1

Cybersecurity Grc Jobs in California (NOW HIRING)

Senior GRC Engineer

San Francisco, CA · On-site

$180K - $200K/yr

About You * 6+ years of cybersecurity GRC experience in high-growth technology environments. * Experience implementing and maturing GRC programs with pragmatic, engineered solutions. * Knowledge of ...

Exposure to cybersecurity, GRC, compliance, or regulated industries (NIST 800-171, CMMC, DFARS, ITAR, or FedRAMP). * Familiarity with Microsoft 365, Intune, Microsoft Defender, and IT ticketing ...

BDR Hunter US

Palo Alto, CA · On-site +1

$70K - $80K/yr

Prior experience prospecting for AI-native, cybersecurity, or SaaS compliance platforms. * Basic understanding of GRC frameworks (SOC 2, ISO 27001, etc.) or security workflows. * Experience running ...

Coordinate with cybersecurity, network, and GRC teams to ensure ongoing compliance with internal and external controls. * Automate routine tasks using shell scripting, Ansible, or similar tooling ...

We have an opening for a hands-on Cyber Security Engineer to provide support for GRC (Governance Risk and Compliance) efforts and implementation of security measures aimed at safeguarding our ...

Cyber Security Engineer

Livermore, CA · On-site

$121K - $185K/yr

We have an opening for a hands-on Cyber Security Engineer to provide support for GRC (Governance Risk and Compliance) efforts and implementation of security measures aimed at safeguarding our ...

Cyber Security Engineer

Livermore, CA · On-site

$121K - $185K/yr

We have an opening for a hands-on Cyber Security Engineer to provide support for GRC (Governance Risk and Compliance) efforts and implementation of security measures aimed at safeguarding our ...

next page

Showing results 1-20

Cybersecurity Grc information

See California salary details

$38K

$57.4K

$85.9K

How much do cybersecurity grc jobs pay per year?

As of Sep 1, 2026, the average yearly pay for cybersecurity grc in California is $57,409.00, according to ZipRecruiter salary data. Most workers in this role earn between $47,400.00 and $63,700.00 per year, depending on experience, location, and employer.

What is Cybersecurity GRC?

Cybersecurity GRC stands for Governance, Risk, and Compliance in the context of cybersecurity. It involves establishing frameworks and processes to ensure an organization's information security aligns with business objectives, regulatory requirements, and risk management strategies. Professionals in this field help identify and manage security risks, create policies and controls, and ensure compliance with laws and standards such as GDPR, HIPAA, or ISO 27001. The goal of Cybersecurity GRC is to protect the organization’s digital assets while enabling responsible growth and innovation.

What are the key skills and qualifications needed to thrive as a Cybersecurity GRC professional?

To thrive as a Cybersecurity GRC professional, you need a solid understanding of cybersecurity frameworks, risk management principles, and regulatory compliance, often supported by a degree in information security or a related field. Familiarity with tools like GRC platforms (e.g., RSA Archer, ServiceNow), as well as certifications such as CISSP, CISM, or CRISC, is typically required. Strong analytical skills, attention to detail, and effective communication are crucial soft skills for collaborating with stakeholders and translating technical risks into business implications. These competencies ensure organizations can proactively manage cyber risks, meet regulatory requirements, and maintain trust with clients and partners.

What are some common challenges faced by professionals in Cybersecurity GRC roles, and how can they be addressed?

Professionals in Cybersecurity GRC (Governance, Risk, and Compliance) often encounter challenges such as keeping up with evolving regulatory requirements, balancing business objectives with security mandates, and fostering collaboration between IT, legal, and business teams. These challenges can be addressed by staying current with industry standards, utilizing automated tools for compliance tracking, and building strong communication channels across departments. Proactively engaging stakeholders and fostering a culture of security awareness also play a crucial role in overcoming these obstacles and ensuring effective risk management.

What is the difference between Cybersecurity Grc vs Cybersecurity Analyst?

AspectCybersecurity GrcCybersecurity Analyst
CertificationsISO 27001, CISSP, CISACompTIA Security+, CEH, CISSP
Work EnvironmentPolicy development, risk management, complianceThreat detection, incident response, vulnerability assessment
Employer & Industry UsageOrganizations focusing on governance and complianceSecurity operations centers, IT departments

Cybersecurity Grc professionals focus on establishing policies, managing risks, and ensuring compliance with regulations. In contrast, Cybersecurity Analysts primarily monitor security systems, analyze threats, and respond to incidents. While both roles require similar certifications and work within the cybersecurity field, Grc roles are more strategic and policy-oriented, whereas Analysts are more technical and operational.

Is cybersecurity GRC in demand?

