1

Cybersecurity Grc Jobs (NOW HIRING)

$70.28 - $93.71/hr

Mehrjährige Berufserfahrung im Bereich Cyber Security, GRC, IT-Risikomanagement oder Security Assurance * Gutes Verständnis für Cyber-Risiken aus Business-, Governance- und Wirkungssicht ...

$140 - $200/hr

The ideal candidate is a seasoned cybersecurity GRC professional with deep automotive regulatory expertise, a collaborative leadership style, and a proven track record managing high-performing teams ...

Showing results 21-40

Cybersecurity Grc information

See salary details

$38.5K

$58.2K

$87K

How much do cybersecurity grc jobs pay per year?

As of Sep 5, 2026, the average yearly pay for cybersecurity grc in the United States is $58,171.00, according to ZipRecruiter salary data. Most workers in this role earn between $48,000.00 and $64,500.00 per year, depending on experience, location, and employer.

What is Cybersecurity GRC?

Cybersecurity GRC stands for Governance, Risk, and Compliance in the context of cybersecurity. It involves establishing frameworks and processes to ensure an organization's information security aligns with business objectives, regulatory requirements, and risk management strategies. Professionals in this field help identify and manage security risks, create policies and controls, and ensure compliance with laws and standards such as GDPR, HIPAA, or ISO 27001. The goal of Cybersecurity GRC is to protect the organization’s digital assets while enabling responsible growth and innovation.

What are the key skills and qualifications needed to thrive as a Cybersecurity GRC professional?

To thrive as a Cybersecurity GRC professional, you need a solid understanding of cybersecurity frameworks, risk management principles, and regulatory compliance, often supported by a degree in information security or a related field. Familiarity with tools like GRC platforms (e.g., RSA Archer, ServiceNow), as well as certifications such as CISSP, CISM, or CRISC, is typically required. Strong analytical skills, attention to detail, and effective communication are crucial soft skills for collaborating with stakeholders and translating technical risks into business implications. These competencies ensure organizations can proactively manage cyber risks, meet regulatory requirements, and maintain trust with clients and partners.

What are some common challenges faced by professionals in Cybersecurity GRC roles, and how can they be addressed?

Professionals in Cybersecurity GRC (Governance, Risk, and Compliance) often encounter challenges such as keeping up with evolving regulatory requirements, balancing business objectives with security mandates, and fostering collaboration between IT, legal, and business teams. These challenges can be addressed by staying current with industry standards, utilizing automated tools for compliance tracking, and building strong communication channels across departments. Proactively engaging stakeholders and fostering a culture of security awareness also play a crucial role in overcoming these obstacles and ensuring effective risk management.

What is the difference between Cybersecurity Grc vs Cybersecurity Analyst?

AspectCybersecurity GrcCybersecurity Analyst
CertificationsISO 27001, CISSP, CISACompTIA Security+, CEH, CISSP
Work EnvironmentPolicy development, risk management, complianceThreat detection, incident response, vulnerability assessment
Employer & Industry UsageOrganizations focusing on governance and complianceSecurity operations centers, IT departments

Cybersecurity Grc professionals focus on establishing policies, managing risks, and ensuring compliance with regulations. In contrast, Cybersecurity Analysts primarily monitor security systems, analyze threats, and respond to incidents. While both roles require similar certifications and work within the cybersecurity field, Grc roles are more strategic and policy-oriented, whereas Analysts are more technical and operational.

Is cybersecurity GRC in demand?

Cybersecurity GRC (Governance, Risk, and Compliance) professionals are in high demand due to increasing cybersecurity threats and regulatory requirements. Organizations seek experts with skills in risk management, compliance frameworks, and security policies, often requiring certifications like CISSP or CISA. The role offers strong job growth prospects across various industries, including finance, healthcare, and technology.

Is cybersecurity GRC in high demand?

Cybersecurity GRC (Governance, Risk, and Compliance) professionals are in high demand due to increasing cybersecurity threats and regulatory requirements. Organizations seek experts with skills in risk management, compliance frameworks, and security policies, often requiring certifications like CISSP or CISA. The role offers strong job growth prospects across various industries.
More about Cybersecurity Grc jobs

What cities are hiring for Cybersecurity Grc jobs?

Cities with the most Cybersecurity Grc job openings:

What are the most commonly searched types of Cybersecurity Grc jobs?

The most popular types of Cybersecurity Grc jobs are:

What states have the most Cybersecurity Grc jobs?

States with the most job openings for Cybersecurity Grc jobs include:

What job categories do people searching Cybersecurity Grc jobs look for?

