1

Cybersecurity Grc Jobs (NOW HIRING)

Senior Cybersecurity GRC

Manhattan, NY · On-site

$110K - $142K/yr

Senior Cybersecurity GRC & Third Party Risk Consultant Location: New York, NY (Onsite/Hybrid) Duration: Long-Term Contract(W2) We are seeking an experienced Senior Cybersecurity GRC & Third Party ...

We are seeking an experienced Cybersecurity GRC Analyst for a 6-month engagement to support our ongoing security compliance and governance initiatives. The ideal candidate will have strong hands-on ...

We are seeking an experienced Cybersecurity GRC Analyst for a 6-month engagement to support our ongoing security compliance and governance initiatives. The ideal candidate will have strong hands-on ...

We are seeking an experienced Cybersecurity GRC Analyst for a 6-month engagement to support our ongoing security compliance and governance initiatives. The ideal candidate will have strong hands-on ...

OR · Hybrid

JOB SUMMARY The Cybersecurity GRC Analyst II plays a key role in supporting the organization's governance, risk, compliance, and audit programs while contributing to day-to-day cybersecurity ...

OR · Hybrid

JOB SUMMARY The Cybersecurity GRC Analyst II plays a key role in supporting the organization's governance, risk, compliance, and audit programs while contributing to day-to-day cybersecurity ...

The Cybersecurity GRC Analyst works closely with IT, Internal Audit, Compliance, Procurement, and business stakeholders to help ensure cybersecurity requirements are defined, documented, assessed ...

next page

Showing results 1-20

Cybersecurity Grc information

See salary details

$38.5K

$58.2K

$87K

How much do cybersecurity grc jobs pay per year?

As of Jul 27, 2026, the average yearly pay for cybersecurity grc in the United States is $58,171.00, according to ZipRecruiter salary data. Most workers in this role earn between $48,000.00 and $64,500.00 per year, depending on experience, location, and employer.

What are some common challenges faced by professionals in Cybersecurity GRC roles, and how can they be addressed?

Professionals in Cybersecurity GRC (Governance, Risk, and Compliance) often encounter challenges such as keeping up with evolving regulatory requirements, balancing business objectives with security mandates, and fostering collaboration between IT, legal, and business teams. These challenges can be addressed by staying current with industry standards, utilizing automated tools for compliance tracking, and building strong communication channels across departments. Proactively engaging stakeholders and fostering a culture of security awareness also play a crucial role in overcoming these obstacles and ensuring effective risk management.

What is Cybersecurity GRC?

Cybersecurity GRC stands for Governance, Risk, and Compliance in the context of cybersecurity. It involves establishing frameworks and processes to ensure an organization's information security aligns with business objectives, regulatory requirements, and risk management strategies. Professionals in this field help identify and manage security risks, create policies and controls, and ensure compliance with laws and standards such as GDPR, HIPAA, or ISO 27001. The goal of Cybersecurity GRC is to protect the organization’s digital assets while enabling responsible growth and innovation.

What are the key skills and qualifications needed to thrive as a Cybersecurity GRC (Governance, Risk, and Compliance) professional, and why are they important?

To thrive as a Cybersecurity GRC professional, you need a solid understanding of cybersecurity frameworks, risk management principles, and regulatory compliance, often supported by a degree in information security or a related field. Familiarity with tools like GRC platforms (e.g., RSA Archer, ServiceNow), as well as certifications such as CISSP, CISM, or CRISC, is typically required. Strong analytical skills, attention to detail, and effective communication are crucial soft skills for collaborating with stakeholders and translating technical risks into business implications. These competencies ensure organizations can proactively manage cyber risks, meet regulatory requirements, and maintain trust with clients and partners.

Is GRC in high demand?

Cybersecurity GRC (Governance, Risk, and Compliance) professionals are in high demand due to increasing cybersecurity regulations and the need for organizations to manage risks effectively. Employers seek candidates with knowledge of compliance frameworks, risk management, and security policies, often requiring certifications like CISA or CISSP. The role offers strong job growth prospects across various industries as cybersecurity threats continue to evolve.

What is the difference between Cybersecurity Grc vs Cybersecurity Analyst?

