Role: Cybersecurity GRC Consultant - NIST CSF 2.0 Location: San Francisco, CA (Onsite) Role Purpose Lead the delivery of a NIST CSF 2.0 cybersecurity gap and maturity assessment for a global ...
Role: Cybersecurity GRC Consultant - NIST CSF 2.0 Location: San Francisco, CA (Onsite) Role Purpose Lead the delivery of a NIST CSF 2.0 cybersecurity gap and maturity assessment for a global ...
Senior Cybersecurity GRC Analyst
Huntington Beach, CA · On-site
$104K - $135K/yr
... cybersecurity governance, risk, compliance (GRC), IT audit, risk management, control assurance, or related disciplines. * Experience assessing control design, operating effectiveness, and evidence ...
Senior Cybersecurity GRC Analyst
Huntington Beach, CA · On-site
$104K - $135K/yr
... cybersecurity governance, risk, compliance (GRC), IT audit, risk management, control assurance, or related disciplines. * Experience assessing control design, operating effectiveness, and evidence ...
Cybersecurity GRC Analyst I, II, or III (Depending on experience) Salary: Starting at $90,000/year+ D.O.E *Actual compensation may vary from posting based on geographic location, work experience ...
Cybersecurity GRC Analyst I, II, or III (Depending on experience) Salary: Starting at $90,000/year+ D.O.E *Actual compensation may vary from posting based on geographic location, work experience ...
Senior GRC Engineer
San Francisco, CA · On-site
$180K - $200K/yr
About You * 6+ years of cybersecurity GRC experience in high-growth technology environments. * Experience implementing and maturing GRC programs with pragmatic, engineered solutions. * Knowledge of ...
Senior GRC Engineer
San Francisco, CA · On-site
$180K - $200K/yr
About You * 6+ years of cybersecurity GRC experience in high-growth technology environments. * Experience implementing and maturing GRC programs with pragmatic, engineered solutions. * Knowledge of ...
Cybersecurity GRC Analyst I, II, or III
Santa Ana, CA · On-site
$90K/yr
Cybersecurity GRC Analyst I, II, or III (Depending on experience) Salary: Starting at $90,000/year+ D.O.E *Actual compensation may vary from posting based on geographic location, work experience ...
Cybersecurity GRC Analyst I, II, or III
Santa Ana, CA · On-site
$90K/yr
Cybersecurity GRC Analyst I, II, or III (Depending on experience) Salary: Starting at $90,000/year+ D.O.E *Actual compensation may vary from posting based on geographic location, work experience ...
Cybersecurity GRC Analyst I, II, or III (Depending on experience) Salary: Starting at $90,000/year+ D.O.E *Actual compensation may vary from posting based on geographic location, work experience ...
Cybersecurity GRC Analyst I, II, or III (Depending on experience) Salary: Starting at $90,000/year+ D.O.E *Actual compensation may vary from posting based on geographic location, work experience ...
Senior GRC Technical Engineer
San Ramon, CA · On-site
$119K - $161K/yr
Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Risk Management, Business, or a related field. * 5+ years of experience in cybersecurity, GRC, security engineering ...
Senior GRC Technical Engineer
San Ramon, CA · On-site
$119K - $161K/yr
Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Risk Management, Business, or a related field. * 5+ years of experience in cybersecurity, GRC, security engineering ...
Senior GRC Technical Engineer
San Ramon, CA · On-site
$119K - $161K/yr
Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Risk Management, Business, or a related field. * 5+ years of experience in cybersecurity, GRC, security engineering ...
Senior GRC Technical Engineer
San Ramon, CA · On-site
$119K - $161K/yr
Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Risk Management, Business, or a related field. * 5+ years of experience in cybersecurity, GRC, security engineering ...
Own and mature the CHAOS Industries cybersecurity GRC program by establishing governance structure, policies, standards, expectations, and accountability across CHAOS businesses. * You'll report to ...
Own and mature the CHAOS Industries cybersecurity GRC program by establishing governance structure, policies, standards, expectations, and accountability across CHAOS businesses. * You'll report to ...
Own and mature the CHAOS Industries cybersecurity GRC program by establishing governance structure, policies, standards, expectations, and accountability across CHAOS businesses. * You'll report to ...
Own and mature the CHAOS Industries cybersecurity GRC program by establishing governance structure, policies, standards, expectations, and accountability across CHAOS businesses. * You'll report to ...
Exposure to cybersecurity, GRC, compliance, or regulated industries (NIST 800-171, CMMC, DFARS, ITAR, or FedRAMP). * Familiarity with Microsoft 365, Intune, Microsoft Defender, and IT ticketing ...
Exposure to cybersecurity, GRC, compliance, or regulated industries (NIST 800-171, CMMC, DFARS, ITAR, or FedRAMP). * Familiarity with Microsoft 365, Intune, Microsoft Defender, and IT ticketing ...
Principal, Cybersecurity & AI GRC
Rosemead, CA · Hybrid
$157K - $220K/yr
Summary of The Principal, Cybersecurity & AI GRC is a strategic advisor responsible for defining and sustaining enterprise-wide frameworks across AI risk, privacy, regulatory compliance, and ...