The top searched job categories for Cybersecurity Grc jobs are:

Infographic showing various Cybersecurity Grc job openings in the United States as of August 2026, with employment types broken down into 94% Full Time, 3% Part Time, and 3% Contract. Highlights an 81% Physical, 6% Hybrid, and 13% Remote job distribution, with an average salary of $58,171 per year, or $28 per hour.

Senior Cyber Security & GRC Engineer

Emergent Software

Hartford, CT • On-site

$140 - $180/hr

Other

Re-posted 7 days ago


Job description

**This position is a direct hire for one of our clients. Our ideal candidates live in the Hartford, Connecticut metro area. East coast & TX candidates will be considered with expectations of occasional travel to Connecticut. Eligible candidates must currently reside in the US and authorized to work in the US without visa sponsorship.**

Our client is seeking an experienced Cyber Security & GRC Engineer to lead and mature an enterprise-wide cybersecurity, governance, risk, and compliance (GRC) program across multiple organizations. This is a senior-level, hands‑on leadership role responsible for developing a unified security and compliance framework that supports NIST CSF 2.0, GDPR, and SOX IT General Controls requirements.

The ideal candidate combines strategic leadership with technical expertise, comfortably engaging executive stakeholders and auditors while also administering security tools, managing risks, implementing controls, and driving compliance initiatives. This role will serve as the owner of the enterprise GRC platform, Vanta, ensuring continuous monitoring, audit readiness, and program maturity across all entities.

Responsibilities
  • Own and mature the enterprise cybersecurity and risk management program across a multi-entity organization.
  • Design, implement, and maintain a harmonized control framework supporting NIST CSF 2.0, GDPR, and SOX ITGC requirements.
  • Lead enterprise governance activities, including risk reviews, KPI/KRI reporting, executive reporting, and steering committee meetings.
  • Serve as the primary liaison for auditors, assessors, clients, and internal stakeholders regarding security and compliance matters.
  • Administer and optimize Vanta as the enterprise GRC system of record.
  • Configure controls, integrations, tests, evidence collection, continuous monitoring, and audit workflows within Vanta.
  • Develop, maintain, and manage enterprise security policies, standards, procedures, exceptions, and policy lifecycle processes.
  • Lead SOX ITGC readiness and compliance efforts.
  • Operationalize GDPR requirements, including records of processing, DPIAs, data subject rights management, vendor oversight, and breach response.
  • Conduct NIST CSF 2.0 assessments, maturity reviews, gap analyses, and remediation planning.
  • Manage enterprise risk assessments, risk registers, third‑party vendor risk programs, and remediation initiatives.
  • Oversee vulnerability management, patch coordination, access reviews, and technical security controls across cloud and on‑premises environments.
  • Lead incident response activities, including preparation, detection, containment, recovery, and post‑incident reviews.
  • Provide security architecture guidance for new systems, integrations, cloud solutions, and data platforms.
  • Build and manage security awareness, phishing simulation, and employee training programs.
  • Partner with business and project teams to ensure security and privacy requirements are incorporated into solution design.
Required Qualifications
  • Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or equivalent experience.
  • 7+ years of information security, cybersecurity, or risk management experience with progression into senior program ownership responsibilities.
  • Hands‑on experience administering a GRC platform, preferably Vanta.
  • Experience implementing, operating, or auditing against NIST CSF, SOX ITGC, and GDPR requirements.
  • Demonstrated success developing and implementing security policies, controls, and governance programs.
  • One or more of the following certifications: CISSP, CISM, CRISC, or CISA.
  • Strong technical knowledge of cloud security, identity and access management, endpoint security, vulnerability management, logging, and security operations.
  • Excellent communication skills with the ability to engage technical teams, business leaders, auditors, and executives.
  • Proven ability to work independently, manage multiple priorities, and drive accountability across stakeholders.
Nice to Have Experience
  • Direct Vanta administration experience.
  • Experience supporting a publicly traded company and SOX Section 404 compliance requirements.
  • Experience leading security programs across multiple organizations or business entities.
  • ISO 27001 Lead Implementer or Lead Auditor certification.
  • SANS/GIAC certifications.
  • Construction, engineering, energy, power generation, or EPC industry experience.
  • Familiarity with AI/ML governance, data security, and secure AI deployment practices.
Our Vetting Process

At Emergent Staffing, we work hard to find the best tech candidates capable of developing high quality results for our clients. If you think you're one of those, please understand that the effort put into this by people like yourself helps us be successful in surrounding you with other top‑notch engineers. Here are the steps of our vetting process for this position:

  • Application (5 minutes)
  • Online Assessment (60 minutes)
  • Initial Phone Interview (30-45 minutes)
  • Virtual Interview with Hiring Manager (30 minutes)
  • Onsite Interview
  • Leadership Team Meeting (if needed)
  • Job Offer!

#EmergentStaffing

#IND99


#J-18808-Ljbffr