize complex requirements, and escalate material risk appropriately.
  • Strong written, analytical, presentation, and stakeholder-management skills across technical teams, business owners, auditors, assessors, vendors, sites, and executives.
  • Proficiency with Microsoft 365 tools, including Excel, PowerPoint, Word, Teams, SharePoint, and Outlook.

Preferred Qualifications

  • Experience in aerospace, defense, manufacturing, engineering, or another highly regulated environment.
  • Experience supporting CMMC Level 2 readiness, NIST SP 800‑171 assessments, DFARS compliance, CUI governance, Supplier Performance Risk System (SPRS) requirements, or defense‑contractor cybersecurity needs.
  • Experience with SOX ITGC, internal or external audit, control testing, information technology risk, and remediation governance.
  • Experience with SSPs, site-specific control documentation, specialized‑asset scoping, CUI flows, system boundaries, evidence validation, and POA &M management.
  • Experience with supplier cyber risk, SaaS and AI governance, M &A due diligence, international operations, export controls, or cross-border access risk.
  • Experience using Governance, Risk, and Compliance (GRC) or audit platforms such as ServiceNow, Jira, Archer, AuditBoard, Drata, Vanta, or Hyperproof.
  • Security+, Certified Information Systems Auditor (CISA), Certified in Risk and Information Systems Control (CRISC), Certified Governance, Risk and Compliance (CGRC), Certified Information Security Manager (CISM), Certified Information Systems Security Professional (CISSP), Cybersecurity Maturity Model Certification Certified CMMC Professional (CMMC CCP), or comparable certification.

This position requires U.S. person status under U.S. export control laws, including U.S. citizens and nationals, lawful permanent residents, refugees, and asylees.

Benefits

  • Medical, dental, and vision insurance
  • 401(k) with company match
  • Paid time off
  • Health Savings Account (HSA) with company contribution
  • Flexible Spending Accounts (FSA)
  • Company‑paid life and AD &D insurance
  • Short‑ and long‑term disability coverage
  • Tuition reimbursement

Karman Space and Defense is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability, genetic information, protected veteran status, or any other status protected by applicable law.