Principal, Cybersecurity & AI GRC
Rosemead, CA · Hybrid
$157K - $220K/yr
Summary of The Principal, Cybersecurity & AI GRC is a strategic advisor responsible for defining and sustaining enterprise-wide frameworks across AI risk, privacy, regulatory compliance, and ...
BDR Hunter US
Palo Alto, CA · On-site +1
$70K - $80K/yr
Prior experience prospecting for AI-native, cybersecurity, or SaaS compliance platforms. * Basic understanding of GRC frameworks (SOC 2, ISO 27001, etc.) or security workflows. * Experience running ...
BDR Hunter US
Palo Alto, CA · On-site +1
$70K - $80K/yr
Prior experience prospecting for AI-native, cybersecurity, or SaaS compliance platforms. * Basic understanding of GRC frameworks (SOC 2, ISO 27001, etc.) or security workflows. * Experience running ...
The role requires managing GRC projects with a focus on cybersecurity and compliance assessments, along with strong communication skills to liaise with various stakeholders. Responsibilities : • 8+ ...
The role requires managing GRC projects with a focus on cybersecurity and compliance assessments, along with strong communication skills to liaise with various stakeholders. Responsibilities : • 8+ ...
RHEL 8 Linux Systems Administrator
El Segundo, CA · On-site
$120K - $160K/yr
Coordinate with cybersecurity, network, and GRC teams to ensure ongoing compliance with internal and external controls. * Automate routine tasks using shell scripting, Ansible, or similar tooling ...
RHEL 8 Linux Systems Administrator
El Segundo, CA · On-site
$120K - $160K/yr
Coordinate with cybersecurity, network, and GRC teams to ensure ongoing compliance with internal and external controls. * Automate routine tasks using shell scripting, Ansible, or similar tooling ...
Cyber Security Engineer
Livermore, CA · On-site
$9.8K/wk
We have an opening for a hands-on Cyber Security Engineer to provide support for GRC (Governance Risk and Compliance) efforts and implementation of security measures aimed at safeguarding our ...
Cyber Security Engineer
Livermore, CA · On-site
$9.8K/wk
We have an opening for a hands-on Cyber Security Engineer to provide support for GRC (Governance Risk and Compliance) efforts and implementation of security measures aimed at safeguarding our ...
Cyber Security Engineer
Livermore, CA · On-site
$121K - $185K/yr
We have an opening for a hands-on Cyber Security Engineer to provide support for GRC (Governance Risk and Compliance) efforts and implementation of security measures aimed at safeguarding our ...
Cyber Security Engineer
Livermore, CA · On-site
$121K - $185K/yr
We have an opening for a hands-on Cyber Security Engineer to provide support for GRC (Governance Risk and Compliance) efforts and implementation of security measures aimed at safeguarding our ...
Cyber Security Engineer
Livermore, CA · On-site
$121K - $185K/yr
We have an opening for a hands-on Cyber Security Engineer to provide support for GRC (Governance Risk and Compliance) efforts and implementation of security measures aimed at safeguarding our ...
Cyber Security Engineer
Livermore, CA · On-site
$121K - $185K/yr
We have an opening for a hands-on Cyber Security Engineer to provide support for GRC (Governance Risk and Compliance) efforts and implementation of security measures aimed at safeguarding our ...
Cybersecurity Program Manager - GRC
$85 - $95/hr
Cybersecurity Program Manager - GRC (San Jose, CA) Job Overview: We are seeking an experienced Cybersecurity Program Manager to lead the development and execution of enterprise-wide cybersecurity ...
Cybersecurity Program Manager - GRC
$85 - $95/hr
Cybersecurity Program Manager - GRC (San Jose, CA) Job Overview: We are seeking an experienced Cybersecurity Program Manager to lead the development and execution of enterprise-wide cybersecurity ...
Principal, Cybersecurity & AI GRC (P1-6105774-1)
Rosemead, CA · On-site
$157K - $220K/yr
Summary of The Principal, Cybersecurity & AI GRC is a strategic advisor responsible for defining and sustaining enterprise-wide frameworks across AI risk, privacy, regulatory compliance, and ...
Principal, Cybersecurity & AI GRC (P1-6105774-1)
Rosemead, CA · On-site
$157K - $220K/yr
Summary of The Principal, Cybersecurity & AI GRC is a strategic advisor responsible for defining and sustaining enterprise-wide frameworks across AI risk, privacy, regulatory compliance, and ...
Cybersecurity Grc information
See California salary details
$38K - $42.3K
8% of jobs
$42.3K - $46.7K
12% of jobs
$47.4K is the 25th percentile. Wages below this are outliers.
$46.7K - $51.1K
29% of jobs
The median wage is $51.3K / yr.
$51.1K - $55.4K
8% of jobs
$55.4K - $59.8K
17% of jobs
$59.9K is the 75th percentile. Wages above this are outliers.
$59.8K - $64.1K
6% of jobs
$64.1K - $68.5K
6% of jobs
$68.5K - $72.8K
5% of jobs
$72.8K - $77.2K
3% of jobs
$77.2K - $81.5K
2% of jobs
$81.5K - $85.9K
2% of jobs
$38K
$57.4K
$85.9K
How much do cybersecurity grc jobs pay per year?