AspectCybersecurity GrcCybersecurity Analyst
CertificationsISO 27001, CISSP, CISACompTIA Security+, CEH, CISSP
Work EnvironmentPolicy development, risk management, complianceThreat detection, incident response, vulnerability assessment
Employer & Industry UsageOrganizations focusing on governance and complianceSecurity operations centers, IT departments

Cybersecurity Grc professionals focus on establishing policies, managing risks, and ensuring compliance with regulations. In contrast, Cybersecurity Analysts primarily monitor security systems, analyze threats, and respond to incidents. While both roles require similar certifications and work within the cybersecurity field, Grc roles are more strategic and policy-oriented, whereas Analysts are more technical and operational.

Can you make $200,000 in cyber security?

Cybersecurity GRC (Governance, Risk, and Compliance) professionals can potentially earn $200,000 or more annually, especially with extensive experience, advanced certifications like CISSP or CISA, and leadership roles such as security managers or directors. Salary levels vary based on industry, location, and company size, with senior positions often reaching or exceeding this threshold.

What is the role of GRC in cybersecurity?

In cybersecurity, GRC (Governance, Risk Management, and Compliance) professionals develop and implement policies to ensure organizations meet security standards, manage risks, and comply with regulations. They use frameworks like ISO 27001 and tools such as risk assessments and audits to protect information assets and support security strategies.

How much do cyber GRC specialists make?

Cybersecurity GRC (Governance, Risk, and Compliance) specialists typically earn between $70,000 and $130,000 annually, depending on experience, certifications, and location. Senior roles or those with advanced certifications like CISSP or CISA can earn higher salaries, especially in larger organizations or high-demand markets.
More about Cybersecurity Grc jobs
What cities are hiring for Cybersecurity Grc jobs? Cities with the most Cybersecurity Grc job openings:
What are the most commonly searched types of Cybersecurity Grc jobs? The most popular types of Cybersecurity Grc jobs are:
What states have the most Cybersecurity Grc jobs? States with the most job openings for Cybersecurity Grc jobs include:
What job categories do people searching Cybersecurity Grc jobs look for? The top searched job categories for Cybersecurity Grc jobs are:
Infographic showing various Cybersecurity Grc job openings in the United States as of July 2026, with employment types broken down into 62% Full Time, and 38% Contract. Highlights an 75% In-person, and 25% Remote job distribution, with an average salary of $58,171 per year, or $28 per hour.

Senior Cybersecurity GRC

BIGDATAAPPTECH LLC

Manhattan, NY • On-site

$110K - $142K/yr

Other

Posted 12 days ago


Job description

Job Title: Senior Cybersecurity GRC & Third Party Risk Consultant
Location: New York, NY (Onsite/Hybrid)
Duration: Long-Term Contract(W2)

Job Description
We are seeking an experienced Senior Cybersecurity GRC & Third Party Risk Consultant to support the implementation and enhancement of Third Party and Fourth Party Risk Management programs. The ideal candidate will have strong expertise in vendor risk management, information security governance, regulatory compliance, and Archer GRC solutions within the banking or financial services industry.

Key Responsibilities
Gather and define business requirements for Third Party and Fourth Party Risk Management initiatives.
Lead the implementation and alignment of SIG 2027 questionnaires, risk domains, and assessment frameworks.
Design and maintain risk taxonomy, risk assessment methodologies, and risk scoring models.
Configure and support RSA Archer TPRM workflows and related GRC processes.
Collaborate with business and technical teams to implement vendor risk workflows, questionnaires, and data models.
Support vendor onboarding, security due diligence, risk assessments, continuous monitoring, and remediation activities.
Ensure compliance with regulatory, governance, audit, and information security requirements.
Participate in User Acceptance Testing (UAT), data validation, issue resolution, and governance approvals.
Develop executive dashboards, KPIs, and risk analytics for vendor risk reporting.
Recommend improvements to Third Party Risk Management processes and governance practices.
Required Skills
10+ years of experience in Third Party Risk Management (TPRM), Vendor Risk Management (VRM), Information Security Risk, or Governance, Risk & Compliance (GRC).
Strong expertise in Third Party and Fourth Party Risk Management frameworks and operating models.
Deep understanding of SIG (Standardized Information Gathering) questionnaires, including SIG 2027.
Experience defining risk taxonomy, risk assessment methodologies, and risk scoring models.
Hands-on experience with RSA Archer TPRM or similar GRC platforms.
Strong knowledge of the vendor lifecycle, including onboarding, due diligence, continuous monitoring, and offboarding.
Experience working with cybersecurity governance, regulatory compliance, and audit frameworks.
Excellent communication, stakeholder management, and documentation skills.