Cybersecurity GRC (Governance, Risk, and Compliance) professionals are in high demand due to increasing cybersecurity threats and regulatory requirements. Organizations seek experts with skills in risk management, compliance frameworks, and security policies, often requiring certifications like CISSP or CISA. The role offers strong job growth prospects across various industries, including finance, healthcare, and technology.

Is cybersecurity GRC in high demand?

Cybersecurity GRC (Governance, Risk, and Compliance) professionals are in high demand due to increasing cybersecurity threats and regulatory requirements. Organizations seek experts with skills in risk management, compliance frameworks, and security policies, often requiring certifications like CISSP or CISA. The role offers strong job growth prospects across various industries.

What are the most commonly searched types of Cybersecurity Grc jobs in California?

The most popular types of Cybersecurity Grc jobs in California are:

What are popular job titles related to Cybersecurity Grc jobs in California?

For Cybersecurity Grc jobs in California, the most frequently searched job titles are:

What job categories do people searching Cybersecurity Grc jobs in California look for?

The top searched job categories for Cybersecurity Grc jobs in California are:

What cities in California are hiring for Cybersecurity Grc jobs?

Cities in California with the most Cybersecurity Grc job openings:

Infographic showing various Cybersecurity Grc job openings in California as of August 2026, with employment types broken down into 92% Full Time, 6% Part Time, and 2% Contract. Highlights an 82% Physical, 6% Hybrid, and 12% Remote job distribution, with an average salary of $57,409 per year, or $27.6 per hour.

Cybersecurity GRC Consultant - NIST CSF 2.0

Mergen IT LLC

San Francisco, CA • On-site

Other

Posted 21 days ago


Job description

Role: Cybersecurity GRC Consultant – NIST CSF 2.0

Location: San Francisco, CA (Onsite)

Role Purpose

Lead the delivery of a NIST CSF 2.0 cybersecurity gap and maturity assessment for a global enterprise program, covering assessment planning, stakeholder engagement, evidence review, maturity scoring, risk-based gap prioritization, executive reporting, and development of a practical improvement roadmap.

Key Responsibilities

  • Own end to end engagement governance, project planning, milestones, risks, dependencies, status reporting, and stakeholder communications.
  • Conduct NIST CSF 2.0 maturity assessment across functions, categories, subcategories, implementation tiers, and profiles.
  • Review policies, standards, procedures, controls, risk registers, asset inventories, KPIs/KRIs, and supporting evidence.
  • Facilitate interviews and workshops with cybersecurity, risk, compliance, technology, and business stakeholders.
  • Define defensible maturity scoring, identify control gaps, assess business risk, and prioritize remediation actions.
  • Develop executive ready assessment reports, maturity dashboards, prioritized recommendations, and near/mid/long term roadmap.

Required Experience

Area

Requirement

Total Experience

10 to 15 years in cybersecurity, GRC, risk management, audit, security consulting, or cybersecurity program assessment.

NIST CSF Expertise

Strong hands on experience with NIST CSF, preferably NIST CSF 2.0 maturity assessments.

Framework Mapping

Experience mapping controls across NIST CSF, ISO 27001, NIST 800 53, CIS Controls, SOC 2, or similar frameworks.

Assessment Delivery

Proven experience conducting enterprise wide cybersecurity maturity, gap, risk, or control assessments.

Stakeholder Management

Ability to conduct interviews/workshops with senior security, risk, compliance, technology, and business stakeholders.

Executive Reporting

Strong experience creating leadership ready cybersecurity reports, maturity dashboards, and roadmap presentations.

Consulting Delivery

Experience working in consulting/advisory environments with structured methodology, governance, and client facing deliverables.

Risk Prioritization

Ability to convert control gaps into risk ranked remediation recommendations and practical roadmaps.

Required Skills

  • Strong expertise in NIST CSF 2.0, cybersecurity governance, risk management, compliance, control maturity models, and ISO 27001 / ISMS.
  • Ability to map controls across NIST CSF, ISO 27001, NIST 800 53, CIS Controls, SOC 2, and similar frameworks.
  • Experience in evidence-based assessment, maturity scoring, risk-based gap prioritization, and remediation roadmap development.
  • Excellent consulting delivery, workshop facilitation, stakeholder management, executive reporting, and written/verbal communication skills.

Preferred Certifications

CISSP, CISM, CISA, CRISC, ISO 27001 Lead Auditor / Lead Implementer, NIST CSF training/certification, PMP / Prince2 / Agile certification preferred.

Tools / Platforms Knowledge Preferred

  • GRC and evidence management platforms such as Archer, ServiceNow GRC, OneTrust, MetricStream, SharePoint, Teams, Excel, PowerPoint, Visio, Power BI, and cybersecurity KPI/KRI dashboarding tools.