What is Cybersecurity GRC?
What are the key skills and qualifications needed to thrive as a Cybersecurity GRC professional?
What are some common challenges faced by professionals in Cybersecurity GRC roles, and how can they be addressed?
What is the difference between Cybersecurity Grc vs Cybersecurity Analyst?
| Aspect | Cybersecurity Grc | Cybersecurity Analyst |
|---|---|---|
| Certifications | ISO 27001, CISSP, CISA | CompTIA Security+, CEH, CISSP |
| Work Environment | Policy development, risk management, compliance | Threat detection, incident response, vulnerability assessment |
| Employer & Industry Usage | Organizations focusing on governance and compliance | Security operations centers, IT departments |
Cybersecurity Grc professionals focus on establishing policies, managing risks, and ensuring compliance with regulations. In contrast, Cybersecurity Analysts primarily monitor security systems, analyze threats, and respond to incidents. While both roles require similar certifications and work within the cybersecurity field, Grc roles are more strategic and policy-oriented, whereas Analysts are more technical and operational.
Is cybersecurity GRC in demand?
Is cybersecurity GRC in high demand?
What are the most commonly searched types of Cybersecurity Grc jobs in California?
The most popular types of Cybersecurity Grc jobs in California are:
What are popular job titles related to Cybersecurity Grc jobs in California?
For Cybersecurity Grc jobs in California, the most frequently searched job titles are:
What job categories do people searching Cybersecurity Grc jobs in California look for?
The top searched job categories for Cybersecurity Grc jobs in California are:
What cities in California are hiring for Cybersecurity Grc jobs?
Cities in California with the most Cybersecurity Grc job openings:

Other
Posted 21 days ago
Job description
Role: Cybersecurity GRC Consultant – NIST CSF 2.0
Location: San Francisco, CA (Onsite)
Role Purpose
Lead the delivery of a NIST CSF 2.0 cybersecurity gap and maturity assessment for a global enterprise program, covering assessment planning, stakeholder engagement, evidence review, maturity scoring, risk-based gap prioritization, executive reporting, and development of a practical improvement roadmap.
Key Responsibilities
- Own end to end engagement governance, project planning, milestones, risks, dependencies, status reporting, and stakeholder communications.
- Conduct NIST CSF 2.0 maturity assessment across functions, categories, subcategories, implementation tiers, and profiles.
- Review policies, standards, procedures, controls, risk registers, asset inventories, KPIs/KRIs, and supporting evidence.
- Facilitate interviews and workshops with cybersecurity, risk, compliance, technology, and business stakeholders.
- Define defensible maturity scoring, identify control gaps, assess business risk, and prioritize remediation actions.
- Develop executive ready assessment reports, maturity dashboards, prioritized recommendations, and near/mid/long term roadmap.
Required Experience
Area
Requirement
Total Experience
10 to 15 years in cybersecurity, GRC, risk management, audit, security consulting, or cybersecurity program assessment.
NIST CSF Expertise
Strong hands on experience with NIST CSF, preferably NIST CSF 2.0 maturity assessments.
Framework Mapping
Experience mapping controls across NIST CSF, ISO 27001, NIST 800 53, CIS Controls, SOC 2, or similar frameworks.
Assessment Delivery
Proven experience conducting enterprise wide cybersecurity maturity, gap, risk, or control assessments.
Stakeholder Management
Ability to conduct interviews/workshops with senior security, risk, compliance, technology, and business stakeholders.
Executive Reporting
Strong experience creating leadership ready cybersecurity reports, maturity dashboards, and roadmap presentations.
Consulting Delivery
Experience working in consulting/advisory environments with structured methodology, governance, and client facing deliverables.
Risk Prioritization
Ability to convert control gaps into risk ranked remediation recommendations and practical roadmaps.
Required Skills
- Strong expertise in NIST CSF 2.0, cybersecurity governance, risk management, compliance, control maturity models, and ISO 27001 / ISMS.
- Ability to map controls across NIST CSF, ISO 27001, NIST 800 53, CIS Controls, SOC 2, and similar frameworks.
- Experience in evidence-based assessment, maturity scoring, risk-based gap prioritization, and remediation roadmap development.
- Excellent consulting delivery, workshop facilitation, stakeholder management, executive reporting, and written/verbal communication skills.
Preferred Certifications
CISSP, CISM, CISA, CRISC, ISO 27001 Lead Auditor / Lead Implementer, NIST CSF training/certification, PMP / Prince2 / Agile certification preferred.
Tools / Platforms Knowledge Preferred
- GRC and evidence management platforms such as Archer, ServiceNow GRC, OneTrust, MetricStream, SharePoint, Teams, Excel, PowerPoint, Visio, Power BI, and cybersecurity KPI/KRI dashboarding tools.
About Mergen IT
Sourced by ZipRecruiter
Industry
It services
Company size
51 - 200 Employees
Headquarters location
Houston, TX, US
Year founded
2014